Waldman on Outsourcing Privacy

Ari Ezra Waldman (Northeastern University) has posted “Outsourcing Privacy” (Notre Dame Law Review, Vol. 96, 2021) on SSRN. Here is the abstract:

An underappreciated part of the narrative of privacy managerialism—and the focus of this Essay—is the information industry’s increasing tendency to outsource privacy compliance responsibilities to technology vendors. In the last three years alone, the International Association of Privacy Professionals has identified more than 250 companies in the privacy technology vendor market. These companies market their products as tools to help companies comply with new privacy laws like the General Data Protection Regulation, with consent orders from the Federal Trade Commission, and with other privacy rules from around the world. They do so by building compliance templates, pre-completed assessment forms, and monitoring consents, among many other things. As such, many of these companies are doing far more than helping companies identify the data they have or answer data access requests; many of them are instantiating their own definitions and interpretations of complex privacy laws into the technologies they create and doing so only with managerial values in mind. This undermines privacy law in four ways: it creates asymmetry between large technology companies and their smaller competitors, it makes privacy law underinclusive by limiting it to those requirements that can be written into code, it erodes expertise by outsourcing human work to artificial intelligence and automated systems, and it creates a “black box” that undermines accountability.

Erdos on Comparing Constitutional Privacy and Data Protection Rights within the EU

David Erdos (University of Cambridge – Faculty of Law; Trinity Hall) has posted “Comparing Constitutional Privacy and Data Protection Rights within the EU” on SSRN. Here is the abstract:

Although both data protection and the right to privacy (or respect for private life) are recognised within the EU Charter, they are otherwise generally seen as having very different constitutional histories. The right of privacy is often seen as traditional and data protection as novel. Based on a comprehensive analysis of rights within EU State constitutions, it is found that this distinction is overdrawn. Only five current EU States recognised a constitutional right to privacy prior to 1990, although approximately three quarters and also the European Convention do so today. Subsidiary constitutional rights related to the home and correspondence but not honour and/or reputation are more long-standing and this helps link the core of privacy to the protection of intimacy. Constitutional rights to data protection emerged roughly contemporaneously and were often linked to a general right to privacy but are still only found in around half of EU States. There is also no clear consensus on specific guarantees, although around half of the States which recognise these do include rights to transparency and a slightly lower number right to rectification. This could suggest that data subject empowerment over a wide range of connected information is an important emerging particularity tied to data protection as a constitutional guarantee.

Price on Problematic Interactions between AI and Health Privacy

W. Nicholson Price II (University of Michigan Law School) has posted “Problematic Interactions between AI and Health Privacy” (Utah Law Review, Forthcoming) on SSRN. Here is the abstract:

The interaction of artificial intelligence (AI) and health privacy is a two-way street. Both directions are problematic. This Essay makes two main points. First, the advent of artificial intelligence weakens the legal protections for health privacy by rendering deidentification less reliable and by inferring health information from unprotected data sources. Second, the legal rules that protect health privacy nonetheless detrimentally impact the development of AI used in the health system by introducing multiple sources of bias: collection and sharing of data by a small set of entities, the process of data collection while following privacy rules, and the use of non-health data to infer health information. The result is an unfortunate anti-synergy: privacy protections are weak and illusory, but rules meant to protect privacy hinder other socially valuable goals. The state of affairs creates biases in health AI, privileges commercial research over academic research, and is ill-suited to either improve health care or protect patients. The health system deeply needs a new bargain between patients and the health system about the uses of patient data.

Greenleaf on Global Tables of Data Privacy Laws and Bills (7th Ed, January 2021)

Graham Greenleaf (University of New South Wales, Faculty of Law) has posted “Global Tables of Data Privacy Laws and Bills (7th Ed, January 2021)” on SSRN. Here is the abstract:

This 2021 7th edition of the Tables detailing data privacy laws in all countries that have such laws or official bills, contains two parts: – the Global Table of Countries with Data Privacy Laws (now 145 countries); and the Global Table of Official Data Privacy Bills (now 23 countries).

These Tables are regarded as the most reliable periodic list of data privacy laws by many organisations across the world.

The data in the Tables is as known at 31 January 2021. The Tables were originally published in (2021) 169 Privacy Laws & Business International Report (PLBIR) pgs 6-19. New editions are published approximately every two years..

The data in the Tables is analysed in a series of three articles by me:

• ‘Global data privacy laws 2021: Despite COVID delays, 145 laws show GDPR dominance’ (2021) 169 PLBIR 1, 3-5,

• ‘Global data privacy laws 2021: Uncertain paths for international standards’ (2021) 169 PLBIR 23-27, and

• ‘Global data privacy 2021: DPAs joining networks are the rule’ (2021) 170 PLBIR 23-27 (will be available on SSRN in due course).

Copies of all legislation listed in the Laws Table are in the National Data Privacy Legislation database, part of the free access Global Data Protection, Privacy & Surveillance Law Library, located on the World Legal Information Institute (WorldLII).

Kilovaty on Psychological Data Breach Harms

Ido Kilovaty (University of Tulsa College of Law, Yale University – Law School) has posted “Psychological Data Breach Harms” (23 North Carolina Journal of Law & Technology (2021)) on SSRN. Here is the abstract:

Cybersecurity law, both in statutory and case law, is primarily based on the premise that data breaches result exclusively in financial harms. Intuitively, legal scholarship has largely been focused on financial harms to the exclusion of non-financial harms, emotional and mental, that also arise from data breaches. There is now a critical mass of research showing that consumers whose information has been compromised suffer from serious emotional and mental conditions as a result. This Article seeks to evaluate cybersecurity law in light of this reality and propose a framework to address these psychological data breach harms.

Psychological data breach harms arising from data breaches raise a plethora of significant challenges which the law does not adequately account for. Consumers suffering these harms are unlikely to pursue litigation, nor are they likely to prevail in it for both standing and cause of action reasons. In similar vein, different cybersecurity law frameworks, such as the Computer Fraud and Abuse Act, data security laws, data breach notification laws, and FTC enforcement do not generally recognize any harms that are non-monetary in nature. Moreover, companies suffering data breaches are not legally required to offer any assistance or mitigation for consumers who may suffer psychological harms. Contributing to these challenges is the fact that breached companies are often not even required to disclose breaches that are unlikely to cause future financial harm.

This Article offers a legal and conceptual framework for psychological data breach harms, which cybersecurity law currently overlooks. First, this Article argues for the recognition of psychological data breach harms within the process of cybersecurity, from the very outset. Second, this Article makes concrete recommendations on how psychological data breach harms ought to be addressed, both by regulators and breached entities, as well as the appropriate remedies. Third, this Article calls for a reconsideration of what we mean by “personal information,” and for the expansion of information categories that cybersecurity law protects.

Mulhoff on Predictive Privacy

Rainer Muhlhoff (Technische Universität Berlin (TU Berlin), Freie Universität Berlin) has posted “Predictive Privacy: Towards an Applied Ethics of Data Analytics” on SSRN. Here is the abstract:

Data analytics and data-driven approaches in Machine Learning are now among the most hailed computing technologies in many industrial domains. One major application is predictive analytics, which is used to predict sensitive attributes, future behavior, or cost, risk and utility functions associated with target groups or individuals based on large sets of behavioral and usage data. This paper stresses the severe ethical and data protection implications of predictive analytics if it is used to predict sensitive information about single individuals or treat individuals differently based on the data many unrelated individuals provided. To tackle these concerns in an applied ethics, first, the paper introduces the concept of “predictive privacy” to formulate an ethical principle protecting individuals and groups against differential treatment based on Machine Learning and Big Data analytics. Secondly, it analyses the typical data processing cycle of predictive systems to provide a step-by-step discussion of ethical implications, locating occurrences of predictive privacy violations. Thirdly, the paper sheds light on what is qualitatively new in the way predictive analytics challenges ethical principles such as human dignity and the (liberal) notion of individual privacy. These new challenges arise when predictive systems transform statistical inferences, which provide knowledge about the cohort of training data donors, into individual predictions, thereby crossing what I call the “prediction gap”. Finally, the paper summarizes that data protection in the age of predictive analytics is a collective matter as we face situations where an individual’s (or group’s) privacy is violated using data other individuals provide about themselves, possibly even anonymously. 

Download of the Week

The Download of the Week is “Privacy Harms” by Danielle Keats Citron (University of Virginia School of Law) and Daniel J. Solove (George Washington University Law School). Here is the abstract:

Privacy harms have become one of the largest impediments in privacy law enforcement. In most tort and contract cases, plaintiffs must establish that they have been harmed. Even when legislation does not require it, courts have taken it upon themselves to add a harm element. Harm is also a requirement to establish standing in federal court. In Spokeo v. Robins, the U.S. Supreme Court has held that courts can override Congress’s judgments about what harm should be cognizable and dismiss cases brought for privacy statute violations.

The caselaw is an inconsistent, incoherent jumble, with no guiding principles. Countless privacy violations are not remedied or addressed on the grounds that there has been no cognizable harm. Courts conclude that many privacy violations, such as thwarted expectations, improper uses of data, and the wrongful transfer of data to other organizations, lack cognizable harm.

Courts struggle with privacy harms because they often involve future uses of personal data that vary widely. When privacy violations do result in negative consequences, the effects are often small – frustration, aggravation, and inconvenience – and dispersed among a large number of people. When these minor harms are done at a vast scale by a large number of actors, they aggregate into more significant harms to people and society. But these harms do not fit well with existing judicial understandings of harm.

This article makes two central contributions. The first is the construction of a road map for courts to understand harm so that privacy violations can be tackled and remedied in a meaningful way. Privacy harms consist of various different types, which to date have been recognized by courts in inconsistent ways. We set forth a typology of privacy harms that elucidates why certain types of privacy harms should be recognized as cognizable. The second contribution is providing an approach to when privacy harm should be required. In many cases, harm should not be required because it is irrelevant to the purpose of the lawsuit. Currently, much privacy litigations suffers from a misalignment of law enforcement goals and remedies. For example, existing methods of litigating privacy cases, such as class actions, often enrich lawyers but fail to achieve meaningful deterrence. Because the personal data of tens of millions of people could be involved, even small actual damages could put companies out of business without providing much of value to each individual. We contend that the law should be guided by the essential question: When and how should privacy regulation be enforced? We offer an approach that aligns enforcement goals with appropriate remedies.

Citron & Solove on Privacy Harms

Danielle Keats Citron (University of Virginia School of Law) and Daniel J. Solove (George Washington University Law School) have posted “Privacy Harms” on SSRN. Here is the abstract:

Privacy harms have become one of the largest impediments in privacy law enforcement. In most tort and contract cases, plaintiffs must establish that they have been harmed. Even when legislation does not require it, courts have taken it upon themselves to add a harm element. Harm is also a requirement to establish standing in federal court. In Spokeo v. Robins, the U.S. Supreme Court has held that courts can override Congress’s judgments about what harm should be cognizable and dismiss cases brought for privacy statute violations.

The caselaw is an inconsistent, incoherent jumble, with no guiding principles. Countless privacy violations are not remedied or addressed on the grounds that there has been no cognizable harm. Courts conclude that many privacy violations, such as thwarted expectations, improper uses of data, and the wrongful transfer of data to other organizations, lack cognizable harm.

Courts struggle with privacy harms because they often involve future uses of personal data that vary widely. When privacy violations do result in negative consequences, the effects are often small – frustration, aggravation, and inconvenience – and dispersed among a large number of people. When these minor harms are done at a vast scale by a large number of actors, they aggregate into more significant harms to people and society. But these harms do not fit well with existing judicial understandings of harm.

This article makes two central contributions. The first is the construction of a road map for courts to understand harm so that privacy violations can be tackled and remedied in a meaningful way. Privacy harms consist of various different types, which to date have been recognized by courts in inconsistent ways. We set forth a typology of privacy harms that elucidates why certain types of privacy harms should be recognized as cognizable. The second contribution is providing an approach to when privacy harm should be required. In many cases, harm should not be required because it is irrelevant to the purpose of the lawsuit. Currently, much privacy litigations suffers from a misalignment of law enforcement goals and remedies. For example, existing methods of litigating privacy cases, such as class actions, often enrich lawyers but fail to achieve meaningful deterrence. Because the personal data of tens of millions of people could be involved, even small actual damages could put companies out of business without providing much of value to each individual. We contend that the law should be guided by the essential question: When and how should privacy regulation be enforced? We offer an approach that aligns enforcement goals with appropriate remedies.

Recommended.

Cofone on Privacy Class Actions

Ignacio Cofone (McGill University Faculty of Law) has posted “Privacy Class Actions” on SSRN. Here is the abstract:

Courts are increasingly being called upon to adjudicate privacy class actions arising from everything from a corporation’s business practices to external events such as hacking. But courts struggle with how to constitute and assess privacy injuries. This is problematic because courts must assess privacy harm throughout different stages in litigation – to determine standing, class certification, and compensation. It is problematic because the uncertainty with how to evaluate and identify privacy harm has produced a Circuit split on the requisite privacy injury sufficient for standing. Lastly, it is problematic because, as a consequence, despite the importance of these class actions for people’s access to justice and ensuring that companies comply with privacy law, their success as a vehicle to these means is hindered.

Privacy class actions are undertheorized. This Article provides a framework for distinguishing which class actions involve harm to people’s privacy interests and which do not, providing courts with the needed framework and proposing how to approach the Circuit split.

This framework’s approach to determining privacy harm has significant theoretical and practical benefits. From a theoretical standpoint, it sheds light on the relationship between privacy loss and actionable privacy harm. By proposing how privacy claims can be evaluated on a continuum, this Article’s proposal is well-suited for evaluating grey areas and, specifically, for class actions. From a practical standpoint, it has consequences for corporate liability and consumer redress for privacy breaches. Most importantly, it gives courts a tool to identify and navigate privacy harm, which continues to be an impediment to privacy class actions and which courts have manifested they are in need of.

Scholz on Indivisibilities in Technology Regulation

Lauren Henry Scholz (Florida State University – College of Law) has posted “Indivisibilities in Technology Regulation” on SSRN. Here is the abstract:

Lee Fennell’s “Slices and Lumps: Division and Aggregation in Law and Life” reveals the benefits of isolating configurations in legal analysis. A key characteristic of configurations — or “lumps” — whether found or created, is that they are indivisible. To say a lump is indivisible is not to say that it is literally impossible to divide, but rather “that it is considerably less valuable when divided, or that it is expensive (perhaps prohibitively so) to divide successfully.”

This Essay will extend Fennell’s approach to indivisibilities to the context of technology regulation. Fennell discusses at least two types of indivisibilities in the book. I will call these indivisibilities of fact and indivisibilities of law. Indivisibilities of fact are facts about the world that make it difficult to divide up a resource in ways other than predetermined lumps. Indivisibilities of law are outcomes at law that are relatively “all-or-nothing.” Indivisibilities of both types are at play in current issues in technology regulation.

With respect to indivisibilities of fact, this Essay will discuss the example of indivisibility of privacy regulation. Some argue that piecemeal, sector-specific privacy regulation is the same as no regulation at all due to realities of the technosocial environment. This comes down to a debate about the degree to which the level of consumer privacy-a fact about the world-is indivisible. With respect to indivisibilities of law, this Essay will discuss the example of consent in the law of adhesion contracts in the digital age. Whether there is consent is a binary distinction, with major implications at law. Some consumer advocates have argued that consent should be segmented into meaningful consent and less meaningful consent. But, perhaps, the concept of consent is indivisible. Whether or not consent can be understood as divisible-a characteristic of the law-has major implications for this area of law and policy.

Recommended.