What measures has Amazon taken to limit employee access and strengthen security procedures in response to the FTC’s report?
A new report from the Federal Trade Commission (FTC) is raising concerns regarding consumer privacy as it reveals that tens of thousands of Amazon employees were able to have access to sensitive information collected from users of the company’s popular Alexa voice assistant.
The FTC’s report, which was released earlier this week, indicates that about 30,000 Amazon employees working in Amazon Web Services were able to retrieve users’ voice recordings and transcripts from Alexa’s database. The information that was made accessible included recordings and transcripts from the company’s Alexa voice assistant, which users interact with to perform tasks such as playing music, ordering groceries, or getting news updates.
The report also found that the company had not done enough to ensure that user data was kept securely. Amazon had failed to implement adequate security measures to protect users’ data and made it accessible to more people than necessary.
The FTC’s report led to a rebuke from the Federal Communications Commission (FCC), which stated that Amazon had violated the FTC’s rules on safeguarding consumer data and invited the Amazon Web Services to present a copy of its privacy policy.
The news has raised serious questions about the security and privacy of users’ data and Amazon’s ability to protect it. In response to the report, Amazon has stated that they take user privacy seriously and have taken steps to limit employee access and strengthen security procedures.
While Amazon has taken steps to address this issue, the news still serves as a reminder for the public to remain skeptical of how their data is being used. As such, it is important for companies and organizations to ensure they have secure and transparent policies in place to protect consumer data.
software. The company didn’t disclose that to users, the FTC said.
Amazon also repeatedly failed to delete location data from Alexa app users who thought they had eliminated their files. “Amazon itself determined that on many occasions between January 2018 and early 2022, Amazon retained Alexa app users’ geo-location information in secondary data storage locations that were insulated from consumers’ deletion requests,” the FTC said in its complaint, which was filed in federal court in Seattle. The company never informed Alexa users that it retained geo-location data they tried to delete, the agency said.
Amazon’s Schmidt said the company “can confirm we’ve deleted geo-location data that customers previously requested we delete, and can confirm that the deletion control is working properly for our customers.”
The FTC’s proposed order, which requires a judge’s signoff, would prohibit Amazon from using data customers had deleted to improve its services, require the company to notify users of its retention and deletion policies and mandate the creation of a privacy program related to use of location data, among other provisions.
Most Read from Bloomberg Businessweek
©2023 Bloomberg L.P.
:rnrn(Bloomberg) — Tens of thousands of Amazon.com Inc. employees once had access to audio recordings of Alexa users, according to US regulators. The Federal Trade Commission (FTC) said this week that some 30,000 Amazon workers had access to audio clips picked up by the company’s voice-activated speakers. This is a shocking revelation, as it demonstrates that access to the recordings went well beyond those employees who were working on Alexa-enabled products.
The FTC’s proposed order would prohibit Amazon from using data customers had deleted to improve its services, require the company to notify users of its retention and deletion policies and mandate the creation of a privacy program related to use of location data, among other provisions. Amazon has ramped up its privacy practices in recent years amid scrutiny from the media, privacy advocacy groups and the FTC.
However, Amazon has repeatedly failed to delete Alexa users’ data, even after customers asked it to. Until mid-2019, when a user requested that Alexa delete their voice recordings, Amazon kept a written transcript that could be used to train its speech-recognition software. The company also failed to delete location data from Alexa app users who thought they had eliminated their files.
The FTC’s tally of employees with access to Alexa recordings covers the period between August 2018 and September 2019, and it’s not clear how many personnel have such access today. Amazon’s Kristy Schmidt said the company “can confirm we’ve deleted geo-location data that customers previously requested we delete, and can confirm that the deletion control is working properly for our customers.”
Amazon’s failure to adequately protect customer data and disclose its practices has raised serious concerns about the company’s commitment to privacy. The FTC’s proposed order is a step in the right direction, but Amazon must continue to take steps to ensure that customer data is secure and that users are aware of how their data is being used.
