Friday, April 5, 2013

Right to Know CA Legislation



The EFF and ACLU of Northern California have helped California Assemblymember Bonnie Lowenthal introduce a new proposal called the Right to Know Act (AB 1291, PDF new window). The legislation is directed for customers wanting to know how much personal information is being disclosed to third parties from businesses that collect information for marketing purposes. Current CA law requires a response within thirty days of the names and addresses of the recipients of that information. This amendment would require the business to 1) provide to any customer, at no charge, a copy of that information, the names of contact information for all 3rd parties that the business shared the information for the last 12 months, and 2) provide information regarding the privacy policy and avoiding disclosure of personal information. Violation of these provisions would constitute an injury to the consumer. It does not create additional categories of privacy.

The EFF considers this a much needed update to the transparency law for the digital age, since the previous version was tailored for direct marketing. For example, the previous statute does not mention location data, which is increasingly valuable as smartphones proliferate. The EFF suggests that because Europeans have similar sorts of access, companies already have the “systems in place to facilitate user access.” It does not acknowledge that importing these systems to the US could incur costs, through software installation or greater demands on consumer service requiring detailed responses (though I can see the second part of the bill being satisfied by a boilerplate description). It also does not access whether requests for personal knowledge will be affected by the bills passing.

Although California is at the forefront of consumer privacy in the US, the bill has just been introduced so there is no knowledge of its probability of passing or existing in a diluted form. Data brokers have been notorious in refusing to name information sources, even to Congressional caucuses (here's an example letter: PDF new window); Senate investigations have been fruitless and their responses have been general, with even one organization (FICO) denying they even are a data broker. Whether they exercise their lobbying power to combat this bill remains to be seen.

Wednesday, April 3, 2013

The NCAA, Kevin Ware, and a T-Shirt

Everyone remembers Kevin Ware's unbelievably painful-looking broken leg right? If not, Google it. Be warned; it's awful. I'm intentionally not linking to the video since it seems that Ware prefers that it not be played over and over

Apparently, Ware's team rallied around him following his injury and won the game. That kind of excitement is what college sports are all about, right? The NCAA sure thinks so; it has decided to sell t-shirts commemorating the injury and Louisville's subsequent victory. The shirts will have Ware's number on the back and the words "Ri5e to the Occasion" on the front and will sell for $24.99. The Nation reports that Ware and his family will receive no compensation from t-shirt sales, which especially smarts because college athletes aren't entitled to worker's compensation meaning that the NCAA probably won't have to pay Ware's long-term rehab costs.

Maybe Ware should consider an appropriation claim to collect some of the proceeds from those t-shirts? Even though it sounds appealing, this may be a legal dead end. Ware's face and name aren't on the shirt, which might mean that Ware can't show that his "likeness" was appropriated (see White v. Samsung Electronics finding that a robot designed to look like Vanna White and used in an advertisement was not a likeness such that White could support an appropriation claim under California law).

Ware may have to wait for the resolution of a current case, O'Bannon v. NCAA, which seeks compensation from the NCAA for the advertising use of student-athletes' names and images. Stay tuned!

Harvard University Secretly AccessResident Deans Mail


A Bloomberg article revealed that one year ago “the administration at Harvard University secretly searched campus e-mail files of 16 resident deans, who sit on the administrative board that probes student infractions, to see who had forwarded an e-mail regarding cheating to the student newspaper, the Boston Globe and the New York Times.” The exam was a government course “Introduction to Congress.” While surreptitious intrusion into an employee’s privacy raises grave concern, the irony of the “right to be left alone” is not lost.
However, “any company [] that provides others with the means to communicate electronically can be a[n] [electronic service] provider,” regardless of the entity’s primary business or function.” Fraser. In other words federal law permits employers to monitor employees’ e-mail as long as the information is stored on employer-provided wire or electronic communications services and the review is authorized by the employer’s own policies. The relevant question then is whether the university gave adequate notice of its policy or practice of monitoring its electronic and computer systems to the deans.
The article note  “Harvard’s employee manual, state that employees have ‘no expectation of privacy’ for anything they write or store on the university’s network.” But maintaining and disseminating a written notice of its electronic monitoring policy does not insulate Harvard from legal risk. The monitoring policy must be comprehensive and must make it clear to the employee that personal web-based e-mail accounts may also be viewed by the employer if accessed from company property this would arguably be sufficient to notify the employee that there should be no expectation of privacy. The administration should not use Orwellian double speak to impose ambiguous monitoring policy on its employees. FTC “best business practice.”
The academic nature of the workplace suggests that the monitoring policy was intended to cover scholarly articles not personal emails. The article note that the arts and science faculty “has a subjective expectation, that ‘faculty e-mail messages stored on Harvard-owned computers to be confidential,’ with some exceptions, according to the policy, which may include legal proceedings and internal investigations.” It’s unlikely that surreptitious access to employee’s email constitutes investigation but even if it does, state and federal wiretap laws may require the university to notify employee within a reasonable time. The Stored Communications Act (SCA) covers employee e-mails stored on a server from unauthorized access or exceeding authorized access. The University’s access arguably did not occur within the course of business. The deans can establish tort claims under state and federal wiretap statutes and deceptive business practice.
But challenges to this type of monitoring are often based on common law invasion of privacy, the outcomes of which are often highly fact and jurisdiction specific. Courts examining the issue have reached differing results under similar circumstances. Courts typically analyze whether the employee had a reasonable expectation of privacy and whether the employer had a legitimate business interest that outweighed the employee’s expectation of privacy. The university secret search was not limited to circumstances where employee misconduct is suspected the university was trying to find out the identity of the whistle blower. Further, the article note faculty considered the “‘privacy of resident deans’ e-mail [] particularly important because of their role in house and student affairs.”
Intentionally accessing an employee’s email is typically found to be an intrusion, so the success of a claim hinges on whether the university’s action would be highly offensive to a reasonable person. The article note students and families tailor their communications on the understandings of confidentiality” and laws have been enacted laws to protect student privacy. It is safe to say yes. 

Monday, April 1, 2013

When Privacy Intrusions Benefit the Population

We all have them...frequent buyers cards. In their most primal state, these simply consist of cardboard business cards that a company simply punches when one purchases a specific item (Sullivan's "buy six, get one free!" for instance). However, in their more complex state, frequent buyers cards can be used to track every last detail of your purchases.

We've all heard that Target knows you're pregnant before you do. And we all kind of get the creeps. While I love my rewards from shopping certain places, I don't feel relief knowing that companies are using my data to predict the next trends, to figure price points, and to track my buying habits.

However, a story with NBC news last week revealed that these frequent buyers cards can be used for something I never even dreamed of: saving people's lives. NBC news outlines the outbreak of e. coli infected spinach last fall. By using frequent buyers cards, investigators were able to track down shopping patterns from infected individuals to figure out what food was causing the illness. Further than that, investigators were able to tell exactly what spinach these individuals purchased, where the spinach came from, and could even track down who else had purchased that spinach to further prevent illness.

At an initial glance, I personally thought this was creepy. Investigators are able to tell that Joe Johnson and I both purchased the same spinach. While this seems like a trivial fact, the "big brother" fear in me was invoked. And then I thought, "how cool!?"

By tracking every purchase by individuals, investigators could track food outbreaks nation wide and would be able to prevent the death of numerous people every year. The possibilities of saving lives though are endless. Say a certain children's product is recalled for a safety hazard or because a toy includes lead paint. Would we not save a number of children by being able to track which individuals purchased the given item and contact them directly that the product has been found to be unsafe? However, on the flip side of that, people are not necessarily comfortable with every purchase being tracked by a computer that can recognize buying habits and further contact someone based on their purchase.

I pose the question on whether purchase tracking is worth it - to save hundreds if not thousands of lives every single year...to simply have purchases tracked?

Sunday, March 31, 2013

A lady never reveals her age... and when IMDb does, she sues them.

An actress's suit against IMDb for listing her age without her permission has survived summary judgment and will proceed to trial. 

U.S. District Judge Marsha Percham denied IMDb's motion for summary judgment on a breach of contract claim.  The suit, originally filed in October 2011, will now proceed to trial and is scheduled to begin on April 8.

Here's a quick refresher to catch you up on how we got here:

According to Hoang, she contacted IMDb to remove an erroneous date of birth from her public IMDb page.  IMDb refused to remove the date of birth unless Hoang could provide evidence that the date was erroneous.  Here's where the story gets interesting... according to Hoang, IMDb accessed the credit card information associated with her account and used it to conduct a search on PrivateEye.com and determine her actual birthday.  With the true date of birth in hand, IMDb then published Hoang's date of birth on her public page.  At no point did the site inform her they had accessed her payment information or conducted a search for her on PrivateEye.com.

Hoang claims that IMDb's publication of her birthday has led to age discrimination by Hollywood casting directors and directly led to her removal from one film project.  Hoang also claimed IMDb was liable for emotional distress, but the ruling by Judge Percham denied Hoang's emotional damages claim.

Judge Percham also denied Hoang's claims under the Consumer Protection Act, finding that Hoang "cannot show that the public interest is impacted by IMDb's actions." 

By alleging a breach of contract, Hoang faces an easier road than if she had alleged  the tort of public disclosure.  The tort requires that the information disclosed be highly offensive to a reasonable person.  I don't think that anyone, outside of Hollywood at least, would find the publication of a woman's age to be particularly scandalous or offensive.  Under the breach of contract claim, she merely needs to demonstrate that IMDb violated its Terms of Service and Privacy Policies by accessing her consumer information without her permission.

From the looks of it, the trial will likely hinge upon whether or not IMDb's actions constituted a response to Hoang's request to remove her incorrect date of birth or, alternatively, an effort by IMDb to improve the services offered by their website.  IMDb's privacy policy explicitly states that it uses personal information to, among other things, respond to user requests and improve the website.


Hoang did request that IMDb remove a false birthday on her page.  IMDb claims that, when asked for evidence that the listed date was erroneous, Hoang provided falsified information to the website.  If I'm IMDb's lawyer, I'm telling the jury that the search was merely a step taken to satisfy Hoang's request to verify her date of birth and the "rare" steps taken in this instance were necessitated by her decision to provide the site with false information in order to appear younger, a violation of the site's Terms of Service.

Alternatively, it could be argued that IMDb's actions were part of maintaining and improving the services of the website.  By providing accurate information about actors, actresses, directors, etc., IMDb is able to fulfill it's role as a resource for casting directors, executives, and other members of the entertainment industry.  The age discrimination in casting is the fault of casting directors, not IMDb.

In opposition, Hoang could (and, dare I say, should) contend that IMDb's actions went well beyond the simple servicing of an administrative request and plenty of alternative (and much less intrusive) forms of action existed, including just leaving the incorrect birthday on the website.  In addition, IMDb's site maintenance and improvements shouldn't come on the backs of intrusions into subscriber's credit card and other personal data.

In my not yet professional opinion, this could shape up to be a really important case in determining just what websites can do with our information and just how broad the terms of rarely read Privacy Policies and Terms of Service are.

Cell Phone Data Privacy in the Wake of Jones and Skinner


          As smartphones become more common, both the law enforcement uses of cell phone data and the privacy concerns related to these uses are on the rise. One aspect of smartphones in particular that has widespread privacy implications is theability to use GPS tracking capability to monitor a person’s every move, simply by tracking the location of their cell phone. A report published by Scientific Reports studied anonymous mobile data for about 1.5 million people. The findings are concerning for privacy advocates – the researchers found that “if they got accurate hourly updates on a person's whereabouts, tracked by their mobile carrier's cell towers, four ‘data points’ were all they needed to figure out the person's identity 95% of the time.” Conversely, given access to mobile data by an individual’s cell phone service provider, law enforcement can track that person’s every move in real time.
          It is unclear whether there is a consensus in modern courts regarding what degree of privacy cell phone users enjoy with regards to their location data. In United States v. Skinner, the Sixth Circuit Court of Appeals held that there is no reasonable expectation of privacy in location data broadcast by a cell phone, thus, the Fourth Amendment does not require the police to obtain a warrant before monitoring a person’s real-time location through cell phone location data. However, privacy advocates argue that this does not mesh with United States v. Jones, decided just seven months earlier, where the Supreme Court held that warrantless long-term GPS monitoring violates the Fourth Amendment.
          It is important to note, for privacy law purposes, that cell phone users knowingly and willingly transmit GPS signals to their cell phone provider in order to use many of the location-based services provided by smartphone apps (Urban Spoon, Google Maps, Foursquare, etc.). Under the Third Party Doctrine, since users have willingly surrendered this information to their cell phone service provider and/or app providers, they have abandoned any claim to privacy that they may have had. According to the Electronic Frontier Foundation (EFF), this is the rationale that the government uses to justify use of location data – “the government claims that cell phone users give up their privacy rights because they have voluntarily disclosed their physical location to the cell phone providers every time a phone connects to the provider's cell tower.” The consequences of such access by law enforcement can be extremely far-reaching; the EFF points out that “location data is extraordinarily sensitive. It can reveal where you worship, where your family and friends live, what sort of doctors you visit, and what meetings and activities you attend.”
          Is it fair to “punish” smartphone users by invading their privacy, especially given the necessity of smartphones in today’s world? Is this even a violation of their privacy at all, given the third party doctrine? What are your expectations of privacy when it comes to cell phone GPS data? Without more clarity from the courts, it is difficult to say what role cell phone location data will play in the criminal law context, but with the growing use of smartphone data to track, apprehend, and charge individuals suspected of crimes, it will surely need to be tackled by the courts head on, sooner rather than later.

Third Party Decision Makers: Government Access to Private Data and the Need for a Warrant Requirement



Facebook’s user agreement gives Facebook the ability to release user data to law enforcement where it has a, “good faith belief,” that it is necessary to prevent harm or that it is required by law.  Such a provision is not unique to Facebook. Yahoo, Twitter, EBay, and others, all have similar provisions buried within their user agreements and terms of service. Increasingly, one of the questions that the privacy debate must answer is: to what extent should consent invalidate the protections that ECPA, the CPA, and even the FTC, traditionally afford user data? While statutes like the Privacy Act regulate the uses and maintenance of government databases, the increasing reliance of the government on information provided by the private sector, raises new questions in the evolving debate over user privacy.
            The current privacy protections for user data are problematic. In my last entry I discussed Google’s requirement that any request for user data by the government, be accompanied by a warrant. While the efforts of Google, and companies like it are admirable, the lack of a unified standard for government access to data collected by private companies is especially troubling for individuals that are concerned with data privacy.
            In Smith, the Court determined that people do not maintain a Fourth Amendment interest in information that they pass on to third parties. While ECPA, FCRA, and even the FTC, regulate how the government can require third parties to disclose user information, there is little protection in place for information that users give to companies, and which the companies then voluntarily disclose. Furthermore, what little regulation may be in place in the form of FTC enforcement agreements (which make it a “promises,” violation to use information in ways other than specified in the user agreement and terms of service) is undercut by vague requirements for disclosure, that allow companies like Facebook, to release information to law enforcement whenever they feel that they have a “good faith belief.”
            As these articles note, government agencies are increasingly using private sector data collectors to gather information that would otherwise be difficult to access. While government regulation like ECPA, the rules propagated by the FTC, and even the Fourth Amendment, regulate how the government can access your data, such protections rapidly become irrelevant when user agreements contain clauses that allow a company to release user data upon request. One way that these articles suggest for protecting user data, is by requiring that the government obtain a warrant before it can access user data from the private sector. While such a requirement would not rise to the level of probable cause necessary for the “super warrant,” governing the Electronic Intercept portion of ECPA, a warrant requirement for the purposes of obtaining private sector data on individual users would be a step in the right direction for user privacy.
            As it now stands, the lack of security controlling government access to private sector user data is in need of reform. While it is true that people may recognize that they give up some degree of privacy when they use Facebook, Google, etc., it is doubtful that they would be comfortable with the truly vast amount of control that they give such companies over their data. Thus, a warrant requirement for government access to user data seems like a good, common sense, step to protecting user privacy and the erosion of civil liberties, in an era where simply avoiding the use of such sites in no longer a viable option.