TrustArc Inc. (formerly TRUSTe) is a privacy compliance technology company based in
Walnut Creek, California
Walnut Creek is a city in Contra Costa County, California, United States, located in the East Bay region of the San Francisco Bay Area, about east of the city of Oakland, California, Oakland. Walnut Creek has a total population of 70,127 per t ...
. The company provides software and services to help corporations update their privacy management processes so they comply with government laws and best practices.
Their
privacy seal or certification of compliance can be used as a marketing tool.
History
TrustArc was founded as a non-profit industry association called TRUSTe in 1997 by
Lori Fena, then executive director of the
Electronic Frontier Foundation
The Electronic Frontier Foundation (EFF) is an American international non-profit digital rights group based in San Francisco, California. It was founded in 1990 to promote Internet civil liberties.
It provides funds for legal defense in court, ...
, and Charles Jennings, a software entrepreneur, with the mission of fostering online commerce by helping businesses and other online organizations self-regulate privacy concerns.
In 2000, TRUSTe became the first organization to join the Safe Harbor framework of the
U.S. Department of Commerce and the
European Union
The European Union (EU) is a supranational union, supranational political union, political and economic union of Member state of the European Union, member states that are Geography of the European Union, located primarily in Europe. The u ...
, and subsequently launched its EU Safe Harbor Seal Program.
[ ] The EU-US Safe Harbor was agreed upon by the Department of Commerce and the EU to provide a framework for American companies to comply with European data and privacy standards.
In 2001, TRUSTe became a
Children's Online Privacy Protection Act
The Children's Online Privacy Protection Act of 1998 (COPPA) is a United States federal law
The law of the United States comprises many levels of Codification (law), codified and uncodified forms of law, of which the supreme law is ...
Safe Harbor organization for the
Federal Trade Commission
The Federal Trade Commission (FTC) is an independent agency of the United States government whose principal mission is the enforcement of civil (non-criminal) United States antitrust law, antitrust law and the promotion of consumer protection. It ...
and thereafter launched its Children's Privacy Seal Program. That year, Fran Maier, who had helped build
Match.com and had been running the company following the departure of its co-founder,
Gary Kremen, joined the organization as executive director. One of her first efforts was to address consumer issues with
email spam
Email spam, also referred to as junk email, spam mail, or simply spam, refers to unsolicited messages sent in bulk via email. The term originates from a Spam (Monty Python), Monty Python sketch, where the name of a canned meat product, "Spam (food ...
, which at the time was estimated to comprise 59 percent of all email traffic.
The same year, TRUSTe's founding executive director, Susan Yamada, who was formerly editor of
Upside Magazine, resigned, though later went on to serve as board chair.
In 2008, TRUSTe changed its structure from a non-profit industry association to a venture-backed for-profit company, raising its first round of capital from
Accel Partners
Accel, formerly known as Accel Partners, is a global venture capital firm. Accel works with startups in seed, early and growth-stage investments. The company has offices in Palo Alto, California and San Francisco, California, with additional ope ...
. This raised the question of whether a for-profit company would be less stringent on the companies it certifies than a non-profit.
In November 2009, Chris Babel, former Senior Vice President of
VeriSign
Verisign, Inc. is an American company based in Reston, Virginia, that operates a diverse array of network infrastructure, including two of the Internet's thirteen root nameservers, the authoritative registry for the , , and generic top-level d ...
's worldwide Authentication Services, joined TRUSTe as
chief executive officer
A chief executive officer (CEO), also known as a chief executive or managing director, is the top-ranking corporate officer charged with the management of an organization, usually a company or a nonprofit organization.
CEOs find roles in variou ...
. Maier remained active in the company until 2014, serving variously as president, CEO and board chair.
In 2013, TRUSTe was approved by th
European Interactive Digital Advertising Allianceas an official certification provider for the EU Self-Regulatory Programme for Online Behavioural Advertising. The same year, TRUSTe was named the first approved Accountability Agent for the Asia-Pacific Economic Cooperation's Cross Border Privacy Rules System.
In 2016, in an effort to help companies prepare for the European Union's
General Data Protection Regulation
The General Data Protection Regulation (Regulation (EU) 2016/679), abbreviated GDPR, is a European Union regulation on information privacy in the European Union (EU) and the European Economic Area (EEA). The GDPR is an important component of ...
, which extends the scope of the EU data protection law established in 1995 to all foreign companies processing data of EU residents, TRUSTe partnered with the
International Association of Privacy Professionals to offer free compliance assessments of a company's privacy practices.
On June 6, 2017, the company changed its name from TRUSTe to TrustArc.
Services

TrustArc's certification subsidiary, TRUSTe, provides privacy dispute resolution services, designed to help oversee consumer requests and complaints regarding the privacy practices of those companies participating in TRUSTe's program.
Criticism and controversies
A ''
Wired
Wired may refer to:
Arts, entertainment, and media Music
* ''Wired'' (Jeff Beck album), 1976
* ''Wired'' (Hugh Cornwell album), 1993
* ''Wired'' (Mallory Knox album), 2017
* "Wired", a song by Prism from their album '' Beat Street''
* "Wired ...
'' article in 2002 questioned whether TRUSTe certification could be trusted, noting that "TRUSTe officials often seemed to be covering for their clients" rather than revoking privacy seals for violations.
In January 2006,
Harvard
Harvard University is a private Ivy League research university in Cambridge, Massachusetts, United States. Founded in 1636 and named for its first benefactor, the Puritan clergyman John Harvard, it is the oldest institution of higher lear ...
economics researcher Benjamin Edelman published a study showing that sites with TRUSTe certification were 50 percent more likely to violate privacy policies than uncertified sites. Edelman also reported that TRUSTe did not go far enough to punish seal holders that break their rules and was not prompt enough in revoking the seal on companies that violate privacy standards.
Federal Trade Commission settlement
On November 17, 2014, the
Federal Trade Commission
The Federal Trade Commission (FTC) is an independent agency of the United States government whose principal mission is the enforcement of civil (non-criminal) United States antitrust law, antitrust law and the promotion of consumer protection. It ...
announced that TRUSTe had agreed to settle a complaint that it misrepresented to consumers its recertification program, and its status as a
non-profit
A nonprofit organization (NPO), also known as a nonbusiness entity, nonprofit institution, not-for-profit organization, or simply a nonprofit, is a non-governmental (private) legal entity organized and operated for a collective, public, or so ...
entity, against a $200,000 penalty. The FTC complaint alleged that from 2006 to 2013, TRUSTe failed, in over 1000 instances, to conduct annual privacy checks on the companies it certified. Consumer organizations, including Center for Digital Democracy and the
Consumer Federation of America
The Consumer Federation of America (CFA) is a non-profit organization founded in 1968 to advance consumer interests through research, education and advocacy.
The CFA's website states that its members are nearly 300 consumer-oriented non-profits, ...
, argued for higher penalties and more FTC oversight, but the FTC declined to increase the penalties.
FTC Commissioner
Maureen Ohlhausen issued a partial dissent to the FTC ruling, "because TRUSTe never misrepresented its corporate status," and had informed clients of its for-profit status.
See also
*
General Data Protection Regulation
The General Data Protection Regulation (Regulation (EU) 2016/679), abbreviated GDPR, is a European Union regulation on information privacy in the European Union (EU) and the European Economic Area (EEA). The GDPR is an important component of ...
*
EU-US Privacy Shield
*
California Privacy Rights Act
References
External links
*
{{DEFAULTSORT:TrustArc
Internet privacy organizations
Politics and technology
Self-regulatory organizations in the United States
Companies established in 1997