Uber agrees to 20 years of user privacy audits in FTC settlement

Uber has come under fire more than once for failing to protect privacy, and now it’s facing the consequences. The ridesharing outfit has settled with the US’ Federal Trade Commission over allegations that it not only didn’t adequately safeguard data, but misrepresented how secure that info really was. Uber didn’t monitor staff access to personal info as closely as it said it did, the FTC says, and it also gave a false impression of how secure that info was when stored on third-party servers. Instead, employees needed just a single key to get full access to data, and it stored some information (including customer locations) online in plain text. It even ditched an automated staff monitoring tool after less than a year.

There’s no mention of a fine in the settlement, but that doesn’t mean Uber is off the hook. In addition to being barred from misrepresenting privacy and security, it’ll have to implement a “comprehensive privacy program” and undergo third-party privacy audits every 2 years for the next 20 years. That’s par for the course as far as FTC settlements go, but it’s a long time in Uber terms — the company may have fulfilled its driverless car ambitions by the time the audits are over.

In a statement, Uber tells us that it welcomes the end of the investigation and sees this as an “opportunity” to prove that it has turned a corner. You can read the full statement below.

The settlement comes right as Uber is in the midst of trying to fix a toxic corporate culture that many blame for Uber’s lax approach to privacy. Uber recently ousted CEO Travis Kalanick, who was frequently blamed for the company’s tendency to test (and sometimes break) legal boundaries. Other executives accused of dodgy behavior have also left the company. The FTC-mandated reforms could still be helpful, but Uber may be better prepared to implement them than it was just months earlier.

“We are pleased to bring the FTC’s investigation to a close. The complaint involved practices that date as far back as 2014. We’ve significantly strengthened our privacy and data security practices since then and will continue to invest heavily in these programs. In 2015, we hired our first Chief Security Officer and now employ hundreds of trained professionals dedicated to protecting user information. This settlement provides an opportunity to work with the FTC to further verify that our programs protect user privacy and personal information.”

Via: CNBC

Source: FTC

Source: Engadget - Read the full article here

Author: Daily Tech Whip

This article is part of our 'News Tiles' service. The site is currently in Beta. When it is fully operational you will be able to search through and arrange the 'Tiles' to display a keyword, product or technology over your chosen time period. For example you would be able to display all of the leading tech articles on the new Kindle Fire, in one spot in real time. You will also have access to our own original reporting and analysis as well as a polished place to post your own thoughts & reviews here, amongst the Daily Tech Whip Community. Please let us know if you have any feedback via the contact form or via Twitter. Don't forget to come back next week and see our full site and claim your name and your own free tech blog.

Share This Post On