SlideShare una empresa de Scribd logo
1 de 22
Old COPPA, New COPPA
“Get Out of Jail Free”
500 Startups – MamaBear Conference
Presented by Shai Samet
May 10, 2013
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
Basic COPPA equation
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
2
personal
information
collected from
child under 13
via the web
(site, app, tablet, etc.)
Verifiable Parental Consent
(plus other requirements)
User acquisition costs
(kidSAFE survey – Jan 2013)
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
3
Companies polled: AOL, Fantage, Gaia Online, Highlights for Kids, Pearson, TBS, WebKinz, many others
Penalties for non-compliance
• Up to $16,000 per violation
• Over 20 FTC lawsuits and $8.4 million in fines since 2000
• Recent fines for COPPA violations:
– Path (app developer) – $800,000
– Artist Arena (various music artist sites) – $1,000,000
– RockYou (social game site) – $250,000
– Disney’s Playdom (for violations by acquired company) – $3,000,000
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
4
Old COPPA vs. New COPPA
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
Key information and features
regulated under new COPPA
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
6
CONTACT INFO
First and Last Name
Home/mailing address
Email address
Phone numbers
Social Security Number
“personal information”
SCREEN/USER NAME
“personal” in some scenarios
(email, AIM, Skype name, etc.)
THIRD PARTY PLUG-INS
Integration with no VPC
means strict liability
GEOLOCATION
“personal” unless location is
not detailed enough
BEHAVIORAL ADS/PROFILES
“personal” if tracking across
multiple services & over time
PHOTOS, VIDEOS, AUDIO
“personal” if contains
image or voice of child
Photos, videos, audio files
(SnapChat, Faces iMake illustrations)
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
7
temporary viewing by others = “collection/disclosure”
faces alone (with no other PI) = VPC
Geolocation information
(News-O-matic illustration)
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
8
Opt-in prompt not enough under new COPPA
Consider coarse location or not uploading the data
Behavioral ads and social plugins
(WebKinz, NeoPets illustrations)
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
9
Behavioral ads no more (contextual ads OK)
FB Connect needs VPC (link to fan page OK)
Verifiable Parental Consent
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
Current options for parental consent
Method Providers Limitations
• Email Plus consent
Internally-
implemented
• Requires parent to activate via email comm’s
• Not sufficient if info will be shared/publicized
• Signed consent form N/A
• Manual
• Requires access to printer and scanner/fax
• Not mobile friendly
Monetary transaction
Payment
processors
• Requires credit card entry and payment
• Payment via PayPal also sufficient
• [Collection of iTunes password not sufficient]
• Phone call or video
conference
N/A
• Manual
• Requires live and trained personnel
• Video-conference requires device with camera
• Govt-issued ID Various
• Requires sharing of highly-sensitive information
• Not ideal for foreign users
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
11
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
12
Likelihood of industry adoption
(kidSAFE survey – Jan 2013)
Penalties for non-compliance
(just a reminder)
• Up to $16,000 per violation
• Over 20 FTC lawsuits and $8.4 million in fines since 2000
• Recent fines for COPPA violations:
– Path (app developer) – $800,000
– Artist Arena (various music artist sites) – $1,000,000
– RockYou (social game site) – $250,000
– Disney’s Playdom (for violations by acquired company) – $3,000,000
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
13
Considerations for Startups and Investors
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
Scaling user growth
(COPPA techniques and loopholes)
• Anonymize child-directed features
– Limit sign-up process to anonymous info (username, password, etc.)
– For interactive features (chat, UGC), filter on the back-end to avoid upfront consent requirement
– For mobile features (geo-location, photos), keep data local to the device (do not upload/share)
– Utilize COPPA’s parental consent exceptions for other features
• Direct your account sign-up process to older users (when allowed)
– If kids under 13 not your “primary audience”, you can limit registration to users 13 and older
– On sites/apps directed to preschoolers, collect registration info from parents/adults
– Put behavioral ads and social plug-ins behind special parents section (or 13+ section)
• When parental consent is required, use least burdensome method
– Avoid collection of payment solely for consent purposes
– Avoid collection of govt-issued ID (last 4 of SSN, driver’s license)
– Consider email-based consent as first option
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
15
Parent-directed registration
(StoryBots illustration)
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
16
Messaging on the page and within data fields must be clearly directed to parents
Parent lock for social features
(StoryBots, TocaBoca app illustrations)
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
17
Math problem before access to web or social sharing features
Swipe to access parents section or apps for sale
Most viable revenue streams
(under new COPPA)
• E-commerce and retail (tied to compelling content or experience)
– Virtual goods, subscriptions, premium content/features (e.g., Wizard 101)
– Game/app downloads, in-app purchases (e.g., Minecraft, Toca Boca)
– Tablets, toys, offline merchandise (e.g., Nabi, Skylanders, Moshi Monsters)
– Brands/stories with TV or licensing potential
• Contextual ads
– Display, text, or video ads (all OK)
– NOT behaviorally-targeted or retargeted ads
• NOT models dependent heavily on social sharing/connections
– Hard to scale with current COPPA restrictions
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
18
Distribution ideas
• Kid-directed platforms
– Popular gaming portals (e.g., Miniclip)
– Kids’ tablets (e.g., nabi, Kurio)
– Other curated environments (e.g., Zui.com, Magic Desktop)
• Schools
– For properties with educational, nutritional, or creative utility (e.g., myNutratek, Minecraft)
– Schools/teachers can provide consent in lieu of parents
• Participation in kidSAFE
– Get noticed by users visiting our site from other popular sites/properties
– Reach our growing database of parents
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
19
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
20
About kidSAFE Seal Program
• Leading safety “seal of approval” program
– Certifying kid-directed sites, apps, software, tablets, and other technologies – GLOBALLY
– Over 100 seal holders since public launch in April 2012
– Fast becoming the industry standard for “online safety”
• kidSAFE+ membership offers full COPPA audit
– Qualifiers receive prestigious kidSAFE+ Seal and many other benefits
– Application for FTC approval coming soon
• Business-friendly, responsive, and highly knowledgeable
– Founder is former attorney and long-time COPPA expert
• For more info, visit kidsafeseal.com or email shai@kidsafeseal.com
Some of our customers
WEBANDPC
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
21
MOBILE
Collectively, these few sites alone account for over 15M unique visitors a month in the US alone (Source: Compete.com)
Questions?
(happy to share the deck)
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
Upcoming kidSAFE Webinar on COPPA – May 30, 2013
(featuring open Q&A session with the FTC)
REGISTER HERE

Más contenido relacionado

Destacado

Fast Company, SMASH summit Presentation
Fast Company, SMASH summit PresentationFast Company, SMASH summit Presentation
Fast Company, SMASH summit Presentation
500 Startups
 
Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013
Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013
Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013
500 Startups
 
Enchanted Diamonds
Enchanted DiamondsEnchanted Diamonds
Enchanted Diamonds
500 Startups
 
Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013
Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013
Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013
500 Startups
 
unSEXY Conf 2013: Isaac Saldana, SendGrid
unSEXY Conf 2013: Isaac Saldana, SendGrid unSEXY Conf 2013: Isaac Saldana, SendGrid
unSEXY Conf 2013: Isaac Saldana, SendGrid
500 Startups
 
Federico Holgado, Designing for Your Redesign, WarmGun 2013
Federico Holgado, Designing for Your Redesign, WarmGun 2013Federico Holgado, Designing for Your Redesign, WarmGun 2013
Federico Holgado, Designing for Your Redesign, WarmGun 2013
500 Startups
 

Destacado (20)

Givesurance
GivesuranceGivesurance
Givesurance
 
Whitney Moss w/ Rookie Moms @ MamaBear Conference, Mt. View 4/20
Whitney Moss w/ Rookie Moms @ MamaBear Conference, Mt. View 4/20Whitney Moss w/ Rookie Moms @ MamaBear Conference, Mt. View 4/20
Whitney Moss w/ Rookie Moms @ MamaBear Conference, Mt. View 4/20
 
Timbuktu
TimbuktuTimbuktu
Timbuktu
 
Dropifi
DropifiDropifi
Dropifi
 
Fast Company, SMASH summit Presentation
Fast Company, SMASH summit PresentationFast Company, SMASH summit Presentation
Fast Company, SMASH summit Presentation
 
Ohmconnect
OhmconnectOhmconnect
Ohmconnect
 
Luca prasso
Luca prassoLuca prasso
Luca prasso
 
Startup Pitch by Anya Shapina w/ PixOwl @ MamaBear Conference, Mt. View 4/20
Startup Pitch by Anya Shapina w/ PixOwl @ MamaBear Conference, Mt. View 4/20Startup Pitch by Anya Shapina w/ PixOwl @ MamaBear Conference, Mt. View 4/20
Startup Pitch by Anya Shapina w/ PixOwl @ MamaBear Conference, Mt. View 4/20
 
Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013
Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013
Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013
 
Startup Pitch by Chandini Ammineni w/ ActivityHero @ MamaBear Conference, Mt....
Startup Pitch by Chandini Ammineni w/ ActivityHero @ MamaBear Conference, Mt....Startup Pitch by Chandini Ammineni w/ ActivityHero @ MamaBear Conference, Mt....
Startup Pitch by Chandini Ammineni w/ ActivityHero @ MamaBear Conference, Mt....
 
Enchanted Diamonds
Enchanted DiamondsEnchanted Diamonds
Enchanted Diamonds
 
Dylan Arena
Dylan Arena Dylan Arena
Dylan Arena
 
Reesio
ReesioReesio
Reesio
 
Dan Greenberg, Sharethrough, SXSW Lean Startup 2013
Dan Greenberg, Sharethrough, SXSW Lean Startup 2013Dan Greenberg, Sharethrough, SXSW Lean Startup 2013
Dan Greenberg, Sharethrough, SXSW Lean Startup 2013
 
Customer Acquisition on Facebook
Customer Acquisition on FacebookCustomer Acquisition on Facebook
Customer Acquisition on Facebook
 
Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013
Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013
Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013
 
Aaron Batalion, LivingSocial, Lean Startup SXSW
Aaron Batalion, LivingSocial, Lean Startup SXSWAaron Batalion, LivingSocial, Lean Startup SXSW
Aaron Batalion, LivingSocial, Lean Startup SXSW
 
unSEXY Conf 2013: Isaac Saldana, SendGrid
unSEXY Conf 2013: Isaac Saldana, SendGrid unSEXY Conf 2013: Isaac Saldana, SendGrid
unSEXY Conf 2013: Isaac Saldana, SendGrid
 
Federico Holgado, Designing for Your Redesign, WarmGun 2013
Federico Holgado, Designing for Your Redesign, WarmGun 2013Federico Holgado, Designing for Your Redesign, WarmGun 2013
Federico Holgado, Designing for Your Redesign, WarmGun 2013
 
CultureAlley
CultureAlleyCultureAlley
CultureAlley
 

Similar a Shai samet

Children Online Privacy Komal Bansal
Children Online Privacy Komal BansalChildren Online Privacy Komal Bansal
Children Online Privacy Komal Bansal
Komal Bansal
 
Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...
Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...
Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...
iof_events
 

Similar a Shai samet (20)

Business COPPA 6 Steps
Business COPPA 6 StepsBusiness COPPA 6 Steps
Business COPPA 6 Steps
 
Children’s Online Privacy Protection Rule- A Six-Step Compliance Plan for You...
Children’s Online Privacy Protection Rule- A Six-Step Compliance Plan for You...Children’s Online Privacy Protection Rule- A Six-Step Compliance Plan for You...
Children’s Online Privacy Protection Rule- A Six-Step Compliance Plan for You...
 
Trending Topics in Data Collection & Targeted Marketing
Trending Topics in Data Collection & Targeted MarketingTrending Topics in Data Collection & Targeted Marketing
Trending Topics in Data Collection & Targeted Marketing
 
The FTC’s Revised COPPA Rules (Stanford Presentation)
The FTC’s Revised COPPA Rules (Stanford Presentation)The FTC’s Revised COPPA Rules (Stanford Presentation)
The FTC’s Revised COPPA Rules (Stanford Presentation)
 
COPPA
COPPACOPPA
COPPA
 
Children Online Privacy Komal Bansal
Children Online Privacy Komal BansalChildren Online Privacy Komal Bansal
Children Online Privacy Komal Bansal
 
Legislation That Internet Marketers Need to Know
Legislation That Internet Marketers Need to KnowLegislation That Internet Marketers Need to Know
Legislation That Internet Marketers Need to Know
 
6: privacy terms
6: privacy terms6: privacy terms
6: privacy terms
 
pig-e-bank
pig-e-bankpig-e-bank
pig-e-bank
 
Moochies presentation
Moochies presentationMoochies presentation
Moochies presentation
 
E safety-slide-presentation
E safety-slide-presentationE safety-slide-presentation
E safety-slide-presentation
 
E safety-slide-presentation
E safety-slide-presentationE safety-slide-presentation
E safety-slide-presentation
 
Protect Privacy to Protect Your Startup
Protect Privacy to Protect Your StartupProtect Privacy to Protect Your Startup
Protect Privacy to Protect Your Startup
 
Thinking Outside the App: How Real World Forces Inform Kids' Media Development
Thinking Outside the App:  How Real World Forces Inform Kids' Media Development Thinking Outside the App:  How Real World Forces Inform Kids' Media Development
Thinking Outside the App: How Real World Forces Inform Kids' Media Development
 
Privacy and Security in Mobile E-Commerce
Privacy and Security in Mobile E-CommercePrivacy and Security in Mobile E-Commerce
Privacy and Security in Mobile E-Commerce
 
Digital Coupons: How & Why
Digital Coupons: How & WhyDigital Coupons: How & Why
Digital Coupons: How & Why
 
Data Compliance Updates in the US and EU
Data Compliance Updates in the US and EUData Compliance Updates in the US and EU
Data Compliance Updates in the US and EU
 
Social Media for School Districts - OTA 15
Social Media for School Districts - OTA 15Social Media for School Districts - OTA 15
Social Media for School Districts - OTA 15
 
Monetization Still A Mystery
Monetization Still A MysteryMonetization Still A Mystery
Monetization Still A Mystery
 
Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...
Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...
Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...
 

Más de 500 Startups

Más de 500 Startups (20)

Get on Board
Get on BoardGet on Board
Get on Board
 
Connected Analytics
Connected AnalyticsConnected Analytics
Connected Analytics
 
Sira Medical
Sira MedicalSira Medical
Sira Medical
 
The Atlas
The AtlasThe Atlas
The Atlas
 
Trash Warrior
Trash WarriorTrash Warrior
Trash Warrior
 
Thematic
ThematicThematic
Thematic
 
Shiplyst
ShiplystShiplyst
Shiplyst
 
Renetec
RenetecRenetec
Renetec
 
Predina
PredinaPredina
Predina
 
Pluto
PlutoPluto
Pluto
 
Plant an App
Plant an AppPlant an App
Plant an App
 
Pilota
PilotaPilota
Pilota
 
Mero Technologies
Mero TechnologiesMero Technologies
Mero Technologies
 
Omnitron Sensors
Omnitron SensorsOmnitron Sensors
Omnitron Sensors
 
Juked
JukedJuked
Juked
 
GamerzClass
GamerzClassGamerzClass
GamerzClass
 
eino
einoeino
eino
 
Cenos
CenosCenos
Cenos
 
Bliinx
BliinxBliinx
Bliinx
 
Butlr
ButlrButlr
Butlr
 

Último

Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
panagenda
 
Structuring Teams and Portfolios for Success
Structuring Teams and Portfolios for SuccessStructuring Teams and Portfolios for Success
Structuring Teams and Portfolios for Success
UXDXConf
 

Último (20)

How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdfHow Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
 
Microsoft CSP Briefing Pre-Engagement - Questionnaire
Microsoft CSP Briefing Pre-Engagement - QuestionnaireMicrosoft CSP Briefing Pre-Engagement - Questionnaire
Microsoft CSP Briefing Pre-Engagement - Questionnaire
 
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
 
WSO2CONMay2024OpenSourceConferenceDebrief.pptx
WSO2CONMay2024OpenSourceConferenceDebrief.pptxWSO2CONMay2024OpenSourceConferenceDebrief.pptx
WSO2CONMay2024OpenSourceConferenceDebrief.pptx
 
Demystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John StaveleyDemystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John Staveley
 
The Metaverse: Are We There Yet?
The  Metaverse:    Are   We  There  Yet?The  Metaverse:    Are   We  There  Yet?
The Metaverse: Are We There Yet?
 
Easier, Faster, and More Powerful – Notes Document Properties Reimagined
Easier, Faster, and More Powerful – Notes Document Properties ReimaginedEasier, Faster, and More Powerful – Notes Document Properties Reimagined
Easier, Faster, and More Powerful – Notes Document Properties Reimagined
 
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
 
Syngulon - Selection technology May 2024.pdf
Syngulon - Selection technology May 2024.pdfSyngulon - Selection technology May 2024.pdf
Syngulon - Selection technology May 2024.pdf
 
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdfThe Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
 
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdfIntroduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
 
PLAI - Acceleration Program for Generative A.I. Startups
PLAI - Acceleration Program for Generative A.I. StartupsPLAI - Acceleration Program for Generative A.I. Startups
PLAI - Acceleration Program for Generative A.I. Startups
 
What's New in Teams Calling, Meetings and Devices April 2024
What's New in Teams Calling, Meetings and Devices April 2024What's New in Teams Calling, Meetings and Devices April 2024
What's New in Teams Calling, Meetings and Devices April 2024
 
Speed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in MinutesSpeed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in Minutes
 
Salesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
Salesforce Adoption – Metrics, Methods, and Motivation, Antone KomSalesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
Salesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
 
Optimizing NoSQL Performance Through Observability
Optimizing NoSQL Performance Through ObservabilityOptimizing NoSQL Performance Through Observability
Optimizing NoSQL Performance Through Observability
 
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfLinux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
 
Structuring Teams and Portfolios for Success
Structuring Teams and Portfolios for SuccessStructuring Teams and Portfolios for Success
Structuring Teams and Portfolios for Success
 
Oauth 2.0 Introduction and Flows with MuleSoft
Oauth 2.0 Introduction and Flows with MuleSoftOauth 2.0 Introduction and Flows with MuleSoft
Oauth 2.0 Introduction and Flows with MuleSoft
 
Designing for Hardware Accessibility at Comcast
Designing for Hardware Accessibility at ComcastDesigning for Hardware Accessibility at Comcast
Designing for Hardware Accessibility at Comcast
 

Shai samet

  • 1. Old COPPA, New COPPA “Get Out of Jail Free” 500 Startups – MamaBear Conference Presented by Shai Samet May 10, 2013 CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION
  • 2. Basic COPPA equation CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 2 personal information collected from child under 13 via the web (site, app, tablet, etc.) Verifiable Parental Consent (plus other requirements)
  • 3. User acquisition costs (kidSAFE survey – Jan 2013) CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 3 Companies polled: AOL, Fantage, Gaia Online, Highlights for Kids, Pearson, TBS, WebKinz, many others
  • 4. Penalties for non-compliance • Up to $16,000 per violation • Over 20 FTC lawsuits and $8.4 million in fines since 2000 • Recent fines for COPPA violations: – Path (app developer) – $800,000 – Artist Arena (various music artist sites) – $1,000,000 – RockYou (social game site) – $250,000 – Disney’s Playdom (for violations by acquired company) – $3,000,000 CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 4
  • 5. Old COPPA vs. New COPPA CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION
  • 6. Key information and features regulated under new COPPA CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 6 CONTACT INFO First and Last Name Home/mailing address Email address Phone numbers Social Security Number “personal information” SCREEN/USER NAME “personal” in some scenarios (email, AIM, Skype name, etc.) THIRD PARTY PLUG-INS Integration with no VPC means strict liability GEOLOCATION “personal” unless location is not detailed enough BEHAVIORAL ADS/PROFILES “personal” if tracking across multiple services & over time PHOTOS, VIDEOS, AUDIO “personal” if contains image or voice of child
  • 7. Photos, videos, audio files (SnapChat, Faces iMake illustrations) CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 7 temporary viewing by others = “collection/disclosure” faces alone (with no other PI) = VPC
  • 8. Geolocation information (News-O-matic illustration) CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 8 Opt-in prompt not enough under new COPPA Consider coarse location or not uploading the data
  • 9. Behavioral ads and social plugins (WebKinz, NeoPets illustrations) CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 9 Behavioral ads no more (contextual ads OK) FB Connect needs VPC (link to fan page OK)
  • 10. Verifiable Parental Consent CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION
  • 11. Current options for parental consent Method Providers Limitations • Email Plus consent Internally- implemented • Requires parent to activate via email comm’s • Not sufficient if info will be shared/publicized • Signed consent form N/A • Manual • Requires access to printer and scanner/fax • Not mobile friendly Monetary transaction Payment processors • Requires credit card entry and payment • Payment via PayPal also sufficient • [Collection of iTunes password not sufficient] • Phone call or video conference N/A • Manual • Requires live and trained personnel • Video-conference requires device with camera • Govt-issued ID Various • Requires sharing of highly-sensitive information • Not ideal for foreign users CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 11
  • 12. CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 12 Likelihood of industry adoption (kidSAFE survey – Jan 2013)
  • 13. Penalties for non-compliance (just a reminder) • Up to $16,000 per violation • Over 20 FTC lawsuits and $8.4 million in fines since 2000 • Recent fines for COPPA violations: – Path (app developer) – $800,000 – Artist Arena (various music artist sites) – $1,000,000 – RockYou (social game site) – $250,000 – Disney’s Playdom (for violations by acquired company) – $3,000,000 CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 13
  • 14. Considerations for Startups and Investors CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION
  • 15. Scaling user growth (COPPA techniques and loopholes) • Anonymize child-directed features – Limit sign-up process to anonymous info (username, password, etc.) – For interactive features (chat, UGC), filter on the back-end to avoid upfront consent requirement – For mobile features (geo-location, photos), keep data local to the device (do not upload/share) – Utilize COPPA’s parental consent exceptions for other features • Direct your account sign-up process to older users (when allowed) – If kids under 13 not your “primary audience”, you can limit registration to users 13 and older – On sites/apps directed to preschoolers, collect registration info from parents/adults – Put behavioral ads and social plug-ins behind special parents section (or 13+ section) • When parental consent is required, use least burdensome method – Avoid collection of payment solely for consent purposes – Avoid collection of govt-issued ID (last 4 of SSN, driver’s license) – Consider email-based consent as first option CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 15
  • 16. Parent-directed registration (StoryBots illustration) CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 16 Messaging on the page and within data fields must be clearly directed to parents
  • 17. Parent lock for social features (StoryBots, TocaBoca app illustrations) CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 17 Math problem before access to web or social sharing features Swipe to access parents section or apps for sale
  • 18. Most viable revenue streams (under new COPPA) • E-commerce and retail (tied to compelling content or experience) – Virtual goods, subscriptions, premium content/features (e.g., Wizard 101) – Game/app downloads, in-app purchases (e.g., Minecraft, Toca Boca) – Tablets, toys, offline merchandise (e.g., Nabi, Skylanders, Moshi Monsters) – Brands/stories with TV or licensing potential • Contextual ads – Display, text, or video ads (all OK) – NOT behaviorally-targeted or retargeted ads • NOT models dependent heavily on social sharing/connections – Hard to scale with current COPPA restrictions CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 18
  • 19. Distribution ideas • Kid-directed platforms – Popular gaming portals (e.g., Miniclip) – Kids’ tablets (e.g., nabi, Kurio) – Other curated environments (e.g., Zui.com, Magic Desktop) • Schools – For properties with educational, nutritional, or creative utility (e.g., myNutratek, Minecraft) – Schools/teachers can provide consent in lieu of parents • Participation in kidSAFE – Get noticed by users visiting our site from other popular sites/properties – Reach our growing database of parents CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 19
  • 20. CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 20 About kidSAFE Seal Program • Leading safety “seal of approval” program – Certifying kid-directed sites, apps, software, tablets, and other technologies – GLOBALLY – Over 100 seal holders since public launch in April 2012 – Fast becoming the industry standard for “online safety” • kidSAFE+ membership offers full COPPA audit – Qualifiers receive prestigious kidSAFE+ Seal and many other benefits – Application for FTC approval coming soon • Business-friendly, responsive, and highly knowledgeable – Founder is former attorney and long-time COPPA expert • For more info, visit kidsafeseal.com or email shai@kidsafeseal.com
  • 21. Some of our customers WEBANDPC CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 21 MOBILE Collectively, these few sites alone account for over 15M unique visitors a month in the US alone (Source: Compete.com)
  • 22. Questions? (happy to share the deck) CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION Upcoming kidSAFE Webinar on COPPA – May 30, 2013 (featuring open Q&A session with the FTC) REGISTER HERE