Trending Alert: The Risk of Information Collection, Storage, and Usage

Recently, several invasions of privacy allegations have manifested into legal complaints with identical fault-based wording: obtaining, collecting, storing, and sharing user data without notice or consent.

California’s Invasion of Privacy Act (CIPA) has been the basis of recent complaints for senior care providers operating in this state, but has now migrated to other states and is being used routinely as a doorstep to invasion of privacy litigation.

Multiple recent claims have been submitted by this self-represented individual, who has become well known for filing a high volume of similar privacy-related demands nationwide.

The approach is straightforward. Software tools are used to identify whether a website may be collecting or tracking user data before giving notice or obtaining visitor consent.

A demand for compensation is then generated, threatening litigation if terms are not met.

Cyber insurers and defense counselors are increasingly familiar with these claims, and in recent discussions with carriers, adjusters have described the increase as voluminous.

With the advancement of reliance on technology, risk mitigation will require a new proactive approach.

Key Takeaways

Mitigating this Specialized Claim Risk

  1. Regularly review website technology and tracking tools.
    Businesses should routinely audit their websites to understand which cookies, pixels, analytics tools, and other tracking technologies are being used, and to ensure they align with privacy requirements.
  2. Keep privacy policies and website terms up to date.
    Privacy notices and terms of use should accurately reflect current website practices, including the types of information collected, use of tracking technologies, and whether information is shared with third parties.
  3. Obtain clear, affirmative consent from website visitors.
    Simply posting a privacy policy or terms of use may not be enough. Businesses should provide clear notice and require users to take affirmative action, such as accepting cookie settings or agreeing to terms, before proceeding.
  4. Implement strong cookie consent practices.
    Use a compliant cookie banner that clearly explains tracking technologies, provides options to accept, reject, or customize cookies, and prevents non-essential tracking tools from activating before a user makes a choice.
  5. Know and manage your third-party vendors.
    Companies can face liability for the actions of vendors that provide website tools or services. Review vendor practices, understand what data is collected or shared, and ensure contracts address privacy responsibilities and protections.

Coverage for these claims vary widely by policy. Notify Propel immediately if you receive any communications regarding an alleged invasion of privacy.

Propel Insurance

Leave a Reply

Legal Fraud Disclaimer

Alera Group, Inc. is aware that there are persons fraudulently impersonating our company by using fake internet domains that appear to look like our legitimate services. If you are contacted by someone claiming to work for Alera Group, or any of our partners, please carefully review the email address and domain. If you have a relationship with our company, please contact us directly and not through any information that is provided in such an email. Please be extremely careful in responding to such emails with personal and financial information, sharing passwords, or any other information of value. Alera Group, or any of our partners, will never send ACH instructions via email and thus we strongly recommend that you verify the authenticity of each wire transfer request by calling your Alera Group contact using the number you have previously called.