Disney Will Pay $10m For Illegally Collecting Personal Data Of Children

Disney will pay $10 million to settle claims by the US Federal Trade Commission (FTC) that it mislabeled videos for children on YouTube, which allowed the collection of kids' personal information without their consent or notification to their parents.

The US Department of Justice (DoJ) has determined that Disney broke the Children’s Online Privacy Protection Rule (COPPA) by neglecting to label a “significant number” of videos it places on YouTube as “Made for Kids.” 

Targeted advertising is disabled on videos designated as intended for children. Disney’s actions allowed the children to be subjected to targeted advertising based on personal data collected without parental notice or consent, the initial complaint says.  

The agency’s proposed order will require changes to how Disney designates videos directed to children on the streaming service and will push YouTube to begin using age assurance technologies, according to the  FTC said. The COPPA Rule was updated in January to require parents to opt in to third-party advertising to children.

The rule mandates that websites and online services get verifiable parental consent before collecting, using, or sharing personal information from children under age 13. 

Disney has uploaded tens of thousands of videos to more than 1,250 YouTube channels since 2020, according to the complaint. Those posted to just three dozen Disney channels drew 1.2 billion views in the US over a three-month period of 2020 alone.  Many of these videos were not properly labeled as being for children. The entertainment giant profited handsomely from the practice, the complaint says. 

Disney receives part of YouTube’s advertising revenue from promotions placed on the videos. It also places its own ads on a subset of videos. 

In November 2019, YouTube told Disney it was required to alert it if content uploaded was directed at children to ensure it was complying with COPPA. YouTube determined what advertising practices would be allowed depending on whether or not Disney labeled it as content made for children.  Videos posted by Disney with a “Not Made for Kids” label included clips of Mickey Mouse cartoons and snippets from child-directed movies such as Frozen, Encanto, Moana, Cars, Tangled, Ratatouille and Toy Story, the complaint says. 

YouTube told Disney that it was failing to label the videos correctly as early as June 2020, the complaint says, but apparently Disney failed to fix the problem. “This case underscores the FTC’s commitment to enforcing COPPA, which was enacted by Congress to ensure that parents, not companies like Disney, make decisions about the collection and use of their children’s personal information online,” FTC Chairman Andrew Ferguson said in a prepared statement. 

In addition to the $10 million fine, the proposed settlement requires Disney to begin alerting parents before collecting personal data from children under age 13 and obtain their consent in accordance with COPPA. Disney is also required to start a program to ensure that videos it uploads to YouTube are properly designated as intended for kids. 

FTC  |  FTC  |  DoJ  |   The Record  |   Bleeping Computer  |  Reuters  

Image: Bo-Shou

You Might Also Read: 

Teach Your Children About Safer Cyber Security:


If you like this website and use the comprehensive 8,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible



 

« Cyber Attacks In Modern Warfare [extract]
Mobile Workplaces Are Making Things Easy For Cyber Attackers  »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Telspace Africa

Telspace Africa

Telspace Africa provide the highest level of IT security solutions including advisory, penetration testing, vulnerability assessments, red teaming, social engineering and training.

Samsung Knox

Samsung Knox

Samsung Knox brings multi-layered defence-grade security to your business’s smartphones and tablets.

Sift

Sift

The Sift Digital Trust Platform protects your business and customers from all vectors of fraud and abuse through our Live Machine Learning, global trust network and automation technologies.

Miradore

Miradore

Miradore is a software company specializing in effective, cloud-based device management. Our goal is to help IT Service Providers and IT departments secure and control devices.

Blancco Technology Group

Blancco Technology Group

Blancco Technology Group is a leading global provider of mobile device diagnostics and secure data erasure solutions.

SoSafe

SoSafe

SoSafe empowers organizations to build a security culture and mitigate risk with its GDPR-compliant awareness programs.

iSecurity Consulting

iSecurity Consulting

iSecurity delivers a complete lifecycle of digital protection services across the globe for public and private sector clients.

eSec Forte Technologies

eSec Forte Technologies

eSec Forte Technologies is a CMMi Level 3 certified Global Consulting and IT Security Services company.

Kontron

Kontron

Kontron offers a combined portfolio of secure hardware, middleware and services for Internet of Things (IoT) and Industry 4.0 applications.

Dectar

Dectar

Dectar (formerly 4Securitas) is a cybersecurity company that provides solutions that predict, detect, defend and react against cybersecurity threats.

Curatrix Technologies

Curatrix Technologies

Curatrix Technologies is a Managed IT Service provider based in Hampshire, UK, providing high quality and reliable Managed IT Services since 2015.

Agile Defense

Agile Defense

Agile Defense is an Information Technology services provider, delivering leading-edge Digital Transformation solutions to the Federal Government.

Nova Microsystems

Nova Microsystems

Nova's mission is to revolutionize cybersecurity through continuous data analysis and dynamic AI-driven encryption.

Axoflow

Axoflow

Axoflow helps organizations to consolidate their existing solutions for logs, metrics, and traces, and evolve them into a cloud native observability infrastructure.

VRS Technologies

VRS Technologies

VRS Technologies LLC offers expert IT solutions in Dubai, including AMC, cybersecurity, and tech rentals. Trusted by businesses for reliable, customized services.