<?xml version="1.0" encoding="ISO-8859-1"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>apprights</title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/" />
    <link rel="self" type="application/atom+xml" href="http://apprights-hankjohnson.house.gov/atom.xml" />
    <id>tag:apprights-hankjohnson.house.gov,2012-06-18:/10</id>
    <updated>2013-05-10T14:36:47Z</updated>
    
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type Enterprise 4.361</generator>

<entry>
    <title>You Spoke, We Listened: H.R. 1913, the APPS Act, Bipartisan Legislation to Protect Your Mobile Privacy</title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2013/05/you-spoke-we-listened-hr-1913-the-apps-act-bipartisan-legislation-to-protect-your-mobile-privacy.shtml" />
    <id>tag:apprights-hankjohnson.house.gov,2013://10.2072</id>

    <published>2013-05-09T21:38:51Z</published>
    <updated>2013-05-10T14:36:47Z</updated>

    <summary>After launching AppRights last June, Congressman Johnson has asked what you think about mobile privacy, what you value, and what rights should be protected by law. The overwhelming majority of the feedback on AppRights confirmed that Congress should act to...</summary>
    <author>
        <name>Bond, Slade</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=39</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<p>After launching AppRights last June, Congressman Johnson has asked what you think about mobile privacy, what you value, and what rights should be protected by law.  The overwhelming majority of the feedback on AppRights confirmed that Congress should act to protect consumers&rsquo; privacy on mobile devices.</p> <p>You told us that you wanted simple controls over privacy on devices, security to prevent data breaches, and notice and information about data collection on the device.</p> <p>And we listened.</p> <p>After an open and honest dialogue, Congressman Johnson today introduced the bipartisan Application Privacy, Protection and Security (APPS) Act of 2013 (H.R. 1913), a bill to increase consumer privacy on mobile devices:</p> <center> <p><iframe width="480" height="360" src="https://www.youtube-nocookie.com/embed/4l7DSwlAeM4" frameborder="0" allowfullscreen=""></iframe></p> </center> <p>The APPS Act would require that app developers give effective notice about data collection and obtain consent from consumers before collecting personal data.  Trust in the mobile marketplace is crucial to its continued growth.  Transparency is the cornerstone of this trust.</p> <p>The APPS act would also require that developers securely maintain personal data.  And it would give consumers a clear way to permanently delete their personal data once they stop using an app.</p> <p>John Simpson, Privacy Project Director at Consumer Watchdog, calls the APPS Act &ldquo;a significant and important step forward in protecting consumers' privacy.&rdquo;  Susan Grant, Director of Consumer Protection at Consumer Federation of America, agrees: &ldquo;This bill is a common-sense approach to an urgent problem &ndash; millions of consumers are using mobile applications for a host of activities, some very personal, and yet they lack basic rights with respect to the data that may be collected about them.&rdquo;</p> <p>Interested in learning more about the APPS Act?  Click here to view <a href="http://apprights-hankjohnson.house.gov/APPS%20Act%20--%20JOHNGA_162_xml%20%287%29.pdf" target="_parent">H.R. 1913</a>&nbsp;and a <a href="http://apprights-hankjohnson.house.gov/One%20Pager%20--%20APPS%20Act.pdf">summary </a>of the need for the APPS Act.</p> <p>To join the online mobile privacy discussion, weigh in via our secure form on <a href="http://www.AppRights.US">www.AppRights.US</a> or interact via Twitter <a href="https://twitter.com/apprightsus">(@AppRightsUS</a>) and <a href="https://www.facebook.com/AppRights">Facebook</a>.<o:p></o:p></p>]]>
        
    </content>
</entry>

<entry>
    <title>AppRights Takes the Conversation to Twitter to Discuss the APPS Act on #PrivChat</title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2013/01/privchat-1.shtml" />
    <id>tag:apprights-hankjohnson.house.gov,2013://10.2071</id>

    <published>2013-01-24T17:08:07Z</published>
    <updated>2013-01-24T22:06:55Z</updated>

    <summary><![CDATA[This week, Congressman Johnson and the AppRights team discussed the APPS Act with the privacy community on Twitter via #PrivChat. &nbsp; #PrivChat is a weekly discussion on emerging privacy issues, moderated by Amie Stepanovich, a privacy attorney at the Electronic...]]></summary>
    <author>
        <name>Bond, Slade</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=39</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<p style="text-align: left; ">This week, Congressman Johnson and the AppRights team discussed the <a href="http://apprights-hankjohnson.house.gov/2013/01/apps-act.shtml" target="_parent">APPS Act</a> with the privacy community on Twitter via #PrivChat. &nbsp;</p> <p style="text-align: left; "><a href="http://epic.org/privchat/" target="_parent">#PrivChat</a> is a weekly discussion on emerging privacy issues, moderated by Amie Stepanovich, a privacy attorney at the Electronic Privacy Information Center (EPIC), and Shaun Dakin, a data privacy advocate and founder of Dakin &amp; Associates. &nbsp;The discussion included a diverse list of participants, from lawyers and advocates to security experts and other people who are interested in privacy and innovation. &nbsp;</p> <p style="text-align: left; ">Before the discussion, we proposed several questions to the group based on provisions in the APPS Act. &nbsp;These included: &nbsp;</p> <p style="text-align: left; margin-left: 40px; "><b>Q1: The APPS Act only applies to developers who collect personal and de-identified data. Is this a balanced approach to mobile privacy, or should the bill apply more broadly to third-party data collection? </b>(background available at CDT: Shielding the Messengers: Protecting Platforms for Expression and Innovation (pdf))</p> <p style="text-align: left; margin-left: 40px; "><b>Q2: Is de-identified data a useful definition, or is all data personal?</b> (background available at Ars Technica: &quot;Anonymized&quot; data really isn't&mdash;and here's why not)</p> <p style="text-align: left; margin-left: 40px; "><b>Q3: The APPS Act also creates a safe harbor for developers that comply with the NTIA's industry code (forthcoming). </b>Does this approach provide too much leeway? (background available at EPIC: NTIA Privacy Multistakeholder Process)</p> <p style="text-align: left; margin-left: 40px; "><b>Q4: The bill would require developers to provide a data-retention policy and create a mechanism for users to signal their intent to opt-out. Is it possible to delete third-party data, or should this provision continue to look to first-party data collection?</b> (background available at Media Post: Did iOS 6 Save Mobile Advertising)</p> <p style="text-align: left; ">The responses to these questions were lively, particularly over whether distinguishing between classes of data or technology is a useful practice. &nbsp;Garrett Cobarr, a user experience designer, researcher, and strategist, commented that:&nbsp;</p> <script async src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <blockquote class="twitter-tweet"> <p><a href="https://twitter.com/search/%23PrivChat">#PrivChat</a> A2: Technology is neither good or bad, it is simply used by good or bad people to do good or bad things. <a href="https://twitter.com/search/%23Privacy">#Privacy</a></p> &mdash; Garrett Cobarr (@GarrettCobarr) <a href="https://twitter.com/GarrettCobarr/status/293771066936000512">January 22, 2013</a></blockquote> <script async src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <p>&nbsp;</p> <blockquote class="twitter-tweet"> <p>@<a href="https://twitter.com/garrettcobarr">garrettcobarr</a> A2 We agree. Promoting responsible and secure collection is at the heart of the bill. <a href="https://twitter.com/search/%23privchat">#privchat</a></p> &mdash; AppRights (@AppRightsUS) <a href="https://twitter.com/AppRightsUS/status/293773349312659457">January 22, 2013</a></blockquote> <script async src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <p>Dr. Daniel Barth Jones, an infectious disease epidemiologist, recently published a paper on the re-identification of health data.  He commented that although de-identified data was a useful category, the language for the bill could be stronger:</p> <blockquote class="twitter-tweet"> <p>&ldquo;@<a href="https://twitter.com/paulbernaluk">paulbernaluk</a>: <a href="https://twitter.com/search/%23Privchat">#Privchat</a> A2: Apps Act 'de-identified' definition &quot;cannot be identified&quot; is unworkable - there is always some small risk...</p> &mdash; Daniel Barth-Jones (@dbarthjones) <a href="https://twitter.com/dbarthjones/status/293799065748127744">January 22, 2013</a></blockquote> <script async src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <p>Congressman Johnson also dropped in on Tuesday's discussion to say hello:</p> <blockquote class="twitter-tweet"> <p>Hey everyone, I gotta run to the Judiciary Committee, but I look forward to following <a href="https://twitter.com/search/%23privchat">#privchat</a> on the APPS Act. <a href="http://t.co/2vti9Dd2" title="http://twitter.com/RepHankJohnson/status/293755740856922112/photo/1">twitter.com/RepHankJohnson&hellip;</a></p> &mdash; Rep. Hank Johnson (@RepHankJohnson) <a href="https://twitter.com/RepHankJohnson/status/293755740856922112">January 22, 2013</a></blockquote> <script async src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <p>You can follow the rest of the conversation by <a href="http://storify.com/privacycamp/privchat-summary-from-1-22-with-apprightsus-priva#publicize" target="_parent">clicking here</a> (the beginning of the conversation is on the bottom of the page).</p> <p><span style="text-align: left; ">This is the second time that the AppRights team opened the legislation process to the privacy and tech community through #PrivChat. &nbsp;In August,&nbsp;</span><a href="https://apprights-hankjohnson.house.gov/2012/08/privchat.shtml" target="_parent" style="text-align: left; ">we asked several questions about mobile privacy</a><span style="text-align: left; ">. &nbsp;These included questions regarding specific types of data collection, the importance of main principles, and whether legislation should distinguish between children and adults on mobile devices. &nbsp;There,&nbsp;Congressman Johnson&nbsp;</span><a href="https://twitter.com/RepHankJohnson/status/230339540223660033/photo/1" target="_parent" style="text-align: left; ">took a moment to reach out during</a><span style="text-align: left; ">&nbsp;his campaign for re-election and introduce himself to the discussion.</span></p> <p>We'd like to thank Amie and Shaun for hosting AppRights on #PrivChat and promoting such a thoughtful discussion on mobile privacy. &nbsp;We're also glad Congressman Johnson was able to join the discussion, and follow it throughout. &nbsp; He launched AppRights to make the legislative process as transparent and open as possible, and we look forward to hearing more ideas about how we can tinker with the APPS Act to make it as strong of a bill as possible before introduction.</p> <p>For more information on the APPS Act, here is a <a href="http://apprights-hankjohnson.house.gov/2013/01/a-section-by-section-background-of-the-apps-act.shtml" target="_parent">section-by-section</a> and <a href="http://apprights-hankjohnson.house.gov/2013/01/summary-of-key-provisions-in-the-apps-act.shtml" target="_parent">summary of its major provisions</a>. Keep letting us know what you think&nbsp;through our secure form on AppRights.us, or interacting with us on <a href="https://www.facebook.com/AppRights" target="_parent">Facebook</a>&nbsp;or <a href="http://twitter.com/apprightsus" target="_parent">Twitter</a>.&nbsp;<br /> &nbsp;</p>]]>
        
    </content>
</entry>

<entry>
    <title>A Section-by-Section Background of the APPS Act   </title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2013/01/a-section-by-section-background-of-the-apps-act.shtml" />
    <id>tag:apprights-hankjohnson.house.gov,2013://10.2070</id>

    <published>2013-01-22T15:01:25Z</published>
    <updated>2013-01-22T15:10:32Z</updated>

    <summary>SEC. 1 SHORT TITLE The Application Privacy, Protection, and Security Act of 2013 or the APPS Act. SEC. 2 TRANSPARENCY, USER CONTROL, AND SECURITY The APPS Act would require that app developers maintain privacy policies, obtain consent from consumers before...</summary>
    <author>
        <name>Bond, Slade</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=39</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<p><u><b>SEC. 1 SHORT TITLE</b></u></p> <p>The Application Privacy, Protection, and Security Act of 2013 or the APPS Act.</p> <p><u><b>SEC. 2 TRANSPARENCY, USER CONTROL, AND SECURITY</b></u></p> <p>The APPS Act would require that app developers maintain privacy policies, obtain consent from consumers before collecting data, and securely maintain the data that they collect.</p> <p><b>Subsection (a) Consent</b></p> <p>Before collecting personal data from a consumer, a developer must notify the consumer of its terms for collecting, using, sharing, storing personal data, and obtain the consumer&rsquo;s consent.  The Federal Trade Commission would also promulgate regulations to specify the format, manner, and timing of this notice.</p> <p>These terms must also disclose certain types of data-collection practices.  These include the categories of personal data and purposes of its use, as well as the categories of third parties that use the personal data after it is initially collected by the developer.</p> <p>Additional, developers would maintain a data-retention policy that notifies the user how long data is stored, and how to delete or opt out of data collection.</p> <p><b>Subsection (b) Withdrawal of Consent</b></p> <p>For consumers that no longer want to use the app, the developer would provide a mechanism for consumers to signal this intent, and to empower consumers to decide the fate of the data that has already been collected.  At the consumer&rsquo;s election, the developer would either delete any personal data collected to the extent practicable, or cease collecting data altogether.  The developer would comply with the consumer&rsquo;s request within a reasonable period of time.</p> <p><b>Subsection (c) Security of personal data and de-identified data</b></p> <p>The APPS Act would require that developers prevent unauthorized access to a user&rsquo;s data through reasonable and appropriate security measures.  This provision would address sub-standard data storage practices by promoting responsible data storage.</p> <p><b>Subsection (d) Exception</b></p> <p>The APPS Act does not displace requirements for developers to disclose or preserve data under federal or state law.</p> <p><u><b>SEC. 3. APPLICATION AND ENFORCEMENT</b></u></p> <p>The APPS Act would be enforced through either the Federal Trade Commission under section 18(a)(1)(B) of the Federal Trade Commission Act prohibiting unfair or deceptive acts or practices, or by a state&rsquo;s attorney general through a federal civil action.  A state could not file a civil action if a federal action is already pending.</p> <p><u><b>SEC. 4.  REGULATIONS</b></u></p> <p>The FTC would promulgate regulations required by the Act within one year of its enactment.</p> <p><u><b>SEC. 5. SAFE HARBOR</b></u></p> <p>The APPS Act contains a safe harbor for companies that comply with the enforceable code of conduct agreed upon through the NTIA&rsquo;s multi-stakeholder process.  This approach give developers flexibility in how they display their privacy policies and interact with consumers, and avoids a heavy-handed legislative approach.</p> <p><u><b>SEC. 6. RELATIONSHIP TO STATE LAW</b></u></p> <p>The APPS Act supersedes state law only to the extent that it provides a higher level of transparency, user control, or security of personal and de-identified data than the state.</p> <p><u><b>SEC. 7. DEFINITIONS</b></u></p> <p>Key definitions include &ldquo;de-identified data,&rdquo; &ldquo;personal data,&rdquo; &ldquo;mobile application,&rdquo; and &ldquo;mobile device.&rdquo;<br /> The term &ldquo;de-identified data&rdquo; means data that cannot identify individuals.</p> <p>The FTC will promulgate a rule to define the term &ldquo;personal data,&rdquo; but it will not include de-identified data.</p> <p>A &ldquo;mobile application&rdquo; is a software program that the user directly interacts with that runs on a mobile device&rsquo;s operating system</p> <p>A &ldquo;mobile device&rdquo; is a smartphone, tablet computer, or similar portable computing device that transmits data over a wireless connection.</p> <p><u><b>SEC. 8. EFFECTIVE DATE</b></u></p> <p>The APPS Act is effective 30 days after the FTC promulgates regulations under section 4.</p>]]>
        
    </content>
</entry>

<entry>
    <title>What Does the APPS Act Do?  A Summary of the Discussion Draft&apos;s Key Provisions </title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2013/01/summary-of-key-provisions-in-the-apps-act.shtml" />
    <id>tag:apprights-hankjohnson.house.gov,2013://10.2069</id>

    <published>2013-01-18T21:44:28Z</published>
    <updated>2013-02-01T19:58:09Z</updated>

    <summary>Earlier this week, Congressman Johnson released the APPS Act to address the public&apos;s growing concern with data collection on mobile devices. This bill would require that app developers maintain privacy policies, obtain consent from consumers before collecting data, and securely...</summary>
    <author>
        <name>Bond, Slade</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=39</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<p class="Default" style="text-align: left; ">Earlier this week, Congressman Johnson<a href="http://apprights-hankjohnson.house.gov/2013/01/apps-act.shtml" target="_parent"> released the APPS Act</a> to address the public's growing concern with data collection on mobile devices.  This bill would require that app developers maintain privacy policies, obtain consent from consumers before collecting data, and securely maintain the data that they collect.  In this post, we review some of the main provisions in the APPS Act, providing a brief summary and clarifying some changes that have occurred since earlier versions.</p> <p>It's great hearing from so many of you.  Please continue to make your voice heard through our secure form on AppRights.us, or interacting with us on <a href="https://www.facebook.com/AppRights" target="_parent">Facebook </a>or <a href="http://twitter.com/apprightsus" target="_parent">Twitter</a>.</p> <p><b>Notice and Consent  </b></p> <p>Under the APPS Act, the app&rsquo;s privacy policy would have to disclose certain types of data-collection practices.  These include the categories of personal data and purposes of its use, as well as the categories of third parties that use the personal data after it is initially collected by the developer.  A developer would also maintain a data retention policy that notifies the user how long data is stored, and how to delete or opt out of data collection.</p> <p><b>Promoting Responsible Self-Regulatory Practices </b></p> <p>Importantly, the bill also has several provisions that encourage responsible data-collection practices by app developers while avoiding federal regulation.  The bill does not apply to de-identified data, which is any data not associated with a person.  Distinguishing between personal and de-identified data serves several important purposes.  First, it promotes data minimization and other strong security practices that avoid or mitigate data breaches.  Second, it avoids the unintended consequence of decreasing consumers&rsquo; privacy on mobile devices by requiring developer&rsquo;s to maintain &ldquo;backdoors&rdquo; for re-identifying data.  This avoids the difficulty of re-identifying data that is already hashed or otherwise de-identified.  Moreover, if this bill did not exclude de-identified data, developers would theoretically have to figure out how to connect de-identified data with individual users so that the developer could delete a user&rsquo;s data with the confidence that it&rsquo;s is actually the user&rsquo;s data.</p> <p>The APPS Act also contains a safe harbor for companies that comply with the enforceable code of conduct agreed upon through the NTIA&rsquo;s multi-stakeholder process.  This approach give developers flexibility in how they display their privacy policies and interact with consumers, and avoids a heavy-handed legislative approach.</p> <p><b>Opting Out of Data Collection and Deleting Data</b></p> <p>For consumers that no longer want to use the app, the APPS Act would also require that developers provide a mechanism for consumers to signal this intent, and to empower consumers to decide the fate of the data that has already been collected.  At the consumer&rsquo;s election, the developer would either delete any personal data collected to the extent practicable, or cease collecting data altogether.</p><p><b>Security</b></p><p>The APPS Act would require that developers prevent unauthorized access to a user&rsquo;s data through reasonable and appropriate security measures.  This provision would address negligent data storage practices by promoting responsible data storage.</p> <p><b>Enforcement</b></p> <p>The APPS Act would be enforced through either the Federal Trade Commission under section 18(a)(1)(B) of the Federal Trade Commission Act prohibiting unfair or deceptive acts or practices, or by a state&rsquo;s attorney general through a federal civil action.  A state could not file a civil action if a federal action is already pending.</p>]]>
        
    </content>
</entry>

<entry>
    <title>The Application Privacy, Protection, and Security (APPS) Act of 2013</title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2013/01/apps-act.shtml" />
    <id>tag:apprights-hankjohnson.house.gov,2013://10.2068</id>

    <published>2013-01-16T22:33:16Z</published>
    <updated>2013-01-16T23:14:46Z</updated>

    <summary>Following an extensive process of listening to the Internet community, public-interest groups, app developers and other industry stakeholders, Congressman Hank Johnson is proud to release the discussion draft of the Application Privacy, Protection, and Security Act of 2013, or the...</summary>
    <author>
        <name>Bond, Slade</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=39</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<p>Following an extensive process of listening to the Internet community, public-interest groups, app developers and other industry stakeholders, Congressman Hank Johnson is proud to release the discussion draft of the Application Privacy, Protection, and Security Act of 2013, or the APPS Act. &nbsp;</p> <p>One of the first bills of its kind, <a href="http://apprights-hankjohnson.house.gov/APPS_Act/APPS%20Act%20--%20JOHNGA_162_xml%20%286%29.pdf" target="_parent">the APPS Act</a> is a careful response to the many perspectives that have reached out to Congressman Johnson through AppRights. &nbsp;This bill addresses the public's growing concern with data collection on mobile devices. &nbsp;It would require that app developers provide transparency through consented terms and conditions, reasonable data security of collected data, and users with control to cease data collection by opting out of the service or deleting the user's personal data to the greatest extent possible. &nbsp;</p> <p>Over the coming days, we will release helpful clarifications of the updated provisions of the APPS Act so that everyone is on the same page. &nbsp;As always, you should continue to make your voice heard through our secure form on AppRights.us, or interacting with us on <a href="https://www.facebook.com/AppRights" target="_parent">Facebook</a>&nbsp;or <a href="http://twitter.com/apprightsus" target="_parent">Twitter</a>.&nbsp;</p> <p>&nbsp;</p> <p>&nbsp;</p> <p class="MsoNormal" align="center" style="text-align: center; "><b><span style="font-size:18.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">[DISCUSSION DRAFT]<o:p></o:p></span></b></p> <p class="MsoNormal"><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">&nbsp;</span></p> <table class="MsoNormalTable" border="0" cellpadding="0" align="left" width="25%" style="width:25.0%;mso-cellspacing:1.5pt;mso-yfti-tbllook:1184;mso-table-lspace:
    2.25pt;mso-table-rspace:2.25pt;mso-table-anchor-vertical:paragraph;mso-table-anchor-horizontal:
    column;mso-table-left:left">     <tbody>         <tr>             <td width="25%" style="width:25.0%;padding:.75pt .75pt .75pt .75pt"><p class="MsoNormal" align="center" style="margin-bottom: 0.0001pt; text-align: center; "><span style="font-size:14.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
            mso-fareast-font-family:&quot;Times New Roman&quot;;font-variant:small-caps">113th   CONGRESS</span><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
            mso-fareast-font-family:&quot;Times New Roman&quot;"><br />             </span><span style="font-size:14.0pt;mso-bidi-font-size:11.0pt;font-family:
            &quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;;
            font-variant:small-caps">1st Session</span><span style="font-size:14.0pt;
            font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;"><o:p></o:p></span></p></td>         </tr>     </tbody> </table> <table class="MsoNormalTable" border="0" cellpadding="0" align="right" width="25%" style="width:25.0%;mso-cellspacing:1.5pt;mso-yfti-tbllook:1184;mso-table-lspace:
    2.25pt;mso-table-rspace:2.25pt;mso-table-anchor-vertical:paragraph;mso-table-anchor-horizontal:
    column;mso-table-left:right;mso-table-top:middle">     <tbody>         <tr>             <td style="padding:.75pt .75pt .75pt .75pt">&nbsp;</td>         </tr>         <tr>             <td style="padding:.75pt .75pt .75pt .75pt">&nbsp;</td>         </tr>     </tbody> </table> <p class="MsoNormal" align="center" style="margin-bottom: 0.0001pt; text-align: center; "><b><span style="font-size:37.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">H. R. __</span></b><span style="font-size:14.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;"><o:p></o:p></span></p> <p class="MsoNormal" style="margin-bottom: 0.0001pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">&nbsp;</span></p> <p class="MsoNormal" style="margin-left: 76pt; text-indent: -24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">To provide for greater transparency in and user control over the treatment of data collected by mobile applications and to enhance the security of such data.<o:p></o:p></span></p> <div class="MsoNormal" align="center" style="margin-bottom: 0.0001pt; text-align: center; "><span style="font-size:14.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">  <hr size="2" width="40%" align="center" /> </span></div> <p class="MsoNormal" align="center" style="margin-bottom: 0.0001pt; text-align: center; "><span style="font-size:15.0pt;mso-bidi-font-size:
11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">IN THE HOUSE OF REPRESENTATIVES</span><span style="font-size:14.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;"><o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 76pt; text-indent: -24pt; "><span style="font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">Mr. <span style="font-variant:small-caps">Johnson </span>of Georgia introduced the following bill; which was referred to the Committee on ______________<o:p></o:p></span></p> <div class="MsoNormal" align="center" style="margin-bottom: 0.0001pt; text-align: center; "><span style="font-size:14.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">  <hr size="2" width="40%" align="center" /> </span></div> <p class="MsoNormal" align="center" style="margin-bottom: 0.0001pt; text-align: center; "><b><span style="font-size:30.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">A BILL</span></b><span style="font-size:14.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;"><o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 76pt; text-indent: -24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">To provide for greater transparency in and user control over the treatment of data collected by mobile applications and to enhance the security of such data.<o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: 24pt; "><i><span style="font-size:14.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled, </span></i><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;"><o:p></o:p></span></p> <p class="MsoNormal" style="margin-bottom: 0.0001pt; text-indent: -24pt; margin-left: 40px; "><a name="HD95ED927D5C54182BF22F7D1909A208D"></a><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">SECTION 1.</span></b><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;"> </span><b><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;;text-transform:uppercase">Short title</span></b><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">.</span></b><span style="font-size:
14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;"><o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: 24pt; "><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">This Act may be cited as the &ldquo;Application Privacy, Protection, and Security Act of 2013&rdquo; or the &ldquo;APPS Act of 2013&rdquo;.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-bottom: 0.0001pt; text-indent: -24pt; margin-left: 40px; "><a name="HADF03D31E6A9423DB0F4E28AAE63DBCE"></a><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">SEC. 2. </span></b><b><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;;text-transform:uppercase">Transparency, user control, and security</span></b><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.</span></b><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;"><o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: 24pt; "><a name="H3EE7EE97D6A04763B1B7F26EDB1B694E"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(a) </span><span style="font-size:14.0pt;mso-bidi-font-size:11.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;;font-variant:
small-caps;letter-spacing:.75pt">Consent to terms and conditions</span><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">.&mdash;<a name="HF4B012DF826C4DF0ABCDA55CD09865AB"></a> <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">(1) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">I</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">N GENERAL</span><span style="font-size:14.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;Before a mobile application collects personal data about a user of the application, the developer of the application shall&mdash;<a name="HD2505F04B87C4D1EB9C75E951F4F0E7D"></a> <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">(A) provide the user with notice of the terms and conditions governing the collection, use, storage, and sharing of the personal data; and<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><a name="H2CFA107325D64E0A93A7EF4C080ABDA2"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(B) obtain the consent of the user to such terms and conditions.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="H7FCB4DB2C474437BAB8C41202010359D"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(2) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">R</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">EQUIRED CONTENT</span><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;The notice required by paragraph (1)(A) shall include the following:<a name="HA6B2AF77E010430E9FEB6D32FFEA3F30"></a> <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">(A) The categories of personal data that will be collected.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><a name="H11F488C6168D4398BC00EAD7F61F7BDC"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(B) The categories of purposes for which the personal data will be used.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><a name="H444323906DE444A38716FE8EADC16797"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(C) The categories of third parties with which the personal data will be shared.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><a name="H073F1A66E38A4D2DA53D4B8E16058FF2"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(D) A data retention policy that governs the length for which the personal data will be stored and the terms and conditions applicable to storage, including a description of the rights of the user under subsection (b) and the process by which the user may exercise such rights.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="H398B8D67CFB140DABC4C81D61B5EC9E0"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(3) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">A</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">DDITIONAL SPECIFICATIONS AND FLEXIBILITY</span><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">.&mdash;The Commission shall by regulation specify the format, manner, and timing of the notice required by paragraph (1)(A). In promulgating the regulations, the Commission shall consider how to ensure the most effective and efficient communication to the user regarding the treatment of personal data.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="HFF8249E908714790931C3AE4777B883C"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(4) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">D</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">IRECT ACCESS TO DATA BY THIRD PARTIES</span><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">.&mdash;For purposes of this Act, if the developer of a mobile application allows a third party to access personal data collected by the application, such personal data shall be considered to be shared with the third party, whether or not such personal data are first transmitted to the developer.<o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: 24pt; "><a name="HD444D3C5B5BC41C2A1597BF3F45D0D7B"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(b) </span><span style="font-size:14.0pt;mso-bidi-font-size:11.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;;font-variant:
small-caps;letter-spacing:.75pt">Withdrawal of consent</span><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">.&mdash;The developer of a mobile application shall&mdash;<a name="HB9C0397B096B4244BD9F4E44E6328AA8"></a> <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">(1) provide a user of the application with a means of&mdash;<a name="H0D9913DFCEAC486FBAF0EE476C4A8E5A"></a> <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">(A) notifying the developer that the user intends to stop using the application; and<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><a name="H405C21F4833848B6800B66C4064535C9"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(B) requesting the developer&mdash;<a name="HA99F45B58C9642FC8FA029EEADEFF713"></a> <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 112pt; text-align: justify; text-indent: 24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">(i) to refrain from any further collection of personal data through the application; and<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 112pt; text-align: justify; text-indent: 24pt; "><a name="HF48069FEFE2849D1AA6C3D1B6C98ED34"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(ii) at the option of the user, either&mdash;<a name="H18CAE9C9BFDB432AACC5ADC2FF28B218"></a> <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 136pt; text-align: justify; text-indent: 24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">(I) to the extent practicable, to delete any personal data collected by the application that is stored by the developer; or<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 136pt; text-align: justify; text-indent: 24pt; "><a name="H61C7078ABCC9498AB5FC2256B7BCD019"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(II) to refrain from any further use or sharing of such data; and<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="H03B217D9867E41398A880429F1AB386D"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(2) within a reasonable and appropriate time after receiving a request under paragraph (1)(B), comply with such request.<o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: 24pt; "><a name="H0E98874EA381426F9CA7F5B69BD8E85C"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(c) </span><span style="font-size:14.0pt;mso-bidi-font-size:11.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;;font-variant:
small-caps;letter-spacing:.75pt">Security of personal data and de-identified data</span><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;The developer of a mobile application shall take reasonable and appropriate measures to prevent unauthorized access to personal data and de-identified data collected by the application.<o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: 24pt; "><a name="H0214FDAC281B4816B59FA53A24F6C82C"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(d) </span><span style="font-size:14.0pt;mso-bidi-font-size:11.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;;font-variant:
small-caps;letter-spacing:.75pt">Exception</span><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;Nothing in this Act prohibits the developer of a mobile application from disclosing or preserving personal data or de-identified data as required by&mdash;<a name="H556BB0646A184FEB9B99F6D2E3B54914"></a> <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">(1) other Federal law (including a court order); or<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="HAF1E8D755CA54E53B85E69D4DEDD9F50"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(2) except as provided in section 6, the law of a State or a political subdivision of a State (including a court order).<o:p></o:p></span></p> <p class="MsoNormal" style="margin-bottom: 0.0001pt; text-indent: -24pt; margin-left: 40px; "><a name="HD573DCC901C34F8C9978572537C4E15C"></a><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">SEC. 3. </span></b><b><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;;text-transform:uppercase">Application and enforcement</span></b><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">.</span></b><span style="font-size:
14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;"><o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: 24pt; "><a name="H6A658D542CAD4036BE5366EA3FB6BC40"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(a) </span><span style="font-size:14.0pt;mso-bidi-font-size:11.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;;font-variant:
small-caps;letter-spacing:.75pt">General application</span><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">.&mdash;The requirements of this Act and the regulations promulgated under this Act apply, according to their terms, to those persons, partnerships, and corporations over which the Commission has authority pursuant to section 5(a)(2) of the Federal Trade Commission Act (15 U.S.C. 45(a)(2)).<o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: 24pt; "><a name="H7751D00E08804BF1A78A93014753563E"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(b) </span><span style="font-size:14.0pt;mso-bidi-font-size:11.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;;font-variant:
small-caps;letter-spacing:.75pt">Enforcement by Federal Trade Commission</span><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">.&mdash;<a name="HE6B3EF677A7D48EF9C1566625DBA25E7"></a> <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">(1) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">U</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">NFAIR OR DECEPTIVE ACTS OR PRACTICES</span><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">.&mdash;A violation of this Act or a regulation promulgated under this Act shall be treated as a violation of a regulation under section 18(a)(1)(B) of the Federal Trade Commission Act (15 U.S.C. 57a(a)(1)(B)) regarding unfair or deceptive acts or practices. <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="HC62471F8464B45F68BC5E4284B563759"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(2) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">P</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">OWERS OF COMMISSION</span><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;The Commission shall enforce this Act and the regulations promulgated under this Act in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (15 U.S.C. 41 et seq.) were incorporated into and made a part of this Act. Any person who violates this Act or a regulation promulgated under this Act shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act.<o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: 24pt; "><a name="HAC854CA880A54CAA9FA3D8CF83ABD42D"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(c) </span><span style="font-size:14.0pt;mso-bidi-font-size:11.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;;font-variant:
small-caps;letter-spacing:.75pt">Actions by States</span><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">.&mdash;<a name="H75A827FFD5CA49FF8D1FF0164B205728"></a> <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">(1) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">I</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">N GENERAL</span><span style="font-size:14.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;In any case in which the attorney general of a State, or an official or agency of a State, has reason to believe that an interest of the residents of such State has been or is threatened or adversely affected by an act or practice in violation of this Act or a regulation promulgated under this Act, the State, as parens patriae, may bring a civil action on behalf of the residents of the State in an appropriate district court of the United States to&mdash;<a name="H71E27DE92E50439D9880132A23022B20"></a> <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">(A) enjoin such act or practice;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><a name="H5143AEA96D71477E9087980854676A63"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(B) enforce compliance with this Act or such regulation;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><a name="H187101F9C14B415587A2B2F3A05A3D6A"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(C) obtain damages, restitution, or other compensation on behalf of residents of the State; or<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><a name="H1384ED6A8B824A5395E52E1F6887F390"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(D) obtain such other legal and equitable relief as the court may consider to be appropriate.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="HA35DFD74611A4947836430DA94710233"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(2) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">N</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">OTICE</span><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;Before filing an action under this subsection, the attorney general, official, or agency of the State involved shall provide to the Commission a written notice of such action and a copy of the complaint for such action. If the attorney general, official, or agency determines that it is not feasible to provide the notice described in this paragraph before the filing of the action, the attorney general, official, or agency shall provide written notice of the action and a copy of the complaint to the Commission immediately upon the filing of the action.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="HA9A366234AEF41D4B1562F1010DB3EAD"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(3) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">A</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">UTHORITY OF COMMISSION</span><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;<a name="H7711E7B054F842C0BD062AE4C49F42DC"></a> <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">(A) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">I</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">N GENERAL</span><span style="font-size:14.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;On receiving notice under paragraph (2) of an action under this subsection, the Commission shall have the right&mdash;<a name="H5EB5099D26B44B5091A8EA2EA7D1A172"></a> <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 112pt; text-align: justify; text-indent: 24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">(i) to intervene in the action;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 112pt; text-align: justify; text-indent: 24pt; "><a name="HD03215D148DE4F35AF04A218E9526DA2"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(ii) upon so intervening, to be heard on all matters arising therein; and<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 112pt; text-align: justify; text-indent: 24pt; "><a name="HAE8ED2ADEEE54B4DA91B7E6FEA8CA5FD"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(iii) to file petitions for appeal.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><a name="HF8638A0C307E4402B1D77638518F5DE2"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(B) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">L</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">IMITATION ON STATE ACTION WHILE FEDERAL ACTION IS PENDING</span><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">.&mdash;If the Commission or the Attorney General of the United States has instituted a civil action for violation of this Act or a regulation promulgated under this Act (referred to in this subparagraph as the &ldquo;Federal action&rdquo;), no State attorney general, official, or agency may bring an action under this subsection during the pendency of the Federal action against any defendant named in the complaint in the Federal action for any violation of this Act or such regulation alleged in such complaint.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="H5626A0400C2C44BC8BB433AF9E35F0DF"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(4) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">R</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">ULE OF CONSTRUCTION</span><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;For purposes of bringing a civil action under this subsection, nothing in this Act shall be construed to prevent an attorney general, official, or agency of a State from exercising the powers conferred on the attorney general, official, or agency by the laws of such State to conduct investigations, administer oaths and affirmations, or compel the attendance of witnesses or the production of documentary and other evidence.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-bottom: 0.0001pt; text-indent: -24pt; margin-left: 40px; "><a name="H9169F3169B2340E98212E6A12EFE5475"></a><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">SEC. 4. </span></b><b><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;;text-transform:uppercase">Regulations</span></b><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">.</span></b><span style="font-size:
14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;"><o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: 24pt; "><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">Not later than 1 year after the date of the enactment of this Act, the Commission shall promulgate regulations in accordance with section 553 of title 5, United States Code, to implement and enforce this Act.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-bottom: 0.0001pt; text-indent: -24pt; margin-left: 40px; "><a name="H34221F35E0564A73B64D293D729175A6"></a><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">SEC. 5. </span></b><b><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;;text-transform:uppercase">Safe harbor</span></b><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">.</span></b><span style="font-size:
14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;"><o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: 24pt; "><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">The developer of a mobile application may satisfy the requirements of this Act and the regulations promulgated under this Act by adopting and following a code of conduct for consumer data privacy (insofar as such code relates to data collected by a mobile application) developed in a multistakeholder process convened by the National Telecommunications and Information Administration, as described in the document issued by the President on February 23, 2012, entitled &ldquo;Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation in the Global Digital Economy&rdquo;.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-bottom: 0.0001pt; text-indent: -24pt; margin-left: 40px; "><a name="HA1CDF085ECD44F9293BBBEE76CB1B6DF"></a><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">SEC. 6. </span></b><b><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;;text-transform:uppercase">Relationship to State law</span></b><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">.</span></b><span style="font-size:
14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;"><o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: 24pt; "><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">This Act and the regulations promulgated under this Act supercede a provision of law of a State or a political subdivision of a State only to the extent that such provision&mdash;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="H59D7B77C6E124DD8A523F8FC846522F4"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(1) conflicts with this Act or such regulations, as determined without regard to section 2(d)(2);<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="HF738CA7685FB4298882982F18D0FAD19"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(2) specifically relates to the treatment of personal data or de-identified data; and<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="H9C3827B060CC4D34A463C869E3E7F726"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(3) provides a level of transparency, user control, or security in the treatment of personal data or de-identified data that is less than the level provided by this Act and such regulations.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-bottom: 0.0001pt; text-indent: -24pt; margin-left: 40px; "><a name="HBAA6E964B4EF43F4B10072C518B21208"></a><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">SEC. 7. </span></b><b><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;;text-transform:uppercase">Definitions</span></b><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">.</span></b><span style="font-size:
14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;"><o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: 24pt; "><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">In this Act:<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="HE0A23A98822A41AF8F83667F3A0CE519"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(1) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">C</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">OMMISSION</span><span style="font-size:14.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;The term &ldquo;Commission&rdquo; means the Federal Trade Commission. <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="H3E9BD0C2E54A4C2CBE71D6FEFB087B63"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(2) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">D</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">E-IDENTIFIED DATA</span><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;The term &ldquo;de-identified data&rdquo; means data from which particular individuals cannot be identified.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="H2FA499112D5E4B1081667D980C483608"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(3) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">D</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">EVELOPER</span><span style="font-size:14.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;The term &ldquo;developer&rdquo; shall have the meaning given such term by the Commission by regulation.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="H7F92F6E7110B40BA8A0D2FBBA1C9D7D1"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(4) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">M</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">OBILE APPLICATION</span><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;The term &ldquo;mobile application&rdquo; means a software program&mdash;<a name="HD528B6A120874C02A19A12492A669EF2"></a> <o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">(A) that runs on the operating system of a mobile device; and<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 88pt; text-align: justify; text-indent: 24pt; "><a name="HF16AE20F19694D6B9B4CEF23A6D0340B"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(B) with which the user of the device directly interacts.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="H88FE89C9412C42B1A68937F65C8FF49D"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(5) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">M</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">OBILE DEVICE</span><span style="font-size:14.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;The term &ldquo;mobile device&rdquo; means a smartphone, tablet computer, or similar portable computing device that transmits data over a wireless connection.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="H80918E375D284C43862F295AF5C2C8D1"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(6) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">P</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">ERSONAL DATA</span><span style="font-size:14.0pt;font-family:
&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;The term &ldquo;personal data&rdquo; shall have the meaning given such term by the Commission by regulation, except that such term shall not include de-identified data.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left: 64pt; text-align: justify; text-indent: 24pt; "><a name="HAB97E2A780E847F5B567C39C9BDA43EC"></a><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">(7) </span><span style="font-size:15.5pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">S</span><span style="font-size:12.0pt;
mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;">TATE</span><span style="font-size:14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">.&mdash;The term &ldquo;State&rdquo; means each of the several States, the District of Columbia, each commonwealth, territory, or possession of the United States, and each federally recognized Indian tribe.<o:p></o:p></span></p> <p class="MsoNormal" style="margin-bottom: 0.0001pt; text-indent: -24pt; margin-left: 40px; "><a name="HF9ED967041474EBE991F42E747870A5A"></a><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">SEC. 8. </span></b><b><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:
&quot;Times New Roman&quot;;text-transform:uppercase">Effective date</span></b><b><span style="font-size:12.0pt;mso-bidi-font-size:11.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;">.</span></b><span style="font-size:
14.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;"><o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: 24pt; "><span style="font-size:14.0pt;
font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;mso-fareast-font-family:&quot;Times New Roman&quot;">This Act shall apply with respect to any collection, use, storage, or sharing of personal data or de-identified data that occurs after the date that is 30 days after the promulgation of final regulations under section 4.<o:p></o:p></span></p> <p class="MsoNormal"><o:p>&nbsp;</o:p></p> <p>&nbsp;</p>]]>
        
    </content>
</entry>

<entry>
    <title> Provision Three: Transparency through Notice and Choice</title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2013/01/provision-three-transparency-through-notice-and-choice.shtml" />
    <id>tag:apprights-hankjohnson.house.gov,2013://10.2066</id>

    <published>2013-01-03T18:24:14Z</published>
    <updated>2013-01-03T18:35:13Z</updated>

    <summary>After listening to all of the feedback that we received through AppRights, the third provision to protect your privacy requires transparent data collection through notice and choice.Before collecting any data from users, developers would be required to provide users with...</summary>
    <author>
        <name>Bond, Slade</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=39</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<p><span style="font-size: small; ">After </span><a href="http://apprights-hankjohnson.house.gov/2012/08/ltr.shtml"><span style="font-size: small; ">listening to all of the feedback</span></a><span style="font-size: small; "> that we received through AppRights, the third provision to protect your privacy requires transparent data collection through notice and choice.</span></p><div><p><span style="font-size: small; ">Before collecting any data from users, developers would be required to provide users with notice of the terms and conditions for collecting, using, and sharing users&rsquo; personal data.&nbsp; This notice would include the categories of personal data collection, the categories of purposes for this collection, and the categories of third parties that share this data following collection by the developer.&nbsp; </span><o:p></o:p></p><p><span style="font-size: small; ">The Federal Trade Commission would determine what type of notice is appropriate through a rulemaking that specifies the format, manner, and timing of the notice.&nbsp; This rulemaking is important for providing flexible protection as norms and technologies change.</span><o:p></o:p></p><p><span style="font-size: small; ">Users would exercise choice by deciding whether to consent to data collection after receiving this notice.</span></p><p><o:p></o:p></p><p><span style="font-size: small; "><b style="font-family: Arial; ">Bill Text</b>: </span></p><p><span style="font-size: small; ">(a) CONSENT TO TERMS AND CONDITIONS.&mdash;</span></p><p style="margin-left: 40px; "><span style="font-size: small; ">(1) IN GENERAL.&mdash;Before a mobile application collects personal data about a user of the application, the developer of the application shall&mdash; </span><o:p></o:p></p><p style="margin-left: 80px; "><span style="font-size: small; ">(A) provide the user with notice of the terms and conditions governing the collection, use, storage, and sharing of the personal data; and </span><o:p></o:p></p><p style="margin-left: 80px; "><span style="font-size: small; ">(B) obtain the consent of the user to such terms and conditions. </span><o:p></o:p></p><p style="margin-left: 40px; "><span style="font-size: small; ">(2) REQUIRED CONTENT.&mdash;The notice required by paragraph (1)(A) shall include the following: </span><o:p></o:p></p><p style="margin-left: 80px; "><span style="font-size: small; ">(A) The categories of personal data that will be collected. </span><o:p></o:p></p><p style="margin-left: 80px; "><span style="font-size: small; ">(B) The categories of purposes for which the personal data will be used.</span><o:p></o:p></p><p style="margin-left: 80px; "><span style="font-size: small; ">(C) The categories of third parties with which the personal data will be shared.</span><o:p></o:p></p><p style="margin-left: 80px; "><span style="font-size: small; ">(D) A description of the rights of the user under subsection (b) and the process by which the user may exercise such rights.</span><o:p></o:p></p><p style="margin-left: 40px; "><span style="font-size: small; ">(3) ADDITIONAL SPECIFICATIONS AND FLEXIBILITY.&mdash;The Commission shall by regulation specify the format, manner, and timing of the notice required by paragraph (1)(A). In promulgating the regulations, the Commission shall consider how to ensure the most effective and efficient communication to the user regarding the treatment of personal data.</span><o:p></o:p></p><p style="margin-left: 40px; "><span style="font-size: small; ">(4) DIRECT ACCESS TO DATA BY THIRD PARTIES.&mdash;For purposes of this Act, if the developer of a mobile application allows a third party to access personal data collected by the application, such personal data shall be considered to be shared with the third party, whether or not such personal data are first transmitted to the developer.</span><o:p></o:p></p><p><span style="font-size: small; "><b>Definitions</b>:</span><o:p></o:p></p><p style="margin-left: 40px; "><span style="font-size: small; ">&nbsp;&bull; The term &ldquo;anonymous data&rdquo; means data from which particular individuals cannot be identified.</span></p><p style="margin-left: 40px; "><span style="font-size: small; ">&bull; The term &ldquo;developer&rdquo; has the meaning given by the Federal Trade Commission by regulation.</span><o:p></o:p></p><p style="margin-left: 40px; "><span style="font-size: small; ">&bull; The term &ldquo;mobile application&rdquo; means a software program (A) that runs on the operating system of a mobile device; and (B) with which the user of the device directly interacts.</span><o:p></o:p></p><p style="margin-left: 40px; "><span style="font-size: small; ">&bull; The term &ldquo;mobile device&rdquo; means a smartphone, tablet computer, or similar portable computing device that transmits data over a wireless connection.</span><o:p></o:p></p><p style="margin-left: 40px; "><span style="font-size: small; ">&bull; The term &ldquo;personal data&rdquo; has the meaning given by the Federal Trade Commission by regulation, but does not include anonymous data.</span><o:p></o:p></p><p><span style="font-size: small; ">We discussed the </span><a href="http://apprights-hankjohnson.house.gov/2012/12/based-on-your-feedback-the.shtml"><span style="font-size: small; ">security provision</span></a><span style="font-size: small; "> last week, the second provision of the mobile privacy legislation that the Congressman intends on introducing in the 113th Congress.&nbsp; This provision protected user data by requiring developers to prevent unauthorized access to a user&rsquo;s data, such as a data breach, through reasonable and appropriate security measures.<span class="apple-converted-space">&nbsp;</span></span></p><p><o:p></o:p></p><p><span style="font-size: small; ">Each provision will have a two-week period for you to let us know about your thoughts and concerns. &nbsp;Once we have heard back from you on all three principles, we will issue another legislative transparency report that explores your feedback before the Congressman introduces legislation.</span><o:p></o:p></p><p><span style="font-size: small; ">We look forward to your input on the transparency provision, and hope you will continue to express your views and concerns regarding mobile privacy. &nbsp;By sharing your thoughts with us through our secure form at AppRights.us, or interacting with us on&nbsp;</span><a href="https://www.facebook.com/AppRights" target="_blank"><span style="font-size: small; ">Facebook&nbsp;</span></a><span style="font-size: small; ">or&nbsp;</span><a href="http://twitter.com/apprightsus" target="_blank"><span style="font-size: small; ">Twitter</span></a><span style="font-size: small; ">, we will work together to find the right solutions to each issue.&nbsp;</span><o:p></o:p></p></div><p><span style="font-size: small; ">&nbsp;</span></p>]]>
        
    </content>
</entry>

<entry>
    <title>Happy Holidays from Congressman Hank Johnson&apos;s Office</title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2012/12/happy-holidays-from-congressman-hank-johnsons-office.shtml" />
    <id>tag:apprights-hankjohnson.house.gov,2012://10.2065</id>

    <published>2012-12-21T17:39:31Z</published>
    <updated>2012-12-21T17:52:44Z</updated>

    <summary><![CDATA[&nbsp; Thank you for taking the time this year to voice your opinion on AppRights. &nbsp;Many of you have contacted us directly with solutions for mobile privacy concerns. &nbsp; &nbsp; We will be back with the final provision for mobile...]]></summary>
    <author>
        <name>Bond, Slade</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=39</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<div>&nbsp;</div> <div>Thank you for taking the time this year to voice your opinion on AppRights. &nbsp;Many of you have contacted us directly with solutions for mobile privacy concerns. &nbsp;</div> <div>&nbsp;</div> <div>We will be back with the final provision for mobile privacy on Thursday, January 3, when we will discuss transparency for mobile apps. &nbsp;In the meantime, keep in touch by using our secure form,&nbsp;or interacting with us on&nbsp;<a href="https://www.facebook.com/AppRights" target="_blank">Facebook&nbsp;</a>or&nbsp;<a href="http://twitter.com/apprightsus" target="_blank">Twitter</a>.&nbsp;</div> <div>&nbsp;</div> <div>We hope you have a safe and happy holiday, and we look forward to working hard with you in the new year!</div> <p>&nbsp;</p>]]>
        
    </content>
</entry>

<entry>
    <title>Provision Two: Requiring Secure Data Collection</title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2012/12/based-on-your-feedback-the.shtml" />
    <id>tag:apprights-hankjohnson.house.gov,2012://10.2064</id>

    <published>2012-12-19T17:33:16Z</published>
    <updated>2012-12-19T17:45:13Z</updated>

    <summary><![CDATA[&nbsp;Based on your feedback, the second provision of the mobile privacy legislation protects the security of users&rsquo; data. &nbsp;It requires that developers prevent unauthorized access to a user&rsquo;s data, such as a data breach, through reasonable and appropriate security measures....]]></summary>
    <author>
        <name>Bond, Slade</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=39</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<div>&nbsp;</div><div>Based on your feedback, the second provision of the mobile privacy legislation protects the security of users&rsquo; data. &nbsp;It requires that developers prevent unauthorized access to a user&rsquo;s data, such as a data breach, through reasonable and appropriate security measures. &nbsp;</div> <div>&nbsp;</div> <div>Last week, we discussed the <a href="http://apprights-hankjohnson.house.gov/2012/12/provision-one-protecting-your-mobile-privacy-through-user-control.shtml" target="_blank">control provision</a>. &nbsp;Under this provision, users would be able to control data collection by deleting the app at any time, along with their data stored by the app. &nbsp;Within a reasonable period of time, developers would not be able to further collect or use that data. &nbsp;</div> <div>&nbsp;</div> <div>Each provision will have a two-week period for you to let us know about your thoughts and concerns. Once we have heard back from you on all three principles, we will issue another legislative transparency report that explores your feedback before the Congressman introduces legislation.</div> <div>&nbsp;</div> <div><b>Bill Text</b>: Security of personal data and anonymous data.&mdash;The developer of a mobile application shall take reasonable and appropriate measures to prevent unauthorized access to personal data and anonymous data collected by the application.</div> <div>&nbsp;</div> <div><b>Definitions</b>:</div> <div>&nbsp;</div> <div style="margin-left: 40px; ">&bull; The term &ldquo;anonymous data&rdquo; means data from which particular individuals cannot be identified.</div> <div style="margin-left: 40px; ">&bull; The term &ldquo;developer&rdquo; has the meaning given by the Federal Trade Commission by regulation.</div> <div style="margin-left: 40px; ">&bull; The term &ldquo;mobile application&rdquo; means a software program (A) that runs on the operating system of a mobile device; and (B) with which the user of the device directly interacts.</div> <div style="margin-left: 40px; ">&bull; The term &ldquo;mobile device&rdquo; means a smartphone, tablet computer, or similar portable computing device that transmits data over a wireless connection.</div> <div style="margin-left: 40px; ">&bull; The term &ldquo;personal data&rdquo; has the meaning given by the Federal Trade Commission by regulation, but does not include anonymous data.</div> <div>&nbsp;</div> <div>We look forward to your input on the security provision, and hope you will continue to express your views and concerns regarding mobile privacy. By sharing your thoughts with us through our secure form at AppRights.us, or interacting with us on <a href="https://www.facebook.com/AppRights" target="_blank">Facebook </a>or <a href="http://twitter.com/apprightsus" target="_blank">Twitter</a>, we will work together to find the right solutions to each issue.&nbsp;</div> <div>&nbsp;</div>]]>
        
    </content>
</entry>

<entry>
    <title>Provision One: Protecting Your Mobile Privacy through User Control      </title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2012/12/provision-one-protecting-your-mobile-privacy-through-user-control.shtml" />
    <id>tag:apprights-hankjohnson.house.gov,2012://10.2063</id>

    <published>2012-12-05T16:43:27Z</published>
    <updated>2012-12-06T22:03:46Z</updated>

    <summary>Starting today, we are releasing provisions for mobile privacy legislation that relates to the transparency, security, and control principles that received so much of your support. Each provision will have a two-week period for you to let us know about...</summary>
    <author>
        <name>Bond, Slade</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=39</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<p>Starting today, we are releasing provisions for mobile privacy legislation that relates to the transparency, security, and control principles that received so much of your support.  Each provision will have a two-week period for you to let us know about your thoughts and concerns.  Once we have heard back from you on all three principles, we will issue another legislative transparency report that explores your feedback before the Congressman introduces legislation.</p> <p><iframe width="640" height="360" src="https://www.youtube-nocookie.com/embed/AHJysMDo7fk" frameborder="0" allowfullscreen=""></iframe></p><p>The majority of the <a href="http://hankjohnson.house.gov/apprights/Legislative%20Transparency%20Report.pdf" target="_blank">feedback that we received</a> on AppRights expressed strong support for user control.  Many of you also told Congressman Johnson that simple controls are important to protecting your privacy on mobile devices.  After listening to these concerns, we have written a user-control provision to address these concerns without threatening the functionality or integrity of the mobile apps that you love.</p> <p>This provision requires developers to allow users to delete a mobile application at any time, along with users&rsquo; other personal data stored by the application.  Developers must cease to collect or use data within a reasonable period of time after the user has deleted the application.</p> <p><b>Bill Text</b>: Withdrawal of consent.&mdash;The developer of a mobile application shall provide a user of the application with the ability at any time, by deleting the application from the mobile device, to&mdash; (1) delete any personal data stored on the device by the application; and (2) prohibit the developer, within a reasonable and appropriate time thereafter, from engaging in any further use or sharing of personal data collected by the application.</p> <p><b>Definitions</b>:</p> <p style="margin-left: 40px; ">&bull;	The term &ldquo;anonymous data&rdquo; means data from which particular individuals cannot be identified.<br /> &bull;	The term &ldquo;developer&rdquo; has the meaning given by the Federal Trade Commission by regulation.<br /> &bull;	The term &ldquo;mobile application&rdquo; means a software program (A) that runs on the operating system of a mobile device; and (B) with which the user of the device directly interacts.<br /> &bull;	The term &ldquo;mobile device&rdquo; means a smartphone, tablet computer, or similar portable computing device that transmits data over a wireless connection.<br /> &bull;	The term &ldquo;personal data&rdquo; has the meaning given by the Federal Trade Commission by regulation, but does not include anonymous data.</p> <p>The app economy has undoubtedly enriched lives, created jobs, and contributed much to education and culture.  But if data is an asset like any other, developers should be responsible and accountable when collecting data.</p> <p>We look forward to your input on this provision, and hope you will continue to express your views and concerns regarding mobile privacy.  By sharing your thoughts with us through our secure form at AppRights.us, or interacting with us on <a href="https://www.facebook.com/AppRights" target="_blank">Facebook</a> or <a href="http://twitter.com/apprightsus" target="_blank">Twitter</a>, we will work together to find the right solutions to each issue. <br /> &nbsp;</p>]]>
        
    </content>
</entry>

<entry>
    <title>AppRights 2.0: Help Us Write Mobile Privacy Legislation</title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2012/12/introducing-the-second-phase-of-apprights-mobile-privacy-legislation.shtml" />
    <id>tag:apprights-hankjohnson.house.gov,2012://10.2062</id>

    <published>2012-12-03T19:20:10Z</published>
    <updated>2012-12-03T21:06:17Z</updated>

    <summary><![CDATA[When first&nbsp;launching AppRights&nbsp;in July, Congressman Hank Johnson&nbsp;pledged&nbsp;to have an open conversation about privacy on mobile devices.&nbsp; This bottom-up approach to mobile privacy has demonstrated that individuals are passionate about being able to control their privacy, ensure their data is secure,...]]></summary>
    <author>
        <name>Bond, Slade</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=39</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<p><span style="font-size: small; "><span style="font-family: Arial; ">When first&nbsp;</span></span><span style="font-size: small; "><a href="http://hankjohnson.house.gov/press-release/hank-launches-apprights-mobile-privacy-initiative"><span style="font-family: Arial; ">launching AppRights</span></a></span><span style="font-size: small; "><span style="font-family: Arial; ">&nbsp;in July, Congressman Hank Johnson&nbsp;</span></span><span style="font-size: small; "><a href="http://www.reddit.com/r/politics/comments/x4rse/apprightsus_in_which_congress_asks_how_to_protect/"><span style="font-family: Arial; ">pledged</span></a></span><span style="font-size: small; "><span style="font-family: Arial; ">&nbsp;to have an open conversation about privacy on mobile devices.&nbsp; This bottom-up approach to mobile privacy has demonstrated that individuals are passionate about being able to control their privacy, ensure their data is secure, and understand what data an app collects on their mobile device.&nbsp;</span></span></p><p><span style="font-size: small; "><span style="font-family: Arial; ">This feedback provided much insight, coalescing around widely-accepted principles that are backed by ample public support.&nbsp; The FTC&nbsp;</span></span><span style="font-size: small; "><a href="https://mtadmin2.house.gov/johnson/mt-static/plugins/FCKeditor/fckeditor/editor/According%20to%20the%20results%20of%20a%20March%201998%20Business%20Week%20survey,%20consumers%20not"><span style="font-family: Arial; ">reported</span></a></span><span style="font-size: small; "><span style="font-family: Arial; ">&nbsp;similar public concerns in 1998, while studies by the Pew Internet &amp; American Life&nbsp;</span></span><span style="font-size: small; "><a href="http://www.pewinternet.org/Reports/2008/Use-of-Cloud-Computing-Applications-and-Services.aspx"><span style="font-family: Arial; ">demonstrate</span></a></span><span style="font-size: small; "><span style="font-family: Arial; ">&nbsp;that individuals demand accountability, security, control, and transparency.&nbsp;</span></span></p><p><span style="font-size: small; "><span style="font-family: Arial; ">After&nbsp;</span></span><span style="font-size: small; "><a href="https://apprights-hankjohnson.house.gov/2012/08/ltr.shtml"><span style="font-family: Arial; ">hearing back from many of you</span></a></span><span style="font-size: small; "><span style="font-family: Arial; ">, the Congressman has worked hard to galvanize these principles into thoughtful proposals for mobile privacy legislation.&nbsp; These proposals address your primary concerns by creating a legislative framework for control, security, and transparency on mobile devices.&nbsp;</span></span></p><p>&nbsp;</p> <p><span style="font-size: small; "><span style="font-family: Arial; "><img alt="AppRights Stats  2.JPG" src="http://hankjohnson.house.gov/apprights/AppRights%20Stats%20%202.JPG" width="540" height="257" class="mt-image-center" style="text-align: center; display: block; margin: 0 auto 20px;" /></span></span></p> <div><p><span style="font-size: small; "><span style="font-family: Arial; ">Starting this week, we will release each provision of the bill that relates to these principles.&nbsp; Because we received the most input on user control, we will begin the discussion this Wednesday with the control provision.&nbsp; After a two-week comment period, we will post the next provision. &nbsp;Once we have reviewed the major principles, we will issue another legislative transparency report that examines the feedback that we receive.</span></span></p><p><span style="font-size: small; "><span style="font-family: Arial; ">We will continue to keep AppRights open and transparent by posting discussions on the meetings that we have with stakeholders and public-interest groups.&nbsp; Above all, we will continue to listen.&nbsp; By sharing your thoughts with us through our secure form at&nbsp;</span></span><span style="font-size: small; "><a href="http://www.apprights.us/" target="_blank"><span style="font-family: Arial; ">AppRights.us</span></a></span><span style="font-size: small; "><span style="font-family: Arial; ">, or interacting with us on&nbsp;</span></span><span style="font-size: small; "><a href="https://www.facebook.com/AppRights" target="_blank"><span style="font-family: Arial; ">Facebook</span></a></span><span style="font-size: small; "><span style="font-family: Arial; ">&nbsp;or&nbsp;</span></span><span style="font-size: small; "><a href="http://twitter.com/apprightsus" target="_blank"><span style="font-family: Arial; ">Twitter</span></a></span><span style="font-size: small; "><span style="font-family: Arial; ">, we will work together to find the right solutions to each issue.&nbsp;</span></span></p></div>]]>
        
    </content>
</entry>

<entry>
    <title>Legislative Transparency Report: A Look at Feedback for AppRights</title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2012/08/ltr.shtml" />
    <id>tag:hankjohnson.house.gov,2012:/apprights//10.2061</id>

    <published>2012-08-23T15:00:34Z</published>
    <updated>2012-12-03T19:35:02Z</updated>

    <summary>When we first launched AppRights, Congressman Hank Johnson pledged to keep everyone informed as we explore legislative options. To keep this process open and transparent, we have used the AppRights blog to discuss our meetings with industry stakeholders and advocacy...</summary>
    <author>
        <name>Bond, Slade</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=39</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<p>When we first launched AppRights, Congressman Hank Johnson pledged to keep everyone informed as we explore legislative options.  <br /> <br /> To keep this process open and transparent, we have used the AppRights blog to discuss our meetings with industry stakeholders and advocacy groups.</p> <p>We have also engaged the internet community on <a href="https://www.facebook.com/AppRights" target="_blank">Facebook</a>, <a href="http://twitter.com/apprightsus" target="_blank">Twitter</a>, and <a href="http://www.reddit.com/r/politics/comments/x4rse/apprightsus_in_which_congress_asks_how_to_protect/" target="_blank">Reddit</a>.  In a <a href="http://hankjohnson.house.gov/apprights/2012/08/privchat.shtml">live chat on Twitter</a>, we asked several questions about how Congress can protect users&rsquo; mobile privacy. Congressman Johnson even <a href="http://twitter.com/RepHankJohnson/status/230339540223660033" target="_blank">dropped by</a> from the campaign trail to participate in the conversation.<br /> <br /> Inspired by the efforts of <a href="http://blog.twitter.com/2012/07/twitter-transparency-report.html" target="_blank">Twitter</a> and <a href="http://googleblog.blogspot.com/2012/06/more-transparency-into-government.html" target="_blank">Google</a>, we are also launching a Legislative Transparency Report to show the feedback we have received for AppRights.  This report includes information on the principles that users are most concerned with, and whether people support legislative options to mobile privacy concerns.  <br /> <br /> The <a href="http://hankjohnson.house.gov/apprights/Legislative%20Transparency%20Report.pdf" target="_blank">Legislative Transparency Report</a> shows that people who are engaging AppRights are predominantly concerned with control over their privacy.  Similarly, many people are also concerned about the security of their data on mobile devices.  Most people support legislation in this area, while a minority of feedback has expressed strong opposition to regulating mobile devices.      <br /> <br /> We hope that these steps continue to shed light on how the internet community, industry stakeholders, and public-interest groups have interacted with Congressman Johnson on mobile privacy.  <br /> <br /> We continue to believe in the importance of working with the Internet and these groups before proposing solutions to users&rsquo; growing privacy concerns.  Stay in touch with us via the secure form at <a href="http://www.apprights.us/" target="_blank">AppRights.us</a>, or interact with us on <a href="https://www.facebook.com/AppRights" target="_blank">Facebook</a> or <a href="http://twitter.com/apprightsus" target="_blank">Twitter</a>.</p> <p><i>(Special thanks to Ariel Shapiro, intern for Rep. Hank Johnson, for her help gathering data for the Legislative Transparency Report)</i></p> <p>&nbsp;</p>]]>
        
    </content>
</entry>

<entry>
    <title>Gamers Weigh In: The Entertainment Consumers Association Supports a Bottom-Up Approach to Internet Legislation</title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2012/08/eca.shtml" />
    <id>tag:hankjohnson.house.gov,2012:/apprights//10.2055</id>

    <published>2012-08-15T16:51:16Z</published>
    <updated>2012-12-03T19:34:27Z</updated>

    <summary><![CDATA[We continue to receive terrific feedback on AppRights from consumers, public-interest groups, and stakeholders. &nbsp;We recently heard from Jennifer Mercurio, the Vice President and General Counsel of the Entertainment Consumers Association (ECA), a non-profit organziation dedicated to representing consumers in...]]></summary>
    <author>
        <name>Bond, Slade</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=39</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<p><span style="font-size: small; "><span style="font-family: Arial; ">We continue to receive terrific feedback on AppRights from consumers, public-interest groups, and stakeholders. &nbsp;</span></span></p><p><span style="font-size: small; "><span style="font-family: Arial; ">We recently heard from Jennifer Mercurio, the Vice President and General Counsel of the </span></span><a href="http://www.theeca.com/" target="_blank"><span style="font-size: small; "><span style="font-family: Arial; ">Entertainment Consumers Association</span></span></a><span style="font-size: small; "><span style="font-family: Arial; "> (ECA), a non-profit organziation dedicated to representing consumers in the digital rights arena. &nbsp;The ECA works on behalf of gamers, film, and music consumers and is dedicated to giving &quot;gamers a collective voice with which to communicate their concerns, address their issues and focus their advocacy efforts.&quot; &nbsp;The ECA has over one-million members that include families, carriers, and mobile devices makers who are concerned about issues like privacy, cybersecurity, and streaming. &nbsp;</span></span></p><p><span style="font-size: small; "><span style="font-family: Arial; "><span style="text-align: center; ">In her letter to the Congressman, Mercurio applauds AppRights for recognizing the &quot;faults in previous legislative attempts and are working to correct them.&quot; &nbsp;In contrast, she pointed out that Congress is &quot;generally deaf to the concerns of consumers,&quot; as shown by legislation like SOPA and CISPA failing in the face of overwhelming disapproval.&nbsp;</span></span></span></p><p><span style="font-size: small; "><span style="font-family: Arial; ">Congressman Johnson agrees: &ldquo;We've all seen what happens when Congress tries to shove legislation down the public's throat without asking the internet what it thinks first,&rdquo; which is why he </span></span><span style="font-size: small; "><a href="https://twitter.com/RepHankJohnson/status/160088341600153600" style="font-family: Arial, sans-serif; font-size: 11pt; "><span style="font-family: Arial; ">opposed SOPA</span></a><span style="font-family: Arial; ">&nbsp;and&nbsp;</span></span><span style="font-size: small; "><a href="http://www.youtube.com/watch?v=xuZR0Wl9rr4&amp;feature=player_embedded" style="font-family: Arial, sans-serif; font-size: 11pt; "><span style="font-family: Arial; ">compared CISPA to &quot;1984&quot;</span></a><span style="font-family: Arial; ">.  </span></span></p><p><span style="font-size: small; "><span style="font-family: Arial; ">We had a chance to catch up with Mercurio to learn more about the perspective of gamers and media-content consumers on mobile privacy.&nbsp; She explained that this is a large community that is passionate about privacy and cybersecurity.&nbsp; </span></span></p><p><o:p></o:p><span style="font-size: small; "><span style="font-family: Arial; ">    Mercurio emphasized that control is an important principle to this community, adding that this is particularly true for parents worried about their children&rsquo;s privacy.&nbsp; &ldquo;Each consumer should be able to control their own privacy,&rdquo; Mercurio concluded. &nbsp;</span></span><o:p></o:p></p><p><o:p></o:p></p><p><span style="font-size: small; "><span style="font-family: Arial; ">Here&rsquo;s a copy of her letter on behalf of the ECA.&nbsp; Let us know if you agree with her take on internet policy via our secure form at<span class="apple-converted-space">&nbsp;</span></span></span><span style="font-family: Arial, sans-serif; "><span style="font-size: small; "><a href="https://hankjohnsonforms.house.gov/apprights/"><span style="font-family: Arial; "><span style="border: 1pt none windowtext; padding: 0in; ">AppRights.us</span></span></a><span style="font-family: Arial; ">, via Twitter (</span></span><span style="font-size: small; "><a href="http://www.twitter.com/apprightsus"><span style="font-family: Arial; "><span style="border: 1pt none windowtext; padding: 0in; ">@AppRightsUS</span></span></a><span style="font-family: Arial; ">), or on<span class="apple-converted-space">&nbsp;</span></span></span></span><span style="font-size: small; "><span style="font-family: Arial, sans-serif; "><a href="https://www.facebook.com/AppRights"><span style="font-family: Arial; "><span style="border: 1pt none windowtext; padding: 0in; ">Facebook</span></span></a></span><span style="font-family: Arial; ">.&nbsp; &nbsp; &nbsp; &nbsp;</span></span></p><p><span style="font-size: small; ">&nbsp;</span></p><p><span style="font-size: small; "><img alt="ECA.JPG" src="http://hankjohnson.house.gov/apprights/ECA.JPG" width="600" height="498" class="mt-image-center" style="text-align: center; display: block; margin: 0 auto -10px;" /></span></p>]]>
        
    </content>
</entry>

<entry>
    <title> How Should We Protect Children&apos;s Safety on Mobile Devices? AppRights Meets with the Family Online Safety Institute (FOSI)   </title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2012/08/how-should-we-protect-childrens-safety-on-mobile-devices-apprights-meets-with-the-family-online-safe.shtml" />
    <id>tag:hankjohnson.house.gov,2012:/apprights//10.2054</id>

    <published>2012-08-15T15:17:07Z</published>
    <updated>2012-12-03T19:36:38Z</updated>

    <summary><![CDATA[Jennifer Hanley and Emma Morris of the Family Online Safety Institute (FOSI) recently provided Congressman Johnson&rsquo;s office with a briefing on children&rsquo;s privacy. FOSI is an international, non-profit organization working to make &ldquo;the online world safer for kids and their...]]></summary>
    <author>
        <name>Bond, Slade</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=39</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<p>Jennifer Hanley and Emma Morris of the <a href="http://www.fosi.org/about-fosi/fosi-mission.html" target="_blank">Family Online Safety Institute</a> (FOSI) recently provided Congressman Johnson&rsquo;s office with a briefing on children&rsquo;s privacy.  FOSI is an international, non-profit organization working to make &ldquo;the online world safer for kids and their families.&rdquo;</p> <p>Hanley, FOSI&rsquo;s legal and policy manager, applauded Congressman Johnson for initiating AppRights, which she called a &ldquo;fascinating project&rdquo; that engages stakeholders and constituents.</p> <p>Hanley also brought our office up to speed on FOSI&rsquo;s work in children&rsquo;s online safety.  Last year, FOSI commissioned a <a href="http://www.fosi.org/research/900-who-needs-parental-controls.html" target="_blank">study</a>&nbsp;that explored parents&rsquo; views about online safety.</p> <p>Although this study found that most parents feel secure about children&rsquo;s safety online, it also demonstrated that parents become increasingly concerned when children engage other platforms like smartphones and handheld devices to access content online.   Another <a href="http://pewinternet.org/Reports/2011/Teens-and-social-media/Summary.aspx" target="_blank">study</a>&nbsp;that Hanley provided points out that 93% of parents have discussed mobile safety with their children.</p> <p>&nbsp;<img alt="FOSI 2.bmp" src="http://hankjohnson.house.gov/apprights/FOSI%202.bmp" width="600" height="218" class="mt-image-center" style="text-align: left; display: block; margin: 0 auto 0px;" /></p> <p>Morris, FOSI&rsquo;s international policy counsel, also provided an overview of the European Union&rsquo;s recent efforts in mobile privacy.  She highlighted the complicated nature of creating uniform transatlantic laws because of the different countries&rsquo; norms and morals on privacy.  She also discussed several emerging regulatory efforts abroad.</p> <p>In a brief on <a href="http://www.fosi.org/fosi-events/european-forum-2012.html" target="_blank">Safety and Privacy in a Digital Europe</a>  she concluded that if European &ldquo;companies share the principles of privacy and safety for all, the call for regulation will diminish.&rdquo;  Morris noted that policymakers should consider these efforts before enacting privacy legislation in the United States.</p> <p>Congressman Johnson will address children&rsquo;s safety online at the Congressional Award Foundation&rsquo;s <a href="http://www.congressionalaward.org/events/YouthTech.php" target="_blank">Youth and Technology Dinner</a> in September, where he will co-chair the dinner and discuss the new technology challenges that face today&rsquo;s youth.</p> <p>Let us know what you think about these issues via the secure form at <a href="https://hankjohnsonforms.house.gov/apprights/">AppRights.us</a>, via Twitter (<a href="http://www.twitter.com/apprightsus">@AppRightsUS</a>), or on <a href="https://www.facebook.com/AppRights">Facebook</a>.</p>]]>
        
    </content>
</entry>

<entry>
    <title>AppRights Takes the Legislative Process to Twitter via #PrivChat</title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2012/08/privchat.shtml" />
    <id>tag:hankjohnson.house.gov,2012:/apprights//10.2047</id>

    <published>2012-08-02T14:45:00Z</published>
    <updated>2012-12-03T19:35:42Z</updated>

    <summary><![CDATA[Tuesday afternoon, Congressman Johnson and the AppRights team opened up the legislative process to the privacy community on Twitter. #PrivChat's co-hosts, Amie Stepanovich of the Electronic Privacy Information Center (EPIC) and Shaun Dakin of Dakin &amp; Associates, invited @RepHankJohnson and...]]></summary>
    <author>
        <name>Ossoff, Jonathan</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=29</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<p>Tuesday afternoon, Congressman Johnson and the AppRights team opened up the legislative process to the privacy community on Twitter.<br /> <br /> <a target="_blank" href="https://epic.org/privchat/">#PrivChat</a>'s co-hosts, <a href="http://www.twitter.com/astepanovich">Amie Stepanovich</a> of the <a href="https://epic.org/" target="_blank">Electronic Privacy Information Center</a> (EPIC) and <a href="http://www.twitter.com/privacycamp" target="_blank">Shaun Dakin</a> of Dakin &amp; Associates, invited <a href="http://www.twitter.com/RepHankJohnson" target="_blank">@RepHankJohnson</a> and <a href="http://www.twitter.com/AppRightsUS" target="_blank">@AppRightsUS</a> to join the weekly discussion as featured guests.&nbsp; We were honored to accept.<br /> <br /> The AppRights team took the opportunity to ask critical questions about how Congress can ensure the privacy of mobile device users.&nbsp; Congressman Johnson took time out of a busy day on the campaign trail to drop in on the conversation.</p> <blockquote class="twitter-tweet "> <p>Hey y&rsquo;all. It&rsquo;s election day down here but I wanted to take a sec to drop in on <a href="https://twitter.com/search/%23PrivChat"><s>#</s><b>PrivChat</b></a>. <a href="https://twitter.com/apprightsus"><s>@</s><b>apprightsus</b></a> <a href="http://t.co/EbdvmhEM" title="http://twitter.com/RepHankJohnson/status/230339540223660033/photo/1">twitter.com/RepHankJohnson&hellip;</a></p> &mdash; Rep. Hank Johnson (@RepHankJohnson) <a href="https://twitter.com/RepHankJohnson/status/230339540223660033" data-datetime="2012-07-31T16:30:01+00:00">July 31, 2012</a></blockquote> <script src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <p><br /> <br /> Our first question: whether <a target="_blank" href="http://www.pcworld.com/article/192803/geolocation_101_how_it_works_the_apps_and_your_privacy.html">geolocation</a> is the most important privacy issue for mobile users.<br /> <br /> A <a target="_blank" href="http://www.pewinternet.org/Reports/2009/14--Teens-and-Mobile-Phones-Data-Memo.aspx">study</a> by the Pew Research Center found 77% of adults used a mobile device in 2008.&nbsp; As more users flock to smartphones with GPS technology, there is a <a target="_blank" href="http://www.nytimes.com/2012/07/15/sunday-review/thats-not-my-phone-its-my-tracker.html">growing</a> concern that mobile devices are becoming de facto tracking devices.&nbsp; As Peter Maass and Megha Rajagopalan wrote recently in the <i>New York Times</i>:</p> <p style="margin-left: 40px;"><i>&ldquo;Thanks to the explosion of GPS technology and smartphone apps, these devices are also taking note of what we buy, where and when we buy it, how much money we have in the bank, whom we text and e-mail, what Web sites we visit, how and where we travel, what time we go to sleep and wake up &mdash; and more.&rdquo; </i></p> <p>A number of the experts and advocates responded to our question.&nbsp; <a target="_blank" href="http://twitter.com/rwchambliss">Wayne Chambliss</a> of <a target="_blank" href="http://geoloqi.com/">Geoloqi</a> wrote:</p> <blockquote data-in-reply-to="230333727614590976" class="twitter-tweet "> <p><a href="https://twitter.com/epicprivacy"><s>@</s><b>epicprivacy</b></a> A1: Inasmuch as geolocation contextualizes (and even de-anonymizes) other mobile consumer data sets, I think so. <a href="https://twitter.com/search/%23privchat"><s>#</s><b>privchat</b></a></p> &mdash; Wayne Chambliss (@rwchambliss) <a data-datetime="2012-07-31T16:09:12+00:00" href="https://twitter.com/rwchambliss/status/230334305111523328">July 31, 2012</a></blockquote> <script src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <p><br /> <br /> <a href="https://twitter.com/jim_adler" target="_blank">Jim Adler</a>, the chief privacy officer at <a target="_blank" href="http://www.intelius.com/">Intelius</a>, asked a philosophical question with serious privacy (and policy) implications:<br /> &nbsp;</p> <blockquote class="twitter-tweet " data-in-reply-to="230333727614590976"> <p><a href="https://twitter.com/epicprivacy"><s>@</s><b>epicprivacy</b></a> A1: Is WHERE you are WHO you are? <a href="https://twitter.com/search/%23privchat"><s>#</s><b>privchat</b></a></p> &mdash; Jim Adler (@jim_adler) <a href="https://twitter.com/jim_adler/status/230334444152688640" data-datetime="2012-07-31T16:09:45+00:00">July 31, 2012</a></blockquote> <script src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <p><br /> &nbsp;<br /> But others disagreed, or pointed to other issues.&nbsp; <a target="_blank" href="http://twitter.com/patrickgage">Patrick Gage Kelley</a>, an assistant professor of computer science at the University of New Mexico, thought that users&rsquo; location is less important:<br /> &nbsp;</p> <blockquote class="twitter-tweet "> <p>A1: Geolocation is NOT most important. Easy to trumpet as a protection, users will share location anyway. It's a false privacy. <a href="https://twitter.com/search/%23privchat"><s>#</s><b>privchat</b></a></p> &mdash; Patrick Gage Kelley (@patrickgage) <a data-datetime="2012-07-31T16:24:35+00:00" href="https://twitter.com/patrickgage/status/230338175669784576">July 31, 2012</a></blockquote> <script src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <p><br /> <br /> Next, we asked whether transparency is the most important principle for mobile privacy or if other principles, like individual control, are more important.&nbsp; The team at <a href="http://blog.hibe.com/hibe/what-is-hibe/" target="_blank">Hibe</a>, a social media platform, weighed in:<br /> &nbsp;</p> <blockquote class="twitter-tweet "> <p>A2: Disclosure, Transparency are really key. These allow users to act according, remove apps, change behaviour, etc. <a href="https://twitter.com/search/%23privchat"><s>#</s><b>privchat</b></a></p> &mdash; Hibe (@Hibecom) <a href="https://twitter.com/Hibecom/status/230336816014819328" data-datetime="2012-07-31T16:19:11+00:00">July 31, 2012</a></blockquote> <script src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <p><br /> <br /> Geoloqi's Wayne Chambliss argued that user control is as or more important than transparency -- steering the car is just as important as seeing through the windshield:<br /> &nbsp;</p> <blockquote data-in-reply-to="230336088030453761" class="twitter-tweet "> <p><a href="https://twitter.com/epicprivacy"><s>@</s><b>epicprivacy</b></a> A2: Without user control, transparency is worthless except forensic scenarios. It's an entangled hierarchy. <a href="https://twitter.com/search/%23privchat"><s>#</s><b>privchat</b></a></p> &mdash; Wayne Chambliss (@rwchambliss) <a data-datetime="2012-07-31T16:29:53+00:00" href="https://twitter.com/rwchambliss/status/230339508871258112">July 31, 2012</a></blockquote> <script src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <p><br /> &nbsp;<br /> We still have serious questions about whether transparency alone is enough.&nbsp; In fact, we have serious questions about whether transparency and user control are even enough together.&nbsp; <br /> <br /> Does the federal government need to step in and set some minimum standards for the handling of consumers' data?&nbsp; Can we simply rely on consumers to make responsible decisions once information is available to them?&nbsp; We asked the question:</p> <blockquote class="twitter-tweet " data-in-reply-to="230336816014819328"> <p><a href="https://twitter.com/hibecom"><s>@</s><b>hibecom</b></a> A2 This gets to heart of legislative dilemma. Informing vs. protecting consumers. <a href="https://twitter.com/search/%23privchat"><s>#</s><b>privchat</b></a></p> &mdash; AppRights (@AppRightsUS) <a href="https://twitter.com/AppRightsUS/status/230337376877158400" data-datetime="2012-07-31T16:21:24+00:00">July 31, 2012</a></blockquote> <script src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <p><br /> <br /> We think this is one of the critical unanswered questions.&nbsp; We raised it in <a target="_blank" href="http://hankjohnson.house.gov/apprights/2012/07/effs-mobile-user-privacy-bill-of-rights.shtml">our initial reaction to EFF's Mobile User Privacy Bill of rights</a>, as well.&nbsp; We want to hear from you!<br /> <br /> Moving to children&rsquo;s online safety, our third question was whether the <a target="_blank" href="http://www.govtrack.us/congress/bills/112/hr1895">Do Not Track Kids Act</a> is constructive legislation to protect children&rsquo;s mobile privacy.&nbsp; We also asked whether legislation should distinguish between children and adults in the first place.<br /> <br /> Jim Adler thought that children differ from adults and deserve stronger privacy protections:</p> <blockquote data-in-reply-to="230340962151440384" class="twitter-tweet "> <p><a href="https://twitter.com/apprightsus"><s>@</s><b>apprightsus</b></a> A3: Kids have a higher privacy barrier even when in public, because they're more vulnerable. <a href="https://twitter.com/search/%23privchat"><s>#</s><b>privchat</b></a></p> &mdash; Jim Adler (@jim_adler) <a data-datetime="2012-07-31T16:40:08+00:00" href="https://twitter.com/jim_adler/status/230342088082989056">July 31, 2012</a></blockquote> <script src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <p><br /> &nbsp;<br /> But <a target="_blank" href="https://twitter.com/JasmineMcNealy">Jasmine McNealy</a>, an Assistant Professor at Syracuse University's <a target="_blank" href="http://newhouse.syr.edu/">Newhouse School of Public Communications</a>, expressed concern that separating children and adults raises First Amendment speech issues like vagueness and overbreadth.&nbsp; Referring to the <a target="_blank" href="http://www.govtrack.us/congress/bills/112/hr1895">Do Not Track Kids Act,</a> she wrote:</p> <blockquote class="twitter-tweet" data-in-reply-to="230343190992023553"> <p><a href="https://twitter.com/apprightsus"><s>@</s><b>apprightsus</b></a> A3: Which ever provisions are saved must have concrete defs &amp; be targeted only on activities/speech that affect kids <a href="https://twitter.com/search/%23privchat"><s>#</s><b>privchat</b></a></p> &mdash; Jasmine McNealy (@JasmineMcNealy) <a href="https://twitter.com/JasmineMcNealy/status/230343995040079872" data-datetime="2012-07-31T16:47:42+00:00">July 31, 2012</a></blockquote> <script src="//platform.twitter.com/widgets.js" charset="utf-8"></script> <p><br /> <br /> We enjoyed and benefited from the #PrivChat discussion and we're glad Congressman Johnson was able to join us.&nbsp; He launched AppRights to make the legislative process as transparent and open as possible, and we look forward to hearing more ideas about how we can empower and protect mobile-device users.<br /> <br /> Get in touch via the <a href="http://www.apprights.us">secure form at AppRights.us</a>, Twitter (<a target="_blank" href="http://www.twitter.com/AppRightsUS">@AppRightsUS</a>), or <a target="_blank" href="http://www.facebook.com/apprights">Facebook</a>.</p>]]>
        
    </content>
</entry>

<entry>
    <title>EFF&apos;s &apos;Mobile User Privacy Bill of Rights&apos; - A Starting Point for Legislation?</title>
    <link rel="alternate" type="text/html" href="http://apprights-hankjohnson.house.gov/2012/07/effs-mobile-user-privacy-bill-of-rights.shtml" />
    <id>tag:hankjohnson.house.gov,2012:/apprights//10.2040</id>

    <published>2012-07-31T14:45:00Z</published>
    <updated>2012-07-31T15:00:55Z</updated>

    <summary><![CDATA[By the AppRights team Last week, Adi Kamdar at the Electronic Frontier Foundation wrote about Congressman Johnson's AppRights project for EFF's &quot;Deeplinks&quot; blog. Introducing Congressman Johnson as &quot;a friend of the Internet,&quot; Kamdar described AppRights as a &quot;heartening&quot; effort &quot;to...]]></summary>
    <author>
        <name>Ossoff, Jonathan</name>
        <uri>http://apprights-hankjohnson.house.gov/johnson/mt-cp.cgi?__mode=view&amp;blog_id=10&amp;id=29</uri>
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://apprights-hankjohnson.house.gov/">
        <![CDATA[<p><b>By the AppRights team<br />    </b></p>    <p>Last week, <a target="_blank" href="https://twitter.com/adikamdar">Adi Kamdar</a> at the Electronic Frontier Foundation <a target="_blank" href="https://www.eff.org/deeplinks/2012/07/rep-hank-johnsons-apprights-seeks-feedback-mobile-privacy">wrote about Congressman Johnson's AppRights project</a> for EFF's &quot;Deeplinks&quot; blog.<br />    <br />    Introducing Congressman Johnson as &quot;a friend of the Internet,&quot; Kamdar described AppRights as a &quot;heartening&quot; effort &quot;to stand up for privacy rights.&quot;&nbsp; Kamdar also wrote that EFF hopes Congressman Johnson and the AppRights team will take a close look at EFF's Mobile Privacy Bill of Rights:</p>    <p style="margin-left: 40px;"><i>Mobile privacy and consumer rights are important issues to EFF, and we hope that Rep. Johnson keeps our previous work on the topic in mind&mdash;most notably our </i><a target="_blank" href="https://www.eff.org/deeplinks/2012/03/best-practices-respect-mobile-user-bill-rights"><i>Mobile User Privacy Bill of Rights</i></a><i>. This document contains key points for developers to keep in mind when it comes to respecting their users' privacy&mdash;including transparently focusing data collection on solely what is needed, as well as giving users more control over their personal data.</i></p>    <p>EFF's Mobile User Privacy Bill of Rights proposes six mobile privacy principles:</p>    <ol>        <li><p><b>Individual control</b>: &quot;Users have a right to exercise control over what personal data applications collect about them and how they use it.&nbsp; ...&nbsp; The right to individual control also includes the ability to remove consent and withdraw that data from application servers.&quot;</p></li>        <li><p><b>Focused data collection</b>: &quot;Address book information and photo collections have already been the subject of major privacy stories and user backlash.Other especially sensitive areas include location data, and the contents and metadata from phone calls and text messages. Developers of mobile applications should only collect the minimum amount required to provide the service, with an eye towards ways to archive the functionality while anonymizing personal information.&quot;</p></li>        <li><p><b>Transparency</b>: &quot;Users need to know what data an app is accessing, how long the data is kept, and with whom it will be shared. Users should be able to access human-readable privacy and security policies, both before and after installation.&quot;</p></li>        <li><p><b>Respect for context</b>: &quot;Applications that collect data should only use or share that data in a manner consistent with the context in which the information was provided.&nbsp; ...&nbsp; When the developer wants to make a secondary use of the data, it must obtain explicit opt-in permission from the user.&quot;</p></li>        <li><p><b>Security</b>: &quot;Developers are responsible for the security of the personal data they collect and store. That means, for example, that it should be encrypted wherever possible, and data moving between a phone and a server should always be encrypted at the transport layer.&quot;</p></li>        <li><p><b>Accountability</b>: &quot;Ultimately, all actors in the mobile industry are responsible for the behavior of the hardware and software they create and deploy. Users have a right to demand accountability from them.&quot;</p></li>    </ol>    <p>In the same document, EFF proposes developers' best practices consistent with these principles:</p>    <div style="float:left; width:360px;"><ul>                    <li><b>Anonymizing and obfuscation</b></li>                    <li><b>Secure data transit</b></li>                    <li><b>Secure data storage</b></li>                    <li><b>Internal security</b></li>                    <li><b>Penetration&nbsp;testing</b></li>                    <li><b>Do Not Track</b></li>                </ul></div>   <div style="float:left; width:120px; height:63px;"><img width="92" height="63" alt="efflogo.png" src="http://hankjohnson.house.gov/apprights/efflogo.png" /><br />                <span style="font-size: smaller;">Electronic Fronti</span><span style="font-size: smaller;">er Foundation</span></div>    <div style="clear:both;">&nbsp;</div>         <p>EFF's baseline principles (and best development practices) for an effective mobile privacy regime are great food for thought.<br />        <br />        Could EFF's Mobile User Privacy Bill of Rights be the starting point for legislation?&nbsp; Several questions come to mind right away.<br />        <br />        Which of these principles should be enforced by law?&nbsp; Would self-regulation better realize any of them?&nbsp; Should we rely on ourselves as consumers to make informed decisions that incentivize best practices by developers?&nbsp; Might legal enforcement of these principles impede innovation?&nbsp; And, of course, are there any rights or principles missing from this list?<br />        <br />        We look forward to continuing the dialogue with EFF, and we want to hear from you. Get in touch via <a href="http://www.apprights.us">the secure form at AppRights.us</a>, Twitter (<a target="_blank" href="http://www.twitter.com/AppRightsUS">AppRightsUS</a>), or <a href="http://www.facebook.com/AppRights">Facebook</a>.</p>]]>
        
    </content>
</entry>

</feed>
