Froomkin, Arencibia & Colangelo on Safety as Privacy

A. Michael Froomkin (University of Miami – School of Law; Yale ISP), Phillip J. Arencibia (Duane Morris LLP), and Zak Colangelo (Lewis Brisbois Bisgaard & Smith LLP) have posted “Safety as Privacy” on SSRN. Here is the abstract:

New technologies, such as internet-connected home devices we have come to call ‘the Internet of Things (IoT)’, connected cars, sensors, drones, internet-connected medical devices, and workplace monitoring of every sort, create privacy gaps that can cause danger to people. In Privacy as Safety, 95 Wash. L. Rev. 141 (2020), two of us sought to emphasize the deep connection between privacy and safety, in order to lay a foundation for arguing that U.S. administrative agencies with a safety mission can and should make privacy protection one of their goals. This article builds on that foundation with a detailed look at the safety missions of several agencies. In each case, we argue that the agency has the discretion, if not necessarily the duty, to demand enhanced privacy practices from those within its jurisdiction, and that the agency should make use of that discretion.

This is the first article in the legal literature to identify the substantial gains to personal privacy that several U.S. agencies tasked with protecting safety could achieve under their existing statutory authority. Examples of agencies with untapped potential include the Federal Trade Commission (FTC), the Consumer Product Safety Commission (CPSC), the Food and Drug Administration (FDA), the National Highway Traffic Safety Administration (NHTSA), the Federal Aviation Administration (FAA), and the Occupational Safety and Health Administration (OSHA). Five of these agencies have an explicit duty to protect the public against threats to safety (or against risk of injury) and thus – as we have argued previously – should protect the public’s privacy when the absence of privacy can create a danger. The FTC’s general authority to fight unfair practices in commerce enables it to regulate commercial practices threatening consumer privacy. The FAA’s duty to ensure air safety could extend beyond airworthiness to regulating spying via drones. The CPSC’s authority to protect against unsafe products authorizes it to regulate products putting consumers’ physical and financial privacy at risk, thus sweeping in many products associated with the IoT. NHTSA’s authority to regulate dangerous practices on the road encompasses authority to require smart car manufacturers include precautions protecting drivers from misuses of connected car data due to the car-maker’s intention and due to security lapses caused by its inattention. Lastly, OSHA’s authority to require safe work environments encompasses protecting workers from privacy risks that threaten their physical and financial safety on the job.

Arguably an omnibus, federal statute regulating data privacy would be preferable to doubling down on the U.S.’s notoriously sectoral approach to privacy regulation. Here, however, we say only that until the political stars align for some future omnibus proposal, there is value in exploring methods that are within our current means. It may be only second best, but it is also much easier to implement. Thus, we offer reasonable legal constructions of certain extant federal statutes that would justify more extensive privacy regulation in the name of providing enhanced safety, a regime that would we argue would be a substantial improvement over the status quo yet not require any new legislation, just a better understanding of certain agencies’ current powers and authorities. Agencies with suitably capacious safety missions should take the opportunity to regulate to protect relevant personal privacy without delay.

Solove & Keats Citron on Standing and Privacy Harms: A Critique of TransUnion v. Ramirez

Daniel J. Solove (George Washington University Law School) and Danielle Keats Citron (University of Virginia School of Law) have posted “Standing and Privacy Harms: A Critique of TransUnion v. Ramirez”
(101 Boston University Law Review Online 62 (2021)). Here is the abstract:

Through the standing doctrine, the U.S. Supreme Court has taken a new step toward severely limiting the effective enforcement of privacy laws.  The recent Supreme Court decision, TransUnion v. Ramirez (U.S. June 25, 2021) revisits the issue of standing and privacy harms under the Fair Credit Reporting Act (FCRA) that began with Spokeo v. Robins, 132 S. Ct. 1441 (2012). In TransUnion, a group of plaintiffs sued TransUnion under FCRA for falsely labeling them as potential terrorists in their credit reports. The Court concluded that only some plaintiffs had standing – those whose credit reports were disseminated. Plaintiffs whose credit reports weren’t disseminated lacked a “concrete” injury and accordingly lacked standing – even though Congress explicitly granted them a private right of action to sue for violations like this and even though a jury had found that TransUnion was at fault.

In this essay, Professors Daniel J. Solove and Danielle Keats Citron engage in an extensive critique of the TransUnion case. They contend that existing standing doctrine incorrectly requires concrete harm. For most of U.S. history, standing required only an infringement on rights. Moreover, when assessing harm, the Court has a crabbed and inadequate understanding of privacy harms. Additionally, allowing courts to nullify private rights of action in federal privacy laws is a usurpation of legislative power that upends the compromises and balances that Congress establishes in laws.  Private rights of action are essential enforcement mechanisms.

Richards on Why Privacy Matters

Neil M. Richards (Washington University School of Law) has posted “Why Privacy Matters: An Introduction” (Oxford Press 2021) on SSRN. Here is the abstract:

Everywhere we look, companies and governments are spying on us–seeking information about us and everyone we know. Ad networks monitor our web-surfing to send us “more relevant” ads. The NSA screens our communications for signs of radicalism. Schools track students’ emails to stop school shootings. Cameras guard every street corner and traffic light, and drones fly in our skies. Databases of human information are assembled for purposes of “training” artificial intelligence programs designed to predict everything from traffic patterns to the location of undocumented migrants. We’re even tracking ourselves, using personal electronics like Apple watches, Fitbits, and other gadgets that have made the “quantified self” a realistic possibility. As Facebook’s Mark Zuckerberg once put it, “the Age of Privacy is over.” But Zuckerberg and others who say “privacy is dead” are wrong. In Why Privacy Matters, Neil Richards explains that privacy isn’t dead, but rather up for grabs.

Richards shows how the fight for privacy is a fight for power that will determine what our future will look like, and whether it will remain fair and free. If we want to build a digital society that is consistent with our hard-won commitments to political freedom, individuality, and human flourishing, then we must make a meaningful commitment to privacy. Privacy matters because good privacy rules can promote the essential human values of human identity, political freedom, and consumer protection. If we want to preserve our commitments to these precious yet fragile values, we will need privacy rules. Richards explains why privacy remains so important and offers strategies that can help us protect it from the forces that are working to undermine it. Pithy and forceful, this is essential reading for anyone interested in a topic that sits at the center of so many current problems.

Selinger & Rhee on Normalizing Surveillance

Evan Selinger (Rochester Institute of Technology) and Judy Hyojoo Rhee (Duke University) have posted “Normalizing Surveillance” (Northern European Journal of Philosophy 22, 1 (2021): 49-74) on SSRN. Here is the abstract:

Definitions of privacy change, as do norms for protecting it. Why, then, are privacy scholars and activists currently worried about “normalization”? This essay explains what normalization means in the context of surveillance concerns and clarifies why normalization has significant governance consequences. We emphasize two things. First, the present is a transitional moment in history. AI-infused surveillance tools offer a window into the unprecedented dangers of automated real-time monitoring and analysis. Second, privacy scholars and ac- tivists can better integrate supporting evidence to counter skepticism about their most disturbing and speculative claims about normalization. Empirical results in moral psychology support the assertion that widespread surveillance typically will lead people to become favorably disposed toward it. If this causal dynamic is pervasive, it can diminish autonomy and contribute to a slippery slope trajectory that diminishes privacy and civil liberties.

Cooper on Congressional Surveillance

Aaron Cooper (Georgetown University Law Center) has posted “Congressional Surveillance” (American University Law Review, Vol. 70, No. 1799, 2021) on SSRN. Here is the abstract:

In recent years, Congress has increasingly used electronic surveillance in high-profile investigations. Reactions to what this Article calls “congressional surveillance” indicate a deep unease among both legal scholars and the broader public about the nature of Congress’s surveillance authority and its normative implications. Despite our ongoing preoccupation with government surveillance, congressional surveillance remains largely unexplored. There is virtually no discussion of how congressional surveillance is treated under key statutory and Fourth Amendment constraints; no consideration of the process or political limits of congressional surveillance; and little scrutiny of congressional surveillance as a tool within the separation of powers.

This Article fills that gap by presenting the first scholarly treatment of congressional surveillance. It argues that to address congressional surveillance, we must first understand its hybrid features of both government surveillance and congressional political power.

Specifically, the Article makes two contributions. First, the Article argues that congressional surveillance operates under fundamentally different constraints than traditional government surveillance. Congressional processes and politics (“process limits”) constrain congressional surveillance more than established statutory and Fourth Amendment mechanisms (“external limits”) or the inherent constraints of congressional authority (“internal limits”).

Second, this Article argues that congressional surveillance is justified as an essential practice within the separation of powers. It offers legitimate benefits to Congress in inter-branch information disputes with the executive and in carrying out basic digital governance. The Article also argues that the Supreme Court’s decision in Trump v. Mazars USA, LLP mistakes a privacy concern that congressional surveillance poses as a threat to the separation of powers. At the same time, this Article rejects the traditional law enforcement approach to protecting individual privacy through judicial gatekeeping. Instead, the Article argues that the treatment of congressional surveillance must account for individual privacy interests while preserving Congress’s ability to assert itself as a co-equal branch—not the Mazars approach, and not a law enforcement approach, but something different.

Hamilton et al. on Developing a Measure of Social, Ethical, and Legal Content for Intelligent Cognitive Assistants

Clovia Hamilton (SUNY Korea), William Swart (East Carolina University), and Gerald M. Stokes (SUNY Korea) have posted “Developing a Measure of Social, Ethical, and Legal Content for Intelligent Cognitive Assistants” (Journal of Strategic Innovation and Sustainability 2021) on SSRN. Here is the abstract:

We address the issue of consumer privacy against the backdrop of the national priority of maintaining global leadership in artificial intelligence, the ongoing research in Artificial Cognitive Assistants, and the explosive growth in the development and application of Voice Activated Personal Assistants (VAPAs) such as Alexa and Siri, spurred on by the needs and opportunities arising out of the COVID-19 global pandemic. We first review the growth and associated legal issues of the of VAPAs in private homes, banks, healthcare, and education. We then summarize the policy guidelines for the development of VAPAs. Then, we classify these into five major categories with associated traits. We follow by developing a relative importance weight for each of the traits and categories; and suggest the establishment of a rating system related to the legal, ethical, functional, and social content policy guidelines established by these organizations. We suggest the establishment of an agency that will use the proposed rating system to inform customers of the implications of adopting a particular VAPA in their sphere.

Ramirez on Spousal Wiretaps in the Digital Age

Karli Ramirez has posted “To Catch a Snooping Spouse: Reevaluating the Roots of the Spousal Wiretap Exception in the Digital Age” (170 U. Pa. L. Rev. (Forthcoming)) on SSRN. Here is the abstract:

Growing concerns over digital privacy can easily create tension in romantic relationships, including marriages. The Federal Wiretap Act is one example of a statutory vehicle for deterring and punishing spying in spousal relationships, but it is an unavailable tool in the Second and Fifth Circuits because of a judge-made spousal exception to the Act in those jurisdictions. Intercepting communications between one’s spouse and a third party is permissible under the spousal exception, making it difficult to hold spying spouses accountable for their actions. This work argues that because the spousal exception was created at the time of continued institutionalized subordination and limited privacy rights of women, two exceedingly outdated and sexist notions, the spousal exception has no basis in modern society and can no longer be seen as good law.

Kröger, Lutz & Ullrich on The Myth of Individual Control Over Privacy

Jacob Leon Kröger (Technische Universität Berlin; Weizenbaum Institute), Otto Hans-Martin Lutz (Weizenbaum Institute), and Stefan Ullrich (Weizenbaum Institute) have posted “The Myth of Individual Control: Mapping the Limitations of Privacy Self-management” on SSRN. Here is the abstract:

Despite years of heavy criticism, privacy self-management (i.e., the principle that people individually manage their privacy via notice and choice) remains the standard of privacy protection throughout the Western world. Building on previous research, this article provides an overview and classification of the manifold obstacles that render privacy self-management largely useless in practice. People’s privacy choices are typically irrational, involuntary and/or circumventable due to human limitations, corporate tricks, legal loopholes and the complexities of modern data processing. Moreover, the self-management approach ignores the consequences that individual privacy choices have on other people and society at large. Regarding future research, we argue that the focus should not be on whether privacy self-management can be fixed by making it more user-friendly or efficient – it cannot. The concept is based on fundamentally wrong assumptions. To meaningfully address the potentials and dangers of personal data processing in the 21st century, a shift away from relying purely on individual control is inevitable. We discuss potential ways forward, stressing the need for government intervention to regulate the social impact of personal data processing.

Yoo on Net Neutrality, Digital Platforms, and Privacy

Christopher S. Yoo (University of Pennsylvania Law School) has posted “The First Amendment, Common Carriers, and Public Accommodations: Net Neutrality, Digital Platforms, and Privacy” (Journal of Free Speech Law, Vol. 1, P. 463, 2021) on SSRN. Here is the abstract:

Recent prominent judicial opinions have assumed that common carriers have few to no First Amendment rights and that calling an actor a common carrier or public accommodation could justify limiting its right to exclude and mandating that it provide nondiscriminatory access. A review of the history reveals that the underlying law is richer than these simple statements would suggest. The principles for determining what constitutes a common carrier or a public accommodation and the level of First Amendment protection both turn on whether the actor holds itself out as serving all members of the public or whether it asserts editorial discretion over whom to carry or host. This gives putative common carriers and public accommodations substantial control over their First Amendment status. The jurisprudence on privacy regulation, quasi-common carriers, non-common carriage services, and public accommodations confirms that the First Amendment protections they enjoy are substantial.

Chawla on Pegasus Spyware – ‘A Privacy Killer’

Ajay Chawla (Delhi High Court) has posted “Pegasus Spyware – ‘A Privacy Killer'” on SSRN. Here is the abstract:

The recent Pegasus Project revelations of about half a lakh people across the world, including several in India, being targeted for cyber surveillance has firmly brought the spotlight on the Pegasus spyware, which is widely understood to be the most sophisticated smartphone attack tool. The revelations also mark the first time that a malicious remote jailbreak exploit had been detected within an iPhone.

Pegasus is a spyware (Trojan/Script) that can be installed remotely on devices running on Apple’s iOS & Google’s Android operating systems. It is developed and marketed by the Israeli technology firm NSO Group. NSO Group sells Pegasus to “vetted governments” for “lawful interception”, which is understood to mean combating terrorism and organized crime, as the firm claims, but suspicions exist that it is availed for other purposes.

Pegasus is a modular malware that can initiate total surveillance on the targeted device, as per a report by digital security company Kaspersky. It installs the necessary modules to read the user’s messages and mail, listen to calls, send back the browser history and more, which basically means taking control of nearly all aspects of your digital life. It can even listen in to encrypted audio and text files on your device that makes all the data on your device up for grabs.

Since Pegasus hacks into the operating system, every activity within the phone can be monitored when the phone is switched on. It’s as if someone is monitoring your phone activity over your shoulders. Pegasus operators can remotely record audio and video from your phone, extract phone messages, use GPS for location tracking, and recover passwords and authentication keys without the user even noticing. It’s only when a device is sent for forensic screening, and experts look into the transfer of data to and from the phone, is when a potential attack can be confirmed. The dooming fact of it all is that since Pegasus exploits zero-day vulnerabilities, there is nothing that can be done regarding such breaches unless operating system developers proactively ship out an update to your phone, aimed to protect you from hi-tech malware like Pegasus.