All Cookies are Not Created Equal: FTC Cracks Down on Targeted Advertising Without User Consent

With the proliferation of consumer personal data laws and cookie consent banners, the Federal Trade Commission (FTC) is ramping up its crusade against businesses in the name of consumer protection by wielding its very broad authority under Section 5 of the FTC Act (Section 5). Section 5 prohibits “unfair or deceptive acts or practices in or affecting commerce” and has been a driving force of the FTC since its inception in 1914. As you can imagine, Section 5, originally empowering the FTC to prevent unfair methods of competition, has changed significantly with the passage of time and evolving business practices. The advent of collecting consumer data for the purposes of cross-contextual behavioral advertising proved to be another watershed moment that adds an arrow to the FTC growing quiver. The recent FTC cases against GoodRx and BetterHelp  are canaries in the coal mine and that we should all listen to because dealerships across the country engage in similar behavior. We will briefly discuss these cases below. For more information about these and other FTC enforcement actions, please visit their library at https://www.ftc.gov/legal-library/browse/cases-proceedings.

The FTC lawsuit against GoodRx alleges that the company integrated third-party tracking tools from Meta, Google, and other advertisers and shared user health data with them for advertising purposes without the user’s consent (also known as “retargeted advertising” as defined below). Additionally, GoodRx used the personal health information to target users with advertisements itself and failed to limit third-party use of their information. According to the FTC, this violated Section 5.

“Retargeted advertising” allows businesses to display advertisements to users who have previously interacted with their website or have shown interest in their products or services. This is a widely used marketing tool because it increases the touch points with that user and makes the user more likely to convert into a sale.

BetterHelp met the same fate at the hands of the FTC for performing similar acts. Brushing aside the more obvious concerns of making false claims and deceptive marketing (BetterHelp said it was “HIPAA Certified” and had seals implying its purported compliance with HIPAA, but no government agency or third party ever reviewed its practices for compliance), we are going to focus on the retargeted advertising aspect of the complaint. BetterHelp had a banner at the bottom of every page on its website, which stated

“We use cookies to help the site function properly, analyze usage, and measure the effectiveness of our ads. We never sell or rent any information you share with us. Read our Privacy Policy [(linked)] to learn more.”

BetterHelp then went through two significant changes in this banner, but neither one of them informed visitors that it would use and disclose their health information for advertising or that third parties would be able to use the visitors’ information for their own purposes. BetterHelp used and disclosed this information through various means, including “web beacons” (specifically pixels) placed on various pages on its website. Information was shared with third-parties such as Facebook, Snapchat, Criteo, and Pintrest to carry out this advertising.

Like GoodRx and BetterHelp, dealerships often use cookies for retargeted advertising with companies such as Google and Meta (Facebook) through one of the many digital advertising vendors. The lesson here – dealerships should implement comprehensive privacy policy disclosures and a well-designed cookie consent banner to avoid the FTC’s scrutiny.

For dealerships that want to avoid becoming the FTC’s next example, they must begin obtaining proper consent for the use and sharing of cookies that collect and track a prospective finance or lease customer’s online information and browsing history (and for those of you wondering, yes, the federal Gramm-Leach Bliley Act defines non-public personal information to include cookies and similar technologies). To state the obvious, this is an action based on federal law, so dealerships in all states (even those without comprehensive privacy laws) must prioritize protecting user data by updating their privacy policies with comprehensive disclosures, a cookie use policy, and a compliant cookie consent banner.

For example, a well-designed cookie banner is a crucial tool for dealerships to obtain users’ informed consent for the use of online tracking in connection with retargeted advertising. However, poorly designed cookie banners can do more harm than good if they are implemented to confuse or trick consumers into consenting to online tracking (often referred to by regulators as “dark patterns”). Unfortunately, many vendors offer cookie banners that don’t actually work and may inadvertently allow cookies and other tracking technologies to deploy before the user has a chance to consent.

In short, online privacy disclosures and cookie consent management should be a top priority for any risk-averse dealership. Updating privacy policies with comprehensive disclosures and implementing a compliant cookie consent banner can help defeat claims similar to those brought against GoodRx and BetterHelp and protect the dealership from other novel privacy allegations like we have seen with the recent uptick of state and federal wiretapping lawsuits stemming from online tracking activities.

If you do not currently have a solution that provides you either of these things, we will be happy to assist. ComplyAuto will build a privacy policy that is unique to your dealership and a cookie consent banner that fulfills all state and federal requirements in our Privacy Rights Management system. If you would like to learn more, contact us at info@complyauto.com.

This article should be used as a compliance aid only and though its accuracy has been made a priority, it is not a substitute for professional legal advice. Each dealer should rely on their own expertise when using it.

 

5 Comments. Leave new

Leave a Reply

Encrypting NPI in Transit & the Safeguards Rule
Deleting Customer Data Stored in Vehicles: Best Practice or a Legal Requirement?

We want to enroll our employees in preventative training to prevent BAR citations and fines.

We received a citation or disciplinary action and need to take remedial training.

Mock OSHA Assessment

FEATURES:

  • On-demand eight-hour assessment that imitates a real OSHA audit.
  • Conducted by an EHS Pro with OSHA-10 or OSHA-30 certification and 5+ years of experience. 
  • Simulated employee interviews
  • Issue tracking and task management
  • Detailed assessment reports after the assessment with images, videos, and recommended steps for remediation.

    Privacy & Cyber Compliance Suite

    FEATURES:

    • Custom legal policies with real-time updates, including the Information Security Program (ISP)
    • Customized Incident Response Plan (IRP)
    • Internal risk assessment tools and hands-on guidance
    • Biannual penetration testing (2) 
    • Biannual vulnerability scans (2)
    • Employee security awareness training and completion tracking
    • Extensive vendor management library – hundreds of vendor-completed GLBA contracts & risk assessments
    • Device & systems inventory automation and mapping tools
    • Unlimited industry-specific internal phishing simulations to train staff
    • Complete 50-state privacy compliance required by your state (CA, CO, CT, DE, IA, IN, MT, OR, TN, TX, UT, VA)
    • Website cookie consent banners and unique consumer privacy request portals
    • Annual report to the Board of Directors generated every year
    • Compliance Guarantee

      CPR/AED Certification

      FEATURES:

      • Instruction provided by Certified American Red Cross Instructors.
      • Practical, hands-on training sessions to practice CPR and AED techniques
      • Proper automated external defibrillator (AEDs) instruction and operation
      • American Red Cross exam and certification
      • Access to study materials, manuals, and resources for continued education and reference.
      • Available for organizations and groups, allowing for tailored training sessions.

      HR Fundamentals

      FEATURES:

      • Customized policy builder with real-time updates
      • E-sign functionality for required employee policies 
      • Online HR training with employee completion tracking
      • State-specific policies and training
      • Employee management tool
      • Training and policies include Workplace Violence, Active Shooter, IT and Electronic Device Use, Biometric Data Privacy, Sexual Harassment, and more 
      • HR Fundamentals access is included with any other ComplyAuto product

        Encrypted Messaging

        FEATURES:

        • Encrypt SMS text and email messaging among staff, clients, and customers when sending and receiving files
        • Track usage and detect violations in real-time
        • Advanced security features include auto-deletion of files, Multi-Factor Authentication protection, IP safelisting, and domain blocklisting
        • Supports compliance with various state and federal regulations and recognized industry standards: GLBA, HIPAA, SOC 2, ISO 27001, NIST, CIS Controls, SEC

          Safety Compliance Suite

          FEATURES:

          • Concierge on-site onboarding 
          • On-demand safety walkthroughs conducted by experienced EHS Pros at various intervals – once, twice, or four times per year
          • Comprehensive Online Training Library and employee progress tracking
          • Automated 50-State Legal Injury & Illness Reporting
          • Policy Builders with Automatic Updates
          • Simplified SDS Creation and Management
          • Guided risk mitigation
          • Signage builder & tracking
          • Efficient equipment inspections with QR Codes
          • Tier 1 Spill Prevention Control and Countermeasure Plan 
          • Automated Tier 2 environmental reporting for all 50 states 
          • Unlimited one-on-one support from our dedicated team
          • Workplace Violence and Active Shooter Policy and Training
          • Unlimited one-on-one support from our dedicated team
          • Automated Tier II environmental reporting for all 50 states.

            EduTech Course 3

            Program to Fulfill AG Disciplinary Order - $299/student

            The California AG routinely penalizes facilities that violate these laws and requires them to perform specific remedies while on probation. One of these remedies requires the ARD to take a course that outlines the laws and regulations of the Automotive Repair Act. This program fulfills the requirement.

            FEATURES:  

            • Comprehensive online course about the Automotive Repair Act

            • Access to training materials anytime (24/7/365)

            • Comprehensive companion manual to the training material

            • Quizzes and final exam to track engagement and learning ability

            • Certificate generated upon completion

            EduTech Course 2

            Remedial Training and Attorney General Disciplinary Order - $299/student

            The Bureau of Automotive Repair (BAR) has allowed violating automotive repair dealers to take a remedial training program in lieu of having their information posted on a public website. Additionally, automotive repair dealers are required to take a training course as part of the California Attorney General’s disciplinary order. 

            This course fulfills both of these requirements.

            Created by California attorneys with over 35 years of combined experience in the automotive repair industry, this course is the only course on the market that is taught by instructors who are certified by the BAR.

            FEATURES:

            • Comprehensive online course about the Automotive Repair Act
            • Instruction by providers certified by the BAR
            • Access to training materials anytime (24/7/365)
            • Comprehensive manual that is a companion to the course
            • Quizzes and final exam to track student engagement and information retention
            • Certificate generated upon completion
            • Automated notification to the Bureau of Automotive Repair, if applicable

             

            EduTech Course 1

            Automotive Repair Act Certification Training - $49/month per rooftop

            With new regulations giving the Bureau of Automotive Repair (BAR) more authority to find violations and enforce citations upon repair facilities, it is now more important than ever to make sure your staff is knowledgeable about the Automotive Repair Act. Protect your repair facility from BAR scrutiny by enrolling into EduTech’s Automotive Repair Act Certification Training. This is the only training in California that is approved by BAR. 

            “Evidence of voluntary participation in retraining [of]…employees” as a mitigating factor. – Guidelines for Disciplinary Orders and Terms of Probation, BAR

            BAR has allowed retraining to be a “factor in mitigation” when investigating a repair facility. Therefore, as a preventative measure, it is strongly recommended that all technicians and service writers enroll into this course to show the BAR that you acknowledge and understand these rules before any investigation ever occurs. 

            All students enrolled in this product will be eligible for our “EduTech Guarantee” which financially protects repair facilities from enforcement by the Bureau of Automotive Repair. For more information, please visit our Terms of Service.

            FEATURES:

            • Online training course about the Automotive Repair Act
            • Only training course that is approved by BAR
            • Access to training materials anytime (24/7/365)
            • Quizzes and final exam to track student engagement and information retention
            • Certificate generated upon completion

            BENEFITS:

            • Lower risk of BAR scrutiny by standardizing correct practices
            • Increased customer satisfaction
            • Establishes good faith efforts and may avoid BAR citation and fine
            • Professional development for service writers and technicians
            • Eligibility for the EduTech Guarantee

            Students enrolled in this product will also have complimentary access to HR training materials and policy builders. Topics include:

            • Sexual harassment (supervisory and non-supervisory)
            • Active shooter
            • Workplace violence
            • Social media use
            • Biometric data (timekeeper or key lockbox)

            F&I Compliance Suite

              • Precise Deal Jacket Audits to identify and address real-world F&I compliance issues accurately.
              • Focused Compliance on specific F&I compliance concerns such as Fair Lending Compliance Solutions, California Litigation, Vehicle Safety Recalls, Used Vehicle History, FTC Buyers Guide & Federal Warranty Disclosures, 
              • Automated EZ Cash Reporting & Anti-Money Laundering with IRS Reporting 
              • Spot Delivery & Unwind Management
              • Real-Time Issue Identification Quickly detect compliance gaps and issues, enabling swift corrective action and risk mitigation.
              • Online F&I Compliance Training 
              • Compliance Guarantee

                Device & Email Security

                FEATURES:

                The combined features create a dynamic defense system that adapts to evolving cybersecurity threats and secures the organization's digital ecosystem.

                • Continuous threat detection and response powered by Coro:
                  • EDR (Endpoint Detection and Response) 
                  • MDR (Managed Detection and Response) 
                  • 24/7 Security Operations Center team
                  • Swift response and alert to potential security breaches
                • Enhanced authentication and access control via Multi-factor Authentication (MFA) powered by Duo Security™
                • Advanced email security to shield e-threats such as phishing, malware, spam, and scams – integrates with Google Workspace & Microsoft Office 365.
                • Data governance and Data Loss Prevention (DLP)  detect and manage employee data-sharing practices. 
                • Device-level encryption for Windows and macOS
                • Public & unencrypted wifi blocking
                • Next-gen antivirus
                • Automated password policy and session locking enforcement