First California lawsuit over mobile privacy issues crashes
Court rules that federal airline laws preempt state statutes in suit seeking to force Delta Air Lines to notify mobile app users about data collection plans
Computerworld - A California state court has dismissed a closely watched lawsuit charging that Delta Air Lines failed to comply with state privacy laws for mobile applications.
In a brief ruling last week, California Superior Court Judge Marla Miller agreed with Delta's claim that the federal Airline Deregulation Act (ADA) of 1978 supersedes state statutes.
The ADA prevents states from enforcing laws that could impact the prices, routes or services offered by an airline.
Delta argued that its mobile application was a service offered by the airline to customers and was therefore was covered by the ADA.
In an email, Delta spokesman Paul Skrbec said that the airline is "pleased the Court has confirmed our view that the California statute does not apply to airlines because it is preempted by federal law. The protection of customer information is something that Delta takes very seriously."
The court's action effectively ends the first lawsuit alleging that a company failed to adhere to a state's privacy laws for mobile applications.
California Attorney General Kamala Harris filed the lawsuit against Delta last December, alleging that the airline had violated the California Online Privacy Protection Act (CalOPPA) by failing to properly disclose the data collection and use policies associated with its Fly Delta smartphone app.
The lawsuit was filed after Delta failed to quickly respond after the state notified it of the alleged privacy violations.
In the complaint, Harris said that Delta had been offering the Fly Delta app since at least 2010 to let customers check in for flights online, view reservations, rebook or cancel flights, check-in baggage, take photographs and other things.
The lawsuit contended that the app violates the CalOPPA law by not providing information on Delta's data collection or use policies.
Harris had contended that Delta's claim that the federal law preempts state laws were without merit. CalOPPA, she argued, merely requires a company to disclose its online privacy policies and in no way affects an airline's prices or services.
While the dismissal of the lawsuit is a setback for Harris, few expect that it will slow down the state's plan to go after alleged violators of online privacy laws.
Last year, Harris struck an agreement with several companies, including Facebook and Google, to make their privacy policies more transparent to users of their mobile applications.
In October, she sent notices to 100 mobile application developers warning them that they weren't in compliance with California privacy laws and urging them to notify customers of their data collection practices within 30 days.
The Delta lawsuit was seen by some as a test of the state's ability to enforce its privacy policies on providers of mobile applications and services. Over the past 18 months or so. Harris and other state and federal regulators have expressed growing concern over the data collection and sharing practices of providers of mobile applications and services.
Just last week, Rep. Hank Johnson (D-Ga.) introduced legislation that would require mobile app developers to provide clear notice to consumers and get their consent before collecting personal data from mobile devices.
"Delta was not a great test case for the California AG so she will be back," said Scott Vernick, partner at the Fox Rothschild LLP law firm in Philadelphia.
"Any company worth its salt, and particularly mobile app developers, should make sure that that they are complying with CalOPPA," he said, Going forward expect other states could enact and strongly enforce such rules, he said.
Harris spokeswoman Lynda Gledhill said today that officials have not decided yet whether to appeal the ruling. "Our office is reviewing the decision and will have no further comment at this time," she said.
Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan, or subscribe to Jaikumar's RSS feed . His e-mail address is email@example.com.
- Franken presses Ford on location data collection practices
- Justices let stand appeals court decision on border searches of laptops
- California lawmakers move to bar state help to NSA
- Appeals court again nixes Google's bid to overturn Street View case
- Older Mac webcams can spy without activating warning light
- Update: Judge rules NSA spy efforts may be unconstitutional
- Perspective: Privacy concerns could keep Amazon delivery drones grounded
- NSA collects data from millions of cellphones daily
- Perspective: Curbing data use is key to reining in NSA
- Lavabit-DOJ dispute zeroes in on encryption key ownership
Read more about Privacy in Computerworld's Privacy Topic Center.
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- HP HAVEn: See the big picture in Big Data HP HAVEn is the industry's first comprehensive, scalable, open, and secure platform for Big Data. Enterprises are drowning in a sea of data...
- What Datapipe customers need to know about the new PCI DSS 3.0 compliance standard This handy quick reference outlines what PCI DSS 3.0 is, who needs to be compliant and how Alert Logic solutions address the new...
- The 12 PCI DSS 3.0 requirements addressed by Peer 1 Hosting This handy quick reference outlines the 12 PCI DSS 3.0 requirements, who needs to be compliant and how Alert Logic solutions address the...
- Defense Throughout the Vulnerability Life Cycle This whitepaper provides insight into how to leverage threat and log management technologies to protect your IT assets throughout their vulnerability life cycle.
- Data Protection and Disaster Recovery with iSCSI and VMware Get this on demand webcast now
- Meg Whitman presents Unlocking IT with Big Data During this Web Event you will hear Meg Whitman, President and CEO, HP discuss HAVEn - the #1 Big Data platform, as well... All Privacy White Papers | Webcasts