Contract Logix, LLC
Volume 160 · 160 F.T.C. 559
deceptive advertisingprivacy data securityonline internet
Cite this decision
Contract Logix, LLC, 160 F.T.C. 559 (2015). Consumer Law Library, https://consumerlawlibrary.org/decisions/v160-0014
Report an error in this record (decision id v160-0014)
Cited by 0 later FTC decisions
Cites
Text (OCR of the scan at left; may contain errors)
IN THE MATTER OF CONTRACT LOGIX, LLC CONSENT ORDER, ETC. IN REGARD TO ALLEGED VIOLATION OF SECTION 5 OF THE FEDERAL TRADE COMMISSION ACT. Docket C-4541; File No. 152 3184 Complaint, September 29, 2015 – Decision, September 29, 2015 This consent order addresses Contract Logix, LLC’s misleading representation of their participation in the Safe Harbor privacy framework agreed upon by the U.S. and the European Union (“EU”). Contact Logix, LLC describes its business as providing contract management software and associated services. The Commission's complaint alleges that Contract Logix, LLC falsely represented that it was a “current” participant in the U.S.-EU Safe Harbor Framework when, in fact, from August 2012 until May 2015, Contract Logix, LLC was not a “current” participant in the U.S.-EU Safe Harbor Framework. The company’s predecessor in interest had submitted its self-certification to the U.S.-EU Safe Harbor Framework, but that self-certification had lapsed. Commerce subsequently updated the company’s status to “not current” on its public website. The consent order prohibits Forensics Consulting Solutions, LLC from making misrepresentations about its membership in any privacy or security program sponsored by the government or any other self-regulatory or standard-setting organization, including, but not limited to, the U.S.-EU Safe Harbor Framework. As well as, requiring Contact Logix, LLC to supply and retain documents relating to their compliance with the Order for a five-year period. The proposed order mandates that Contact Logix, LLC submit an initial compliance report to the FTC, and make available to the FTC subsequent reports.
Participants For the Commission: Ruth Yodaiken For the Respondent: Edward Glynn and Mark E. Schreiber, Locke Lord LLP.
COMPLAINT The Federal Trade Commission, having reason to believe that Contract Logix, LLC, a limited liability company, has violated the Federal Trade Commission Act (“FTC Act”), and it appearing to the Commission that this proceeding is in the public interest, alleges:
VOLUME 160 Complaint 1. Respondent Contract Logix, LLC (“Contract Logix”) is a Delaware limited liability company with its principal office or place of business at 248 Mill Road, Chelmsford, Massachusetts. In August 2012, respondent acquired the assets of Contract Logix, Inc., a corporation with its principal office or place of business at the same address. Respondent acquired, inter alia, the website www.contractlogix.com and has operated that website since August 2012.
2. Respondent Contract Logix describes the business it offers on contractlogix.com as providing contract management software and associated services.
3. The acts and practices of respondent as alleged in this complaint have been in or affecting commerce, as “commerce” is defined in Section 4 of the FTC Act.
4. Respondent has set forth on its website, www.contractlogix.com, privacy policies and statements about its practices, including statements related to its participation in the Safe Harbor privacy framework agreed upon by the U.S. and the European Union (“U.S.-EU Safe Harbor Framework”). The Safe Harbor Framework 5. The U.S.-EU Safe Harbor Framework provides a method for U.S. companies to transfer personal data outside of Europe that is consistent with the requirements of the European Union Directive on Data Protection (“Directive”). Enacted in 1995, the Directive sets forth European Union (“EU”) requirements for privacy and the protection of personal data. Among other things, it requires EU Member States to implement legislation that prohibits the transfer of personal data outside the EU, with exceptions, unless the European Commission (“EC”) has made a determination that the recipient jurisdiction’s laws ensure the protection of such personal data. This determination is referred to commonly as meeting the EU’s “adequacy” standard. 6. To satisfy the EU adequacy standard for certain commercial transfers, the U.S. Department of Commerce (“Commerce”) and the EC negotiated the U.S.-EU Safe Harbor Framework, which went into effect in 2000. The U.S.-EU Safe CONTRACT LOGIX, LLC 561 Complaint Harbor Framework allows U.S. companies to transfer personal data lawfully from the EU. To join the U.S.-EU Safe Harbor Framework, a company must self-certify to Commerce that it complies with seven principles and related requirements that have been deemed to meet the EU’s adequacy standard. 7. The seven principles are: notice, choice, onward transfer, security, data integrity, access, and enforcement. Among other things, the enforcement principle requires companies to provide a readily available and affordable independent recourse mechanism to investigate and resolve an individual’s complaints and disputes. 8. Companies under the jurisdiction of the U.S. Federal Trade Commission (“FTC”), as well as the U.S. Department of Transportation, are eligible to join the U.S.-EU Safe Harbor Framework. A company under the FTC’s jurisdiction that claims it has self-certified to the Safe Harbor principles, but failed to self-certify to Commerce, may be subject to an enforcement action based on the FTC’s deception authority under Section 5 of the FTC Act.
9. Commerce maintains a public website, www.export.gov/safeharbor, where it posts the names of companies that have self-certified to the U.S.-EU Safe Harbor Framework. The listing of companies indicates whether their self-certification is “current” or “not current” and a date when recertification is due. Companies are required to re-certify every year in order to retain their status as current members of the U.S.- EU Safe Harbor Framework.
Violations of Section 5 of the FTC Act Misrepresentations Regarding Safe Harbor Participation 10. In July 2010, Contract Logix, Inc. submitted to Commerce a self-certification of compliance with the U.S.-EU Safe Harbor Framework.
11. In July 2012, Contract Logix, Inc. did not renew its selfcertification to the U.S.-EU Safe Harbor Framework, and Commerce subsequently updated respondent’s status to “not current” on its public website.
VOLUME 160 Complaint 12. In August 2012, Contract Logix, LLC acquired the assets of Contract Logix, Inc., including the website www.contractlogix.com.
13. Since at least August 2012 until May 2015, respondent disseminated or caused to be disseminated privacy policies and statements on the Contract Logix website, www.contractlogix.com, including but not limited to, the following statements:
E.U.Safe Harbor Privacy Policy Contract Logix,Inc. E.U.Safeharbor Privacy Policy Contract Logix Inc. . recognizes that privacy is very important to our customers, and we pledge to protect the security and privacy of any personal information that customers provide to us. This includes customer's names, addresses, telephone numbers, email addresses and any information that can be linked to an individual. Not only does Contract Logix strive to collect, use and disclose personal information in a manner consistent with the laws of the countries in which it does business, but it also has a tradition of upholding the highest ethical standards in its business practices. This Safe Harbor Privacy Policy (the "Policy") sets forth the privacy principles that Contract Logix follows with respect to transfers of personal information from the European Union (EU) to the . SAFEHARBOR The United States Department of Commerce and the European Commission have agreed on a set of data protection principles and frequently asked questions (the "Safe Harbor Principles") to enable companies to satisfy the EU law requirement that personal information transferred from the EU to the be adequately protected. Consistent with its CONTRACT LOGIX, LLC 563 Decision and Order pledge to protect personal privacy, Contract Logix adheres to the Safe Harbor Principles.
14. Through the means described in Paragraph 13, respondent represented, expressly or by implication, that it was a current participant in the U.S.-EU Safe Harbor Framework. 15. In truth and in fact, beginning in August 2012, respondent was not a current participant in the U.S.-EU Safe Harbor Framework. Therefore, the representation set forth in Paragraph 14 is false and misleading.
16. The acts and practices of respondent as alleged in this complaint constitute deceptive acts or practices, in or affecting commerce, in violation of Section 5(a) of the Federal Trade Commission Act.
THEREFORE, the Federal Trade Commission this twentyninth day of September 2015, has issued this complaint against respondent.
By the Commission.
DECISION AND ORDER The Federal Trade Commission (“Commission” or “FTC”), having initiated an investigation of certain acts and practices of the respondent named in the caption hereof, and the respondent having been furnished thereafter with a copy of a draft complaint that the Bureau of Consumer Protection proposed to present to the Commission for its consideration and which, if issued by the Commission, would charge respondent with violations of the Federal Trade Commission Act (“FTC Act”), 15 U.S.C. § 45 et seq.;
The respondent and counsel for the Commission having thereafter executed an Agreement Containing Consent Order VOLUME 160 Decision and Order (“Consent Agreement”), which includes: a statement by respondent that it neither admits nor denies any of the allegations in the draft complaint, except as specifically stated in the Consent Agreement, and, only for purposes of this action, admits the facts necessary to establish jurisdiction; and waivers and other provisions as required by the Commission’s Rules; and The Commission having thereafter considered the matter and having determined that it had reason to believe that the respondent violated the FTC Act, and that a complaint should issue stating its charges in that respect, and having thereupon accepted the executed Consent Agreement and placed such agreement on the public record for a period of thirty (30) days for the receipt and consideration of public comments, now in further conformity with the procedure prescribed by Commission Rule 2.34, 16 C.F.R. § 2.34, the Commission hereby issues its complaint, makes the following jurisdictional findings, and enters the following Order: 1. Respondent Contract Logix, LLC is a Delaware limited liability company with its principal office or place of business at 248 Mill Road, Chelmsford, Massachusetts.
2. The Federal Trade Commission has jurisdiction of the subject matter of this proceeding and of the respondent, and the proceeding is in the public interest. ORDER DEFINITIONS For purposes of this Order, the following definitions shall apply:
A. Unless otherwise specified, “respondent” shall mean Contract Logix, LLC, and its successors and assigns. B. “Commerce” shall mean as defined in Section 4 of the Federal Trade Commission Act, 15 U.S.C. § 44. CONTRACT LOGIX, LLC 565 Decision and Order I.
IT IS ORDERED that respondent and its officers, agents, representatives, and employees, whether acting directly or indirectly, in connection with the advertising, marketing, promotion, offering for sale, or sale of any product or service, in or affecting commerce, shall not misrepresent in any manner, expressly or by implication, the extent to which it is a member of, adheres to, complies with, is certified by, is endorsed by, or otherwise participates in any privacy or security program sponsored by the government or any self-regulatory or standardsetting organization, including, but not limited to, the U.S.-EU Safe Harbor Framework and the U.S.-Swiss Safe Harbor Framework.
II.
IT IS FURTHER ORDERED that respondent shall maintain and upon request make available to the Federal Trade Commission for inspection and copying, a print or electronic copy of, for a period of five (5) years from the date of preparation or dissemination, whichever is later, all documents relating to compliance with this order, including but not limited to: A. all advertisements, promotional materials, and any other statements containing any representations covered by this order, with all materials relied upon in disseminating the representation; and B. any documents, whether prepared by or on behalf of respondent, that call into question respondent’s compliance with this order.
III.
IT IS FURTHER ORDERED that respondent shall deliver a copy of this order to all current and future principals, officers, directors, and managers, and to all current and future employees, agents, and representatives having responsibilities relating to the subject matter of this order. Respondent shall deliver this order to such current personnel within thirty (30) days after service of this order, and to such future personnel within thirty (30) days after VOLUME 160 Decision and Order the person assumes such position or responsibilities Respondent must secure a signed and dated statement acknowledging receipt of this order, within thirty (30) days of delivery, from all persons receiving a copy of the order pursuant to this section. IV.
IT IS FURTHER ORDERED that respondent shall notify the Commission within fourteen (14) days of any change in the corporations that may affect compliance obligations arising under this order, including, but not limited to: a dissolution, assignment, sale, merger, or other action that would result in the emergence of a successor corporation; the creation or dissolution of a subsidiary, parent, or affiliate that engages in any acts or practices subject to this order; the proposed filing of a bankruptcy petition; or a change in the corporate name or address. Unless otherwise directed by a representative of the Commission in writing, all notices required by this Part shall be emailed to [email protected] or sent by overnight courier (not the U.S. Postal Service) to: Associate Director of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue, N.W., Washington, D.C. 20580. The subject line must begin: In re Contract Logix, LLC, FTC File No. 1523184. V.
IT IS FURTHER ORDERED that respondent, and its successors and assigns, within sixty (60) days after the date of service of this order, shall file with the Commission a true and accurate report, in writing, setting forth in detail the manner and form of its compliance with this order. Within ten (10) days of receipt of written notice from a representative of the Commission, it shall submit an additional true and accurate written report. VI.
This order will terminate on September 29, 2035, or twenty (20) years from the most recent date that the United States or the Commission files a complaint (with or without an accompanying consent decree) in federal court alleging any violation of the order, whichever comes later; provided, however, that the filing of such a complaint will not affect the duration of: CONTRACT LOGIX, LLC 567 Analysis to Aid Public Comment A. any Part in this order that terminates in fewer than twenty (20) years;
B. this order’s application to any respondent that is not named as a defendant in such complaint; and C. this order if such complaint is filed after the order has terminated pursuant to this Part.
Provided, further, that if such complaint is dismissed or a federal court rules that respondent did not violate any provision of the order, and the dismissal or ruling is either not appealed or upheld on appeal, then the order as to such respondent will terminate according to this Part as though the complaint had never been filed, except that the order will not terminate between the date such complaint is filed and the later of the deadline for appealing such dismissal or ruling and the date such dismissal or ruling is upheld on appeal.
By the Commission.
ANALYSIS OF CONSENT ORDER TO AID PUBLIC COMMENT The Federal Trade Commission (“FTC” or “Commission”) has accepted, subject to final approval, a consent agreement applicable to Contract Logix, LLC (“Contract Logix”). The proposed consent order has been placed on the public record for thirty (30) days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After thirty (30) days, the Commission will again review the agreement and the comments received, and will decide whether it should withdraw from the agreement and take appropriate action or make final the agreement's proposed order.
VOLUME 160 Analysis to Aid Public Comment This matter concerns alleged false or misleading representations that the company made to consumers concerning its participation in the Safe Harbor privacy Framework agreed upon by the U.S. and the European Union (“EU”) (“U.S.-EU Safe Harbor Framework”). The U.S.-EU Safe Harbor Framework allows U.S. companies to transfer data outside the EU consistent with EU law. To join the U.S.-EU Safe Harbor Framework, a company must self-certify to the U.S. Department of Commerce (“Commerce”) that it complies with a set of principles and related requirements that have been deemed by the European Commission as providing “adequate” privacy protection. These principles include notice, choice, onward transfer, security, data integrity, access, and enforcement. Commerce maintains a public website, www.export.gov/safeharbor, where it posts the names of companies that have self-certified to the Safe Harbor Framework. The listing of companies indicates whether their self-certification is “current” or “not current.” Companies are required to re-certify every year in order to retain their status as current members of the Safe Harbor Framework. Contract Logix describes its business as providing contract management software and associated services. According to the Commission's complaint, the company has set forth on its website, www.contractlogix.com, privacy policies and statements about its practices, including statements related to its participation in the U.S-EU Safe Harbor Framework. The Commission's complaint alleges that Contract Logix falsely represented that it was a “current” participant in the U.S.-EU Safe Harbor Framework when, in fact, from August 2012 until May 2015, Contract Logix was not a “current” participant in the U.S.-EU Safe Harbor Framework. The company’s predecessor in interest had submitted its selfcertification to the U.S.-EU Safe Harbor Framework, but that selfcertification had lapsed. Commerce subsequently updated the company’s status to “not current” on its public website. Part I of the proposed order prohibits Contract Logix from making misrepresentations about its membership in any privacy or security program sponsored by the government or any self-regulatory or standard-setting organization, including, CONTRACT LOGIX, LLC 569 Analysis to Aid Public Comment but not limited to, the U.S.-EU Safe Harbor Framework and the U.S.-Swiss Safe Harbor Framework.
Parts II through VI of the proposed order are reporting and compliance provisions. Part II requires Contract Logix to retain documents relating to its compliance with the order for a five-year period. Part III requires dissemination of the order now and in the future to persons with responsibilities relating to the subject matter of the order. Part IV ensures notification to the FTC of changes in corporate status. Part V mandates that Contract Logix submit an initial compliance report to the FTC, and make available to the FTC subsequent reports. Part VI is a provision “sunsetting” the order after twenty (20) years, with certain exceptions.
The purpose of this analysis is to facilitate public comment on the proposed order. It is not intended to constitute an official interpretation of the proposed complaint or order or to modify the order’s terms in any way.
VOLUME 160 Complaint