{"id":34641,"date":"2023-01-26T10:46:40","date_gmt":"2023-01-26T15:46:40","guid":{"rendered":"https:\/\/www.itworldcanada.com?p=524015"},"modified":"2023-01-27T09:41:39","modified_gmt":"2023-01-27T14:41:39","slug":"breaking-news-home-depot-canada-criticized-by-privacy-commissioner","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/breaking-news-home-depot-canada-criticized-by-privacy-commissioner\/","title":{"rendered":"Breaking news: Home Depot Canada criticized by privacy commissioner"},"content":{"rendered":"<p data-ar-index=\"0\">The Canadian division of Home Depot didn\u2019t get customers\u2019 consent before sharing details of customers\u2019 e-receipts \u2013 including encoded email addresses and in-store purchase information \u2013 with Facebook parent Meta Platforms, says Canada\u2019s privacy commissioner.<\/p>\n<p data-ar-index=\"1\"><a href=\"https:\/\/www.priv.gc.ca\/en\/opc-actions-and-decisions\/investigations\/investigations-into-businesses\/2023\/pipeda-2023-001\/\" rel=\"noopener\">In a report released Thursday,<\/a> Commissioner Philippe Dufresne said <a href=\"https:\/\/www.homedepot.ca\/en\/home.html\" rel=\"noopener\">Home Depot of Canada<\/a> confirmed that the data was shipped without the knowledge or consent of customers in violation of the federal Personal Information Protection and Electronic Documents Act (PIPEDA).<\/p>\n<p data-ar-index=\"2\">It was done through Meta\u2019s Offline Conversions program. Home Depot had been collecting customer email addresses at store checkouts for the stated purpose of providing customers with an electronic copy of their receipt since at least 2018. However, the investigation revealed that during this period, the encoded email addresses, along with high-level details about each customer\u2019s in-store purchases, were also sent to Meta.<\/p>\n<p data-ar-index=\"3\">\u201cWhen customers were prompted to provide their email address [at check-out], they were never informed that their information would be shared with Meta by Home Depot, or how it could be used by either company,\u201d Dufresne said in a news release accompanying the decision. \u201cThis information would have been material to a customer\u2019s decision about whether or not to obtain an e-receipt.\u201d<\/p>\n<p data-ar-index=\"4\">\u201cAs businesses increasingly look to deliver services electronically, they must carefully consider any consequential uses of personal information, which may require additional consent,\u201d Dufresne said.<\/p>\n<p data-ar-index=\"5\">\u201cIn this case, it is unlikely that Home Depot customers would have expected that their personal information would be shared with a third-party social media platform simply because they opted for an electronic receipt.<\/p>\n<p data-ar-index=\"6\">\u201cAs Canada marks <a href=\"https:\/\/www.itworldcanada.com\/article\/data-privacy-week-some-canadian-firms-have-shortcomings-in-treating-privacy-says-regulator\/523554\" rel=\"noopener\">Data Privacy Week<\/a>, it is the perfect time to remind companies that they must obtain valid consent at the point of sale to engage in this type of business activity.\u201d<\/p>\n<p data-ar-index=\"7\">Information sent to Meta was used to verify if a customer had a Facebook account, the ruling said. If they did, Meta compared the person\u2019s in-store purchases to Home Depot\u2019s advertisements sent over the platform to measure and report on the effectiveness of those ads. Meta\u2019s Offline Conversions contractual terms also allowed it to use the customer information for its own business purposes, including user profiling and targeted advertising, unrelated to Home Depot.<\/p>\n<p data-ar-index=\"8\">Each email address Home Depot shared with Meta was encoded so that it could not be read by individuals at Facebook. Meta employed an automated process that allowed it to match email addresses attached to Facebook accounts. Email addresses not already associated with a Facebook account could not be linked to individuals.<\/p>\n<p data-ar-index=\"9\">While the details of a person\u2019s in-store purchases may not have been sensitive in the context of Home Depot, they could be highly sensitive in other retail contexts, where they reveal, for example, information about an individual\u2019s health or sexuality.<\/p>\n<p data-ar-index=\"10\">During the investigation, Home Depot said that it relied on implied consent and that its privacy statement, accessible through its website and in print upon request at retail locations, adequately explained that the company uses \u201cde-identified information for internal business purposes, such as marketing, customer service, and business analytics.\u201d The website statement also says the company \u201cmay share information for business purposes,\u201d including \u201cwith third parties.\u201d Home Depot also relied on Facebook\u2019s privacy statement, which explained the Offline Conversions program.<\/p>\n<p data-ar-index=\"11\">The commissioner rejected that argument, as the privacy statements Home Depot relied on for consent were not readily available to customers at the check-out counter, and consumers would have no reason to seek them out. Moreover, the commissioner found that Home Depot\u2019s privacy statement did not clearly explain the practice.<\/p>\n<p data-ar-index=\"12\">The company said that it did not notify customers of its information sharing agreement with Meta just prior to issuing e-receipts due to the risk of \u201cconsent fatigue.\u201d<\/p>\n<p data-ar-index=\"13\">\u201cConsumers need clear information at key transaction points, empowering them to make decisions about how their personal information should be used,\u201d\u00a0 Dufresne said. \u201cConsent fatigue is not a valid reason for failing to obtain meaningful consent. Many customers would be surprised, as the complainant was in this case, to learn that their personal information had been shared with a third party like Facebook without their knowledge and consent.\u201d<\/p>\n<p data-ar-index=\"14\">As a result of the investigation, the\u00a0Office of the Privacy Commissioner (OPC) recommended that Home Depot:<\/p>\n<ul>\n<li>cease disclosing the personal information of customers requesting an e-receipt to Meta until it is able to implement measures to ensure valid consent;<\/li>\n<li>implement measures to obtain express, opt-in consent from customers prior to sharing the information with Meta, should it resume the practice; and<\/li>\n<li>ensure meaningful consent by providing customers requesting an e-receipt with key information regarding its sharing of information with Meta at the point of sale, and by strengthening its privacy statement to include a detailed explanation of its practices and how customers can withdraw consent.<\/li>\n<\/ul>\n<p data-ar-index=\"15\">Home Depot was fully cooperative throughout the investigation, the OPC said, and has agreed to implement the <abbr title=\"Office of the Privacy Commissioner of Canada\">OPC<\/abbr>\u2019s recommendations. The company stopped sharing customer information with Meta in October 2022.<\/p>\n<p data-ar-index=\"16\">The post <a href=\"https:\/\/www.itworldcanada.com\/article\/breaking-news-home-depot-canada-criticized-by-privacy-commissioner\/524015\">Breaking news: Home Depot Canada criticized by privacy commissioner<\/a> first appeared on <a href=\"https:\/\/www.itworldcanada.com\/\">IT World Canada<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Retailer didn&#8217;t get consumers&#8217; consent when it sent e-receipt data to Meta, says federal privacy co<\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[361,16],"tags":[817,698,275],"class_list":["post-34641","post","type-post","status-publish","format-standard","hentry","category-privacy","category-security","tag-home-depot","tag-privacy-comissioner-of-canada","tag-top-story"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/34641","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=34641"}],"version-history":[{"count":3,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/34641\/revisions"}],"predecessor-version":[{"id":34693,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/34641\/revisions\/34693"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=34641"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=34641"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=34641"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}