Google has agreed to settle Federal Trade Commission (FTC) charges that it used deceptive tactics and violated its own privacy promises to consumers when it launched its social network, Google Buzz, in 2010, the FTC said on Wednesday.
Under the deal, Google agreed to have independent privacy audits every two years for the next 20 years.
The agency alleges the practices violate the FTC Act. The proposed settlement bars the company from future privacy misrepresentations, requires it to implement a comprehensive privacy program, and calls for regular, independent privacy audits for the next 20 years.
"When companies make privacy pledges, they need to honor them," said Jon Leibowitz, Chairman of the FTC. "This is a tough settlement that ensures that Google will honor its commitments to consumers and build strong privacy protections into all of its operations."
According to the FTC complaint, Google launched its Buzz social network through its Gmail web-based email product. Although Google led Gmail users to believe that they could choose whether or not they wanted to join the network, the options for declining or leaving the social network were ineffective. For users who joined the Buzz network, the controls for limiting the sharing of their personal information were confusing and difficult to find, the agency alleged.
On the day Buzz was launched, Gmail users got a message announcing the new service and were given two options: "Sweet! Check out Buzz," and "Nah, go to my inbox." However, the FTC complaint alleged that some Gmail users who clicked on "Nah..." were nonetheless enrolled in certain features of the Google Buzz social network. For those Gmail users who clicked on "Sweet!," the FTC alleges that they were not adequately informed that the identity of individuals they emailed most frequently would be made public by default. Google also offered a "Turn Off Buzz" option that did not fully remove the user from the social network.
In response to the Buzz launch, Google received thousands of complaints from consumers who were concerned about public disclosure of their email contacts which included, in some cases, ex-spouses, patients, students, employers, or competitors. According to the FTC complaint, Google made certain changes to the Buzz product in response to those complaints.
The agency also alleges that by offering options like "Nah, go to my inbox," and "Turn Off Buzz," Google misrepresented that consumers who clicked on these options would not be enrolled in Buzz. In fact, they were enrolled in certain features of Buzz.
The complaint further alleges that a screen that asked consumers enrolling in Buzz, "How do you want to appear to others?" indicated that consumers could exercise control over what personal information would be made public. The FTC charged that Google failed to disclose adequately that consumers' frequent email contacts would become public by default.
Finally, the agency alleges that Google misrepresented that it was treating personal information from the European Union in accordance with the U.S.-EU Safe Harbor privacy framework. The framework is a voluntary program administered by the U.S. Department of Commerce in consultation with the European Commission. To participate, a company must self-certify annually to the Department of Commerce that it complies with a defined set of privacy principles. The complaint alleges that Google's assertion that it adhered to the Safe Harbor principles was false because the company failed to give consumers notice and choice before using their information for a purpose different from that for which it was collected.