BBB National Programs Insights

Children's Advertising Review Unit (CARU): Business Privacy Tips

Jul 23, 2019, 15:00 PM by BBB National Programs
Data Privacy Day is an international effort to empower individuals to take ownership of their online presence and inspire businesses to respect privacy. To celebrate, we’re sharing tips companies and small businesses can use to help ensure that a website or online service complies with COPPA.

Data Privacy Day is an international effort to empower individuals to take ownership of their online presence and inspire businesses to respect privacy. To celebrate, we’re sharing tips companies and small businesses can use to help ensure that a website or online service complies with COPPA.

  1. Draft Your Own Privacy Policy. You would be surprised how many companies cut and paste other privacy policies or templates. Unfortunately, privacy is not a one-size-fits-all type of situation. You need to draft a policy for your site or service that accurately reflects your specific privacy practices or you render the document useless. Make sure you include everything that applicable laws require. But be straight and to the point. The FTC frowns upon including unrelated or confusing information, which serves only to misdirect readers’ attention from what is important.
  2. Shout It From the Rooftop. Make sure that all your third-party service providers are aware that your product is child-targeted. Under COPPA, you are strictly liable for any information that they collect from you so make sure that they are treating the collection of user information appropriately.
  3. Respect Your Teachers. If you are providing your website or service to schools, ensure that the school receives the same notice for consent that you would provide to a parent before collecting information from children. For example, under COPPA, you must inform parents of all personal information your service collects or can be publicly disclosed by children.
  4. Less is More. When it comes to information collection, the less you collect, the better. Collect only what personal information you truly require to participate in the service you offer. Every piece of personal information you collect should have a specified business purpose. And you should list that purpose in your privacy policy.
  5. Call Me Maybe. Be sure that you list your full contact information for your company in your privacy policy. Include your business address, phone number and an email address for an inbox that is regularly monitored. When it comes to children’s privacy, your organization needs to be readily available.
  6. Easy Way Out. Provide parents and guardians with an easily accessible method to delete a child’s personal information or opt out of future collection.
  7. No Means No.  Before collecting or allowing children to disclose personal information, you must get verifiable parental consent. Do not collect any personal information from children other than a parent’s email address before you obtain parental consent. 
  8. Captive Audience. Determine who your audience is: you may intend to operate a service directed to teens, but if you attract a substantial number of children, you may be required to comply with COPPA. See Section G of the COPPA FAQs.
  9. Location, Location, Location. If you collect or allow third-parties to collect geolocation data you may need parental consent first. If the address collected is sufficient to identify a street name and city or town, you need parental consent.
  10. Join a Safe Harbor! If you’re concerned that your website or online service does not comply with COPPA, have no fear! You can join a certified Safe Harbor program to help you get into compliance with COPPA. CARU was the first FTC-approved Safe Harbor and we’re here to assist you.

 

If you have any questions about COPPA compliance or joining CARU’s Safe Harbor program, please email CARU at info@caru.bbb.org.

Podcast

Why Teens Need Unique Privacy Protections

Teens are at risk online now more than ever, and the amount of their personal data being collected is vast. Tune in to our latest podcast to hear our experts discuss the key findings from their latest whitepaper on teenage privacy in the mobile app marketplace and the privacy implications of in-app purchases and interest-based advertising (IBA).
Read More
Podcast

Time for Revolution in the Direct Selling Industry

In this podcast episode, Direct Selling Association (DSA) President Joe Mariano discusses how the nature of the fast-changing direct-selling marketplace has informed the industry’s approach to self-regulation, how the Direct Selling Self-Regulatory Council (DSSRC) has helped, and the work that lies ahead.
Read more
Podcast

The Confidence and Perception Behind Online Reviews

For the majority, online reviews and ratings hold considerable merit in influencing purchasing decisions. They have integrated into a form of advertising for today’s companies. People feel more assured about spending their money on brands with five-star reviews than those with little to no feedback. A purpose that was once fulfilled primarily by word-of-mouth and social cues has been...
Read more
Podcast

A Cashless Future

How close are we from entering into a world where cash is no longer accepted? Do we truly understand the benefits and implications of completely going cashless and relying solely on financial transactions that are intimately connected with our data? Dr. Shelle Santana, Associate Professor at the Harvard University Business School, answers these questions and more on this episode of the >Better Series podcast.
Read more