• Home
  • Et Cetera

Infosecurity.US

FTC: SONY BMG Will Pay $1 Million Civil Penalty For Child Privacy Breach

By Marc Handelman on December 12th, 2008

Raised FTC Seal

Wired’s David Kravets reports the Federal Trade Commission has fined Sony BMG Music Entertainment, a general partnership subsidiary of Sony Corporation of America (NYSE: SNE) for unlawfully garnering and publicizing personally identifiable information (including electronic media files) from kids under the age of 13.  Infosecurity.US applauds the FTC in their efforts to protect the children of the United States. The Federal Trade Commission’s announcement appears after the jump.

From the complaint: “Sony BMG Music Settles Charges Its Music Fan Websites Violated the Children’s Online Privacy Protection Act”

Company Will Pay $1 Million Civil Penalty

Sony BMG Music Entertainment (Sony Music) has agreed to pay $1 million as part of a settlement to resolve Federal Trade Commission charges that it violated the Children’s Online Privacy Protection Act (COPPA) and the Commission’s implementing Rule. The Commission’s complaint alleges that, through its music fan Web sites, Sony Music improperly collected, maintained and disclosed personal information from thousands of children under the age of 13, without their parents’ consent. The civil penalty to be paid by Sony Music matches the largest penalty ever in a COPPA case.

Sony BMG Music Entertainment, a subsidiary of Sony Corporation of America, represents hundreds of popular musicians and entertainers, including numerous artists popular with children and teenagers. The company operates over 1,000 Web sites for its musical artists and labels. Sony Music requires users to submit a broad range of personal information, together with date of birth, in order to register for these sites. On 196 of these sites, Sony Music knowingly collected personal information from at least 30,000 underage children without first obtaining their parents’ consent, in violation of COPPA. Many of these sites also enable children to create personal fan pages, review artists’ albums, upload photos or videos, post comments on message boards and in online forums, and engage in private messaging. In this way, children were able to interact with Sony Music fans of all ages, including adults.

“Sites with social networking features, like any Web sites, need to get parental consent before collecting kids’ personal information,” said FTC Chairman William E. Kovacic. “Sony Music is paying the penalty for falling down on its COPPA obligations.”

COPPA prohibits unfair or deceptive acts or practices in connection with the collection, use, or disclosure of personally identifiable information from and about children under 13 on the Internet. The law requires operators to notify parents and obtain their consent before collecting, using, or disclosing children’s personal information.

The FTC’s complaint alleges that Sony Music violated COPPA by failing to provide sufficient notice on the Sony Music Web sites of what information the company collects online from children, how it uses such information, and its disclosure practices; failing to provide direct notice to parents of Sony Music’s information practices; failing to obtain verifiable parental consent; and, failing to provide a reasonable means for parents to review the personal information collected from their children and to refuse to permit its further use or maintenance.

The FTC’s complaint also charges Sony Music with violating Section 5 of the Federal Trade Commission Act by falsely stating in its privacy policy that users who indicate that they are under 13 on its Web site registration pages will be restricted from participating in Sony Music’s web page activities. In fact, Sony Music accepted registrations from children who entered a date of birth indicating that they were under 13.

The Commission’s consent order calls for Sony Music to pay a $1 million civil penalty. In addition, the order specifically prohibits Sony Music from violating any provision of the Rule, and requires it to delete all personal information collected and maintained in violation of the Rule. The company is required to distribute the order and the FTC’s “How to Comply with the Children’s Online Privacy Protection Rule” to company personnel. The order also contains standard compliance, reporting, and record keeping provisions to help ensure the company abides by its terms.

To provide resources to parents and their children about children’s privacy in general, and social networking sites in particular, the order requires Sony Music to link to certain FTC consumer education materials for the next five years. The company must include a link to the children’s privacy section of the Commission’s www.ftc.gov Web site on any site it operates that is subject to COPPA. In addition, Sony Music must include links to the social networking section of the Commission’s www.onguardonline.gov web site on any of its sites that offer users the opportunity to create publicly viewable profiles.

The Commission vote approving the complaint and consent order was 4-0. On December 10, 2008, the Department of Justice, on behalf of the FTC, filed the complaint in the U.S. District Court for the Southern District of New York and submitted the consent decree for the court’s approval.

NOTE: The Commission authorizes the filing of a complaint when it has “reason to believe” that the law has or is being violated, and it appears to the Commission that a proceeding is in the public interest. A complaint is not a finding or ruling that the defendant has actually violated the law.

NOTE: Consent orders are for settlement purposes only and do not necessarily constitute an admission by the defendant of a law violation. Consent orders have the force of law when signed by the judge.

The Federal Trade Commission works for consumers to prevent fraudulent, deceptive, and unfair business practices and to provide information to help spot, stop, and avoid them. To file a complaint in English or Spanish, visit the FTC’s online Complaint Assistant or call 1-877-FTC-HELP (1-877-382-4357). The FTC enters complaints into Consumer Sentinel, a secure, online database available to more than 1,500 civil and criminal law enforcement agencies in the U.S. and abroad. The FTC’s Web site provides free information on a variety of consumer topics.

  • Sony pays $1M to FTC for illegally collecting data on kids
  • Sony Music sued over children’s online privacy
  • Sony sued for collecting kids data
  • Sony collects information on little kids, has to put sign in yard
Reblog this post [with Zemanta]

Categories: Children's Privacy, Childrens' Rights, Cybercrime, Cybercrime Vectors, Data Security, Features, Infosecurity
Tags: Features, Federal Trade Commission, Sony, Sony BMG Music Entertainment, Sony Corporation of America

Related Headlines

    Related posts:

    1. Rogue ISP Kaput – US FTC Orders Closure
    2. Questionable Data Broker SPOKEO Scrutinized, FTC Complaint Filed
    3. FTC Moves Against ScareWare Purveyors
    4. LifeLock Coughs Up $12,000,000, Settles FTC Lawsuit
    5. FourSquare or “How Your Privacy Was Breached Last Summer”

Comments are closed.

« ENISA Issues New Web 2.0 Security and Privacy Position Paper FTC Moves Against ScareWare Purveyors »
  • Latest
  • Random
  • Bookmarks
  • Archives
  • Steve Benson: Persian Lights…
  • New, Pernicious BotNet Emerges
  • VMWare Announces ESX Console Security Update
  • Nick Anderson: Egg
  • Doppelgänger Infinitus
  • Robert Ariall: Iran For Cover
  • Data Leakage Wednesdays: Old Printer Vector
  • XKCD: Exoplanets
  • Apple Releases Magic Footpad, Raises Ante On Bipedal Computer Controls
  • Science Tuesday: Asteroidal Discoveries Mapped, 01980 – 02010
  • Superstitious? Microsoft Tempts Fate – Thirteen On The Thirteenth
  • XKCD: Power Tools
  • XKCD: Internet Argument
  • Oracle Enterprise Linux Security Advisory: NTP
  • XKCD: Blockbuster Mining
  • XKCD: Spirits’ Lament
  • Computerworld and Secunia: The Sky Is Falling…Almost All Windows PC At Risk
  • Oracle Releases Critical Enterprise Linux Patches
  • FreeBSD Project Releases Two New Security Advisories
  • Oracle Announces Multiple, Critical, Enterprise Linux Updates
  • Apple
  • BSD
  • Closson
  • Darknet
  • Debian
  • Finnigan
  • ha.ckers
  • Hoff
  • Insecure
  • Krebs
  • Layer8
  • MSRC
  • Network Security Blog
  • NSA SEL
  • openSUSE
  • RedHat
  • SANS
  • Schneier
  • Security Eunoia
  • Securosis
  • Shimel
  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
Subscribe

Featured Blog - Blogs.com SANS Security Reading Room KnotOriginal: fine art to hang on your body and walls Member - Security Bloggers Network

Dilbert

KnotOriginal

Featured Video

QOTD

RSS Security Bloggers Network

  • Two Wheel EV Recumbant: Zerotracer 2010/09/02 Davi Ottenheimer
  • Ben Franklin’s Endpoint Security Advice 2010/09/02 Jeff Hughes
  • Configuring Conditional SSH Connections 2010/09/02 Xavier
  • Truecrypt and USB drives 2010/09/02 always peace
  • LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs 2010/09/02 Andrew Hay
  • Safe Web Surfing Rule # 1: READ the URL 2010/09/02 Tom Kelchner
  • Heartland Set To Pay Discover $5M For 2008 Data Breach 2010/09/02 spinman
  • User’s Opinions on Malware Infections 2010/09/02 spinman
  • Acunetix Web Vulnerability Scanner 7 Released 2010/09/02 spinman
  • LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs 2010/09/02 Anton Chuvakin

RSS Cryptography

  • Monitor: Schrodinger's cat and mouse 2010/09/02
  • How to configure a Junos security device 2010/09/02
  • Net Effect: Hay-what? 2010/09/02
  • The Art of Proof 2010/09/02
  • Quantum crypto cracked, researchers say 2010/09/01

RSS SANS ISC

  • Microsoft EMETv2 released, (Thu, Sep 2nd) 2010/09/02
  • SDF, please!, (Thu, Sep 2nd) 2010/09/02
  • Month of Undisclosed 0-day Bugs, (Wed, Sep 1st) 2010/09/01
  • Microsoft issues updates to sysinternals ProcDump and Process Monitor: http://blogs.technet.com/b/sysinternals/archive/2010/08/30/updates-procdump-process-monitor-and-a-new-mark-s-blog-post.aspx, (Wed, Sep 1st) 2010/09/01
  • VMWARE releases 2 security advisories for ESX Service Console: http://lists.vmware.com/pipermail/security-announce/2010/000103.html and http://lists.vmware.com/pipermail/security-announce/2010/000104.html, (Wed, Sep 1st) 2010/09/01

RSS Oracle

  • Going to Oracle OpenWorld 2010? 2010/09/02
  • Automatic Time Zone support in Application Express 4.0 2010/09/02
  • EBS, Collaborate, Security, BPEL, OWB, Blog of Note, Hyperion, EPM, Burnout, WiFi 2010/09/02
  • Details of Tuxedo sessions at OOW 2010/09/02
  • JavaOne Preview on TechCast Live! (Tues., Sept. 7, 10am PT) 2010/09/02
  • links for 2010-09-02 2010/09/02
  • Join us for a Bersin & Associates Webcast - "Evolution of ERPs: Driving Business Value through Integrated Talent Management" 2010/09/02

RSS MySQL

  • Join MySQL at OSCON 2010/07/02
  • TechCast Live: Jono Bacon and Luke Kowalski on MySQL Community 2010/05/21
  • What's New in the MySQL Enterprise Spring 2010 Release? - Interview with Mark Matthews and Andy Bang 2010/05/17
  • Introduction to MySQL 5.5 2010/04/13
  • Why Should I Check Out a MySQL-Based Column Database ? 2010/02/12
  • A deep look at MySQL 5.5 partitioning enhancements 2009/12/24
  • Sun "Tech Days" Conference World Tour Kicks Off in Brazil 2009/12/07

RSS Linux

  • A Guide to Today's Top 10 Linux Distributions - NetworkWorld.com 2010/09/02
  • Embedded Linux Conference videos available - LWN.net 2010/09/02
  • Net Applications' iOS vs Linux Report Confuses Me - Muktware (blog) 2010/09/02
  • Cloudlinux Named Editor's Choice By Web Host Magazine & Buyer's Guide - PR Urgent 2010/09/02
  • Samsung's 3D TV remote let's you take the screen with you - Geek.com 2010/09/02

RSS MAC OSX

  • Samsung Reveals Half-Pint iPad, The Galaxy Tab 2010/09/02 Eli Milchman
  • Daily Deals: New nano, touch and Apple TV 2010/09/02 Ed Sutherland
  • iPhone 4 Coffee Table Gets You Better Reception Than iPod Table? 2010/09/02 Nicole Martinelli
  • Walkman Outsells iPods in Japan, Can Wristwatch Nano Change That? 2010/09/02 Nicole Martinelli
  • Amazon: Buy – Don’t Rent – 99-Cent Fox, ABC TV Episodes 2010/09/02 Ed Sutherland
  • Analyst: New Apple TV Rival for Cable’s Video-on-Demand 2010/09/02 Ed Sutherland
  • iTunes Ping And Facebook: What’s Going On? 2010/09/02 Giles Turnbull

RSS Microsoft

  • Update on Security Advisory 2269637 2010/08/31 MSRCTEAM
  • Microsoft Security Advisory 2269637 Released 2010/08/22 MSRCTEAM
  • August 2010 Webcast and QA 2010/08/12 MSRCTEAM
  • Update on the publicly disclosed Win32k.sys EoP Vulnerability 2010/08/10 MSRCTEAM
  • August 2010 Security Bulletin Release 2010/08/10 MSRCTEAM
  • August 2010 Bulletin Release Advance Notification 2010/08/05 MSRCTEAM
  • August 2010 Out-of-Band Security Release Webcast Q&A 2010/08/03 MSRCTEAM

RSS Network

  • How to get started with a blade system 2010/09/02
  • Opsview Community Edition review 2010/09/02
  • Cacti review 2010/09/02
  • Brocade adds 100G Ethernet to switch and router line 2010/09/02
  • Is Cisco making a play for Skype? 2010/08/31
  • Skype launches Skype Connect enterprise voice calling 2010/08/31
  • Sonos ZonePlayer S5 review 2010/08/25

Daily Posts

September 2010
S M T W T F S
« Aug    
 1234
567891011
12131415161718
19202122232425
2627282930  
Creative Commons License
The Infosecurity.US Blog is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

Find the best blogs at Blogs.com.

Creative Commons Attribution-Share Alike 3.0 U.S. License ©2010 Infosecurity.US

Subscribe