LAW: BEHAVIOURAL TARGETING, INFLUENCER MARKETING AND SOCIAL MEDIA - - PowerPoint PPT Presentation

law behavioural
SMART_READER_LITE
LIVE PREVIEW

LAW: BEHAVIOURAL TARGETING, INFLUENCER MARKETING AND SOCIAL MEDIA - - PowerPoint PPT Presentation

CANADIAN ADVERTISING LAW: BEHAVIOURAL TARGETING, INFLUENCER MARKETING AND SOCIAL MEDIA Daniel Cole, Partner and Chris Oates, Partner, Gowling WLG Presented to Association of Canadian Advertisers, October 29, 2019 Meaningful Consent and


slide-1
SLIDE 1

CANADIAN ADVERTISING LAW: BEHAVIOURAL TARGETING, INFLUENCER MARKETING AND SOCIAL MEDIA

Daniel Cole, Partner and Chris Oates, Partner, Gowling WLG Presented to Association of Canadian Advertisers, October 29, 2019

slide-2
SLIDE 2

Meaningful Consent and Behavioural Advertising

slide-3
SLIDE 3

3

The Personal Information Protection And Electronic Documents Act (“PIPEDA”)

  • Regulates the collection, use and disclosure of “personal information”

in the private sector.

  • The provinces of British Columbia, Alberta, and Quebec have

‘substantially similar’ provincial privacy laws.

  • Separate laws apply in the public sector, and in many provinces, to

health information custodians

REGULATORY FRAMEWORK

slide-4
SLIDE 4

4

Overarching principles of Canadian privacy law:

1.

Disclose the purposes for which you collect personal information;

2.

Obtain informed consent to those purposes;

3.

Limit the collection of personal information to what is necessary for purpose(s) identified;

4.

Use personal information only in accordance with the purposes disclosed;

5.

Provide adequate security for the information you collect, proportionate to its sensitivity; and

6.

Retain personal information only as long as needed for the disclosed purposes.

COLLECTING PERSONAL INFORMATION

slide-5
SLIDE 5

‘Personal Information’ examples

  • Guidance on Behavioural Advertising and Tracking:

Taking a broad, contextual view of the definition of personal information, the OPC will generally consider information collected for the purpose of OBA to be personal information, given: the fact that the purpose behind collecting information is to create profiles of individuals that in turn permit the serving of targeted ads; the powerful means available for gathering and analyzing disparate bits of data and the serious possibility of identifying affected individuals; and the potentially highly personalized nature of the resulting advertising

  • Results of Commissioner Initiated Investigation into a Relevant Ads Program: Account,

demographic and network usage information are Personal Information as they are linked to a specific customer.

  • Apple Targeted Advertising: the Apple UDID and Ad ID constitute Personal Information

as Apple has the capacity to link them with individuals.

PERSONAL INFORMATION

5

5

slide-6
SLIDE 6

The requirement for consent in PIPEDA is tied to what it is reasonable to expect the individual would understand:

  • ...the consent of an individual is only valid if it is reasonable to expect that an

individual to whom the organization’s activities are directed would understand the nature, purpose and consequences of the collection, use or disclosure of the personal information to which they are consenting.

VALID CONSENT

6

slide-7
SLIDE 7

The Office of the Privacy Commissioner has published guidance on meaningful consent.

  • Key Recommendations:

1.

Emphasize key elements- avoid information overload by highlighting elements such as:

  • What information is collected?
  • For what purposes is it collected, used, and disclosed? Highlight matters that would not be
  • bvious.
  • With whom is it shared?
  • Any risk of harm?

2.

Provide information in a layered format- Allow individuals to control the level of detail they get.

GUIDELINES FOR MEANINGFUL CONSENT

7

slide-8
SLIDE 8
  • Key Recommendations:

3.

Provide individuals with an option to say “yes” or “no” to non-integral collections, uses and disclosures of information.

4.

Explore innovative concepts to obtain consent, such as ‘just in time’ notices, and interactive privacy tools. Take advantage of the dynamic nature of the online environment.

5.

Consider the consumer’s perspective, and ensure the information provided is understandable:

  • Clear explanations
  • Language suitable for diverse audiences
  • Easily accessible

GUIDELINES FOR MEANINGFUL CONSENT

8

slide-9
SLIDE 9
  • Key Recommendations:

6.

Treat consent as a dynamic and ongoing process- including when policies change. When policies are changed, or information is used for new purposes, users must be notified and consent.

7.

Be able to demonstrate your consent processes are effective: “pointing to a line buried in a privacy policy will not suffice”. In assessing consent practices, consider:

  • The sensitivity of the information
  • The reasonable expectations of the individual
  • Whether there is a risk of harm
  • Any underlying context (e.g. the age of the individual)

GUIDELINES FOR MEANINGFUL CONSENT

9

slide-10
SLIDE 10

Potential Challenges:

1.

Forcing a “yes” or “no” option ignores the availability of implied consent under PIPEDA, and poses challenges with regard to CASL.

  • The “must do” is offering clear and accessible choices for non-integral uses of

personal information → this includes behavioural advertising

2.

There is little to suggest what “demonstrating effectiveness” of one’s consent processes means in practice.

3.

Considering “risk of harm” at the consent stage (in contrast to breach assessment) can be very conjectural, and moreover, adds to the what is already often very detailed disclosure.

GUIDELINES FOR MEANINGFUL CONSENT

10

slide-11
SLIDE 11
  • OBA involves tracking consumers' online activities and browsing behaviour, across

websites and over time, to deliver advertisements better targeted to their perceived interests.

  • May include consumer profiles built for different Internet users by collecting

information about their preferences using a variety of tracking technologies, such as cookies.

  • The profiles attempt to predict a consumer's interests from past activity. Targeted

advertisements are then served based on a specific profile.

  • Same underlying principles would apply to offline- Canadian privacy law is technology

neutral!

11

BEHAVIOURAL ADVERTISING

slide-12
SLIDE 12

Privacy Commissioner Guidelines for opt-out consent:

  • The individual must be made aware of the purposes for which you are collecting

personal information.

  • The individual must be informed at the time or

before information is collected and informed of the parties involved.

  • There must be an easily available opt-out, that takes effect immediately and is

persistent.

  • The information is not sensitive. Opt-in consent is required for sensitive information.
  • The information is de-identified or destroyed as soon as possible.

BEHAVIOURAL ADVERTISING

A clause buried in a privacy policy would not be adequate!

12

slide-13
SLIDE 13

Be Transparent about OBA Practices

  • Be clear, comprehensive and concise.
  • Describe all personal information collected and for what purposes.
  • Provide this information before data collection.
  • Use an ad icon, pop-up or just-in-time notice to provide this information,

rather than simply hiding it in a lengthy privacy policy.

13

BEHAVIOURAL ADVERTISING BEST PRACTICES

slide-14
SLIDE 14

Provide a User Friendly Opt-Out Mechanism

  • Process should be easy.
  • Display mechanism prominently on a webpage.
  • Opt-out must take effect immediately and be permanent/persistent.
  • Provide notice of successful opt-out.
  • Ensure the opt-out does not prevent use of other site features (e.g.

purchase functionality).

14

BEHAVIOURAL ADVERTISING BEST PRACTICES

slide-15
SLIDE 15

Organizations must disclose:

1.

Actual types of information the website passively collects and how the organization uses this information. (e.g. the information collected for targeted advertising, and how to out out)

2.

Technology used to collect this information.

3.

Website's practices with third-party advertisers.

4.

Whether the organization pairs this information with other types of personal information collected from: the user; third parties; or other sources.

15

CONSENT TAKE-AWAYS

slide-16
SLIDE 16
  • Consider whether opt-out or opt-in consent is appropriate depending on information

sensitivity, the amount of data collected and combined and the reasonable expectations of affected individuals.

  • Where possible, limit collection to non-sensitive data.
  • Disclose meaningful risks and benefits.
  • Do not use tracking tools that do not enable users to opt-out. Provide a clear and

easy to use opt-out.

16

CONSENT TAKE-AWAYS

slide-17
SLIDE 17

INAPPROPRIATE PRACTICES NO-GO ZONES

slide-18
SLIDE 18

The Office of the Privacy Commissioner has published guidance on Inappropriate Data Practices. These seek to interpret and apply the principle that organizations may only collect, use or disclose personal information in a manner that a reasonable person would consider appropriate in the circumstances - even with consent.

GUIDELINES ON INAPPROPRIATE DATA PRACTICES

18

slide-19
SLIDE 19

Key Recommendations:

1.

“No-go Zones” including:

  • Using information for unlawful practices- including genetic testing, and using credit score

information to target advertising

  • Profiling that leads to unfair, unethical, or discriminatory treatment
  • Collection, use, and disclosure that is known or “likely” to cause significant harm - including to

reputation and relationships or negative effects on one’s credit score

  • Publishing information to charge for its removal
  • Requesting social media account access for employee screening
  • “Surveillance” through the audio or visual functionality on one’s own device

GUIDELINES ON INAPPROPRIATE DATA PRACTICES

19

slide-20
SLIDE 20

Influencers and Social Media

slide-21
SLIDE 21

21

slide-22
SLIDE 22

22

slide-23
SLIDE 23

23

slide-24
SLIDE 24

24

slide-25
SLIDE 25

25

slide-26
SLIDE 26

26

slide-27
SLIDE 27

27

slide-28
SLIDE 28

28

Love a quick #DuaneReade run? Even @KatieHeigl can’t resist shopping #NYC's favorite drugstore

slide-29
SLIDE 29

29

slide-30
SLIDE 30

30

slide-31
SLIDE 31

31

slide-32
SLIDE 32

Sourcing Content:

1.

same rules apply…

2.

“commercial” purposes…

3.

flow-through license…

4.

specific usage rules…

5.

implied endorsement…

6.

check EACH social media site…

32

slide-33
SLIDE 33

33

slide-34
SLIDE 34

gowlingwlg.com

Gowling WLG (Canada) LLP is a member of Gowling WLG, an international law firm which consists of independent and autonomous entities providing services around the world. Our structure is explained in more detail at gowlingwlg.com/legal

CONTACT

Daniel Cole

Partner daniel.cole@gowlingwlg.com +1 416 814-5666

Christopher Oates

Partner chris.oates@gowlingwlg.com +1 416 369-7333