BUSINESS MANAGEMENT GREAT WORK, ON TIME, NO PLAGARISM, A+ WORK

profilePelicans!!322
Algorithms_and_the_Privacy_Tor.pdf

Aileen Nielsen*

Algorithms and the Privacy Torts https://doi.org/10.1515/jtl-2025-0017 Received June 13, 2025; accepted July 3, 2025; published online July 18, 2025

Abstract: Drawing on recent consumer privacy litigation, this work identifies three recurring doctrinal questions that arise from the interaction between algorithmic activity and privacy tort claims. First, can algorithmic conduct give rise to liability under privacy torts, particularly where intentional conduct is required? Second, can disclosing or holding out information or representations to algorithms fulfill pub- licity elements of the privacy torts? Third, is use of an algorithm per se offensive or will offensiveness be judged contextually, as for human conduct? A survey of recent case law reveals that courts generally accept algorithmic conduct as sufficient to perpetrate a tortious act – whether intrusion, disclosure, or publication, but they show more skepticism when algorithms are posited as the audience necessary to fulfill a publicity element. Put differently, legally algorithms can act but not see. Further, algorithms are inherently neither aggravating nor mitigating factors as to offensiveness. This work contributes to the growing literature on tort liability and artificial intelligence by surfacing a neglected body of case law in which courts have already long engagedwith algorithmic conduct. These privacy torts decisions suggest that AI tort liability is emerging incrementally and contextually. The privacy torts can serve as an informative barometer for likely judicial treatment of future algo- rithmic use cases.

Keywords: privacy law; algorithms; artificial intelligence; consumer privacy

1 Introduction

In recent decades consumers have increasingly alleged that firms have intruded upon their seclusion through algorithmic collection, retention, or transmission of electronic personal data. Most often, plaintiffs do not claim that a human accessed or viewed information; rather the intrusion is typically alleged to be perpetrated solely through automated processes. A substantial number of such claims have survived

Visiting Assistant Professor, Harvard Law School, [email protected]. The author thanks Emily Hua, Pedro Ribeiro Morais e Silva, and Chloe Suzman for excellent research assistance.

*Corresponding author: Aileen Nielsen, Harvard Law School, Cambridge, USA, E-mail: [email protected]

J. Tort Law 2025; 18(1): 365–385

motions to dismiss, suggesting that courts find such intentional tort claims plausible, evenwithout any allegation of human access to the private information in question.1

This ongoing, largely procedural jurisprudence offers two insights for better understanding privacy law and the likely future of algorithms under the torts sys- tem. These consumer privacy torts cases illustrate courts’ willingness to distinguish between the identity of the actor and the identity of the tortfeasor: algorithmsmay be the instrumentality of an invasion, but legal responsibility attaches to the human or (more typically) corporate deployer. Contrary to some predictions in artificial in- telligence (AI) torts scholarship that AI is likely to escape torts liability absent doctrinal reform, courts have shown little difficulty attributing the actions of privacy-invasive algorithms to their deployers (these latter themselves often legal rather than natural persons). The consumer privacy torts cases show us that plain- tiffs raising claims against a legal person deploying an algorithmic actor need not face substantial obstacles in establishing a prima facie case for the intentional tort of intrusion upon seclusion. That itself is an instructive data point. It is, at the least, surprising that torts originally understood to address social embarassment and humiliation are nonetheless adopting to the deployment of algorithmic agents by legal persons, without a single human eye or ear alleged to be involved in the process.

These cases demonstrate a subtle but meaningful challenge to traditional understandings of the privacy torts even beyond intrusion upon seclusion. Histori- cally, the privacy torts have been closely tied to social embarrassment, reputational harm, and interference with individual self-presentation – harms that might be thought relevant or redressable onlywhen one natural person invades the privacy of another.2 Even in more expansive formulations to justify the privacy torts, such as a sense of well-being or the health of democracy itself, these justifications typically emphasize the anticipated consequences of a human seeing, knowing, or believing something about another.3 Yet courts have shown a readiness to apply the privacy

1 Decisions on the merits in such cases remain rare, but a growing body of procedural rulings supports the view that algorithms are legally capable of acts that trigger liability under the privacy torts. A similar lack of judicial decisions on themerits has beennotedwith regard to FTC enforcement of consumer privacy. See Daniel J. Solove &Woodrow Hartzog, The FTC and the New Common Law of Privacy, 114 COLUM. L. REV. 583 (2014) (“Despite over 15 years of FTC enforcement, there is no mean- ingful body of judicial decisions to show for it. The cases have nearly all resulted in settlement agreements.”). 2 See James S. Taylor, Torts – Invasion of Privacy by Postcard Advertising, 51 MICH. L. REV. 613, 614 (1953) (“[T]he gist of the cause of action for violation of one’s right of privacy is the personal affront to his dignity by intrusion into his private activities, and the destruction of his self-esteem by publi- cation of the truth.”). 3 Edward J. Bloustein, Privacy as an Aspect of HumanDignity:AnAnswer to Dean Prosser, 39 N.Y.U. L. REV. 962, 973–74 (1964). (“He who may intrude upon another at will is the master of the other and, in fact, intrusion is a primary weapon of the tyrant”).

366 A. Nielsen

torts to harms perpetrated exclusively by algorithms, even with no allegation of imminent likelihood of human eyes or ears. In this way courts are expanding privacy torts doctrine in ways that don’t clearly map onto the narrowly cabined rationales typically offered in scholarship or jurisprudence. In accepting the possibility that the privacy torts may be perpetrated by algorithms, in cases in which no human has consumed or likely will consume any information about the victim, courts have implicitly endorsed a broader conception of what constitutes an invasion of privacy and what kinds of actions can be punished under the law. Given this implicit doctrinal expansion, courts may likewise be prepared to broaden their under- standing of relevant negligence and products liability theories to accommodate the social reality of algorithms and AI.4

This work focuses on uses of algorithms, which are understood broadly as software capable of operating semi-autonomously in response to data inputs and user actions. While the use of terms like “algorithms” and “AI” is deliberately imprecise here, a slight distinction is made as follows. In this work, algorithms are distinguished from more recent forms of data-driven software (and hardware) commonly referred to as artificial intelligence (AI), where this latter typically involve higher levels of autonomy and computational intensity as compared to algorithms. Here “algorithm” refers to software of the past decades, and “AI” contemplates prospective commercial practices or the most cutting edge contemporary practices.

To return to the main thread: courts have readily accepted intrusion upon seclusion claims evenwhere there is no human viewer. But not all consumer privacy tort claims against algorithmic use have succeeded. Courts have been hesitant to treat dissemination of information or representations to other algorithms as satis- fying the “publicity” element required by torts such as public disclosure of private facts or appropriation of likeness. Taken together, these observations suggest a doctrinal boundary: while algorithms may gather or process information in ways that constitute a tortious act, they may not easily stand in for a human public when that public is an element of tortious invasion of privacy.

The possibility of a further human/algorithm distinction arises in assessing the offensiveness of algorithmic conduct. Onemight imagine that the algorithmic nature of the conduct could itself play a role in the offensiveness analysis implicated by the privacy torts. For example, use of analog recording equipment has often been legally adequate to fulfill an offensiveness element in the intrusion tort, even where that recording equipment was used in a public location and by a participant in a voluntary interaction, suggesting a strong presumption of offensiveness in the case

4 For example, with regard to negligence, courts maywiden their understanding of foreseeability to accommodate liability for AImisbehavior.With regard to products liability, courtsmayfind that AI in some specific commercial instantiation is a product.

Algorithms and the Privacy Torts 367

of undisclosed recording equipment. Such jurisprudence suggests that use of some kinds of recording technologies can be legally sufficient to fulfill an offensiveness element and may even create a strong presumption in favor of such a finding. Might algorithms, also a form of recording equipment, be understood as per se offensive recording technology? It appears not. Rather than building on this line of prior cases pointing to the near per se offensiveness of certain undisclosed recording devices, algorithmic privacy tort claims are assessed contextually for offensiveness.

The work proceeds as follows. First, common elements across the invasion of privacy torts are discussed. Second, recent case law addressing algorithms as perpetrator (algorithm as actor), as public (algorithm as public), and as prurience (algorithmic use as offensive) are analyzed separately. The work concludes in laying out some limitations of the case law review method presented here.

2 Laying out Common Elements

The Second Restatement of Torts is the foundational authority for defining the pri- vacy torts. For example, the overwhelming majority of states that have expressly recognized the tort of intrusion upon seclusion have expressly adopted the Restatement, and they likewise lean heavily on the Restatement for the other inva- sion of privacy theories.5 This work therefore adopts the Second Restatement’s de- scriptions of the four privacy torts: intrusion upon seclusion, appropriation of name or likeness, publicity given to private life, and publicity placing a person in a false light. Table 1 reproduces the Restatement language and identifies common concep- tual elements with highlighting.

In Table 1, the elements highlighted in aqua identify tortious acts: intruding, appropriating, or giving publicity. These acts are often qualified by a requisite mental state (e.g., “intentionally intrudes,” “reckless disregard”), reflecting these torts’ heightened standards of care, which often require actions of an intentional character or at the least something beyond mere negligence. The elements high- lighted in yellow pertain to the requirement of a public, that is of exposure or transmission of information or representations to third-parties. Three privacy torts require some form of viewing by ormaking available of content to third parties.6 The elements highlighted in magenta relate to prurience, or offensiveness. The language

5 Eli A. Meltz, No Harm, No Foul? “Attempted” Invasion of Privacy and the Tort of Intrusion Upon Seclusion, 83 FORDHAM L. REV. 3431, 3440–41 (2015) (documenting that at least 27 US states have explicitly adopted the Second Restatement’s definition of intrusion upon seclusion). 6 This requirement of publicity is of a less demanding character than the publication requirement for the defamation tort. Note that the intrusion tort is a distinct case in which an alleged tortfeasor’s own viewing (or information collection) can constitute the tort; third party viewing is required.

368 A. Nielsen

is identical across the elements (“highly offensive to a reasonable person”), although the requirement is not always holistically applied to the actions (as in the case of intrusion) but can be specific to assessing the content of disclosures or representa- tions (as in disclosure and false light).

This article takes the evolving consumer privacy torts case law on algorithmic privacy invasions as a lens through which to examine how the common law is already adapting to questions of algorithmic tort liability. The work focuses on three questions that arise frequently across privacy tort doctrines in consumer digital privacy litigation, a domain characterized by pervasive use of algorithms: 1. Can algorithms perpetrate tortious invasions of privacy? 2. Can algorithms serve as third party viewers, when such is a required element? 3. Does the use of algorithms make conduct per se offensive (or inoffensive, or

neither)?

Table : Second Restatement of Torts descriptions of the four privacy torts.

Privacy tort Restatement description

Intrusion upon seclusion One who intentionally intrudes, physically or otherwise, upon the solitude or seclusion of another or his private affairs or concerns, is subject to liability to the other for invasion of his privacy, if the intrusion would be highly offensive to a reasonable person.a

Appropriation of name or likeness

One who appropriates to his own use or benefit the name or likeness of another is subject to liability to the other for invasion of his privacy.b

Publicity given to private life

One who gives publicity to a matter concerning the private life of another is subject to liability to the other for invasion of his privacy, if the matter publicized is of a kind that

(a) would be highly offensive to a reasonable person, and (b) is not of legitimate concern to the public.c

Publicity placing person in a false light

One who gives publicity to a matter concerning another that places the other before the public in a false light is subject to liability to the other for invasion of his privacy, if

(a) the false light in which the other was placed would be highly offensive to a reasonable person, and

(b) the actor had knowledge of or acted in reckless disregard as to the falsity of the publicized matter and the false light in which the other would be placed.d

aRestatement (Second) of Torts § B (). bRestatement (Second) of Torts § C (). cRestatement (Second) of Torts § D (). dRestatement (Second) of Torts § E ().

Algorithms and the Privacy Torts 369

Table 2 presents the organization of the common elements across the research questions. As can readily be seen in the first row of Table 2, the privacy torts are surprisingly expansive with regard to the spectrum of culpability these theories accommodate. Not all privacy torts require intentional conduct; some accept negli- gence or recklessness for acts or for other elements. This makes the privacy torts a productive domain for exploring how more autonomous AI systems might be adjudicated under tort law – perhaps even under themore plaintiff-friendly theories of negligence and products liability, for which lower standards of culpability are the norm. Considering that AI has yet to clearly present in substantial numbers of litigated cases,11 the privacy torts can provide helpful information as to where the judiciary may see room for expanding tort theories to address challenges posed by AI.

Further, as can be seen in the bottom row of Table 2, the privacy torts incor- porate a normatively inflected element to delineate the legal protections of privacy.

Table : Second Restatement of Torts definitions of the four privacy torts.

Intrusion Appropriation Disclosure False light

AI as perpetrator Standard of conduct Intentional Intentional Negligent Reckless

AI as public Third party viewing? N Y Y Y AI as prurience Offensiveness assessment? Y N Y Y

7 Invasion of privacy is often understood as a constellation of intentional torts, but in fact the standard of conduct need not be intentional for all cases. The standards listed here will clearly not be uniform across the states but nonetheless identify examples where lower standards of conduct are readily identifiable. 8 “The value of the plaintiff’s name is … appropriated … only when the publicity is given for the purpose of appropriating to the defendant’s benefit the commercial or other values associated with the name or the likeness that the right of privacy is invaded. Restatement (Second) of Torts § 652C (1977), comment d, emphasis added. On the other hand, under relevant state statutes that address interests implicated by misappropriation, sometimes a lesser showing is adequate. See e.g. Cohen v. Facebook, Inc., 798 F.Supp.2d 1090 (2011) (finding that plaintiffs need to allege a knowing use of their personal data for purposes of advertising to state a claim under California Civil Code § 3344)”. 9 See e.g. Stasi v. Inmediata Health Group Corp., 501 F.Supp.3d 898 (2020). 10 Recklessness is explicit with regard to the false light in which the other would be placed. As to the separate element of giving publicity, the standard is not always set at intentional but can reflect knowing behavior. See e.g. Cal. Civ. Code § 3344 (West 2024), under which plaintiffs must allege a knowing use. 11 It’s a separate question whether there will be a surge of AI-related litigation at some point in the near future. This has often been predicted but has yet to materialize. See Aileen Nielsen, AI’s Cate- gorical Fairness, AM. J. L. EQ. (forthcoming 2025).

370 A. Nielsen

Various scholarship has put forward frameworks and concepts to adjudicate acceptable and unacceptable technological uses, such a theory of “creepiness,” to understand the contours of privacy violations in technology use.12 But these lines of scholarship may be conceptual surplusage; tort law already has a well-developed framework for assessing offensiveness – one that may do much of the same normative work as concepts like creepiness. Understanding how courts have applied the offensiveness standard in modern consumer private litigation may shed light on the social acceptability and legal risk of novel AI use cases.

3 AI as Perpetrator

The question of perpetrating privacy torts via machine is not much younger than the privacy torts themselves. Courts have dealt with such cases for at least 60 years. For example, in the oft-taught 1964 case of Hamberger v. Eastman, the Supreme Court of New Hampshire sided with plaintiffs, a married couple who discovered a hidden recording device in their bedroom capable of transmitting audio content to their landlord’s residence. Even though plaintiffs did not make a showing that audio content had been transmitted to the landlord or that the landlord had listened to such content, the court found that the plaintiffs had adequately stated a claim for intru- sion upon seclusion. The issue of machine capacity to intrude upon seclusion re- mains evergreen, and courts have discussed the question at length farmore recently. For example, in the 2011 case of Koeppel v. Speirs, the Supreme Court of Iowa made clear that the mere presence of a camera in a restroom, even where evidence demonstrated that the camera was not functioning and therefore could not transmit information, constituted an adequate showing by plaintiff of intrusion upon seclu- sion to defeat a motion for summary judgment.13 Key to both the Hamberger and Koeppel holdings was the legal conclusion that the harm recognized by intrusion upon seclusion is not the fact of a human actually accessing information or seeing/ hearing private things but instead the victim's experience of perceiving or fearing such behavior.

In evaluating machines intruding upon seclusion, the Hamberger and Koeppel courts addressed the question of what was necessary to show an intrusion, that is what constituted an intrusion and what constituted the harm addressed by this tort. The Koeppel court reviewed decisions from a number of states, identifying both the Hamberger rationale (a majority rule that recognized the harm addressed as the

12 Omer Tene& Jules Polonetsky,A Theory of Creepy: Technology, Privacy, and Shifting Social Norms, 16 YALE J.L. & TECH. 59 (2013), https://ssrn.com/abstract=2326830. 13 Koeppel v. Speirs, 808 N.W.2d 177 (Iowa 2011).

Algorithms and the Privacy Torts 371

sense of being surveilled rather than the fact of being surveilled) but also an opposing, minority rule, this latter of which would require the showing of human viewing or hearing to establish intrusion. Adopting Hamberger’s rationale, the Koeppel court explained.

[I]t is important to keep in mind that the tort protects against acts that interfere with a person’s mental well-being by intentionally exposing the person in an area cloaked with privacy…[W]e find the approach taken in Hamberger and its progeny [to not require a showing of human viewing or listening] is more consistent with the spirit and purpose of the protection of privacy.14

Under the majority rule, the interest protected by intrusion is that of a person’s subjective sense of protection and well-being. It is with reference to this under- standing of the harm that the mere presence of a machine or use of an algorithm, even absent human access to information, can constitute intrusion upon seclusion. It is precisely for this reason, under the majority rule’s interpretation of the interest protected, that intrusion upon seclusion has such a lengthy history of addressing the question of machine rather than human acts. This is not just for recording equip- ment. Likewise, and for similar reasons, allegations of intrusion upon seclusion as perpetrated by robo-dialers have been consistently recognized as viable allegations of intrusion upon seclusion.15

Consumer privacy litigation appears to benefit from theHamberger rationale. In the 2022 case of In re Google RTB Consumer Privacy Litigation,16 the fact that Google used data in ways undisclosed to customers (and therefore, nonconsensually) meant that Google might be liable for intrusion upon seclusion, even though algorithms alone processed the data.17 In the 2023 case of Doe v. Regents of University of Cali- fornia, a federal district court concluded thatMeta Pixel’s scraping of sensitive health

14 Koeppel v. Speirs, 808 N.W.2d 177, 184 (Iowa 2011). Internal citations omitted. The court also went on to clarify “[H]arm from intrusion arises when the plaintiff reasonably believes an intrusion has occurred. Therefore, the standard we establish to satisfy the intrusion element does not create a claim for attempted invasion of privacy.” Id at 185. Internal citations omitted. 15 See e.g. Masuda v. Citibank, N.A., 38 F. Supp. 3d 1130 (N.D. Cal. 2014). See also e.g. Romero v. Dept. Stores Natl. Bank, 725 Fed. Appx. 537 (9th Cir. 2018). 16 In re Google RTB Consumer Priv. Litig., 606 F. Supp. 3d 935 (N.D. Cal. 2022). 17 Further, this is a case where the record clearly established the use of algorithms in privacy- relevant domains. In re Google RTB Consumer Priv. Litig., 606 F. Supp. 3d 935, 946 (N.D. Cal. 2022) (“Google points to the following language as sufficient disclosure of the practice challenged in this lawsuit:

– Google uses ‘automated systems and algorithms to analyze your content’ in order to ‘customize our services for you, such as providing recommendations and personalized search results, content, and ads (which you can change or turn off in Ad Settings.’

– ‘We may show you personalized ads based on your interests.’” internal citations omitted).

372 A. Nielsen

data from a healthcare provider’s patient portal could constitute intrusion upon seclusion, despite no allegation that a human ever saw the data.18 In another 2023 case, Griffith v. TikTok, TikTok was alleged to have built into its targeted advertising software development kits (SDKs) undisclosed methods of collecting data to enhance the effectiveness of targeted ad delivery. This circumstance alone, without any allegation of human access to the data, could constitute an adequate intrusion claim.19 In none of these circumstances was there an allegation of human viewing. In all of these cases, plaintiffs defeatedmotions to dismiss as to their claims of intrusion upon seclusion.

Intrusion formally requires an intentional act, a fact not often discussed in con- sumer privacy litigation. But intrusion claims premised on algorithmic behavior can fail on the basis of a lack of intent. For example, in Doe I v. Google (by the court’s own description “another pixel case”) a plaintiff took the unusual step of suing Google (the provider of an analytics service that surveils consumers via the loading of a pixel on a webpage) rather than suing the firm that deployed Google’s code.20 Google’s motion to dismiss was granted for two reasons: the federal district court found both that the plaintiffhad failed toproduce evidence as to intent and the courtwasunconvinced that any facts alleged by plaintiff would be adequate to establish offensiveness.21

The court’s analysis as to the lack of intent under the intrusion allegation was brief, in part because the court had already discussed intent in the related allegations violations of the California Invasion of Privacy Act (CIPA).22 In defending against the intrusion claim, Google argued as follows.

Google contends that it did not read, attempt to read, or learn the contents of any communi- cation. Google asserts that it merely offers a tool for websites to record user interactions for

18 Doe v. Regents of the Univ. of Cal., 672 F. Supp. 3d 813 (N.D. Cal. 2023). 19 Griffith v. TikTok, Inc., 697 F. Supp. 3d 963 (C.D. Cal. 2023). 20 Doe I v. Google LLC, 741 F. Supp. 3d 828, 836 (N.D. Cal. 2024) (“This is another pixel case. In many pixel cases, the plaintiffs sue the owner of the web property they interacted with, alleging that the owner installed source code that caused their personal information to be transmitted to a third party. But in this case, the plaintiffs have sued the third party that offers the source code: Google. They allege that their health care providers use Google source code to analyze traffic on theirweb properties, that their personal health information is transmitted to Google as part of this process, and that Google feeds this information into its own advertising machinery. For this, the plaintiffs assert, Google is liable for violating their privacy rights”). 21 Doe I v.Google LLC, 741 F. Supp. 3d 828, 844 (N.D. Cal. 2024) (“Given the twoflawed assumptions the plaintiffsmake – about where Google source code is present on a givenweb property and about what features of Google’s products the health care providers have enabled – there is noway to understand the nature of the intrusion, and thus no way to assess whether it rises to the level of being highly offensive.Moreover, as already discussed, the plaintiffs have not adequately alleged intent, which is a necessary element of an invasion of privacy claim”). 22 Cal. Penal Code § 631(a).

Algorithms and the Privacy Torts 373

themselves. This, as Google sees it, is akin to providing a tape recorder for a party to use during a communication. And because Google is simply giving websites a service that allows them to record and analyze their own data, Google contends it is not itself engaging in the conduct – reading or learning the contents of communications – prohibited by the statute.23

The court did not accept the strongest form of Google’s argument, namely the notion that provision of a software tool must be inadequate to establish intent. But the court recognized that the facts of the case were inadequate to establish intentional conduct.

[T]he complaint and incorporatedmaterials stand for the proposition that Google does not want to receive private health information and has instructed providers not to send it. [E]ven if some private health information is inadvertently sent to Google – and subsequently gets integrated into the reports – the plaintiffs fail to plausibly allege Google is intentionally reading or learning the contents of the plaintiffs’ private health communications.24

The intent issue surfaced most immediately in relation to the CIPA allegation rather than the intrusion claim, a circumstance which only emphasizes that assessments of intent have typically not been strongly emphasized in reviews of intrusion claims in consumer privacy litigation. Further, Doe I did not reject the notion that algorithmic acts (or the production of algorithmic tools) could suffice for intentional intrusion; rather the court pointed to a lack of evidence on this point in the plaintiff’s pleadings in this case. It was likely the facts of this case – perhaps especially the fact that Google allegedmisuse by users of its algorithms – thatmade the plaintiff’s case vulnerable to a challenge as to the intentional standard of conduct.

It may be that the intrusion tort – despite being an intentional tort – recognizes liability in cases of algorithmic actions because of the doctrinal split highlighted supra. The very harm recognized by this privacy tort –which can relate to the impact of antisocial behaviors on the subject of surveillance rather than on the information acquisition actually accomplished by the viewing by a human deployer – explicitly lends itself to the notion that a machine can be adequate to induce the harmful distressrecognized byHamberger as the harm addressed by the intrusion tort. Might there be something special about the intrusion tort that doesn’t translate more broadly in the domain of invasion of privacy? It could be that the other privacy torts, which do not look to a plaintiff’s subjective experience or fear of being seen, pose more of an obstacle for plaintiffs seeking to challenge algorithmic actions. But, this turns out not to be the case, as we can see when we expand our review of cases to encompass other invasion of privacy torts.

23 Doe I v. Google LLC, 741 F. Supp. 3d 828, 843 (N.D. Cal. 2024). Internal citations omitted. 24 Doe I v. Google LLC, 741 F. Supp. 3d 828, 844 (N.D. Cal. 2024).

374 A. Nielsen

Consumer privacy torts plaintiffs have also survived motions to dismiss when bringing appropriation of personality claims. In the 2024 case of Forrest v. Meta Platforms,25 the plaintiff, a prominent Australian businessman, learned that his name and likeness appeared on Facebook ads endorsing “cryptocurrency and other fraudulent investment products.”26 The plaintiff brought suit under an appropria- tion of name or likeness theory, and Meta defended on the basis that it had not created the ads and therefore had not committed an act covered by appropriation. But plaintiff alleged that Facebook’s algorithms had been used to produce the problematic content and alleged liability on that basis; plaintiff did not assert liability on the basis of Facebook hosting the content (a theory that would likely have likely failed under the Communications Decency Act).27 Plaintiff’s allegations were adequate in a federal district court’s view for establishing the necessity of a fact- intensive review, and so Facebook failed to convince the court to dismiss the suit. Forrest provides an example of liability for appropriation brought about by algo- rithmic actions, showing that liability for algorithmic acts is not limited to the intrusion tort. Also interesting is that both Doe I and Forrest treated cases of claims against a corporate entity for creating an algorithmic tool rather than for direct deployment of an algorithm. Forrest shows that acts enabled by an algorithmic tool may sometimes be plausible theories of liability for algorithm creators, even where there is a subsequent, intervening actor entailed by the chain of causation.

Forrest provides indicia on how we might expect the judiciary to look at uses of AI in torts litigation. The allegation that Facebook provided tools used for a tortious made it a matter of factual query rather than a question of law as to whether Facebook had established that the allegations came within the immunity protections

25 Forrest v. Meta Platforms, Inc., 737 F. Supp. 3d 808 (N.D. Cal. 2024). 26 Id at 808. 27 Forrest v. Meta Platforms, Inc., 737 F. Supp. 3d 808, 814 (N.D. Cal. 2024) (“Dr. Forrest alleges that Meta’s software ultimately determineswhat completed ads look like andwho sees them. One tool, for example, takes the images, videos, text, and audio that the advertiser supplies and “mixes and matches them” to change how the ad looks and improve performance. Compl. 120. This tool is enabled by default. It can adjust the appearance of an ad based on how likely each viewer is to respond. The software can create videos from images and can highlight key phrases from text. Dr. Forrest alleges that at least some of the scam ads he is challenging were created using this tool. Another tool uses generative artificial intelligence to automatically optimize an ad so that the audience will be more likely to interact with it. This AI tool can addmusic, fine-tune visuals, and even add 3-D animation. In addition to determining the appearance of an ad, Meta’s software also determines which users are eventually shown the ad”).

Algorithms and the Privacy Torts 375

of §230 of the Communications Decency Act (CDA), a statute often found to block torts claims associated with platforms’ uses of algorithms and AI.28 The fact of Facebook’s AI offerings established a plausible position that Facebook was not engaging in activities immunized from liability under CDA §230 and so meant that the plaintiff could survive amotion to dismiss with regard to his appropriation of likeness claims. Thus, under invasion of privacy theories, the use of algorithms (or AI) may (contrary to the predictions ofmost AI torts scholarship) enhance the scope of potential liability for defendants, both in raising plaintiff workarounds against CDA §230 liability and also in enabling new modalities of “committing” the “act” that creates invasion of privacy liability.

Courts have shown little hesitation in recognizing that algorithmic activity can lead to liability for invasion of privacy, at least in cases where a juridical person clearly stands in some direct relation to that algorithm.29 This observation specific to the privacy torts may eventually presage a broader proposition about tort law: the existence of an automated intermediary need not prevent courts from finding that a wrongful act occurred, even an intentional wrongful act, for which liability may be attributed to a natural or judicial person. Further, that creation or use of algorithms or AI may even expand the scope of liability for defendants, perhaps through establishing bounds on §230 immunity, as in Forrester.

4 AI as Public

The privacy torts that entail some disclosure or holding out of information or rep- resentation have historically been understood to presuppose exposure to a mean- ingful number of human observers, be it to vindicate the reputational concerns addressed by disclosure and false light claims, or to capture the economic interests implicated in appropriation. Courts have been markedly less open to the notion that algorithms might serve as the requisite audiences for purposes of satisfying the “publicity” elements embedded in the torts that entail some notion of a “public” than they have been with the notion that algorithms might perpetrate tortious acts.

The judiciary’s resistance to algorithmic publicsmay be traced in part to the core doctrinal materials on this point. In a comment, the Restatement describes the publicity requirement as follows:

28 Forrest v.Meta Platforms, Inc., 737 F. Supp. 3d 808, 817–18 (N.D. Cal. 2024). This question has also gained urgency specifically in the special case of generative AI. See Peter J. Benson & Valerie C. Brannon, Section 230 Immunity and Generative Artificial Intelligence, CONG. RSCH. SERV., Dec. 28, 2023). 29 The word “direct” is both notoriously lacking in precision but nonetheless pervasive for good reason: there isn’t an adequate and more precise substitute. This work leaves the reader to apply intuition.

376 A. Nielsen

“Publicity”…means that the matter is made public, by communicating it to the public at large, or to so many persons that the matter must be regarded as substantially certain to become one of public knowledge.30

On first impression, this language might suggest that machines cannot be members of the public; the public seems to be made up of persons. But there are plausible arguments that the language is in fact more capacious than such a narrow under- standing.31 To begin, one might make the case for an algorithmic public premised (as in intrusion) on a theory of harm that need not require actual consumption of the information. If “public at large” is taken tomean that information need only bemade available in principle, regardless of whether any human actually accesses that in- formation, there is some room to cover the fact of algorithms being ready to serve content as enough to fulfill a publicity element.

There is also another reading of the language capacious enough to include algorithms as public: the word “persons” need not refer only to natural persons. In a variety of contexts, courts have long accepted that “persons” can include legal per- sons, such as corporations. If a public need only comprise “persons”, and if that can include juridical persons, it is not such a far step to find that a public can comprise algorithms. After all, why should algorithms as actors on behalf of juridical persons be distinguished from juridical persons themselves? Such textual arguments are plausible; certainly the use of “persons” injects some uncertainty as to whether these references are necessarily to be understood as exclusively natural persons.

Further, remembering the timeline of some relevant cases shows that the au- thors of the Restatement could reasonably have anticipated such questions. By the time of the Second Restatement, Hamberger had already been decided and gained some attention. And, Hamberger was not alone in addressing the question of ma- chines as relevant to the private torts; other cases had also dealt with the question of

30 Restatement (Second) of Torts § 652D (1977). Comments under the different headings of the four torts can sometimes inform as to others. For example, Comment b (“Private life”) to § 652D references “invasion of privacy” twice when discussing what constitutes private life and does not invoke the named tort of its corresponding section. 31 It bears recognizing that the language of the Restatement may not hold up to such close textual reading as it is subjected to here. For example, if one is to read the Restatement language and interpret the language closely, it would be difficult to know what to do with the phrasing of the invasion of privacy torts “one….another” to reference the putative defendant and plaintiff respec- tively. It is uncontroversial that juridical persons can be defendants but not plaintiffs when it comes to invasions of privacy. It is therefore surprising that the “one…another” language seem to imply a symmetry of entities as between plaintiff and defendant, perhaps suggesting natural persons filling both roles.

Algorithms and the Privacy Torts 377

machines too, at least with respect to intrusion.32 The Restatement authors had opportunities to contemplate the possibility of machine watchers and to make the conceptual leap from machines as perpetrators to machines as members of the public. The unclear language, certainly susceptible to an interpretation that permits machine publics, is therefore surprising. The Restatement lacks clarity as to exactly who or what can be members of the public.

Some decisions have left room for an algorithmic public, if only directly and on procedural grounds. In the 2024 case of J.C. v. Catholic Health System, a post Tran- sUnion33 standing decision, plaintiff argued that a health system’s use of pixel tracking technology to collect her personal health information and transmit that information to technology firms (Meta and Google) adequately alleged an injury sufficiently analogous to that of the disclosure tort. Defendants argued against standing on the basis that ”plaintiff fail[ed] to allege that her data was viewed by any person (i.e. as opposed to a computer or algorithm)”.34 Although the court in J.C. did not explicitly address the defendant’s argument concerning the absence of human involvement, it nonetheless held that the disclosure tort and its associated harms were sufficient to establish Article III standing. The court reasoned that, by analogy to the tort of public disclosure of private facts, such harms need not involve human viewing or consumption of the disclosed information.

But another federal district court contemplating standing on similar facts has gone the other way. The decision, Andrews v. Prisma Health, even came out in the samemonth and year as J.C. (August 2024), which explains the failure of each case to account for the other. both parties’ failure to discuss the other decision. In Andrews,

32 For example, inMarks v. Bell. Tel. Co. of Pennsylvania, plaintiff attorneys brought suit, including an invasion of privacy theory, to challenge Bell’s installation of a recorder connector that auto- matically recorded all outgoing and incoming calls. Plaintiff attorneys sought to protect the confi- dentiality of their telephone communications with their clients but they failed to succeed in alleging an invasion of privacy tort even where use of the audio recording equipment was uncontested. The court would not entertain the notion that an invasion of privacy could take place by means of a recording device. 460 Pa. 73, 86–87, 331 A.2d 424, 431 (1975). (“[T]he interest the law seeks to protect is the right to keep one’s private conversations safe from unauthorized listeners. Thus a basic element of this form of the tort is the intentional overhearing by one not intended to be a party to the communication of the contents of a private conversation. In the absence of an overhearing of a private communication, this tort has not been committed. Note that the court did not explicitly say that a recording device could not be a listener or a party but that was the very basis of the decision.”) TheMarks court in turn pointed to earlier case law that had likewise addressed the issue and some out the same way, such as LeCrone v. Ohio Bell Telephone Co., 120 Ohio App. 129, 201 N.E.2d 533 (1963). 33 TransUnion LLC v. Ramirez, 594 U.S. 413 (2021). 34 J.C. v. Cath.Health Sys. Inc., No. 1:23-CV-00796(JLS) (JJM), 2024WL 5136236, at *4 (W.D.N.Y. Aug. 29, 2024), report and recommendation adopted, No. 23-CV-796 (JLS) (JJM), 2025 WL 351043 (W.D.N.Y. Jan. 31, 2025).

378 A. Nielsen

plaintiffs also alleged capture of health information, but the court rejected standing. The Andrews court invoked a lack of human use of the information as a key factor35

[T]he Complaint generally alleges that, when using the Pixel and CAPI, Facebook obtains the confidential information and then sells it to third-party marketers who geotarget users’ Face- book pages… [N]othing in the Complaint alleges that any person at Facebook accessed or viewed Plaintiff’s Private Information. [See id. 86 (alleging that the “viewing, processing, and analyzing” of the confidential information “was performed by computers and/or algorithms programmed and designed by Facebook employees”).] Therefore…Plaintiff’s alleged harm is not closely related to the traditional tort of disclosure of private information.36

The Andrews court found neither the receipt of information by a third-party legal person nor the algorithmic use of that information as adequate to establish standing premised on harms analogous to those addressed by the disclosure tort. Both Andrews and J.C. had the opportunity to directly address the “no humans involved” argument, but only one found this argument dispositive. Of course these cases are relatively new, and we may well have more indicia from additional trial court decisions soon. In the meantime, the fact of initial disagreement suggests that this fact pattern reflects a close case, unlike the cases looking at algorithmic actions disussed supra.

It is not surprising that much of the (little) case law that sheds light on how and whether algorithms can fulfill certain roles in the privacy torts comes by way of analogy in standing cases. Plaintiffs in privacy suits are particularly challenged by the need to craft arguments that meet recently imposed, heightened Article III standing requirements. Nonetheless many cases do make it past the standing query to address the substantive question of tort law. In In re Google RTB Consumer Privacy Litigation (discussed supra),37 a federal district court addressed a plaintiff’s claim of public disclosure of private facts in a scenario alleging vast distribution of data to networks of bidders for ads, that is to a vast algorithmic network:

Google argues plaintiffs only allege disclosure to a limited group of RTB participants which would not qualify as “widely published.” This argument does not persuade. Plaintiffs allege that Google operates “the world’s largest ad exchange” by way of Google’s RTB process, and that through Google’s RTB process, over 1 million publishers are known to participate in the RTB bidding process. Of those publishers, Google gave publicity to plaintiffs’ and class members’ private facts and the use of their sensitive information by selling it to hundreds of companies. Given the large number of participants in the RTB bidding process, the Courtfinds that plaintiffs have adequately alleged disclosure.38

35 Andrews v. Prisma Health, No. 6:23-CV-03153-JDA, 2024 WL 3861384, at *7 (D.S.C. Aug. 16, 2024). 36 Andrews v. Prisma Health, No. 6:23-CV-03153-JDA, 2024 WL 3861384, at *7 (D.S.C. Aug. 16, 2024). 37 In re Google RTB Consumer Priv. Litig., 606 F. Supp. 3d 935 (N.D. Cal. 2022). 38 In re Google RTB Consumer Priv. Litig., 606 F. Supp. 3d 935, 947 (N.D. Cal. 2022)

Algorithms and the Privacy Torts 379

The real-time bidding (RTB) process is driven exclusively by algorithmic actors; therefore circulating information to “RTB participants” in realitymeant passing data among algorithmic actors deployed by differentfirms.39 TheRTB decision evinces the plausible theory that algorithms can be the public for the disclosure tort, though the position is notmade explicit. Notably, the idea that code alone had processed the data did not explicitly justify the decision; indeed neither party appears to have pushed hard on this idea. Google premised its defense against the disclosure tort on its limiting of access to a select group of participants (that is, not the public at large) while the court rejected these arguments due to the “large number” of such partic- ipants. From the RTB litigation, we can see that a sufficiently high number of algo- rithms parsing information may be legally adequate as “the public” in the disclosure tort. From the conflict between J.C. and Andrews, we see that a few algorithms may not be enough.

Another issue baked into the RTB decision is the question of whether it is a legal person that is “viewing” information or an algorithm that is “viewing” information under the facts alleged. Of course, in either case this is a legal fiction, but might one interpretation of the facts appear more plausible to courts than the other? To date, courts do not appear to have distinguished between these interpretations. What’s more, even in non-technology scenarios, privacy torts caselaw has not clearly dealt with the question of distinguishing juridical persons from their human employees. Occasionally a complaint may plead privacy torts against both a legal person and some of its employees, but there isn’t as yet readily identifiable caselaw on this issue. Interestingly, this suggests another unexpected possible legal development. Future judicial decisions might explicitly adopt the view that the public need not comprise natural persons but instead that legal persons may be adequate. If so, further questions arise. For example, are numeracy requirements for legal persons and natural persons be the same or different? Again, caselaw seems not to have addressed these questions but might in future consumer privacy cases with fact patterns like RTB. At the least, RTB suggests as a preliminary matter that the number of algorithms needed for a public may be substantially larger than the number of natural persons.

Courts are clearly less likely to recognize algorithmic publics than they are to recognize algorithmic actors, at least in the context of the consumer privacy torts litigation that has taken place in recent years. This points toward a likely broader limitation on AI’s legal standing in tort and other private law domains: where lia- bility depends not just on conduct but on relational meanings and social in- teractions – such as implied by public disclosure of private information or of torts

39 Google, How Our Bidding Algorithms Learn, Google Ads Help, https://support.google.com/google- ads/answer/10970825 (last visited Apr. 25, 2025).

380 A. Nielsen

addressing reputational damage –AI entitiesmay be unlikely to substitute legally for humans. In emerging AI-related claims, courts may be willing to attribute mechan- ical and algorithmic acts to human actors but may be more cautious about imputing social meanings, emotions, or community-based harms to interactions between humans and AI alone. Under the privacy torts, algorithmsmay be able to “do”, legally speaking, but not to “see.”

5 AI as Prurience

Because algorithms are such effective and scalable collectors of information, they are oft maligned by consumers, politicians, and privacy advocates alike. Courts have therefore long had occasion to consider the question whether algorithmic collection of information is highly offensive, and if so underwhat circumstances. A 2020 federal district court case,NewMexico ex rel. Balderas v. Tiny Lab Productions, presented an extensive review of cases addressing the offensiveness prong of various alleged algorithmic invasions of private, andfinding courts in other jurisdictions evenly split on the matter of offensiveness of algorithmic data collection.40 The Balderas court

40 New Mexico ex rel. Balderas v. Tiny Lab Prods., 457 F. Supp. 3d 1103, 1125 (D.N.M. 2020), on reconsideration, 516 F. Supp. 3d 1293 (D.N.M. 2021) (New Mexico courts have not had occasion to consider whether the circumstances under which the Ad Networks are alleged to have intruded on app users’ seclusion would be deemed highly offensive to a reasonable person. Courts in other jurisdictions, however, have considered whether allegations of electronic information collection are sufficient to state an intrusion on seclusion claim, to differing results. Compare, e.g., Manigault- Johnson v. Google, LLC, No. 18-cv-1032, 2019 WL 3006646 (D.S.C. Mar. 31, 2019) (finding allegations analogous to those here insufficient to allege offensiveness element of intrusion on seclusion claim), Yunker v. PandoraMedia, 11-cv-3113, 2013WL 1282980 (N.D. Cal. Mar. 26, 2013) (finding allegations that Pandora obtained plaintiff’s personally identifiable information and provided that information to advertising libraries for marketing purposes insufficient “to allege that Pandora’s conduct consti- tutes an egregious breach of social norms”), and In re iPhone App. Litig., 844 F. Supp. 2d 1040 (N.D. Cal. 2012) (holding that information allegedly disclosed to third parties, including unique device identifier number, personal data, and geolocation information from plaintiff’s iDevices, did not “constitute an egregious breach of social norms”), withMcDonald v. Kiloo ApS, 385 F. Supp. 3d 1022 (N.D. Cal. 2019) (finding allegations virtually identical to those here adequate to allege offensiveness element of intrusion on seclusion claim), Opperman v. Path, 87 F. Supp. 3d 1018 (N.D. Cal. 2014) (in declining to conclude as a matter of law that defendants’ copying of plaintiffs’ address books was not highly offensive, noting that ‘while the court recognizes that attitudes toward privacy are evolving in the age of the Internet, smartphones, and social networks, the Court does not believe that the surreptitious theft of personal contact information… has come to be qualified as ‘routine commercial behavior’’), and In re: Vizio, Inc., Consumer Privacy Litig., 238 F. Supp. 3d 1204 (C.D. Cal. 2017) (finding that plaintiffs plausibly alleged that defendant’s collection of plaintiffs’ video viewing history ‘amount[ed] to a highly offensive intrusion’).

Algorithms and the Privacy Torts 381

noted that many decisions as to offensiveness of algorithmic information collection presented nearly identical fact patterns, usually centering on the surreptitious algorithmic collection of personal information to guide targeted advertising. Some courts dismissed such behavior as falling far short of an egregious violation of social norms, while others characterized the same behavior as similar to theft and rejected contentions that such behavior was either routine or acceptable.

Part of the split in authority might be related to whether offensiveness was evaluated with a descriptive or normative emphasis.41 If offensiveness is understood as driven largely by an empirical assessment of how common a certain behavior is, and the offensiveness element as requiring a showing of unusual or atypical behavior, this requirement would be more challenging for plaintiffs to fulfill given that commercial surveillance is both pervasive and widely known to be so. If on the other hand, offensiveness is understood to be a normative judgment, this leaves far more room for finding algorithmic data collection practices to be highly offensive.

Of cousre, it's not an all or nothing questionwhether algorithmic data collection is offensive. Courts will look to nuances of the case, such as the nature of the data collected or on the degree of duplicity in obtaining data. Certain kinds of data collection have been judged insufficiently sensitive such that even covert surveil- lance of such data does not rise to the level of very offensive behavior. For example, in Oliver v. Noom, automated collection of keystrokes and mouse movements via session replay software was deemed not (sufficiently) offensive.42 On the other hand, collection of information about children (often thought to be sensitive regardless of the precise nature of the data) combinedwith a perceived duplicity in intrface design was found highly offensive inMcDonald v. Kiloo ApS.43 Sometimes the perception of duplicity can give rise to highly offensive behavior evenwhen the data collected isn’t particularly sensitive. In In re Google Inc. Cookie Placement Consumer Privacy Liti- gation, the Third Circuit zeroed in on Google’s covert circumvention of cookie blockers, although the cookies themselves were not alleged to harvest or record any particularly sensitive information. The combination of deception, scale, and

41 CfKenneth S. Abraham&G. EdwardWhite,TheOffensiveness Torts, 17 J. TORT L. 1, 3 (2024) (“[T]here is a greater degree of normative discretion exercised in adjudicating most of the intentional torts than is sometimes realized. The very notion of intentional “harm” is at least as much normative as it is empirical”). 42 Oliver v. Noom, Inc., No. 2:22-CV-1857, 2023 WL 8600576 (W.D. Pa. Aug. 22, 2023). Note that this assessment by the court may very well be out of step with the judgment of most Americans. This may indeed be a reflection of the relatively unpredictable outcome of offensiveness analyses under the privacy torts more generally. See Patricia Sànchez Abril & Alissa del Riego, Judging Offensiveness: A Rubric for Privacy Torts, 100 N.C. L. REV. 1557 (2022). 43 McDonald v. Kiloo ApS, 385 F. Supp. 3d 1022 (N.D. Cal. 2019).

382 A. Nielsen

indefinite surveillance reflected in Google’s conduct – executed entirely through code – was enough to survive a motion to dismiss.44

This cases discussed here have related purely to intrusion upon seclusion. As discussed supra, the disclosure and false light torts also incorporate offensiveness elements, although in these latter cases the offensiveness element applies to the information or representation at issue. Consumer privacy litigation that has turned on algorithmic acts has not, so far, triggered discussions of offensiveness in relation to these torts. As seen supra there have been successful invocations of theories of disclosure, specifically in In re Google RTB Consumer Privacy Litigation and J.C. (this latter a standing case). Though offensivenesswas not treated explicitly in those cases, the favorable outcomes to plaintiffs who defeated motions to dismiss suggests that those cases were not thought to be close cases when it came to the offensiveness of disclosing the particular information at issue. The RTB case represents a typical case of commercial surveillance for advertising, a close case under Balderas, while J.C. was a case about health information, a category that has long been understood to be sensitive and for which adequacy of offensiveness would seem to be clear.45

Courts recognize that purely algorithmic information collection can fulfill an offensiveness requirement when algorithms enable deception, exploitation, or vio- lations of reasonable expectations, but are less willing to find offensiveness where the algorithmic actions are perceived to merely automate common and socially acceptable behaviors. The review is highly contextual. This suggests that outside the privacy torts, courts evaluating AI-related conduct are likely to emphasize contextual assessments of social norms and may focus heavily on whether the use of AI mag- nifies deceit, power asymmetries, or hidden manipulation. This could be relevant in many distinct ways, including assessing whether the breach of a duty occurred or determining the availability of a punitive damages instruction for a jury.

6 Limitations

This analysis examines recent consumer privacy litigation as a window into how courts may construe common law tort claims involving AI. The case law offers valuable insights but is subject to three principal limitations. First, there is a lack of distinction between algorithms and firms; neither is a natural person but one is a juridical person. Under the facts of several cases discussed here, much could

44 In re Google Inc. Cookie Placement Consumer Priv. Litig., 806 F.3d 125 (3d Cir. 2015). 45 Of course since this was a standing case post TransUnion the question was not whether the facts constituted a prima facie case of disclosure but only whether the harms alleged were sufficiently analogous to harms traditionally addressed under the common law.

Algorithms and the Privacy Torts 383

plausibly have beenmade of such a distinction but wasn’t. As a result, it is sometimes ambiguous whether litigation concerns human versus algorithmic conduct or rather human versus corporate conduct. This is not so much a limitation of the doctrinal review here as a reflection of litigation reality: tort claims in this space are likely to arise only when an identifiable firm has deployed a contested algorithm. In such contexts, it may not matter whether it is the algorithm or the legal person that “views” the content – indeed the algorithm and the firm may be legally and func- tionally indistinguishable.

Second, most of the reviewed cases here involve software that collects and transmits information in a deterministic or nearly deterministic manner, rather than algorithmic systems characterized by highly adaptive or data-conditioned outputs. While such litigation may illuminate how courts distinguish between hu- man and non-human actors or attribute liability to legal persons for automated conduct, these cases may be less instructive for tort questions involving fore- seeability, reasonableness, or adaptive behavior. This is not a limitation of privacy tort case law to shed law on AI liability more generally, but rather a reflection of the fact that more complex algorithmic systems have not yet generated much case law.

Finally, this survey is incomplete even within the domain of privacy torts. The analysis focused on three shared elements across the four classic privacy torts. Other doctrinal components – though less uniform – also deserve further attention. For instance, while this work interrogates what counts as “the public” for purposes of a privacy violation, equally important is how courts define what counts as private information in the first place. Privacy is not a binary category but often depends on context and relational dynamics.46 What is private in relation to algorithmic actors or audiences may differ from what is private in relation to human actors or audi- ences. Similar complexities arise with respect to elements like false light or legiti- mate interest. Representations that could reasonablymislead an algorithm are likely different from those that could reasonably mislead humans. Likewise, with respect to the disclosure tort, while human publics have a wide range of legitimate interests, it is unclear whether algorithms – lacking legal personhood and constitutional rights–have a comparable scope of legitimate interests. This work has not examined such questions.

7 Conclusions

This article has explored how the classic privacy torts have already confronted some torts doctrinal challenges posed by algorithms. Courts have been willing to find

46 Helen Nissenbaum, A Contextual Approach to Privacy Online, 140 DAEDALUS 32, 33 (2011).

384 A. Nielsen

algorithmic actions as legally adequate to perpetrate invasions of privacy but less ready to recognize the possibility of an algorithmic public. When it comes to pruri- ence, algorithms neither exacerbate nor mitigate offensiveness categorically, but are instead judged contextually. The privacy torts offer a helpful early laboratory for observing how private law may adapt to harms arising from algorithms and AI.

Algorithms and the Privacy Torts 385

Reproduced with permission of copyright owner. Further reproduction prohibited without permission.

  • Algorithms and the Privacy Torts
  • 1 Introduction
  • 2 Laying out Common Elements
  • 3 AI as Perpetrator
  • 4 AI as Public
  • 5 AI as Prurience
  • 6 Limitations
  • 7 Conclusions

<< /ASCII85EncodePages false /AllowTransparency false /AutoPositionEPSFiles true /AutoRotatePages /None /Binding /Left /CalGrayProfile (Dot Gain 20%) /CalRGBProfile (sRGB IEC61966-2.1) /CalCMYKProfile (Euroscale Coated v2) /sRGBProfile (sRGB IEC61966-2.1) /CannotEmbedFontPolicy /Warning /CompatibilityLevel 1.7 /CompressObjects /Tags /CompressPages true /ConvertImagesToIndexed true /PassThroughJPEGImages false /CreateJobTicket false /DefaultRenderingIntent /Default /DetectBlends true /DetectCurves 0.1000 /ColorConversionStrategy /sRGB /DoThumbnails true /EmbedAllFonts true /EmbedOpenType false /ParseICCProfilesInComments true /EmbedJobOptions true /DSCReportingLevel 0 /EmitDSCWarnings false /EndPage -1 /ImageMemory 1048576 /LockDistillerParams false /MaxSubsetPct 35 /Optimize true /OPM 1 /ParseDSCComments true /ParseDSCCommentsForDocInfo true /PreserveCopyPage true /PreserveDICMYKValues true /PreserveEPSInfo true /PreserveFlatness false /PreserveHalftoneInfo false /PreserveOPIComments false /PreserveOverprintSettings true /StartPage 1 /SubsetFonts true /TransferFunctionInfo /Apply /UCRandBGInfo /Remove /UsePrologue false /ColorSettingsFile () /AlwaysEmbed [ true ] /NeverEmbed [ true ] /AntiAliasColorImages false /CropColorImages false /ColorImageMinResolution 300 /ColorImageMinResolutionPolicy /OK /DownsampleColorImages true /ColorImageDownsampleType /Bicubic /ColorImageResolution 300 /ColorImageDepth -1 /ColorImageMinDownsampleDepth 1 /ColorImageDownsampleThreshold 1.50000 /EncodeColorImages true /ColorImageFilter /DCTEncode /AutoFilterColorImages true /ColorImageAutoFilterStrategy /JPEG /ColorACSImageDict << /QFactor 0.15 /HSamples [1 1 1 1] /VSamples [1 1 1 1] >> /ColorImageDict << /QFactor 0.15 /HSamples [1 1 1 1] /VSamples [1 1 1 1] >> /JPEG2000ColorACSImageDict << /TileWidth 256 /TileHeight 256 /Quality 10 >> /JPEG2000ColorImageDict << /TileWidth 256 /TileHeight 256 /Quality 30 >> /AntiAliasGrayImages false /CropGrayImages false /GrayImageMinResolution 300 /GrayImageMinResolutionPolicy /OK /DownsampleGrayImages true /GrayImageDownsampleType /Bicubic /GrayImageResolution 300 /GrayImageDepth -1 /GrayImageMinDownsampleDepth 2 /GrayImageDownsampleThreshold 1.50000 /EncodeGrayImages true /GrayImageFilter /DCTEncode /AutoFilterGrayImages true /GrayImageAutoFilterStrategy /JPEG /GrayACSImageDict << /QFactor 0.15 /HSamples [1 1 1 1] /VSamples [1 1 1 1] >> /GrayImageDict << /QFactor 0.15 /HSamples [1 1 1 1] /VSamples [1 1 1 1] >> /JPEG2000GrayACSImageDict << /TileWidth 256 /TileHeight 256 /Quality 30 >> /JPEG2000GrayImageDict << /TileWidth 256 /TileHeight 256 /Quality 30 >> /AntiAliasMonoImages false /CropMonoImages false /MonoImageMinResolution 600 /MonoImageMinResolutionPolicy /OK /DownsampleMonoImages true /MonoImageDownsampleType /Bicubic /MonoImageResolution 1000 /MonoImageDepth -1 /MonoImageDownsampleThreshold 1.10000 /EncodeMonoImages true /MonoImageFilter /CCITTFaxEncode /MonoImageDict << /K -1 >> /AllowPSXObjects false /CheckCompliance [ /None ] /PDFX1aCheck false /PDFX3Check false /PDFXCompliantPDFOnly false /PDFXNoTrimBoxError false /PDFXTrimBoxToMediaBoxOffset [ 0.00000 0.00000 0.00000 0.00000 ] /PDFXSetBleedBoxToMediaBox true /PDFXBleedBoxToTrimBoxOffset [ 0.00000 0.00000 0.00000 0.00000 ] /PDFXOutputIntentProfile (None) /PDFXOutputConditionIdentifier () /PDFXOutputCondition () /PDFXRegistryName () /PDFXTrapped /False /CreateJDFFile false /Description << /DEU <FEFF00280073006500650020006700650072006d0061006e002000620065006c006f00770029000d005500730065002000740068006500730065002000730065007400740069006e0067007300200074006f002000700072006f006400750063006500200063006f006e00740065006e00740020007000720069006e00740069006e0067002000660069006c006500730020006100630063006f007200640069006e006700200074006f002000740068006500200064006100740061002000640065006c0069007600650072007900200072006500710075006900720065006d0065006e007400730020006f00660020004400650020004700720075007900740065007200200028004a006f00750072006e0061006c002000500072006f00640075006300740069006f006e002900200044006100740065003a002000300033002f00300031002f0032003000310035002e0020005400720061006e00730070006100720065006e0063006900650073002000610072006500200072006500640075006300650064002c002000520047004200200069006d0061006700650073002000610072006500200063006f006e00760065007200740065006400200069006e0074006f002000490053004f00200043006f0061007400650064002000760032002e002000410020005000440046002f0058002d0031006100200069007300200063007200650061007400650064002e000d005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f005f000d000d00560065007200770065006e00640065006e0020005300690065002000640069006500730065002000450069006e007300740065006c006c0075006e00670065006e002c00200075006d00200044007200750063006b0076006f0072006c006100670065006e0020006600fc0072002000640065006e00200049006e00680061006c0074002000670065006d00e400df002000640065006e00200044006100740065006e0061006e006c006900650066006500720075006e0067007300620065007300740069006d006d0075006e00670065006e00200076006f006e0020004400450020004700520055005900540045005200200028004a006f00750072006e0061006c002000500072006f00640075006300740069006f006e00290020005300740061006e0064003a002000300031002e00300033002e00320030003100350020007a0075002000650072007a0065007500670065006e002e0020005400720061006e00730070006100720065006e007a0065006e002000770065007200640065006e00200072006500640075007a0069006500720074002c0020005200470042002d00420069006c006400650072002000770065007200640065006e00200069006e002000490053004f00200043006f00610074006500640020007600320020006b006f006e00760065007200740069006500720074002e00200045007300200077006900720064002000650069006e00650020005000440046002f0058002d00310061002000650072007a0065007500670074002e> /ENU () /ENN () >> /Namespace [ (Adobe) (Common) (1.0) ] /OtherNamespaces [ << /AsReaderSpreads false /CropImagesToFrames true /ErrorControl /WarnAndContinue /FlattenerIgnoreSpreadOverrides false /IncludeGuidesGrids false /IncludeNonPrinting false /IncludeSlug false /Namespace [ (Adobe) (InDesign) (4.0) ] /OmitPlacedBitmaps false /OmitPlacedEPS false /OmitPlacedPDF false /SimulateOverprint /Legacy >> << /AllowImageBreaks true /AllowTableBreaks true /ExpandPage false /HonorBaseURL true /HonorRolloverEffect false /IgnoreHTMLPageBreaks false /IncludeHeaderFooter false /MarginOffset [ 0 0 0 0 ] /MetadataAuthor () /MetadataKeywords () /MetadataSubject () /MetadataTitle () /MetricPageSize [ 0 0 ] /MetricUnit /inch /MobileCompatible 0 /Namespace [ (Adobe) (GoLive) (8.0) ] /OpenZoomToHTMLFontSize false /PageOrientation /Portrait /RemoveBackground false /ShrinkContent true /TreatColorsAs /MainMonitorColors /UseEmbeddedProfiles false /UseHTMLTitleAsMetadata true >> << /AddBleedMarks false /AddColorBars false /AddCropMarks false /AddPageInfo false /AddRegMarks false /BleedOffset [ 0 0 0 0 ] /ConvertColors /ConvertToCMYK /DestinationProfileName (ISO Coated v2 \(ECI\)) /DestinationProfileSelector /UseName /Downsample16BitImages true /FlattenerPreset << /ClipComplexRegions true /ConvertStrokesToOutlines false /ConvertTextToOutlines false /GradientResolution 300 /LineArtTextResolution 1200 /PresetName <FEFF005B0048006F006800650020004100750066006C00F600730075006E0067005D> /PresetSelector /HighResolution /RasterVectorBalance 1 >> /FormElements true /GenerateStructure false /IncludeBookmarks false /IncludeHyperlinks false /IncludeInteractive false /IncludeLayers false /IncludeProfiles false /MarksOffset 8.503940 /MarksWeight 0.250000 /MultimediaHandling /UseObjectSettings /Namespace [ (Adobe) (CreativeSuite) (2.0) ] /PDFXOutputIntentProfileSelector /UseName /PageMarksFile /RomanDefault /PreserveEditing true /UntaggedCMYKHandling /LeaveUntagged /UntaggedRGBHandling /UseDocumentProfile /UseDocumentBleed false >> ] >> setdistillerparams << /HWResolution [600 600] /PageSize [595.276 841.890] >> setpagedevice