Protecting Privacy in Online Identity: A Review of the Letter and Spirit of the Fair Credit Reporting Act’s Application to Identity Providers
CDT has filed these comments in advance of the FTC's 3rd "Exploring Privacy" Roundtables.
In our November 2009 paper, Issues for Responsible User-Centric Identity, CDT made clear that we believe that user-centric federated identity has great promise to make online interactions easier, more secure, and more easily controlled by the user if key questions relating to privacy, security and recourse are addressed properly.
CDT has continued to look for answers to these questions and to develop innovative ways to enforce those solutions. Through this work, we also looked at existing structures that address similar issues, giving individuals control over information about themselves. It was during this review that the breadth of the Fair Credit Reporting Act (FCRA) became apparent.