5.2 User Preferences, Retention, Disposal, and Privacy Notices
Key Takeaways
- Preference management must actually suppress email, SMS, cookie/sale-share choices, and (where required) Global Privacy Control signals through a single source of truth
- Retention schedules are tied to purpose; a legal hold freezes covered records but is not a license to keep unrelated data forever
- NIST SP 800-88 Rev. 1 sanitization methods are Clear, Purge, and Destroy; reformatting a drive is not Purge
- The FACTA Disposal Rule (16 CFR Part 682) requires reasonable measures to protect consumer-report information at disposal — shred or erase so it cannot practicably be reconstructed, or diligence plus a monitored disposal contract
- A privacy notice that over-promises (never share, always encrypt, honor every signal) is an FTC Act Section 5 deception case under the 1983 Policy Statement on Deception
User Preferences, Retention, Disposal, and Privacy Notices
Domain I.C performance indicator 4 groups three operational duties that live or die together: honor user preferences, keep data only as long as the purpose (and the law) require, dispose of it so it cannot be reconstructed, and tell the truth in a privacy notice. A company that publishes a beautiful notice and then ignores preferences, hoards records, or tosses consumer reports in a dumpster has built the exact fact pattern the FTC uses in Section 5 cases.
Preference management
User preferences are recorded choices about how the company may contact a person or use data for advertising and sale. On the exam, treat them as operational controls, not as a customer-service courtesy.
- Email. Commercial email is also governed by the Controlling the Assault of Non-Solicited Pornography and Marketing Act (CAN-SPAM) — the unsubscribe must actually work. Statutory detail sits in Domain II (Chapter 10). Here, know that the preference center must suppress.
- SMS and calls. Marketing texts and autodialed calls overlap the Telephone Consumer Protection Act (TCPA). Chapter 10 owns the consent rules. The operational point in this chapter: a cookie banner is not TCPA consent.
- Cookies, sale, and share. Comprehensive state laws give consumers the right to opt out of sale, sharing (California's term for cross-context behavioral advertising), and targeted advertising. A banner choice, a "Do Not Sell or Share My Personal Information" link, or a Global Privacy Control (GPC) / universal opt-out mechanism (UOOM) is a preference the stack must honor where those laws apply.
- Channel consistency. An email opt-out that does not stop the SMS vendor, or a GPC signal that the tag manager ignores, is a preference failure — and, if the notice promised honor, a deception problem.
Build a preference center that writes to a single source of truth, pushes suppressions to vendors, logs the timestamp and channel, and survives a vendor swap.
Retention schedules tied to purpose
A retention schedule is a written table of data categories, the purpose for keeping each category, the period, and the disposal method. U.S. sectoral statutes sometimes set floors (tax records, employment files, certain Fair Credit Reporting Act (FCRA) consumer-report duties). Comprehensive state privacy laws increasingly require that retention be reasonably necessary for the disclosed purpose. The privacy principle is the same even when no statute names a number: if the purpose is gone and no legal hold applies, the data should go.
Over-retention is not "being careful." It enlarges the blast radius of the next incident and contradicts a notice that said "we keep data only as long as needed."
A legal hold overrides the schedule for the records it covers. It does not authorize keeping unrelated marketing lists "in case." When the hold lifts, the schedule resumes and disposal runs.
Secure disposal: NIST and the FACTA Disposal Rule
Disposal is the last control on the schedule. Two sources dominate the exam.
NIST Special Publication 800-88 Revision 1, Guidelines for Media Sanitization (December 2014), remains the current final federal guidance. (Revision 2 has circulated as a draft; do not treat a draft as the binding text.) Sanitization renders access to the data infeasible for a given level of effort. Three methods:
| Method | What it does | Typical use |
|---|---|---|
| Clear | Logical overwrite of user-addressable storage | Reuse inside the same organization at moderate confidentiality |
| Purge | Degauss, cryptographic erase, or other techniques that defeat laboratory recovery | Higher confidentiality, or media that will leave your control |
| Destroy | Shred, pulverize, incinerate, or melt so the media cannot be reused | Highest confidentiality or end of media life |
Reformatting a drive is not Purge. Dragging a folder to the trash is not Clear. Choose the method from the confidentiality of the data and whether the media will be reused, resold, or discarded.
The FACTA Disposal Rule, 16 CFR Part 682, is a binding FTC rule, not a brochure. Any person who maintains or possesses consumer information — information from or derived from a consumer report — for a business purpose must take reasonable measures to protect against unauthorized access to or use of that information in connection with its disposal. The Rule's own examples (16 CFR § 682.3) are the ones to recite:
- Implement and monitor policies that require burning, pulverizing, or shredding of paper so the information cannot practicably be read or reconstructed.
- Implement and monitor policies that require destruction or erasure of electronic media to the same standard.
- After due diligence, enter into and monitor a written contract with a party in the record-destruction business. Diligence can include an independent audit, references, a recognized trade-association certification, or review of the vendor's security procedures.
The Rule took effect 1 June 2005. Entities already under the GLBA Safeguards Rule may fold Disposal Rule duties into that information-security program. The Disposal Rule does not apply only to consumer-reporting agencies; employers, landlords, and lenders that possess consumer-report information are in scope.
Scenario. A lender boxes five years of printed consumer reports and hires the cheapest shredder that answers the phone. There is no written contract, no site visit, and no certificate of destruction. The boxes later appear intact at a recycling yard. That is a Disposal Rule failure (no reasonable measures, no diligence) and an accountability failure. A privacy notice that said "we securely destroy credit reports" is also a Section 5 representation.
Effective privacy notices and layered design
An effective privacy notice tells a reasonable reader six things:
- Who is collecting (legal name, and any brands that share the same notice).
- What is collected, including data collected automatically.
- Why — purposes specific enough that a new purpose would be a change.
- Sharing — categories of recipients: processors, affiliates, advertisers, consumer-reporting agencies.
- Rights — access, deletion, correction, opt-out of sale, share, or targeted advertising, as applicable.
- Contact — a working method, not a dead mailbox.
Layered notice is the exam's preferred design: a short notice or just-in-time prompt with the material points, plus a link to the full policy. The California Online Privacy Protection Act (CalOPPA) (Cal. Bus. & Prof. Code §§ 22575–22579) separately requires operators of commercial sites and online services that collect personally identifiable information from California consumers to conspicuously post a privacy policy and, after the 2013 amendment, to say how the operator responds to Do Not Track browser signals and whether third parties collect information over time and across sites. CalOPPA is a posting statute with a 30-day post-notice cure. It is not a substitute for telling the truth, and it is not the same instrument as a GPC honor duty under the CCPA.
The exam trap: over-promising becomes Section 5
A notice is a material representation. Under the FTC's 1983 Policy Statement on Deception, a deceptive act is a representation, omission, or practice that is likely to mislead a consumer acting reasonably under the circumstances and that is material. Intent to lie is not required.
Classic over-promises: "We never share personal information" while an advertising pixel fires hashed emails; "we encrypt all health data at rest" while backups sit in plaintext; "we honor every Do Not Track signal" while the tag manager ignores GPC; "we delete within 30 days" while the warehouse job never runs. Those sentences become FTC Act Section 5 deception counts — and state unfair and deceptive acts and practices (UDAP) counts — even when no comprehensive federal privacy statute covers the underlying practice.
Exam traps. Do not treat FACTA disposal as optional best practice. Do not call NIST SP 800-88 a statute. Do not let a legal hold become an excuse for infinite retention of unrelated data. Do not write a notice that marketing and engineering cannot operationally keep.
Under the FACTA Disposal Rule, which action best satisfies the reasonable-measures standard?
A company keeps marketing emails forever, just in case. Counsel later issues a legal hold on a subset of those mailboxes. What is the correct retention analysis?
A privacy notice says "We never share your personal information with third parties." The company drops a third-party advertising pixel that sends hashed emails to an ad platform. The strongest federal theory is: