login-customizer domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home1/natiopq9/public_html/wp-includes/functions.php on line 6131The post FTC Settlement with Zoom Concerning Alleged Data-Security Lapses appeared first on The National Law Forum.
]]>On November 9, 2020, the United States Federal Trade Commission (FTC) announced that it had entered into a consent agreement, subject to final approval, with videoconferencing company Zoom Video Communications, Inc. (Zoom). The consent agreement settles allegations that Zoom engaged in a series of deceptive and unfair practices that undermined the security of its users. The Commission voted 3–2 to accept the settlement, with Commissioners Chopra and Slaughter voting no and issuing dissenting statements asserting that the FTC’s action did not go far enough.
While the FTC generally does not identify what triggers a law enforcement action, there have been many news articles and a number of class actions filed in connection with Zoom’s data-security practices over the past six months that likely led to this action.
According to the complaint accompanying the consent agreement, the number of daily Zoom meetings grew from approximately 10 million in December 2019 to 300 million in April 2020. Zoom allows users to have one-on-one and group meetings, and users can also chat with others in the meeting, share their screens, and record videoconferences, among other things. Given the sensitive information that is often shared during a Zoom meeting—such as financial information, health information, proprietary business information, and trade secrets—appropriate data security is critical.
According to the FTC’s complaint, Zoom made numerous prominent representations touting the strength of its privacy and security measures employed to protect users’ personal information. These representations included claims relating to end-to-end encryption, as well as claims regarding the level of encryption. In addition, the complaint alleged that Zoom made deceptive claims regarding the secure storage for Zoom meeting recordings. The complaint also alleged that Zoom compromised the security of some users when it installed software called a ZoomOpener web server, which allowed Zoom to automatically launch and have a user join a meeting by bypassing an Apple Safari browser safeguard, which would have provided users with a warning box prior to launching the Zoom app.
The proposed settlement is consistent with many of the FTC’s recent data-security settlements and includes several of the newer provisions designed to strengthen such settlements. Specifically, the proposed settlement prohibits Zoom from misrepresenting its privacy and security practices in the future and requires Zoom to do the following:
Submit a report to the FTC upon the discovery of any covered incident. A covered incident is defined as an incident in which personal information is accessed or acquired without authorization and that requires reporting to any government entity.
As with a number of high-profile privacy or data-security settlements, the FTC’s Commissioners issued several separate statements expressing their views and their visions for the FTC’s privacy and data security program.
Notably, Commissioner Chopra issued a nine-page dissenting statement expressing concern with companies that, in the interest of acting and growing quickly, engage in deceptive practices, which he believes harms consumers and competition. Commissioner Chopra criticized the consent agreement because in his view it does not help affected parties, it does not include a monetary penalty, and thus it does not provide for meaningful accountability for Zoom. Finally, Commissioner Chopra stated that he believes that the Zoom settlement undermines the Commission’s effort to receive more authority from Congress to protect personal information.
Commissioner Slaughter also dissented, focusing her dissenting statement on her belief that the Commission’s action does not more robustly address the associated privacy issues connected to Zoom’s actions. In addition, Commissioner Slaughter took issue with the settlement’s failure to provide recourse for consumers.
The majority, Chairman Simons and Commissioners Phillips and Wilson, issued a statement indicating that they felt that the proposed relief “appropriately addresses the conduct alleged in the complaint and is an effective, efficient resolution of this investigation.”
The post FTC Settlement with Zoom Concerning Alleged Data-Security Lapses appeared first on The National Law Forum.
]]>