You are here

Advertising Law Basics: What Dry Cleaners Need to Know (Conclusion)

What you collect, you’re responsible for

CHICAGO — No matter how large or small a business is, protecting its customers’ online privacy is a duty that applies to every company. 

This was one of the messages explored during a National Federation of Independent Business (NFIB) Small Business Legal Center webinar, “Advertising and Privacy Law Basics for Building Consumer Trust,” presented by Mary K. Engle, executive vice president of policy at BBB National Programs.

In Part 1 of this series, we examined the importance of ensuring that the message of advertising is clear to reasonable consumers and that claims can be backed up. In Part 2, we looked at who can bring advertising challenges and claims regulators are currently watching closely. Today, we’ll conclude by exploring what federal agencies expect of companies that handle their customers’ protected information.

“Almost every business collects some sort of consumer data, whether it’s email addresses, payment information, other customer profiles, or even website or app analytics,” Engle says. “Privacy laws are rapidly expanding, and it’s getting more complicated because of the many different states that are issuing privacy laws.”

A Patchwork, Not One Law

Unlike the European Union, the U.S. has no single comprehensive privacy statute, and Engle says she doesn’t expect one soon. In its place, obligations come from three directions: general federal consumer protection law, industry-specific federal statutes and a growing list of state laws.

On the federal side, the same FTC Act provision that governs advertising also covers privacy, and industry-specific laws like COPPA for children’s data, HIPAA for health information and the Gramm-Leach-Bliley Act for financial data may or may not apply depending on your business. The CAN-SPAM Act, though, applies broadly to anyone doing email marketing.

States have moved faster. Roughly 19 states now have general privacy laws, led by California’s CCPA and CPRA, the broadest of the group, though it currently exempts companies under $25 million in annual revenue. Colorado, Virginia and others have followed with similar frameworks. 

Most share the same core rights: letting consumers see and delete the data collected about them, opt out of targeted advertising, and receive clear notice about what’s collected, how it’s used and who it’s shared with. And the obligation follows the customer, not the business. “Really, every state where they’re selling products,” Engle says when asked whether online sellers need to comply only in their home state.

Where the FTC Focuses

As the primary federal privacy enforcer, the FTC watches three things: deceptive privacy promises, unfair data practices and inadequate security measures. The common thread across FTC cases, Engle says, comes down to one idea: “Say what you do and do what you say.” A privacy policy that promises protections a company doesn’t actually deliver is exactly the kind of mismatch that draws scrutiny, even without a specific complaint.

Sharing data with outside vendors is common and usually fine, Engle says, as long as those vendors are reputable and the sharing is disclosed. Targeted advertising is a frequent question. “It’s not that you can’t share information with them,” Engle says when asked whether businesses can still advertise on Facebook and Instagram. “It’s just that you have to tell consumers about it.” Sensitive categories, like health or financial information, require opt-in consent rather than a policy consumers are assumed to have read.

Handing targeted advertising off to a third-party company doesn’t shift the responsibility either. 

“Both parties are responsible,” Engle says. “That’s why your privacy policy needs to accurately state what information you’re collecting and that it’s being shared with third parties for advertising.” 

Security failures carry legal exposure too, though not automatically. “It’s not what’s called strict liability, meaning that if there’s a breach, you’re automatically liable or responsible,” Engle says. “It’s more of a reasonableness standard. Did you have in place sufficient reasonable safeguards to protect against the breach?” Weak, easily guessed passwords and poor access controls are common culprits behind the breaches regulators end up examining.

Practical Steps That Don’t Require a Legal Department

Engle’s recommendations for small businesses are straightforward:

  • Post a privacy notice that matches actual practices rather than a boilerplate one copied from elsewhere.
  • Know what data is collected and why.
  • Watch for third-party tools or software development kits quietly collecting more than intended.
  • Use reputable vendors.
  • Offer real opt-outs for marketing.
  • Keep an eye on state law developments, even in states that don’t yet regulate you directly.

She also offered one rule that covers most of it: “Don’t collect data that you don’t need, or that you can’t explain why you’re collecting it or what you’re doing with it, or that you can’t protect.”

For Engle, the advertising and privacy rules covered across this series point to the same conclusion. “We’re trying to help businesses out, and help them comply,” she says. “The goal is always compliance, not enforcement.”

For Part 1, click HERE. For Part 2, click HERE.

Advertising Law Basics-What Dry Cleaners Need to Know

(Image licensed by Ingram Image)

Have a question or comment? E-mail our editor Dave Davis at [email protected].