Home Data-Driven Thinking Geofencing Could Become A Magnet For Regulatory Scrutiny

Geofencing Could Become A Magnet For Regulatory Scrutiny

SHARE:

Data-Driven Thinking” is written by members of the media community and contains fresh ideas on the digital revolution in media.

Today’s column is written by Richard B. Newman, internet marketing attorney at Hinch Newman.

Geofencing is becoming increasingly popular as a means by which to deliver hypertargeted advertising content.

At the same time, today’s data privacy regulatory environment is increasingly aggressive and gaining international momentum. Geofencing raises a number of legal concerns that digital marketers must consider to avoid being caught in regulatory crosshairs.

Marketers use geofencing to create virtual boundaries linked to monitor mobile phones and internet-enabled mobile devices that enter or leave a specific area. Once consumers enter that area, marketers can send or display targeted advertisements in open apps or web browsers.

Apps regularly collect the precise whereabouts of consumers during their use. In the process, one or more third parties collect and share that location data to provide their services, which may include targeted advertising.

It would be a mistake for marketers that employ geofencing technologies for collecting and using personal data to assume that no risk exists merely because they are gathering what has traditionally not been considered personally identifiable information.

California’s Consumer Privacy Act of 2018 (CCPA) is, in many ways, more stringent than the EU’s General Data Protection Regulation (GDPR). CCPA defines “personal information” to include browsing and search history, in addition to inferences derived therefrom.

Although GDPR is not clear on the definition of location data, location data can most certainly qualify as personal data whenever it relates to an identifiable individual.

US regulators have already cracked down on the use of locating data. In 2017, the Massachusetts attorney general settled [PDF] a case involving geofencing around women’s reproductive healthcare facilities. Once women crossed the virtual fence, the advertiser sent targeted ads to their mobile devices.

The Massachusetts AG alleged that the advertiser’s use of geofencing violated the Massachusetts Consumer Protection Act because it tracked consumers’ locations and disclosed them to third-party advertisers to target consumers with potentially unwanted advertising based on inferences about their private, sensitive and intimate medical or physical condition.

Last year, the Federal Trade Commission sent letters to marketers of electronic devices and apps that appeared to collect precise geolocation data from children, warning that they may be violating the Children’s Online Privacy Protection Act (COPPA). One letter was directed to a Chinese company that sold a “child’s first cellphone” that included geofencing “safe zones.”

These warning letters are also significant because the recipients were based outside the United States. The FTC stated that “[t]he COPPA Rule applies to foreign-based websites and online services that are involved in commerce in the United States. This would include, among others, foreign-based sites or services that are directed to children in the United States, or that knowingly collect personal information from children in the United States.”

The services failed to provide direct notice of their collection practices and failed to seek verifiable parental consent before collecting, using or disclosing personal information as required by COPPA, according the agency.

European regulators have also taken action on location-based data protection abuses. In 2015, France’s Commission nationale de l’informatique et des libertés censured billboard giant JCDecaux for installing Wi-Fi boxes on their signs that captured the unique media access control addresses that identified passing smartphones without informed consent.

The new golden rule when processing the locations of smart mobile devices for direct marketing is affirmative opt-in consent.

Prominent and comprehensive geofencing notices should be displayed. Even better, clear, conspicuous and special notices should be displayed when the data is collected and prior to collection on the perimeter of coverage areas.

Just-in-time notices should include, without limitation, the purpose of the tracking and how information is used, the entity responsible for the tracking, the information being obtained, the information that is shared with third parties, how the information is secured, how collection can be stopped and how long the information is retained.

Enhanced privacy notices and written information about security policies should always be implemented.

Digital marketers and app developers should deliberately consider all applicable laws, regulations and best practices prior to implementing or developing geofencing or geotracking campaigns and technologies. Data privacy obligations and restrictions may vary by jurisdiction, and regulators will become incrementally more attentive as new technology facilitates cutting-edge marketing methods based on consumers’ personal information.

Follow Richard B. Newman (@FTCLawDefense) and AdExchanger (@adexchanger) on Twitter.

Must Read

TV Manufacturer Telly Touts Programmatic Home Screen Ads

Telly, the startup that gives away free smart TVs in exchange for data and ad exposure, is making its home screen ads available for brands to buy programmatically – and pushing for industry standards to help attract more spend. 

AI Is Helping L’Oréal Brainstorm Unique Ways To Reach Male Audiences

L’Oréal adopted creative AI platform Springboards to generate creative ideas that led to a collaborative, ongoing ideation process.

AdExchanger's Big Story podcast with journalistic insights on advertising, marketing and ad tech

Google Had Its Day In Court. Now, It’s Amazon’s Turn

Google won’t have to break up its ads business after being declared an online monopolist. Meanwhile, Amazon faces a lawsuit from the FTC alleging that it charged advertisers more than necessary for ecommerce ads.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

The FTC’s Amazon Lawsuit Is Ad Tech’s History Of Opacity Repeating Itself

Buy-side experts said it’s another example of a Big Tech platform taking advantage of the lack of transparency built into programmatic ad auctions. And they’re not optimistic change is coming.

How The Fin Tech Clearco Finances Ecommerce Startups (Without Losing Its Shirt)

This week, the Commerce Media Newsletter catches up with a startup from outside the world of data-driven advertising, but with an interesting position when it comes to ecommerce advertising. That’s Clearco, a Canadian fin tech company founded in 2015.

LOS ANGELES, CALIFORNIA - APRIL 26: Halo Collar CMO Seth Solomons attends a Celebration to Shine a Light On Dog Safety With Halo Collar on April 26, 2022 in Los Angeles, California. (Photo by Stefanie Keenan/Getty Images for Halo Collar)

How Halo Collar Uses Data And Incrementality To Raise Both Awareness And Sales

Halo Collar, a dog collar brand with direct-to-consumer origins, is preparing for its retail expansion by honing its first-party data strategy and incrementality measurement.