Solove on AI and Privacy

Daniel J. Solove (George Washington U Law) has posted “Artificial Intelligence and Privacy” (77 Florida Law Review (forthcoming Jan 2025)) on SSRN. Here is the abstract:

This Article aims to establish a foundational understanding of the intersection between artificial intelligence (AI) and privacy, outlining the current problems AI poses to privacy and suggesting potential directions for the law’s evolution in this area. Thus far, few commentators have explored the overall landscape of how AI and privacy interrelate. This Article seeks to map this territory.

Some commentators question whether privacy law is appropriate for addressing AI. In this Article, I contend that although existing privacy law falls far short of addressing the privacy problems with AI, privacy law properly conceptualized and constituted would go a long way toward addressing them.

Privacy problems emerge with AI’s inputs and outputs. These privacy problems are often not new; they are variations of longstanding privacy problems. But AI remixes existing privacy problems in complex and unique ways. Some problems are blended together in ways that challenge existing regulatory frameworks. In many instances, AI exacerbates existing problems, often threatening to take them to unprecedented levels.

Overall, AI is not an unexpected upheaval for privacy; it is, in many ways, the future that has long been predicted. But AI glaringly exposes the longstanding shortcomings, infirmities, and wrong approaches of existing privacy laws.

Ultimately, whether through patches to old laws or as part of new laws, many issues must be addressed to address the privacy problems that AI is affecting. In this Article, I provide a roadmap to the key issues that the law must tackle and guidance about the approaches that can work and those that will fail.

Gilman & Wagman on The Law and Economics of Privacy

Daniel J. Gilman (International Center for Law & Economics) & Liad Wagman (Illinois Institute of Technology – Stuart School of Business) have posted “The Law and Economics of Privacy” on SSRN. Here is the abstract:

Consumer welfare has been a north star of the Federal Trade Commission (FTC), providing an organizing principle for diverse issues under the Commission’s dual competition and consumer protection missions and, specifically, a uniform ground on which to examine the law and economics of privacy matters and the tradeoffs that privacy policies entail. This paper provides the first contemporary literature synthesis by former FTC staff that brings together the legal and economics literatures on privacy. Our observations are the following: (a) privacy is a complex subject, not a simple attribute of goods and services or a simple state of affairs; (b) privacy policies entail complex tradeoffs for and across individuals; (c) the economic literature finds diverse effects, both intended and unintended, of privacy policies, including on competition and innovation; (d) while there is diverse and growing evidence of the costs of privacy policies, countervailing benefits have been understudied and, as of yet, empirical evidence of such benefits remains slight; and (e) observed costs associated with omnibus policies suggest caution regarding one-size-fits-all regulation.

Keats Citron on A More Perfect Privacy

Danielle Keats Citron (U Virginia Law) has posted “A More Perfect Privacy” (Boston U Law Review, Forthcoming) on SSRN. Here is the abstract:

Fifty years ago, federal and state lawmakers called for the regulation of a criminal justice “databank” connecting federal, state, and local agencies. There was bipartisan concern that the system imperiled constitutional commitments and people’s crucial life opportunities, including jobs, education, housing, and licenses. Bipartisan congressional concerns of the 1970s should be cause for re-invigoration, not resignation. Recounting the insights of members of the 93rd and 94th Congresses should embolden us. Their concerns clarify the headwinds that reformers face. Then, as now, powerful interests want us to think that privacy and public safety are incompatible. They want us to view diminished expectations of privacy as acceptable, even valuable. Revisiting this history should remind the public that totalizing surveillance is neither acceptable nor desirable. Privacy can and should be ours.

Keats Citron on the Surveilled Student

Danielle Keats Citron (U Virginia Law) has posted “The Surveilled Student” (Stanford Law Review, v. 76) on SSRN. Here is the abstract:

We live in a golden age of student surveillance. Some surveillance is old school: video cameras, school resource officers, and tip lines. Old-school surveillance, which is largely cabined in time and location, is now paired with new-school surveillance, which extends monitoring far beyond school hours and hallways. School-provided laptops have corporate software installed that does two things: first, it blocks “objectionable” material and informs administrators about the content that students tried to access; second, it scans students’ online activities wherever (home) and whenever (weekends). If inclined, teachers and school resource officers can watch in real-time students’ searches, browsing, emails, chats, photos, calendar invites, geolocation, and more. Companies continuously monitor students’ laptop activity in the name of safety. Student surveillance is 24 hours a day, seven days a week, 365 days a year. There is no reprieve.

This essay does what many school districts and companies refuse to do in the open—provide a clear-eyed analysis of the costs and benefits of student surveillance. My assessment is limited to what investigative journalists, advocacy groups, and researchers have discovered about opaque corporate practices and companies reveal. What we know is too little—the lack of transparency is part of the problem. Lawmakers and the public need a full view of the stakes, so they can have a meaningful say.

Children’s safety is a paramount value. The question remains whether student surveillance protects students from self-harm, violence, and cyber bullying, as companies claim. School administrators say that the monitoring services make them “feel” safer and better informed. But feeling isn’t fact. Continuous and indiscriminate monitoring of students’ online activities is “security theater.” From what we know, students may be less safe and less well-off. Companies claim that their algorithms detect suicidal ideation, bullying, and impending violence, and that content moderators alert school officials and law enforcement so they can prevent harm. Proof of concept is scant, but from what we do know, most often, alerts from surveillance companies create a chain reaction of discipline for minor infractions. Serious punishment, like suspension, is disproportionately meted out to Black female and male students. Monitoring systems “out” LGBTQ+ students to teachers and parents (who may be unsupportive or worse). These costs are mostly borne by students from disadvantaged backgrounds—a blow to equal opportunity.

Dragnet-style surveillance exacts profound costs to what I describe as student intimate privacy. Student intimate privacy is essential for children’s self-development and self-expression. Unlike most other periods in their lives, students experience tremendous personal growth and development. Students’ job is learning, listening, reading, speaking, exploring, and befriending. It is figuring out who they are and want to become. Schools play a central role in all of that—their job is preparing and cultivating an engaged citizenry. Student surveillance diminishes that potential. It harms students as listeners because filtering software blocks sources of knowledge, including news stories and resources for sexual health; it harms students as speakers because it creates an atmosphere of fear and intimidation that results in self-censorship and conformity.

Schools justify their contracts with surveillance companies by pointing to a federal law designed to prevent students from accessing obscene material, a law that by its own terms rejects continuous tracking of students’ online activities. Congress must step in to clear up the confusion. Lawmakers should provide incentives to schools to ensure that surveillance technologies work and that they minimize intrusions on student intimate privacy, free expression, and equal opportunity to the greatest extent possible. Reforms providing vigorous protection for students’ intimate privacy are crucial to students’ free expression and schools’ role in cultivating democratic citizens.

Hartzog, Selinger & Gunawan on Privacy Nicks: How the Law Normalizes Surveillance

Woodrow Hartzog (Boston University School of Law; Stanford Law School Center for Internet and Society), Evan Selinger
(Rochester Institute of Technology – Department of Philosophy), and Johanna Gunawan (Northeastern University Khoury College of Computer Sciences) have posted “Privacy Nicks: How the Law Normalizes Surveillance” (101 Washington University Law Review, Forthcoming) on SSRN. Here is the abstract:

Privacy law is failing to protect individuals from being watched and exposed, despite stronger surveillance and data protection rules. The problem is that our rules look to social norms to set thresholds for privacy violations, but people can get used to being observed. In this article, we argue that by ignoring de minimis privacy encroachments, the law is complicit in normalizing surveillance. Privacy law helps acclimate people to being watched by ignoring smaller, more frequent, and more mundane privacy diminutions. We call these reductions “privacy nicks,” like the proverbial “thousand cuts” that lead to death.

Privacy nicks come from the proliferation of cameras and biometric sensors on doorbells, glasses, and watches, and the drift of surveillance and data analytics into new areas of our lives like travel, exercise, and social gatherings. Under our theory of privacy nicks as the Achilles heel of surveillance law, invasive practices become routine through repeated exposures that acclimate us to being vulnerable and watched in increasingly intimate ways. With acclimation comes resignation, and this shift in attitude biases how citizens and lawmakers view reasonable measures and fair tradeoffs.

Because the law looks to norms and people’s expectations to set thresholds for what counts as a privacy violation, the normalization of these nicks results in a constant re-negotiation of privacy standards to society’s disadvantage. When this happens, the legal and social threshold for rejecting invasive new practices keeps getting redrawn, excusing ever more aggressive intrusions. In effect, the test of what privacy law allows is whatever people will tolerate. There is no rule to stop us from tolerating everything. This article provides a new theory and terminology to understand where privacy law falls short and suggests a way to escape the current surveillance spiral.

Dvoskin on Speaking Back to Sexual Privacy Invasions

Brenda Dvoskin (Harvard Law) has posted “Speaking Back to Sexual Privacy Invasions” (Washington Law Review, Vol. 98, 2023) on SSRN. Here is the abstract:

Many big players in the internet ecosystem do not like hosting sexual expression. They often justify these bans as a protection of sexual privacy. For example, Meta states that it removes sexual imagery to prevent the nonconsensual distribution of sexual images. In response, this Article argues that banning digital sexual expression is counterproductive if the aim is to alleviate the harms inflicted by sexual privacy losses.

Contemporary sexual privacy theory, however, lacks analytical tools to explain why nudity bans harm the interests they intend to protect. This Article aims at building those tools. The main contribution is an invitation to locate part of the harm that victims experience not in the unwanted exposure but in the social interpretations of that exposure. If social interpretations make losses of sexual privacy exceptionally harmful, we should focus on both preventing invasions and changing those interpretations. Sexual expression is a powerful discourse that often aims at rewriting the social script that underlies the social sanctions we collectively impose on victims. Thus, the Article argues that protecting sexual expression ought to be an essential piece of a content moderation system designed from a sexual privacy perspective.

Schultz & Dincer on Clearview AI Litigation

Jason Schultz (NYU Law) and Melodi Dincer (same) have posted “Amici Brief of Science, Legal, and Technology Scholars in Renderos et al. v. Clearview AI, Inc. et al., No. RG21096898 (Superior Ct. Alameda County)” on SSRN. Here is the abstract:

This Amici Brief was filed before the Superior Court of the State of California, County of Alameda in the case of Renderos et al. v. Clearview AI, Inc. et al. in support of Plaintiffs’ opposition to Defendant Clearview’s Special Motion to Strike Pursuant to California Code of Civil Procedure § 425.16 (California’s anti-SLAPP statute).

For over a century, the right of publicity (ROP) has protected individuals from unwanted commercial exploitation of their identities. Originating around the turn of the twentieth century in response to the newest image-appropriation technologies of the time, the ROP has continued to evolve to cover each new wave of technologies enabling companies to exploit peoples’ identities as part of their business models.

The latest example of such a technology is Defendant Clearview AI’s facial recognition (FR) application. Clearview boasts that the primary economic value of its app stems from commercially exploiting its massive facial image database, filled with millions of individual likenesses and identities that it appropriated through images scraped from across the internet. Clearview’s misappropriations also extend to training its algorithm, matching identities to new images, and displaying results to customers. The purpose of Clearview’s product is to allow customers to identify an individual using only a picture of their face. Without the capacity to exploit millions of likenesses and identities, Clearview’s system would fail to function as a commercial product.

Clearview attempts to avoid ROP liability by arguing (1) that it cannot be liable because humans rarely witness its acts of misappropriation and (2) that its app and business strategy are forms of protected speech under the First Amendment.

In this brief, Amici Science, Legal, and Technology Scholars urge the Court to reject Clearview’s arguments and allow Plaintiffs’ ROP claim to proceed. First, Amici describe how the ROP claim against Clearview’s FR technology is consistent with those upheld by the courts for over a century, tracing the parallel evolutions of early image-appropriation technologies and of the ROP as a legal limitation on their capacity to exploit identities for profit. Amici then apply each ROP element to Clearview’s FR app. Second, Amici challenge Clearview’s claim to protection under the anti-SLAPP statute. Clearview does not appropriate images and identities as a form of speech in connection with a public issue. Clearview is a visual surveillance company that built its app off misappropriated images for the exclusive purpose of selling and operating its commercial surveillance services, using proprietary software that it attempts to keep as far from public scrutiny as possible.

If the Court finds this case is insulated from judicial review, a company can appropriate billions of individuals’ images and identities without consent, enmesh those identities in its product, license that product widely, profit lavishly, and continue with business as usual. As new products emerge that similarly undermine one’s ability to control who can use their identity and how, individuals will have less legal recourse than their ancestors had a century ago.

Faced with these facts, this Court should reject Clearview’s anti-SLAPP Motion and find Plaintiffs have alleged a legally valid ROP claim at this early stage.

Lundqvist on Regulating Data Access and Portability of Data in the EU

Bjorn Lundqvist (Stockholm University – Faculty of Law) has posted “Regulating the Data-Driven Economy Under EU Law – Access and Portability of Data” on SSRN. Here is the abstract:

While business users face difficulties accessing and porting data on platforms, the Digital Markets Act and the proposed Data Act have been hailed as the legislative tools enabling users access and transfer the data they have generated on platforms controlled by gatekeepers or Internet of Things manufacturers. The tools provided by the Digital Markets Act and the proposed Data Act respectively are discussed in this manuscript and the author argues that users should have a more elaborated right to first access the data they produce on platforms, with Internet of Thing devices and in ecosystems, and secondly transfer such data from platform to platform, cloud to cloud, thing to thing or in-house. A right to access and transfer data could have several benefits; it benefits dissemination of data, creativity and innovation in connected markets and it promotes competition between platforms, clouds and ecosystem providers. Creativity will be enhanced because necessary data — being the raw material for new innovations—will be more broadly disbursed. It will also benefit consumers having a disbursed and disseminated data commons for the development of ideas, innovations, and the exchange of knowledge.

Indeed, with an aim of finding a solution for dysfunctional and unfair data-driven markets; the proposal is that the EU should introduce an access and transfer governance right to data, an Access and Transfer Right (ATR). A new form of right, however not derived from the idea of exclusive control of the object of property, but on a right to access and transfer data. A governance right that can work in tandem with data protection rules benefiting individuals and businesses. Areas that will be explored include the subject-matter of the protection, potential right holders and the scope of the protection, including exceptions and limitations under intellectual property law and competition law.

Yoo on The Overlooked Systemic Impact of the Right to Be Forgotten

Christopher S. Yoo (University of Pennsylvania Carey Law School) has posted “The Overlooked Systemic Impact of the Right to Be Forgotten: Lessons from Adverse Selection, Moral Hazard, and Ban the Box” (University of Pennsylvania Law Review Online, vol. 170, forthcoming) on SSRN. Here is the abstract:

The right to be forgotten, which began as a part of European law, has found increasing acceptance in state privacy statutes recently enacted in the U.S. Commentators have largely analyzed the right to be forgotten as a clash between the privacy interests of data subjects and the free speech rights of those holding the data. Framing the issues as a clash of individual rights largely ignores the important scholarly literatures exploring how giving data subjects the ability to render certain information unobservable can give rise to systemic effects that can harm society as a whole. This Essay fills this gap by exploring what the right to be forgotten can learn from the literatures exploring the implications of adverse selection, moral hazard, and the emerging policy intervention know as ban the box.

Ohm & Kim on The Internet of Things

Paul Ohm (Georgetown University Law Center) and Nathaniel Kim have posted “Legacy Switches: A Proposal to Protect Privacy, Security, Competition, and the Environment from the Internet of Things” (Ohio State Law Journal, Forthcoming) on SSRN. Here is the abstract:

The Internet of Things (IoT) promises us a life of automated convenience. Bright and shiny—if cheaply made and plasticky—“smart” thermostats, doorbells, cameras, and fridges carry out the functions once performed by “dumb” equivalents but in an automated, connected, and generally “better” way. This convenience comes at a significant cost. IoT devices listen to, record, and share our behavior, habits, speech, social interactions, and location minute-by-minute, 24/7. All of this information feeds a growing surveillance economy, as this data is bought, sold, and analyzed to predict our behavior, subject us to targeted advertising, and manipulate our actions. Many cheap IoT gadgets are developed on a shoestring budget, leaving them unsecure and vulnerable to attack. Malicious actors (and their automated computer programs) target IoT devices, breaking into them to spy on their owners or enlisting them into massive botnets used to cripple websites or critical infrastructure. These problems magnify over time, as IoT vendors focus on selling the next version of the device rather than on securing the preexisting installed base.

Consumers interested in protecting themselves from these harms may decide to replace outdated devices with newer, not-quite-yet-obsolete versions. Doing this does nothing to slow the growth of the surveillance economy and may even exacerbate it, as new devices tend to listen and record more than the models they replace. And even though replacing IoT devices can temporarily forestall security harms, asking consumers to replace all of their smart devices every few years introduces different harms. It harms the environment, filling our landfills with nonbiodegradable plastic housings and circuit parts which leach toxic materials into our air, soil, and water. It forces consumers to waste time, attention, and money tending to hard-wired, infrastructural devices that in the past would have lasted for decades. It compounds the harms of inequality, as those with more disposable income and connections to electricians and contractors have access to better security and privacy than those with less.

We propose a novel, simple, and concrete solution to address all of these problems. Every IoT device manufacturer should build a switch into their device called a “legacy switch.” When the consumer flips this switch, it should disable any smart feature that contributes to security or privacy risks. A legacy switch will render a smart thermostat just a thermostat and a smart doorbell just a doorbell. The switch will disable microphones, sensors, and wireless connectivity. Any user should find it easy to use and easy to verify whether the switch has been toggled.

This Article proposes legacy switches, elaborates key implementation details for any law requiring them, and connects them to the ongoing conversation about power, privacy, and platforms. The proposal to require legacy switches should be seen as a small but meaningful step toward taming the unchecked and destructive tendencies of the new networked economy.