Starbucks and other three catering enterprises rectified, and induced registered members of consumers to pay attention to the official account and claim personal information rights | law enforcement | personal information
Infringement of consumer personal information rights has become a common problem in the catering industry, and Shanghai regulatory authorities have taken a heavy blow.
Recently, after the launch of the "Bright Sword Pujiang Consumer Personal Information Rights Protection Special Law Enforcement Action", law enforcement officers from the Shanghai Cyberspace Administration and the Municipal Market Supervision Bureau conducted on-site law enforcement on Starbucks, Shake Shack, and Tiantai restaurants in two separate routes based on consumer reporting clues. It was found that three catering enterprises frequently induced users to obtain mobile phone numbers, induced consumers to provide accurate location information, frequently popped up windows to induce registered members, and induced consumers to pay attention to official account.
On the afternoon of June 19th, the Shanghai Cyberspace Administration and the Market Supervision Bureau, together with the Xuhui Cyberspace Administration and Huangpu Cyberspace Administration, lawfully interviewed relevant enterprises and required Starbucks, Shake Shack, and Tiantai restaurants to comprehensively rectify their behavior of excessive collection of personal information, according to the Shanghai Cyberspace Administration and the Market Supervision Bureau.
The heads of three companies stated that the reason for the problem is a lack of understanding of legal provisions such as the Personal Information Protection Law and the Methods for Determining the Illegal Collection and Use of Personal Information by APPs. The next step will be to carry out self inspection and rectification based on the requirements of the interview, drawing lessons from others.
At present, Shake Shack and Tiantai Restaurant have made preliminary improvements to the existing problems, and Starbucks is actively adjusting. The Shanghai Cyberspace Administration and the Municipal Market Supervision Bureau will continue to follow up on the rectification of enterprises and guide them to do a good job in personal information protection compliance.
The Shanghai Cyberspace Administration once again reminds that catering enterprises are suspected of illegal and irregular collection and use of personal information during the ordering process. It is hoped that operators will take the initiative to rectify the situation:
When using the mini program to scan and place orders for the first time, consumers did not receive any significant privacy policy prompts from the merchant through "pop ups" or other means.
2. Merchants do not have the option to "agree" or "refuse" in their service agreement and privacy policy, and consumers are allowed to provide personal information by default.
3. Merchants request personal sensitive information unrelated to catering services from consumers beyond their scope.
4. After scanning the QR code and placing an order, pop-up prompts such as "One click login on WeChat" to obtain a nickname and avatar, "One click login on WeChat phone number" to obtain a phone number, or when purchasing an order, consumers are required to provide their phone number. If consumers refuse the above authorization, they will not be able to place an order.
5. After scanning the QR code to place an order, the merchant applies for accurate location information on the grounds of selecting nearby stores, etc. If the consumer refuses, they will not be able to place an order.
6. After scanning the QR code to place an order, the merchant applies for precise location information. However, after the consumer refuses, they still frequently pop up windows to apply for location information, and the consumer is unable to use the store search function normally.
7. In the name of optimizing the service experience and providing member discounts, merchants induce consumers to authorize accurate location information or mobile phone numbers and other personal information, and induce consumers to pay attention to the enterprise official account. After consumers refuse, pop-up applications still appear repeatedly on the page, affecting consumers' normal use.
8. Without consumer consent or anonymization, merchants provide consumer personal information to third parties for use, and consumers frequently receive targeted advertising and marketing messages.
Under the guidance of the Network Law Enforcement and Supervision Bureau of the State Cyberspace Administration, the "Bright Sword Pujiang Consumer Personal Information Rights Protection Special Law Enforcement Action" is currently focusing on the centralized rectification of the catering industry.
In view of the common problems in the catering industry, such as mandatory request for user mobile phone numbers, inducing consumers to provide accurate location information, and mandatory attention to official account, the Shanghai Municipal Cyberspace Office and the Shanghai Municipal Market Supervision Bureau, together with relevant industry competent departments, carried out education and training from point to point, and made case statements to promote catering enterprises to actively fulfill their personal information protection obligations. At the same time, we will increase law enforcement efforts, carry out comprehensive industry governance, effectively protect the legitimate rights and interests of citizens' personal information, and promote a significant improvement in the current situation of personal information protection in the catering industry. Welcome netizens to actively participate in the "Bright Sword Pujiang" special action and provide clues based on facts.