Online Trust Alliance Audit Finds 74% of U.S. Presidential Candidates’ Websites Fail to Respect Americans’ Privacy

Share Article

Candidates are sharing, selling and trading voters’ sensitive data with third parties

Online Trust Alliance

In this era of consumers’ mounting distrust of data and privacy practices, candidates must move beyond a compliance mindset and embrace responsible data stewardship.

The Online Trust Alliance (OTA), the non-profit with the mission to enhance online trust, today released its Presidential Candidate Online Trust Audit. The report evaluates the privacy, security and consumer protection practices of the top presidential candidates’ websites. After a thorough assessment, 17 of the 23 websites, or 74 percent received failing grades.

Conversely, the 26 percent that passed performed so admirably that they achieved “Honor Roll” status. There was no middle ground—either the websites had failing or excellent scores.

Poor Privacy Practices
All the failures can be attributed to troubling privacy practices, with 74 percent of candidates’ websites scoring an “F” grade in this category. Some websites failed due to nonexistent or inadequate privacy policy disclosures. Others flunked because they reserve the right to liberally share or sell their donors and site visitors’ personally identifiable information (PII), including addresses, phone numbers, employers and even passport numbers, with unaffiliated third parties that the candidates deem as like-minded organizations.

“Although political websites may not be beholden to the same security and privacy standards as industry, our findings clearly reveal that these campaigns’ data practices are out of alignment with consumer expectations and Federal Trade Commission guidelines for the business community,” said Craig Spiezle, Executive Director and President of OTA. “In this era of consumers’ mounting distrust of data and privacy practices, candidates must move beyond a compliance mindset and embrace responsible data stewardship.”

OTA recommends that voters review a candidate’s site for published privacy policies before making a donation or completing an online form. Unfortunately, 17 percent of the evaluated websites did not even have a discoverable privacy policy. Failure to disclose such information potentially puts candidates at odds with various federal and state regulations.

Bright Spots: Security and Consumer Protection
On a positive note, the candidates’ websites received excellent scores for server security, with only one site having an observed vulnerability (not serious enough to fail). This trend can be ascribed to the adoption of best practices and the fact that they are all relatively simple, recently built sites. 70 percent of the sites have implemented Always-On SSL, which encrypts the web session between the user and website, enhancing both data security and privacy of the user.

All candidates had excellent consumer protection scores. This category accounts for measures implemented to help protect one’s domain and email communications from eavesdropping through the adoption of best practices including email encryption and authentication protocols. This is important because deficiencies in this area can put campaigns at risk of phishing schemes whereby cybercriminals use spoofed domains to send fraudulent emails that appear to be from the candidate. Recipients are then tricked into donating money or revealing personal information, putting them at risk for identity theft.

Passing and Failing Candidates
The breakdown of candidates whose websites made OTA’s Honor Roll or failed the evaluation is as follows:

HONOR ROLL:
Jeb Bush (R)
Lincoln Chafee (D)
Chris Christie (R)
Martin O'Malley (D)
Rick Santorum (R)
Scott Walker (R)

FAILING GRADES:
Ben Carson (R)
Hillary Clinton (D)
Ted Cruz (R)
Carly Fiorina (R)
Jim Gilmore (R)
Lindsey Graham (R)
Mike Huckabee (R)
Bobby Jindal (R)
John Kasich (R)
Lawrence Lessig (D)
George Pataki (R)
Rand Paul (R)
Marco Rubio (R)
Bernie Sanders (D)
Jill Stein (G)
Donald Trump (R)
Jim Webb (D)

The complete report and methodology is posted here. In addition, the OTA will conduct a webinar briefing about the report on Friday, Sept. 25 at 1 p.m. EDT/10 a.m. PDT. Register Today

About OTA:
The Online Trust Alliance (OTA) is a non-profit with the mission to enhance online trust and user empowerment while promoting innovation and the vitality of the Internet. Its goal is to help educate businesses, policy makers and stakeholders while developing and advancing best practices and tools to enhance the protection of users' security, privacy and identity. OTA supports collaborative public-private partnerships, benchmark reporting, and meaningful self-regulation and data stewardship. Its members and supporters include leaders spanning the public policy, technology, ecommerce, social networking, mobile, email and interactive marketing, financial, service provider, government agency and industry organization sectors.

Contact:
Bradley Barth | Program Executive
VOXUS PR for OTA
253.444.5923
bbarth(at)voxuspr(dot)com

Share article on social media or email:

View article via:

Pdf Print

Contact Author

Bradley Barth
@otalliance
Follow >
Visit website