Surveillance Mitigation: Identify a form of surveillance that you encounter in your everyday life
Washington and Lee Law Review
Volume 70 | Issue 1 Article 6
1-1-2013
Information Privacy and Data Control in Cloud Computing: Consumers, Privacy Preferences, and Market Efficiency Jay P. Kesan
Carol M. Hayes
Masooda N. Bashir
Follow this and additional works at: http://scholarlycommons.law.wlu.edu/wlulr Part of the Computer Law Commons
This Article is brought to you for free and open access by the Law School Journals at Washington & Lee University School of Law Scholarly Commons. It has been accepted for inclusion in Washington and Lee Law Review by an authorized administrator of Washington & Lee University School of Law Scholarly Commons. For more information, please contact [email protected].
Recommended Citation Jay P. Kesan, Carol M. Hayes, and Masooda N. Bashir, Information Privacy and Data Control in Cloud Computing : Consumers, Privacy Preferences, and Market Efficiency, 70 Wash. & Lee L. Rev. 341 (2013), http://scholarlycommons.law.wlu.edu/wlulr/vol70/iss1/6
This is the second excerpt from this article. The full article can be found on the Moodle.
341
Information Privacy and Data Control in Cloud Computing: Consumers,
Privacy Preferences, and Market Efficiency
Jay P. Kesan∗ Carol M. Hayes∗∗
Masooda N. Bashir∗∗∗
Abstract
So many of our daily activities now take place “in the cloud,” where we use our devices to tap into massive networks that span the globe. Virtually every time that we plug into a new service, the service requires us to click the seemingly ubiquitous box indicating that we have read and agreed to the provider’s terms of service (TOS) and privacy policy. If a user does not click on this box, he is denied access to the service, but agreeing to these terms without reading them can negatively impact the user’s legal rights.
As part of this work, we analyzed and categorized the terms of TOS agreements and privacy policies of several major cloud services to aid in our assessment of the state of user privacy in the cloud. Our empirical analysis showed that providers take similar approaches to user privacy and were consistently more detailed when describing the user’s obligations to the provider than when describing the provider’s obligations to the user. This asymmetry, combined with these terms’ nonnegotiable nature, led us to
∗ Professor and H. Ross & Helen Workman Research Scholar, University of Illinois College of Law. ∗∗ Research Associate, University of Illinois College of Law; Fall 2010 Fellow in the Christine Mirzayan Science and Technology Policy Graduate Fellowship program at the National Academy of Sciences. ∗∗∗ Assistant Director for Social Trust Initiatives, Information Trust Institute, University of Illinois. The authors also wish to acknowledge the excellent research assistance of Robert Zielinski in preparing this work.
342 70 WASH. & LEE L. REV. 341 (2013)
conclude that the current approach to user privacy in the cloud is in need of serious revision.
In this Article, we suggest adopting a legal regime that requires companies to provide baseline protections for personal information and also to take steps to enhance the parties’ control over their own data. We emphasize the need for a regime that allows for “data control” in the cloud, which we define as consisting of two parts: (1) the ability to withdraw data and require a service provider to stop using or storing the user’s information (data withdrawal); and (2) the ability to move data to a new location without being locked into a particular provider (data mobility). Ultimately, our goal with this piece is to apply established law and privacy theories to services in the cloud and set forth a model for the protection of information privacy that recognizes the importance of informed and empowered users.
Table of Contents
I. Introduction ..................................................................... 344 II. Cloud Computing Fundamentals .................................... 347
A. Background Technology ............................................ 347 1. The Internet ......................................................... 349 2. Mobile Computing ............................................... 351 3. Security ................................................................ 352 4. Related Regulations ............................................. 353
B. What Is Cloud Computing? ....................................... 354 1. Defining Cloud Computing .................................. 355 2. Growth of Cloud Computing ................................ 356 3. Uses of Cloud Computing .................................... 358 4. Types of Cloud Computing Services .................... 360
C. Advantages and Disadvantages of Cloud Computing ................................................................. 362
D. Cloud Computing Legal Issues ................................. 365 1. Privacy ................................................................. 366 2. Jurisdiction .......................................................... 368
E. Calls for Action in the Cloud ..................................... 371 1. Transparency and Control ................................... 372
F. Cloud Services in Different Industries ..................... 373
INFORMATION PRIVACY AND DATA CONTROL 343
III. Privacy Fundamentals .................................................... 375 A. Privacy Theories ........................................................ 375
1. Warren and Brandeis .......................................... 380 2. Prosser ................................................................. 381
a. Prosser’s Privacy Torts and Information Privacy ............................................................ 383
3. Modern Informational Privacy Theory ................ 384 a. Concepts of Privacy ........................................ 386 b. The First Amendment Critique ..................... 388 c. Privacy as a Commodity ................................. 390
B. Privacy Law ............................................................... 392 1. Steps Toward Regulation of Privacy ................... 393 2. Federal Privacy Statutes and State Laws .......... 395
a. Electronic Communications Privacy Act ....... 399 (1) Stored Communications Act ..................... 401 (2) Applying the SCA to the Cloud ................ 405
3. Case Law .............................................................. 407 a. Fourth Amendment ........................................ 408 b. Stored Communications Act........................... 414 c. Contracts and Privacy .................................... 416
4. European Privacy Law ........................................ 418 a. The Safe Harbor Framework ......................... 419
IV. Companies, Customer Data, and Customer- Company Interactions ..................................................... 421 A. Companies and Customer Data ................................ 421
1. Terms of Service Agreements .............................. 421 a. TOS Agreements as Contracts of Adhesion ......................................................... 424
2. Privacy Policies .................................................... 425 a. Sharing Information with the Government ... 427
3. Effects of Security Breaches ................................ 430 4. Protecting Consumer Data—Who Watches the Watchers? ...................................................... 432 5. Tracking Technologies and Behavioral Marketing ............................................................ 436 6. Personally Identifiable Information and “Anonymous” Information ................................... 440
V. Empirical Analysis of Agreements and Policies in the Cloud .......................................................................... 443
344 70 WASH. & LEE L. REV. 341 (2013)
A. Methodology............................................................... 444 B. Terms of Service Agreements .................................... 446
C. Privacy Policies .......................................................... 449 D. Analysis and Discussion ............................................ 457
E. Implications ............................................................... 459 VI. Recommendations—Building a Baseline for
Facilitating Transactions in the Cloud ........................... 460 A. Building the Baseline ................................................ 460
1. Baseline Regulation ............................................. 462 B. Data Control .............................................................. 464
1. Personally Identifiable Information .................... 465 2. Secondary Use ..................................................... 466 3. Course-of-Business Data ..................................... 468
VII. Conclusion ........................................................................ 471
“You have zero privacy anyway. Get over it.” —Scott McNealy, Chairman and former CEO of Sun
Microsystems, 1999
INFORMATION PRIVACY AND DATA CONTROL 375
III. Privacy Fundamentals
A. Privacy Theories
“Privacy” is an example of a word that can mean many different things.154 It can be a handmade sign on the door of a teenager’s room prohibiting entry by parents and little brothers. It can be the right to make one’s own decisions without undue burden imposed by the government. On the Web, some people might consider social networking posts “private” if they are only viewable by the poster’s four hundred closest friends,155 while others do not consider anything that they do on the Web “private” unless all data is heavily encrypted and all of their traffic is routed through an anonymizer.156
152. See McCarthy, supra note 95, at 2263–64 (discussing new federal law governing PHR privacy and security). 153. See id. at 2267 (“PHRs should be required to employ best practices in data encryption, password protection, and authentication in order to safeguard PHI stored on their servers.”). 154. See Anita L. Allen, Privacy-As-Data Control: Conceptual, Practical, and Moral Limits of the Paradigm, 32 CONN. L. REV. 861, 864 (2000) [hereinafter Allen, Data Control] (noting the wide variation in how “privacy” is defined, even among people who seemingly are talking about the same privacy paradigm of privacy being data control). 155. Some argue, however, that such postings are still functionally private because of the boundaries that exist by making a posting viewable only by certain people. See Richards & Solove, supra note 1, at 1920–21 (citing Lior Jacob Strahilevitz, A Social Networks Theory of Privacy, 72 U. CHI. L. REV. 919 (2005)). This view arguably does not consider the potential of screenshots of “friends only” postings being reposted elsewhere. 156. These three categories of privacy have been referred to as physical and proprietary privacy, decisional privacy, and informational privacy. Allen, Data
376 70 WASH. & LEE L. REV. 341 (2013)
Some view privacy as a negative freedom, providing a freedom from something instead of a claim to something else.157 Perhaps the most prevalent view of privacy over the years has been the secrecy paradigm of privacy, where privacy is limited to things that are secret.158 There is also an “invasion conception” of privacy, where privacy violations are viewed as invasions of an interest.159 Some view privacy as referring to inaccessibility, when a person or information about her is inaccessible to others.160 Some also address what sort of harm is necessary to find a privacy violation. Solove asserts that there can be an infringement of privacy “even if no secrets are revealed and even if nobody is watching us,” connecting the concepts of privacy and human dignity.161
The importance of privacy is sometimes stated in grandiose terms, tying the concept of privacy to democratic ideals like
Control, supra note 154, at 865–66. 157. See Anita L. Allen, Coercing Privacy, 40 WM. & MARY L. REV. 723, 747– 48 (1999) [hereinafter Allen, Coercing Privacy] (discussing conservative and liberal interpretations of the right to privacy). 158. See Solove, Taxonomy, supra note 111, at 497–98 (“Under the secrecy paradigm . . . if the information is not previously hidden, then no privacy interest is implicated by the collection or dissemination of the information. In many areas of law, this narrow view of privacy has limited the recognition of privacy violations.”). This paradigm can be seen in the approach courts have taken to the Fourth Amendment, as well as in the tort of intrusion upon seclusion. Id. Solove takes the view that the secrecy paradigm approach to information privacy law is outmoded. SOLOVE, DIGITAL PERSON, supra note 2, at 143. 159. See SOLOVE, DIGITAL PERSON, supra note 2, at 8 (defining the invasion conception of privacy). Solove says that the Warren and Brandeis theory of privacy falls within this conception of privacy, with a focus on the existence of discrete wrongs to individuals. See id. at 93–94 (discussing the two models for the protection of privacy). Solove also criticizes the invasion conception of privacy by arguing that it overlooks the structural nature of certain privacy problems that affect not just an individual, but also society as a whole. See id. at 97. 160. See Allen, Data Control, supra note 154, at 867 (“[O]ther than in contexts in which ‘privacy’ holds its decisional and proprietary meanings, privacy refers to a degree of inaccessibility of a person or information about her to others’ five senses and surveillance devices.”); Allen, Coercing Privacy, supra note 157, at 724 (“Privacy obtains where persons and personal information are, to a degree, inaccessible to others.”). 161. SOLOVE, DIGITAL PERSON, supra note 2, at 44, 55.
INFORMATION PRIVACY AND DATA CONTROL 377
independent thought and the right to take political actions.162 Alan Westin, an early information privacy scholar, defined privacy as “the claim of individuals, groups, or institutions to determine for themselves when, how, and to what extent information about them is communicated to others.”163 The law has taken a number of approaches to address different concerns associated with privacy. The right to privacy has been recognized in the United States for over a century, though coherent definitions have generally been lacking.164 Solove views privacy as a concept that encompasses many different kinds of distinct but interrelated issues.165
The concept of privacy also overlaps with constitutional protections under the Fourth Amendment, where the focus is on a “reasonable expectation of privacy.”166 This legal concept is connected to several philosophical questions: what is privacy, where does it exist, and is it reasonable to expect a particular action to be private? If the government conducts surveillance somewhere that there is an expectation of privacy, a warrant is
162. See Allen, Coercing Privacy, supra note 157, at 734 (“Liberal theorists claim that we need privacy to be persons, independent thinkers, free political actors, and citizens of a tolerant democracy.”); Solove, Taxonomy, supra note 111, at 489 (citing Julie Cohen and Paul Schwartz for the argument that “privacy is a constitutive element of a civil society”). 163. ALAN F. WESTIN, PRIVACY AND FREEDOM 7 (1967). 164. See Richards, supra note 114, at 1155 (discussing the sometimes uneasy coexistence of privacy and speech); Paul M. Schwartz & Karl-Nikolaus Peifer, Prosser’s Privacy and the German Right of Personality: Are Four Privacy Torts Better than One Unitary Concept?, 98 CAL. L. REV. 1925, 1963 (2010) (“[I]n their comprehensive work, Privacy, Property and Personality, [the authors] argue that the right of privacy in the United States ‘remains somewhat conceptually uncertain and poorly defined.’” (quoting HUW BEVERLEY-SMITH ET AL., PRIVACY, PROPERTY AND PERSONALITY 207 (2005))); Solove, Taxonomy, supra note 111, at 562 (“But our understanding of privacy remains in a fog, and the law remains fragmented and inconsistent.”). 165. Richards & Solove, supra note 1, at 1914–15; Solove, Taxonomy, supra note 111, at 562. 166. See Rebecca N. Cordero, No Expectation of Privacy: Should School Officials be Able to Search Students’ Lockers Without Any Suspicion of Wrong Doing?, 31 U. BALT. L. REV. 305, 308 (2002) (“In his concurrence, Justice Harlan coined the term a ‘reasonable expectation of privacy’ to describe an area subject to the protection of the Fourth Amendment.”).
378 70 WASH. & LEE L. REV. 341 (2013)
necessary to protect against unreasonable intrusion.167 Generally, public surveillance is not viewed as an intrusion because behaviors are being exposed to the public, but there may be exceptions when such surveillance is overzealous.168 As one court said, “The mere fact that a person can be seen by someone does not automatically mean that he or she can legally be forced to be subject to being seen by everyone.”169
The Fourth Amendment protection against unreasonable searches and seizures, the protections afforded to electronic communications under the ECPA, and privacy torts are three large legal categories for the concept of privacy.170 As we examine in later sections, the application of the Fourth Amendment and the ECPA to the Information Age is far from clear. Additionally, there is also a sense that privacy tort law is ineffective at addressing these issues.171 The traditional model for privacy protection simply does not address the sorts of privacy problems that have arisen recently.172
The desire for privacy is arguably an innate human trait, and privacy theorists thus often make philosophical or literary allusions when explaining the importance of privacy. One of the most vivid images for the modern information privacy problems is Jeremy Bentham’s design for a prison that he called the
167. Katz v. United States, 389 U.S. 347, 360–61 (1967) (Harlan, J., concurring). 168. See Solove, Taxonomy, supra note 111, at 498 (“In some cases, however, courts have recognized a harm in public surveillance.”).
169. Sanders v. Am. Broad. Comps., Inc., 978 P.2d 67, 72 (Cal. 1999). 170. Other relevant elements of constitutional law include the freedom of association and the freedom of anonymous speech under the First Amendment. See SOLOVE, DIGITAL PERSON, supra note 2, at 64–65 (discussing the right to privacy). 171. See Richards & Solove, supra note 1, at 1889 (“Today, the chorus of opinion is that the tort law of privacy has been ineffective, particularly in remedying the burgeoning collection, use, and dissemination of personal information in the Information Age.”). 172. See id. at 1918 (“Tort law has not emerged as the leading protector of privacy.”). Solove argues that many of the privacy problems we confront today are systemic in nature, stemming from information flows, with multiple actors being responsible for these problems. Daniel J. Solove, Identity Theft, Privacy, and the Architecture of Vulnerability, 54 HASTINGS L.J. 1227, 1232 (2003) [hereinafter Solove, Architecture].
INFORMATION PRIVACY AND DATA CONTROL 379
Panopticon.173 In the Panopticon, prison cells are distributed around a central observation tower, and someone placed in the tower can monitor all of the prison cells without the prisoners knowing when they are being observed, and this fear of observation leads to the prisoners behaving better.174 In the context of the Internet, Schwartz has argued that there is a danger both of a government Panopticon and private Panopticons operated by private entities that collect and use information while resisting attempts at transparency.175
Privacy concerns gained more public visibility in the early 1980s, perhaps due to the era’s relationship with George Orwell’s dystopian novel Nineteen Eighty Four.176 Similar to the Panopticon, the telescreens of Nineteen Eighty Four allowed the government to monitor citizens without their knowledge that they were being observed.177 Perhaps thanks in part to this work of fiction—and the fact that it is required reading for many high school seniors—U.S. citizens are keenly aware when government action has the potential to intrude on privacy and lead to an authoritarian state.178
173. See MICHEL FOUCAULT, DISCIPLINE AND PUNISH: THE BIRTH OF THE PRISON 201 (Alan Sheridan trans., 1977) (listing the essential elements of the Panopticon’s effectiveness being visibility and unverifiability, visibility referring to that of the tower, and unverifiability referring to the prisoners’ inability to know whether they are being observed). 174. Id. at 201; Solove, Architecture, supra note 172, at 1240. Solove also notes Foucault’s argument that the Panopticon represents power relations in society. Id. at 1240. 175. See Paul M. Schwartz, Internet Privacy and the State, 32 CONN. L. REV. 815, 852–53 (2000) [hereinafter Schwartz, State] (discussing the creation of a privately operated Panopticon in the context of Internet privacy). 176. See Schwartz & Solove, supra note 3, at 1825–26 (“Part of this attention was driven, in turn, by the arrival of George Orwell’s titular year, 1984.”). 177. SOLOVE, DIGITAL PERSON, supra note 2, at 31. 178. See James Bamford, The NSA Is Building the Country’s Biggest Spy Center (Watch What You Say), WIRED (Mar. 15, 2012), http://www. wired.com/threatlevel/2012/03/ff_nsadatacenter/all/1 (last visited Feb. 3, 2013) (describing a massive new National Security Agency data collection center under construction) (on file with the Washington and Lee Law Review). Solove takes issue with the frequent comparisons to Nineteen Eighty Four, instead arguing that because the privacy threats are distributed across private companies and government bureaucracy, a better comparison would be to Kafka’s The Trial. SOLOVE, DIGITAL PERSON, supra note 2, at 7–9 (“[F]or a more
INFORMATION PRIVACY AND DATA CONTROL 421
IV. Companies, Customer Data, and Customer-Company Interactions
A. Companies and Customer Data
In this Article, we examine the interaction between privacy theories, privacy law, and the relationships between consumers and the companies that serve them in the cloud. These relationships are largely defined by TOS agreements and privacy policies, and these agreements typically enumerate what a consumer can expect concerning the use of his personal information. The concerns about how companies handle customer data go beyond these agreements, however, and include issues like data security, identity theft, and behavioral marketing.
1. Terms of Service Agreements
TOS agreements set forth terms governing the relationship between a service provider and its customers.402 Generally, cloud- based services targeted at individual users are accompanied by non-negotiable TOS agreements that favor the service provider
401. See James T. Sunosky, Privacy Online: A Primer on the European Union’s Directive and United States’ Safe Harbor Privacy Principles, 9 CURRENTS: INT’L TRADE L.J. 80, 85 (2000) (explaining the benefits of the Safe Harbor Privacy Principles). 402. See Joshua A.T. Fairfield, Contemporary Issues in Cyberlaw: Nexus Crystals: Crystallizing Limits on Contractual Control of Virtual Worlds, 38 WM. MITCHELL L. REV. 43, 44 (2011) (referring to terms of use and EULAs as the “social contract of the new millennium,” setting forth the rights and redresses of citizens).
Several pages pertaining to specific legal approaches to privacy removed. The full article is available on the Moodle.
422 70 WASH. & LEE L. REV. 341 (2013)
over the end user.403 TOS agreements will generally address things like metering, monitoring, and data backup,404 and often include clauses in which the provider disclaims liability for harm and forbids customers from using the company’s intellectual property without authorization.405 Some also include terms concerning the retention, control, and ownership of a user’s information.406 TOS agreements take a variety of approaches to customer information. Some include terms that allow providers to access customer information for advertising and other purposes relating to the business, while others are less transparent about what the company may do with customer information, and still others make explicit promises in their TOS agreements that the companies will not access customers’ data.407
The terms of TOS agreements can have a significant impact outside the context of the provider–customer relationship, potentially affecting the consumer’s legal rights. The DOJ has recently argued that violating a website’s TOS agreement amounts to unauthorized access under the CFAA,408 and courts
403. See Bagley, supra note 295, at 163 (“Google’s profit model is based on offering free services to consumers in exchange for their consent to non- negotiable terms of service.”); Wittow & Buller, supra note 7, at 7 (“The SLAs of cloud-based applications and services generally are non-negotiable and much more favorable to the provider than to the end user.”). 404. See Martin, supra note 44, at 311 (noting the difficulties of providing good customer service because of the lack of standards to measure a cloud’s performance). 405. See Bagley, supra note 295, at 178 (“[L]anguage in a TOS agreement merely disclaims liability for any damage to a user’s computer data and forbids unauthorized use or redistribution of intellectual property.”). 406. See id. (explaining that TOS clauses “also dictate the terms by which the entity will retain, control, and own a user’s information”). Google’s TOS agreement includes a provision giving the company a license to use the customer’s data in ways that would otherwise violate the customer’s copyright. See Google Policies and Principles, Terms of Service, GOOGLE (Mar. 1, 2012), http://www.google.com/policies/terms/ (last visited Feb. 3, 2013) (providing that Google may use personal data in accordance with their privacy policies) (on file with the Washington and Lee Law Review). 407. See Robison, supra note 4, at 1215–17 (providing an examination of existing cloud providers). 408. See Declan McCullagh, DOJ: Lying on Match.com Needs to Be a Crime, CNET (Nov. 14, 2011, 11:58 PM), http://news.cnet.com/8301-31921_3-57324779- 281/doj-lying-on-match.com-needs-to-be-a-crime/ (last visited Feb. 3, 2013) (discussing the DOJ’s stance on CFAA violations in the context of popular
INFORMATION PRIVACY AND DATA CONTROL 423
have also examined whether agreeing to an expansive TOS agreement or a broad privacy policy may cause a person to lose a reasonable expectation of privacy.409 As discussed above in Part III.B.2.a, the terms of TOS agreements may also impact the application of the SCA.410
It is very important that consumers read and understand the terms of cloud services’ TOS agreements because of the large amounts of sometimes sensitive information stored with these services.411 Consumers should pay special attention to how the TOS agreements address customer data, including the information that the company claims rights in, and how the consumer can terminate his relationship with the cloud provider.412 Consumers might be storing information solely in the cloud, making it very important for the TOS agreements to
websites such as MySpace and Match.com) (on file with the Washington and Lee Law Review). The Ninth Circuit, however, recently rejected the DOJ’s argument on the reach of the CFAA in United States v. Nosal. See United States v. Nosal, 676 F.3d 854, 863 (9th Cir. 2012) (holding that the language “exceeds authorized access” in the CFAA should be narrowly interpreted and is therefore limited to violations of restrictions on access to information, and not restrictions on its use); Richard Santalesa, Ninth Circuit Narrows Reach of CFAA in En Banc U.S. v. Nosal Decision, INFO. LAW GROUP (Apr. 13, 2012), http://www.infolaw group.com/2012/04/articles/computer-fraud-and-abuse-act-c/ninth-circuit-narrows- reach-of-cfaa-in-en-banc-us-v-nosal-decision/ (last visited Feb. 3, 2013) (discussing the decision in United States v. Nosal) (on file with the Washington and Lee Law Review). 409. See United States v. Warshak, 631 F.3d 266, 287 (6th Cir. 2010) (stating that such protections likely would not apply to content stored with a provider that includes terms in an agreement reserving the right to “audit, inspect, and monitor” e-mail content); Bagley, supra note 295, at 181 (discussing cases examining the Fourth Amendment in the context of Terms of Service agreements). 410. See supra Part III.B.2.a (discussing the Electronic Communications Privacy Act). 411. See Soma, Gates, & Smith, supra note 16, at 534 (examining the “blurred lines” between work and home life that e-technology has created and suggesting that “users must make a good faith effort to read, understand, and ask questions about service provider privacy and terms of use policies”); see also Stylianou, supra note 44, at 593 (noting that such terms attract greater scrutiny because of the large amount of data stored with these providers). 412. See Wittow & Buller, supra note 7, at 7 (asserting that cloud service TOS agreements should address data migration issues to assure business continuity and to protect the customer’s continued access to data after the customer’s relationship with the provider is dissolved).
424 70 WASH. & LEE L. REV. 341 (2013)
include provisions protecting customers’ ability to retrieve their content if, for example, a service is shut down.413
a. TOS Agreements as Contracts of Adhesion
Under the common law of contracts, forming a contract requires mutual assent.414 When a contract is not subject to negotiation and is offered by the more powerful party on a “take it or leave it” basis, the contract is often referred to as a contract of adhesion.415 Privacy policies and TOS agreements typically meet this definition for an adhesion contract.416 Such contracts are not automatically invalid, but they may be subject to greater scrutiny.
Excessively oppressive TOS terms may be invalidated if the court concludes that the terms are unconscionable.417 Unconscionability analysis often has two prongs, and courts evaluate the circumstances for both procedural and substantive unconscionability.418 Courts might be more willing to find
413. This issue has come up recently in the context of the shutdown of Megaupload. Megan Geuss, Megaupload User Asks for His Perfectly Legal Videos Back, ARS TECHNICA (Mar. 21, 2012, 10:10 PM), http://arstechnica.com/tech-policy/news/2012/03/megaupload-user-asks-for-his- perfectly-legal-videos-back.ars (last visited Feb. 3, 2013) (discussing the shutdown of the file-sharing locker Megaupload and the inability of customers to access their legally stored videos) (on file with the Washington and Lee Law Review). 414. See, e.g., 1 RICHARD A. LORD, WILLISTON ON CONTRACTS § 4:1 (4th ed. 2012) (“[M]utual assent is essential to the formation of informal contracts . . . .”). 415. See Nolo’s Plain-English Law Dictionary, NOLO, http://www.nolo.com/dictionary/adhesion-contract-(contract-of-adhesion)- term.html (last visited Feb. 3, 2013) (providing the definition of an adhesion contract) (on file with the Washington and Lee Law Review); see also Bagley, supra note 295, at 183 (“[E]lectronic contracts of adhesion are limiting the private rights of an individual to protect their privacy in services so vital to daily life.”). 416. Solove, Architecture, supra note 172, at 1235 (arguing that the idea that users give informed consent to these terms is a fiction, due to the total lack of negotiation). 417. See Bragg v. Linden Research, Inc., 487 F. Supp. 2d 593, 605 (E.D. Pa. 2007) (finding an arbitration provision to be both procedurally and substantively unconscionable).
418. Id.
INFORMATION PRIVACY AND DATA CONTROL 425
unconscionability when there are no market alternatives, but the diverse reality of the cloud market makes it unlikely that a lack of market alternatives will be a persuasive argument.419
The unequal bargaining power between the provider and its customers means that providers often subject customers to terms that are more favorable to the provider.420 At least one court has looked favorably on a provider prohibiting the use of “bots” with its service,421 and Martin expresses concern that this opens the door for “predatory software vendor[s]” to prohibit customers from using third party software with the vendor’s projects, thereby eliminating beneficial effects of innovation by third parties.422
2. Privacy Policies
Privacy policies and TOS agreements often overlap, though for our purposes we consider privacy policies to be more focused on making the customer aware of the company’s policies regarding their data instead of the customer’s obligations concerning the service. Terms in a provider’s privacy policy might address things like the quantity and nature of collected data and the company’s policies on data retention and customer control over data.423 Privacy policies often also address data security issues, like the use of SSL encryption during data transmission.424 However, many of these providers insert
419. See Bagley, supra note 295, at 179 (discussing the difficulty of demonstrating unconscionability “in the search engine, e-mail, and digital media services market, where there are many companies even though only a few giants dominate”).
420. See supra note 403 and accompanying text. 421. See MDY Indus., LLC v. Blizzard Entm’t, Inc., 629 F.3d 928, 950 (9th Cir. 2010) (finding that the prohibition of the use of “bots” was permitted under the Digital Millennium Copyright Act). 422. Martin, supra note 44, at 312. 423. See Stylianou, supra note 44, at 599, 602 (discussing the quantity and nature of collected data as well as data retention policies and data storage location). 424. See id. at 603 (providing a discussion of data safety, security, and integrity).
426 70 WASH. & LEE L. REV. 341 (2013)
provisions in their privacy policies or TOS agreements that repudiate any liability for data loss, and reserve to the provider the right to discontinue the service at the provider’s sole discretion.425
Privacy policies typically consist of information provided by the service provider about how the provider may gather, use, disclose, and manage the personal information of its customers.426 Privacy policies, like TOS agreements, are often adhesion contracts marked by significant advantages being reserved for the service provider, such as the right to amend its privacy policy unilaterally with little notice to its customers.427 Privacy policies may include broad permissions to allow the provider to access information for its own marketing purposes and to disclose customer information to its business partners for business- related purposes.428 Privacy policies also might not be considered contracts at all, but purely as notices about a company’s policy. However, few consumers actually read a company’s privacy policy, and even fewer understand it.429 Solove criticizes many
425. See id. at 604 (examining Amazon’s, Mozy’s, and Apple’s data protection disclosures). 426. See Cascia, supra note 17, at 888 (“A privacy policy is a legal agreement between the user and the provider that discloses some or all of the ways the provider gathers, uses, discloses and manages a customer’s personal information.”). 427. See SOLOVE, DIGITAL PERSON, supra note 2, at 82–83 (arguing that privacy policies are not a meaningful contract, with no bargaining over terms and containing mostly unreliable, vague promises); Cascia, supra note 17, at 889–90 (discussing Google’s privacy policy and noting that “Google reserves the right to unilaterally amend its privacy policy leaving it essentially meaningless”). Birnhack and Elkin-Koren argue that if such a term is included, user privacy is not being effectively guaranteed by upfront notice and consent. See Birnhack & Elkin-Koren, supra note 108, at 365 (arguing that “if the user agrees upfront to any use of data as detailed by an adjustable privacy policy, the user does not exercise real control over the collection and use of personal data”). 428. See Soma, Gates, & Smith, supra note 16, at 532 (noting that providers often include terms in e-messaging policies and usage agreements permitting the provider to access the systems for “routine monitoring purposes” and to comply with lawful requests by the government or litigants); infra Part V (providing an empirical analysis of agreements and policies in the cloud). 429. See Schwartz & Solove, supra note 3, at 1856 (“[S]tudies have shown that few consumers read privacy policies, and that those who do frequently fail to understand them.”).
INFORMATION PRIVACY AND DATA CONTROL 427
privacy policies as being “written in obtuse prose,” containing large amounts of extraneous information.430
Cloud services collect a lot of data, both through the customer’s voluntary disclosure of data and through the provider’s automatic collection of information through its operations or advertising policy.431 Many privacy policies assure limited use of customer information.432 Some, however, are vague, leaving ambiguities and loopholes. Transparency in privacy policies is very important, and consumers should be informed about how their data will be collected and used.433 In this Article, we posit that reserving explicit rights for consumers to control their data will raise consumer awareness of privacy issues. We anticipate that this raised awareness, combined with the increased control that an individual has over the use of his data, will have a positive effect on the market for cloud services.
a. Sharing Information with the Government
Consumers will often encounter inherent limitations in how much control they can exercise over their data because of common policies permitting the sharing of data with government entities. Privacy policies typically contain provisions reserving to the provider the right to disclose customer information pursuant to lawful government requests.434 Companies like Google and AT&T
430. SOLOVE, DIGITAL PERSON, supra note 2, at 82. 431. See Stylianou, supra note 44, at 599 (examining the quantity and nature of collected data by cloud services). Some companies may also collect information from other sources that pertains to the user indirectly. See id. at 601 (using Microsoft as an example to demonstrate that the practice of indirect data collection is increasing). 432. See id. at 601, 604 (discussing Microsoft’s, IBM’s, and Amazon’s privacy and data protection policies). 433. See Birnhack & Elkin-Koren, supra note 108, at 353 (explaining the importance of user consent to data collection). 434. See Google Privacy Policy, GOOGLE (July 27, 2012), http://www. google.com/policies/privacy/ (noting that Google may share user data for legal reasons) (last visited Feb. 3, 2013) (on file with the Washington and Lee Law Review); see also Soghoian, supra note 5, at 393–94 (citing a public statement by the CEO of Google in which the CEO listed assisting with lawful investigations as being one of the main reasons that Google keeps detailed data of the online
428 70 WASH. & LEE L. REV. 341 (2013)
collect large amounts of personal user data from customers.435 This sort of information was formerly used for marketing and research purposes, but recently the U.S. government has been building national security databases that contain personal user data provided by cooperating telecommunications companies like AT&T.436 Sometimes, providers may voluntarily provide data to government entities to improve the provider’s own security.437
Governments have requested personal user information from various companies for a variety of purposes over the years.438 This is not limited to the United States. For example, the government of the United Kingdom is considering using data obtained by social networking sites for the purpose of monitoring users to prevent terrorism and crime.439 Generally, private companies that turn over information to the government are not considered state actors by doing so.440 Cloud providers sometimes also are required
activity of its customers). 435. See Bagley, supra note 295, at 155–56 (“[T]hird parties such as information service provider, Google, and telecommunication giant, AT&T, amass large amounts of personal user data.”). 436. See id. at 156 (noting that “in recent years the United States government has built national security databases with personal user data allegedly obtained from cooperating telecommunication companies” that has resulted in Fourth Amendment litigation); Soghoian, supra note 5, at 385–86 (discussing wiretaps obtained through telecommunication companies and Internet providers working with law enforcement officers). Bagley cites the wiretapping controversy as an example that did not involve warrants or subpoenas, but instead relied on voluntary agreements with private companies. See Bagley, supra note 295, at 156–57 (criticizing that the “traditional legal process was evaded” in this situation because “private companies did the data gathering and managed the phone calls” and the companies involved waived their Fourth Amendment rights). 437. See Bagley, supra note 295, at 154 (citing the example of Google voluntarily providing data to the NSA). 438. See id. at 161–62 (noting that the government sought user information from airlines after the September 11th attacks and from hotels and car rental agencies in 2003 to thwart terrorist threats against Las Vegas). 439. See id. at 164 (discussing the United Kingdom’s potential plan to use data collected by social networking sites). 440. See id. at 162 (“[P]rivate companies are not restrained as state actors when they voluntarily hand consumer data to the government . . . they are treated as a third party in whom a consumer is placing their trust.”). But see id. at 188 (arguing that there may be entwinement sufficient to find state action if a communication provider assigns employees to work with government agencies
INFORMATION PRIVACY AND DATA CONTROL 429
to comply with certain content laws of other countries, like Skype’s Chinese counterpart that was required to implement a filter to prohibit text messages that included phrases like “Falungong” and “Dalai Lama.”441 There are also some concerns about the U.S. government’s ability to exploit software vulnerabilities or even enable the microphones of cellular phones remotely as part of criminal investigations.442
There are a number of other reasons why government officials might request information. The federal government recently used data associated with customer shopping cards to trace the source of salmonella poisoning.443 The DOJ has also requested search records from companies like Google and Microsoft in the course of its investigation into the effectiveness of child protection legislation.444 However, the court in that case did not compel Google to turn over actual search queries, noting in dicta that there may be an expectation of privacy in such queries.445
In addition to requesting the cooperation of private companies, the government itself has been collecting personal information for many years. Solove notes in his book that there are almost 2,000 databases of personal information maintained
and respond to government requests). 441. Soghoian, supra note 5, at 408. Skype denied allegations that its Chinese software contained a backdoor to allow surveillance by the Chinese government, but it came out in 2008 that when text messages using this software were filtered, the offending message and the identities of the sender and recipient were forwarded to a publicly accessible server in China. See id. at 408–09 (providing a discussion of the TOM-Software). 442. See id. at 400–02 (discussing the FBI’s use of “roving bug” software). 443. See Martin, supra note 44, at 299 (examining use of consumer data by the federal government). 444. See Gonzales v. Google, 234 F.R.D. 674, 679 (N.D. Cal. 2006) (examining a subpoena by the U.S. Attorney General to Google to compile and produce information from the search engine’s index and search queries); Bagley, supra note 295, at 165 (discussing litigation involving subpoenas for online user data). 445. See Gonzales, 234 F.R.D. at 684 (denying the motion to order Google to disclose search queries of its users); Bagley, supra note 295, at 165 (noting that, “[i]n the end, Google was compelled only to generate a list of URLs, rather than actual user search queries”).
430 70 WASH. & LEE L. REV. 341 (2013)
by the federal government.446 Personal information collection as part of the census began in 1790, with the questions becoming more personal until the 1890 census, which included questions about things like diseases, disabilities, and finances.447 The massive databases that are already maintained by the government and over which citizens have no control might appear to threaten any attempts to improve informational privacy. Requiring data control protections in the private sector may seem like a relatively small issue compared to government databases. However, private data held by governments generally do not leave the government’s possession, and thus the circulation of this information is not as problematic as the circulation of information collected in the private sector.
3. Effects of Security Breaches
A major reason that we argue for consumers to be in control of their data is that we think consumers should be empowered to take proactive steps to protect their information. Consumers, in our view, should be free to withdraw their data from a service if they learn of security failings in that service. One of the dangers of insufficient data security for data in the cloud is the risk of identity theft as a result of data breaches.448 According to the Identity Theft Resource Center, in 2009 there were at least 498 publicly reported data breaches, impacting 222 million total
446. SOLOVE, DIGITAL PERSON, supra note 2, at 15. Richards also notes that the government has huge databases of information about citizens. See Richards, supra note 114, at 1156 (discussing the history of personal data collection by the federal government that began as early as the nineteenth century). 447. See SOLOVE, DIGITAL PERSON, supra note 2, at 13 (providing a historical look at the collection of public data by the federal government). The public outcry in response to the intrusiveness of the questions in the 1890 census eventually led to legislation to ensure the confidentiality of census data. See id. (“When the 1890 census included questions about diseases, disabilities, and finances, it sparked a public outcry, ultimately leading to the passage in the early twentieth century of stricter laws protecting the confidentiality of census data.”). 448. See Lanois, supra note 18, at 44 (discussing the increasing amount of “commercial, personal, and even secret data and other sensitive information . . . flowing around the globe in the cloud”).
INFORMATION PRIVACY AND DATA CONTROL 431
records.449 A single data breach of a credit card processing company in 2012 may have resulted in 1.5 million credit card accounts being compromised.450
Identity theft is a federal crime and has been referred to as the most rapidly growing white collar crime,451 though some criticize the law as not being adequately supported by resources or sufficient criminal sentences.452 Approximately half a million people are victims of identity theft every year.453 Twenty-six percent of consumer complaints submitted to the FTC in 2008 concerned identity theft.454
But identity theft is not the only risk related to data breaches.455 Some breaches can involve very personal and embarrassing information, such as when a firm accidentally posted to the Internet the names, addresses, phone numbers, credit card information, and details of the sex lives of ninety psychotherapy patients.456 Sometimes, breaches are due to a serious failing in a company’s procedures. In one instance, Metromail Corporation hired prison inmates to enter personal information into Metromail’s databases, and one inmate started sending sexually explicit letters with information about the recipients’ lives.457 In another more troubling instance, the
449. Wittow & Buller, supra note 7, at 9. 450. Credit Card Data Breach Contained, Says Global Payments, BBC NEWS (Apr. 3, 2012, 5:59 ET), http://www.bbc.co.uk/news/technology-17596394 (last visited Feb. 3, 2013) (on file with the Washington and Lee Law Review). 451. See SOLOVE, DIGITAL PERSON, supra note 2, at 110 (stating that the FTC estimated that 10 million Americans were victims of identity theft in 2003). 452. See Solove, Architecture, supra note 172, at 1248 (noting the problems with viewing identity theft as an exclusively criminal matter).
453. Id. at 1244. 454. Wittow & Buller, supra note 7, at 9.
455. See Solove, Architecture, supra note 172, at 1258 (“With ever more frequency, we are hearing stories about security glitches and other instances of personal data being leaked and abused.”). 456. See id. (providing examples of instances of security breaches of personal information in recent years). 457. See SOLOVE, DIGITAL PERSON, supra note 2, at 53 (discussing “irresponsible and careless uses of personal information”). In another Metromail incident, a reporter contacted Metromail and successfully purchased a list of 5,000 children after giving the name of the buyer as a known child molester and murderer. See id. at 53–54 (illustrating a lack of care and accountability in
432 70 WASH. & LEE L. REV. 341 (2013)
company Docusearch provided a man with information about a woman named Amy Lynn Boyer, which the man then used in finding and murdering Boyer.458
Cloud providers might not bear the risk of loss due to fraud, but companies have many incentives to secure data and prevent security breaches because large-scale breaches often result in negative publicity. Security breaches can destroy consumer confidence and devastate a company’s bottom line.459 However, this decrease in consumer confidence may not effectively incentivize the creation of stronger security protocols if cloud service providers store data in proprietary formats, making it difficult for current customers to leave. Thus, we argue that data control and format transparency could have benefits for security in the cloud by giving providers incentives to keep data secure in order to retain customers.
4. Protecting Consumer Data—Who Watches the Watchers?
Currently, consumers have fairly little control over their data, but there are other entities to help address data security issues. Several private bodies have set standards enabling companies to either seek certification as to the adequacy of their privacy practices, or otherwise measure their own actions against industry standards. These options include SAS 70 certification, which involves audits of firms’ control mechanisms to protect information;460 the Payment Card Industry Data Security
corporate data collection). 458. See Remsburg v. Docusearch, Inc., 816 A.2d 1001, 1009 (N.H. 2003) (finding that Docusearch owed a duty of reasonable care when the company disclosed Boyer’s information to Liam Youens); SOLOVE, DIGITAL PERSON, supra note 2, at 54 (providing the facts of the Docusearch case); Richards & Solove, supra note 1, at 1923 (discussing the holding in Docusearch and noting duty of care issues arising from computer databases). 459. See Rhodes & Kunis, supra note 23, at 26 (“A security breach affecting a corporation can destroy consumer confidence and be devastating to the bottom line.”). There was recently a breach at Heartland Security, leading to a loss of 130 million credit card numbers. Id. at 45. Heartland has suffered major financial damages since the breach, including a $60 million settlement with Visa over the breach. Id.
460. See SAS 70 Overview, SAS 70, http://sas70.com/sas70_overview.html
INFORMATION PRIVACY AND DATA CONTROL 433
Standard, which created IT guidelines for the credit card industry aimed at reducing the risk of a security breach;461 and the Financial Industry Regulatory Authority (FINRA), which requires members to have policies and procedures addressing customer record safety, protecting against unauthorized access, and protecting against relevant anticipated threats.462 Companies on the Web may also seek TRUSTe certification for their privacy practices.463 These organizations are elements of the self- regulatory framework that U.S. businesses currently use with regard to privacy. However, these certification authorities are largely sector-specific, and thus we recommend broader protections that do not rely on sector-specific self-regulatory bodies.
When the sector-specific self-regulatory framework fails, there are sometimes other private solutions available. Customers may, for example, sue companies in the event of a database security breach, though courts disagree about whether a customer has standing based on a mere risk of future identity
(last visited Feb. 3, 2013) (providing an overview of the standards) (on file with the Washington and Lee Law Review); see also Martin, supra note 44, at 297 (“[P]ublic companies that fail to obtain SAS 70 qualification by adhering to certain procedures and controls can easily lose the confidence of investors and customers.”). 461. See PCI SSC Data Security Standards Overview, PCI SEC. STANDARDS COUNCIL, https://www.pcisecuritystandards.org/security_standards/ (last visited Feb. 3, 2013) (providing an overview of the “comprehensive standards and supporting materials to enhance payment card data security”) (on file with the Washington and Lee Law Review); see also Rhodes & Kunis, supra note 23, at 44 (discussing the PCI DSS guidelines). Rhodes and Kunis note that there is a lack of direct enforcement of the PCI DSS, but argue that companies have incentive to enact the standards on their own. See id. at 45 (discussing the financial incentive to enact standards with the example of a breach at Heartland Security that resulted in a $60 million settlement with Visa). 462. See About the Financial Industry Regulatory Authority, FINRA, http:// www.finra.org/AboutFINRA/ (last visited Feb. 3, 2013) (providing FINRA’s mission and message statement) (on file with the Washington and Lee Law Review); see also Rhodes & Kunis, supra note 23, at 46 (providing background on FINRA). 463. See Protecting Consumer Information Online, TRUSTE, http://www. truste.com/why_TRUSTe_privacy_services/privacy_best_practices (last visited Feb. 3, 2013) (providing examples of the best privacy practices that businesses can utilize to build trust with their customers) (on file with the Washington and Lee Law Review).
434 70 WASH. & LEE L. REV. 341 (2013)
theft or if standing requires actual identity theft to have occurred.464 There are also other organizations that focus on online consumer protection issues, including the Electronic Privacy Information Center (EPIC) and Digital Due Process (DDP). These organizations are more policy-oriented and may do things like filing privacy-oriented amicus briefs in relevant litigation.
In terms of government intervention, the FTC has also become involved with personal data security and other privacy issues, using its authority to challenge unfair or deceptive practices.465 The first FTC action that primarily concerned a company’s data security practices was in 2004 against BJ’s Wholesale Club after hundreds of instances of identity theft arose due to BJ’s data security failings.466 An advantage to FTC involvement over private litigation by consumers is the ability of the FTC to bring an action against a company in the absence of identity theft. For example, the FTC fined Choicepoint in 2006 after a breach resulted in 163,000 private financial records being compromised, citing Choicepoint’s privacy policy as containing “inaccurate and misleading assertions about its security procedures.”467 The FTC may also bring an action when a company fails to adequately secure its data, even if there has not
464. See Jonathon J. Darrow & Stephen D. Lichtenstein, “Do You Really Need My Social Security Number?”: Data Collection Practices in the Digital Age, 10 N.C. J. L. & TECH. 1, 30 (2008) (discussing the issue of standing in consumer data breach cases). 465. See Rhodes & Kunis, supra note 23, at 36 (discussing the FTC’s jurisdiction and enforcement authority); Wittow & Buller, supra note 7, at 9 (noting that, as of the time of the authors’ writing, the FTC had filed twenty- seven enforcement actions concerning the data security practices of companies). The FTC requires companies to institute “reasonable safeguards” to protect information, and what is “reasonable” depends on factors like how sensitive the data is and how costly it would be for the company to avoid potential risks. See Rhodes & Kunis, supra note 23, at 36 (discussing the “reasonableness” standard applied by the FTC beginning in 2006 to bolster the enforcement of data security risks). 466. See Rhodes & Kunis, supra note 23, at 37 (noting the FTC’s conclusion that the security failings amounted to an unfair practice in violation of federal law).
467. Id.
INFORMATION PRIVACY AND DATA CONTROL 435
actually been a data breach.468 The FTC could also potentially bring an action against a business that uses deceptive practices to obtain information.469
As an alternative to extending current regulations to new data issues in the cloud, some argue that the FTC and its current authorities could be used to enforce a company’s privacy policy against it.470 However, after examining a number of privacy policies, we argue that this approach would not be wise given the reality that many companies adopt vague privacy policy language regarding the company’s own obligations.471 It is also unclear whether the FTC would be the appropriate regulatory body in all instances because the FTC usually regulates e-commerce issues, but providers whose services count as telecommunications or information services would also be governed by FCC regulations.472 We also assert that relying on government
468. See Schwartz & Solove, supra note 3, at 1856–57 (“[T]he [FTC] has taken actions against companies that fail to provide adequate data security . . . even in the absence of a data breach, though more typically it acts only once a data spill has occurred.”). The FTC also settled an enforcement action against Sears in 2009, based on Sears’s practice of tracking customers without adequately disclosing details of the tracking program to the customers, and another action against EchoMetrix in 2010 concerning parental control software that also provided information to marketers about children’s computer activity. See id. at 1858 (discussing the “more substantive approach to disclosure of company behaviors” taken by the FTC in enforcement actions). 469. See Richards, supra note 114, at 1185 (“The use of fraud or other deceptive practices in obtaining consumer data could also constitute a violation of the Uniform Deceptive Trade Practices Act (UDTPA), and would fall within the powers of the Federal Trade Commission (FTC) to deter and punish unfair trade practices . . . .”). 470. See SOLOVE, DIGITAL PERSON, supra note 2, at 72 (noting that the FTC has recently brought actions for “unfair or deceptive acts or practices” against companies that violate their own privacy policies); McCarthy, supra note 95, at 2260 (discussing the possibility of enforcing PHR vendors’ privacy policies against them). McCarthy argues, however, that HIPAA would be a stronger way to address privacy issues with personal health records. See id. at 2261 (contrasting HIPAA and the FTC by stating that “HIPAA mandates that covered entities take constant concern over privacy and security by continually auditing, monitoring, and augmenting security when necessary”). 471. See infra Part V.C (providing an analysis of and statistical information on privacy policies). 472. See Soma, Gates, & Smith, supra note 16, at 490–91 (suggesting the possibility of a joint rulemaking between the FTC and FCC to address these issues).
436 70 WASH. & LEE L. REV. 341 (2013)
agencies to address the failure of companies to give consumers meaningful control over their data would be ineffectual because the most likely approach would be through adjudication, in which individual consumers would not be clearly represented, in an adjudicatory process that by definition would only address problems on an ad hoc basis. On this point, we argue that regulating this behavior in advance would be more beneficial to consumers than case-by-case adjudication.
5. Tracking Technologies and Behavioral Marketing
Another element of privacy policies that is relevant to the issue of data control is the use of technologies to track consumer behavior. Privacy policies typically address the tracking technologies that a website uses for advertising or other purposes. When tracking users, advertisers may use technologies like cookies, flash cookies, and Web beacons. The degree to which companies disclose the use of these tracking technologies varies.473 The information collected using these tracking technologies can then be used by companies to profile consumers.474 Consumers typically have the option to decline some tracking technologies, often by adjusting the settings of their Web browsers to decline all cookies. However, we suggest that this option does not represent a meaningful exercise of
473. See Birnhack & Elkin-Koren, supra note 108, at 372 (providing data comparing actual privacy practices to declared privacy practices of numerous websites); Lanois, supra note 18, at 34 (referencing a study that found that the top fifty websites installed, on average, sixty-four pieces of tracking technology when a visitor loaded the site, and usually did not provide a warning that they were doing so). 474. See Richards, supra note 114, at 1157 (discussing the “profiling industry” and noting that the profiles may include “a person’s social security number, shopping preferences, health information . . . financial information, race, weight, clothing size, arrest record, lifestyle preferences, hobbies, religion, reading preferences, homeownership, charitable contributions, mail order purchases and type, and pet ownership”); see also SOLOVE, DIGITAL PERSON, supra note 2, at 50 (noting private companies’ recent use of information to categorize people as either angel customers or demon customers, and the practices of some banks to deny credit card applications from college students majoring in liberal arts).
INFORMATION PRIVACY AND DATA CONTROL 437
control because many websites require cookies to be enabled for website functionality.
A cookie is a text file that is downloaded to a user’s computer when she accesses a website, and it acts as an identifier for the computer on which it is stored.475 Cookies by themselves do not contain a user’s personal information under most definitions of the term,476 but a company called DoubleClick provides a service to websites, connecting cookies to personal information to enable more targeted advertising.477 Flash cookies have a similar effect to text cookies, but some flash cookies may be able to reconstruct previously deleted browser cookies and cannot be controlled by the user.478 Recent research revealed that out of the one hundred most popular websites, fifty-four used flash cookies, but only four sites mentioned the use of flash cookies in their privacy policies.479 Web beacons, the third type of tracking technology noted above, permit the advertiser to observe a user’s website activity in real time.480
Behavioral marketing is advertising that is targeted at individuals based on their past behavior patterns.481 The environment of behavioral marketing has developed substantially
475. See SOLOVE, DIGITAL PERSON, supra note 2, at 24 (referring to cookies as “a form of high-tech cattle-branding”); Lanois, supra note 18, at 33 (explaining how cookies work and why they are useful for both advertising and consumers). 476. However, because cookies typically collect a user’s IP address, this is sufficient to find that cookies collect “personal data” for purposes of the EU’s Data Protection Directive. See Lanois, supra note 18, at 41 (“In practice, almost all cookies involve the processing of personal data because even if the user’s real identity remains anonymous, cookies typically involve the collection of the user’s IP address, the processing of unique identifiers, or both which are personal data within the scope of the Data Protection Directive.”). 477. See SOLOVE, DIGITAL PERSON, supra note 2, at 24–25 (explaining how DoubleClick functions). 478. See Lanois, supra note 18, at 35 (discussing a lawsuit that involved the distinction between flash cookies and traditional cookies).
479. Id. at 36. 480. See Schwartz & Solove, supra note 3, at 1851 (“Some technology, particularly the beacon, or ‘Web bug,’ permits real-time observation of a user’s activity on an Internet page, including where one’s mouse moved and the information that one typed, such as search queries or personal information that an individual filled into a form.”).
481. See id. at 1849 (introducing the concept of behavioral marketing).
438 70 WASH. & LEE L. REV. 341 (2013)
over the last century, becoming more effective as marketers have gained access to more detailed information.482 Behavioral marketing has led to advertisers buying access to individuals who match a particular consumer profile.483 There is a market for consumer data that is collected and can be used for targeting advertisements, with information about an individual’s browsing habits selling for a fraction of a cent on the data exchange.484
Because declining all cookies would likely lessen a user’s Web browsing experience, researchers have worked to develop a technology that focuses on collection by third parties, like third- party advertisers that collect data for behavioral advertising. Concerns over such data collection and the possible privacy implications thereof have led to calls for a “Do Not Track” (DNT) standard, similar to a “Do Not Call” registry, that would allow users to opt out of tracking by third parties.485 Mozilla’s Firefox already includes DNT capabilities.486 Additionally, Microsoft made DNT the default setting for Internet Explorer 10, and Google announced that Google Chrome would have DNT capabilities by the end of 2012.487
482. See SOLOVE, DIGITAL PERSON, supra note 2, at 19 (noting that direct mail has a yield-per-cost ratio double that of television advertisements). 483. See Lanois, supra note 18, at 34 (noting that user profiles are bought and sold on exchanges that resemble the stock market); Schwartz & Solove, supra note 3, at 1851 (“Marketers draw on extensive databases . . . . They are able to cross-reference online activity with offline records including home ownership, family income, marital status, zip code, and a host of other information, such as one’s recent purchases as well as favorite restaurants, movies, and TV shows.”). 484. See Richards, supra note 114, at 1157–58 (noting that in some places, consumer profiles can be bought for $65 for a thousand names); Schwartz & Solove, supra note 3, at 1852 (explaining that browsing information sells for as little as a tenth of a cent but that it adds up to a billion-dollar industry). 485. See Do Not Track, Universal Web Tracking Opt Out, http://donottrack.us/ (last visited Feb. 3, 2013) (providing an overview of the “Do Not Track” policy proposal) (on file with the Washington and Lee Law Review). 486. See Do Not Track, MOZILLA FIREFOX, http://www.mozilla.org/en-US/dnt/ (last visited Feb. 3, 2013) (providing answers to frequently asked questions about the “Do Not Track” preference) (on file with the Washington and Lee Law Review). 487. See Kate Solomon, Chrome Adds Do Not Track, Rolling Out by End of the Year, TECHRADAR (Sept. 24, 2012), http://www.techradar.com/news/internet/ web/chrome-adds-do-not-track-rolling-out-by-end-of-the-year-1099241 (last
INFORMATION PRIVACY AND DATA CONTROL 439
Modern consumers are often uneasy about the pervasiveness of behavioral advertising,488 and some research questions the ultimate value of targeted advertising.489 However, there is currently not much recourse available to consumers whose data is mined. The privacy torts typically require an invasion to be of an offensive nature, but most of the time, information collection is of largely innocuous information.490 For these reasons, one of our proposals relevant to data control focuses on the possibility of withdrawing data that was mined using these technologies. A DNT system, as described above, may also assist with limiting future unauthorized collection, provided that most websites eventually adopt it. At the time of this writing, however, many websites and advertisers have not adopted a DNT-friendly implementation.491 Even if the market solutions become more viable, our proposed data withdrawal and data portability rights are designed to inform and empower consumers, enabling more meaningful participation in the vigorous market for cloud services. In our view, such rights would be complementary to, and not supplanted by, an effective opt-out DNT regime.
visited Feb. 3, 2013) (explaining the DNT option that will be added to the Google Chrome browser) (on file with the Washington and Lee Law Review). 488. See Schwartz & Solove, supra note 3, at 1854 (suggesting that consumer objections to behavioral advertising should be addressed through policy). 489. Aleecia M. McDonald & Lori Faith Cranor, The Cost of Reading Privacy Policies, 4 J.L. & POL’Y INFO. SOC’Y 540, 541 (2008) (concluding that targeted advertising “may have negative social utility” after taking into account the opportunity costs required if everyone read and understood privacy policies). 490. See Richards & Solove, supra note 1, at 1919 (citing Shibley v. Time, Inc. for its holding that disclosure of subscriber information did not meet the requirements of causing “mental suffering, shame or humiliation to a person of ordinary sensibilities.” (citing Shibley v. Time, Inc., 341 N.E.2d 337 (Ct. App. Ohio 1975))). 491. See Solomon, supra note 487 (“The main problem with DNT, though, is that not all that many websites and advertisers actually abide by it, since it’s more of a guideline than an actual rule.”). In fact, some critics say that DNT simply does not work and, in addition, that advertisers are adopting an interpretation of DNT that is contrary to the intent of those promoting DNT. See Ed Bott, Why Do Not Track is Worse Than a Miserable Failure, ZDNET (Sept. 21, 2012, 12:35 GMT), http://www.zdnet.com/why-do-not-track-is-worse-than-a- miserable-failure-7000004634/ (last visited Feb. 3, 2013) (criticizing DNT and arguing that it does not work) (on file with the Washington and Lee Law Review).
440 70 WASH. & LEE L. REV. 341 (2013)
6. Personally Identifiable Information and “Anonymous” Information
The final concept that we will address in the context of privacy policies is the treatment of certain types of information. Arguments about the degree of protection to which information is entitled often turn on the type of information being protected. In the context of information privacy, the focus is often on personally identifiable information (PII), and on information that is considered sensitive. Computer use in the 1960s led to PII becoming more of an issue because companies and government entities were processing a lot of personal data.492 PII is a term that is often used to describe information that is clearly connected to a specific person, though there is no uniform definition of the term.493 Service providers often focus on assuring customers that their PII will be kept safe.
Regulatory intervention is often focused on protecting PII, in part because of the threats posed by identity thieves. Statutes define PII in several different ways. Some define PII as information that is personally identifiable, some define PII as information that is not public, and some define it by providing specific examples of information that is PII.494 With PII, the question is often whether information is identified or identifiable, which respectively refers to whether information immediately connects to an identified person or can be used to lead to an identified person, given more information.495 In the United States, the concept of PII is largely limited to identified data, whereas the European Union takes an expansionist view of PII that treats identified data the same as data that is only identifiable.496 Schwartz and Solove argue that the European
492. See Schwartz & Solove, supra note 3, at 1820 (explaining why the PII became an issue in the 1960s). 493. See id. at 1816 (“Given PII’s importance, it is surprising that information privacy law in the United States lacks a uniform definition of the term.”).
494. See id. at 1828 (identifying the competing definitions of PII). 495. See id. at 1817 (setting forth a “PII 2.0” model that proposes “two categories of PII, ‘identified’ and ‘identifiable’ data,” and treats them differently).
496. See id. (comparing the United States and European models); see also id.
INFORMATION PRIVACY AND DATA CONTROL 441
Union’s expansionist approach is more consistent with the technology than a reductionist approach that limits PII protections to identified personal data.497
The idea of categorizing information as PII, however, has become more problematic over the years. The line between identified and identifiable has become increasingly blurred, as has the line between sensitive and nonsensitive. A social security number is generally viewed as very sensitive information, but date of birth may be considered less so. However, computer science has shown that a person’s social security number can be estimated to some degree of accuracy if one knows the person’s date of birth and the city in which they were born.498 If a database contains a very large amount of nonsensitive information, the aggregation of the information can track a person’s whole existence.499 A person’s search queries are an example of seemingly anonymous information that could nonetheless lead to an identifiable person, especially considering common behaviors like searching for local businesses, information on particular medical diagnoses, and vanity searches when an individual will often search for her own name to see what results emerge.500
at 1875 (noting that Canada takes a similar approach to that of the European Union). 497. See id. at 1875 (“The European Union’s expansionist approach to PII is more in tune with technology than is the United States’ reductionist approach.”). 498. See id. at 1846 (citing a recent study by Alessandro Acquisti and Ralph Gross). 499. See Bagley, supra note 295, at 164 (“The synthesis of data from a user’s web search history coupled with email, photos, documents, voicemails, phone logs, and location, creates a profile of an individual that serves as behavior modeling for advertisers. This same data could just as easily be disclosed to law enforcement officials for criminal profiling.”); see also Richards, supra note 114, at 1158 (acknowledging the privacy concern that “uber-databases can be created, composed of nonsensitive information in such enormous quantities that the database constitutes a highly detailed dossier of a person’s entire existence”). 500. See Paul Ohm, Broken Promises of Privacy: Responding to the Surprising Failure of Anonymization, 57 UCLA L. REV. 1701, 1717–18 (2010) (providing an example of AOL search queries being used to identify individuals); Schwartz & Solove, supra note 3, at 1848 (explaining that “if the user has engaged in a highly specific search, or multiple searches, she becomes more
460 70 WASH. & LEE L. REV. 341 (2013)
VI. Recommendations—Building a Baseline for Facilitating Transactions in the Cloud
In the United States, privacy is largely protected using narrow laws that apply only to specific categories of information. To the extent that laws of general applicability apply to privacy in the cloud, like the Fourth Amendment and the SCA, customers may inadvertently remove their own privacy protections by agreeing to excessively broad terms in a cloud service’s privacy policy. Even though the FTC has brought actions against companies that violate their own privacy policies, these actions arguably serve only to give the providers incentives to write privacy policies that are as vague about the providers’ obligations as possible.
After examining the privacy policies and TOS agreements in our sample and analyzing a variety of legal issues and privacy theories, we have arrived at a series of recommendations to what we see as the failure of the contractarian paradigm to adequately protect parties that indicate agreement with these terms. We recommend a new legal regime that would emphasize empowering consumers by setting a baseline of protection to ensure that a consumer has control over her own data. The baseline would be designed to protect the most sensitive information without hindering market development.
A. Building the Baseline
One of our foundational arguments is that relatively modest regulatory intervention into the relationship between providers
Section on an empirical review of Privacy Policies and TOS agreements removed. The full article is available on the Moodle.
INFORMATION PRIVACY AND DATA CONTROL 461
and consumers could support positive social change with regard to privacy protections. To some extent, legal regulations can provide structure for social interactions, and the strength of the legal control can affect perceptions of social control and personal freedom.519 Regulating privacy would involve the regulation of relationships, perhaps by placing limits on organizational power.520
When implementing a legislative system to address problems, policy makers can either choose to implement rules, which tend to focus on strict requirements, or standards, which tend to be more flexible and open-ended. In regulating technologies, standards may be superior to rules because standards are more adaptable to further technological change.521 Detailed and inflexible sets of rules can either chill technological development, or in the alternative can quickly become obsolete if the progress of technology continues unimpeded.522 On the other hand, if the implemented regulations are too open-ended and vague, they can end up being entirely ineffective.523 A study by Birnhack and Elkin-Koren questions the very idea that regulation of personal data collection and use would be effective at all.524 While we do not suggest specific language for regulations
519. See Solove, Architecture, supra note 172, at 1240–41 (explaining his use of the term “architecture” to describe the protection or diminishing of privacy in our society). 520. See id. at 1242 (“Protecting privacy thus depends upon regulating relationships, often by enforcing limits on the power of bureaucratic organizations.”). 521. See Schwartz & Solove, supra note 3, at 1871–72 (describing how “standards are generally the superior choice for dealing with situations of rapid change because . . . rules can become obsolete”). 522. See Solove, Architecture, supra note 172, at 1275 (summarizing research that shows how regulations, “if too specific, can quickly become obsolete, discourage innovation, and be costly and inefficient”). 523. See id. (“However, rules that are too open-ended and vague can end up being toothless. Although security standards must not be overly specific, they must contain meaningful minimum requirements.”). 524. See Birnhack & Elkin-Koren, supra note 108, at 343 (noting a low level of compliance with information privacy laws across several categories of websites in Israel). The authors noted that popular websites were more likely to comply with the privacy protection laws, perhaps because popular websites were likely to be maintained by organizations with the resources to have legal departments, and perhaps because complying with the law also serves as a
462 70 WASH. & LEE L. REV. 341 (2013)
in this Article, we encourage policy makers to construct a regime that strikes a balance between rules and standards to make the new data protection regime specific enough to address discrete problems and open-ended enough to allow it to evolve.
1. Baseline Regulation
We recommend a regime that includes baseline privacy protections that would set a floor for the permissible approaches of companies that handle consumer information. The variation in the approaches taken by companies in our relatively small sample underscores the need for more uniformity.
Many questions exist about the appropriate levels of baseline protections, posing interesting questions for future research. Baseline regulations should first identify minimum requirements in order to protect certain types of sensitive information. Such regulations should explicitly address the protection of personal health information, social security numbers, and financial information like bank account numbers and credit cards. The baseline regulation could also include a provision that places the risk of loss for online fraud on a cloud provider.525 Opponents of our approach may point to the results of the Birnhack and Elkin- Koren study, an empirical study of Israeli websites that suggests that regulations setting a baseline for privacy agreements are not truly effective due to low compliance rates.526 But the authors of that study failed to focus on enforcement, and more effective enforcement would likely improve the efficacy of such regulations.
After establishing categories of sensitive information that must receive special protection, the next question concerns what minimum requirements should be included to protect consumer information. Baseline regulations might, for example, include
signal to consumers that the company is more reliable. See id. 525. See Soghoian, supra note 5, at 378–79 (noting that cloud computing providers do not have the same incentive as banks and online merchants to protect customers from online fraud because the banks and online retailers legally bear the risk of loss instead of the consumer). 526. See Birnhack & Elkin-Koren, supra note 108, at 383 (describing how the authors “found that some areas of the law are simply irrelevant in the daily practices of websites”).
INFORMATION PRIVACY AND DATA CONTROL 463
requirements for data security. End users are generally ignorant of many data protection issues, so there is not sufficient market demand for firms to pay more attention to security issues like the need to encrypt information.527 This could be addressed using regulations that require data to be encrypted.528 We envision two primary options for security baseline regulation: language requiring the use of “best available security technology,” or language requiring the use of “industry standard security technology.” The comparison of these two options is another possible direction for future research.
We further suggest that baseline regulations should also address issues related to data breaches. First, the regulation should include security breach notification requirements in order to give users the information necessary to assess the negative consequences of a cloud vendor’s security failures.529 Second, there should be viable private causes of action for data breaches to address the current problem of consumers not having standing to sue a company after a breach in the absence of a distinct injury like identity theft. Some scholars have suggested finding companies strictly liable for data leaks,530 creating a new common law tort based on the use of Fair Information Practices,531 and
527. See Soghoian, supra note 5, at 380 (stating that many consumers know very little about data encryption and describing how this provides “no incentive to [devote resources] to something for which most customers have not expressed a want”). 528. See id. at 382–83 (proposing that government regulators require cloud service providers to use encryption just as this has already been done in the banking and health industries). 529. Martin suggests a similar approach. See Martin, supra note 44, at 313 (“Congress should create new breach notification requirements that allow users to assess the exposure, damage, and operational costs of any security failures on the part of a cloud vendor.”). 530. See Danielle Keats Citron, Reservoirs of Danger: The Evolution of Public and Private Law at the Dawn of the Information Age, 80 S. CAL. L. REV. 241, 245 (2007) (suggesting “a Rylands strict-liability model to address the hazards of leaking databases”). 531. See Sarah Ludington, Reining in the Data Traders: A Tort for the Misuse of Personal Information, 66 MD. L. REV. 140, 140 (2006) (suggesting “a new common law tort . . . to force reform and accountability . . . and to provide remedies for individuals who have suffered harm to their core privacy interests” and stating that this tort “borrows from . . . the Fair Information Practices from the Privacy Act of 1974”).
464 70 WASH. & LEE L. REV. 341 (2013)
imposing liability for breach of trust if a company misuses information.532 Imposing fiduciary obligations in some circumstances may also provide adequate private causes of action in response to security breaches. It is possible that some of the issues relating to information privacy could be resolved through the common law, such as if privacy tort law were expanded to take intangible harms into account, including the harm from the disclosure of data that is not embarrassing.533 We argue that an emphasis on private enforcement options would preserve the viability of the market by limiting excessive legislative oversight of business practices.
B. Data Control
The most important part of our proposal for a new legal regime that sets a floor for the use of data by private companies concerns data control, which we have defined in this Article as encompassing the ideas of data mobility and data withdrawal. In the cloud context, there are two sets of information that we are concerned about: PII, and what we call “course-of-business” data that is stored as part of the customer’s use of the service. Related to the use of PII, we are also concerned about secondary use of such information, including secondary use by third parties. We further argue that data mobility and data withdrawal provisions as described below would attract consumers who are more risk averse and who would not use these services in the absence of these protections, thus leading to a net benefit to the industry.
532. See Jessica Litman, Information Privacy/Information Property, 52 STAN. L. REV. 1283, 1288 (2000) (“[A] rubric based loosely on breach of confidence might persuade courts to recognize at least limited data privacy rights.”). 533. See Richards & Solove, supra note 1, at 1922–23
Courts can readily understand the harm caused by the disclosure of a naked photograph of a person, but they struggle in locating a harm when non-embarrassing data is disclosed or leaked. A broader understanding of harm is needed in order for the privacy torts to apply to the extensive gathering, dissemination, and use of information by various businesses and organizations.
INFORMATION PRIVACY AND DATA CONTROL 465
Thus, these provisions should be mandatory, and the regulations should prevent parties from contracting around these terms.
1. Personally Identifiable Information
Baseline privacy regulations should protect the ability of consumers to control the use of their PII in the cloud. The security of PII should be paramount to prevent fraud and identity theft. This part of our recommendation is by no means revolutionary, however, because privacy policies are centered on protection of PII, and most privacy theorists focus on PII as the class of information that must be afforded the most protection.
We also encourage discussions of PII to consider the commodification of data. If consumers are free to use their PII as a form of currency, disclosing it to obtain desired services, should there be limits on what information consumers can trade? If privacy is viewed as property, and property itself is really a bundle of rights, there may be some types of information where it would be against the best interest of society to permit the free trade thereof. For example, the relationship between doctors and patients is typically viewed as sacrosanct. We thus suggest that personal health information is one category of information that service providers outside this circle would not be able to seek under our proposed legal regime.
The problem of reidentification raises additional issues because it can lead to anonymized, descriptive information about the consumer being reattached to the consumer’s identity. While we would not recommend a regime that stifles innovation and academic creativity, a legal regime to protect PII in the cloud also needs some forward-looking provisions addressing the possibility that reidentification science could lead to threats to personal privacy in the future. These provisions, for example, might prohibit the use of public records for reidentification purposes unless the user certifies compliance with some form of privacy standard.
466 70 WASH. & LEE L. REV. 341 (2013)
2. Secondary Use
Secondary use of PII is another very important consideration. Those who argue for limitations on secondary use suggest that the use of data should be limited to the purpose for which it was initially collected, absent further consent being obtained.534 Existing rules prohibiting secondary use include legal ethics rules that prohibit a lawyer from using client information for a purpose unrelated to the interests of the client, and restrictions in the Fair Credit Reporting Act that prohibit an employer who obtains an employee’s credit report from using this information for nonemployment purposes.535
Once PII is properly collected, we suggest imposing further limits on secondary use of the PII. One option is to give the consumer the ability to restrict secondary use of her PII. Privacy policies often give the customer the ability to access and amend PII stored on the collecting company’s system, so requiring these provisions to address secondary use would likely not be excessively burdensome.
However, privacy policies do not give consumers control over PII given to third parties unconnected to the consumer. To address this third-party problem, the baseline regime should guarantee consumers a right of data withdrawal. By permitting data withdrawal when a consumer’s information is being used in a way that goes against the wishes of the consumer, we secure the right of consumers to control their data and feel more secure.536 To solidify this data withdrawal right, we recommend
534. See Richards, supra note 114, at 1190 (defining secondary use prohibitions as “the requirement that data collected for one purpose may be used for that purpose only, absent consent”); Solove, Taxonomy, supra note 111, at 521 (“‘Secondary use’ is the use of data for purposes unrelated to the purposes for which the data was initially collected without the data subject’s consent.”). 535. See Richards, supra note 114, at 1190–91. However, Solove argues that the restrictions in the Fair Credit Reporting Act do not adequately restrict secondary uses of covered information. See SOLOVE, DIGITAL PERSON, supra note 2, at 67–68 (describing how effective lobbying by the credit reporting industry led to an exemption for “names, addresses, former addresses, telephone number, SSN, employment information, and birthdate”). 536. Our proposed right of data withdrawal is ideologically similar to the proposed “right to be forgotten” in European privacy law, which is supported by the European Commission, though many worry that a right to be forgotten is
INFORMATION PRIVACY AND DATA CONTROL 467
giving consumers the ability to serve a notice-and-takedown order on third parties to require the removal of the consumer’s PII from the third party’s system. We recognize that consumers may have difficulty obtaining information about the secondary use of their PII, but argue that combining a notice-and-takedown regime with controls to enable meaningful informed choices could potentially address some of the problems relating to the secondary use of PII by third parties. Designing controls to enable meaningful informed choices is outside the scope of this Article, but it is an important and related issue that should be the subject of further study.
Under a regime allowing for notice and takedown of PII, a party who wants his PII removed from a specific service could contact the operator of that service to (1) assert his rights in the PII, and (2) request that the PII be taken down. At that time, the operator would have to comply and notify the original submitter of the information about the takedown. The original submitter would then have an opportunity to contest the takedown and assert that the PII was not wrongfully made available. This proposal of a notice-and-takedown approach is patterned after the procedures of the Digital Millennium Copyright Act (DMCA),537 which permits copyright owners to serve a notice on a website when infringing material has been posted.538 Our notice-and- takedown proposal would permit consumers to request that entities take down information that was either posted by the consumer and then republished elsewhere, or that was derived from information posted by the consumer. The notice and
impossible to enforce. See European Comm’n, Commission Welcomes European Parliament Rapporteurs’ Support for Strong EU Data Protection Rules (Jan. 8, 2013), http://ec.europa.eu/commission_2010-2014/reding/pdf/m13_4_en.pdf (last visited Feb. 3, 2013) (on file with the Washington and Lee Law Review). Our proposed model for a right of data withdrawal, however, operationalizes this difficult concept by drawing from the notice-and-takedown procedures of the Digital Millennium Copyright Act (DMCA). 537. See Digital Millennium Copyright Act, Pub. L. No. 105-304, 112 Stat. 2860 (1998) (codified as amended in scattered sections of 17 U.S.C.). 538. See 17 U.S.C. § 512(c)(3) (2006) (establishing a “notice and takedown” procedure to handle allegations that content on a host website infringes an owner’s copyright).
468 70 WASH. & LEE L. REV. 341 (2013)
takedown approach could apply to secondary use by the original entity entrusted with the information, as well as to third parties.
Another option we suggest is for the baseline regulation to declare that some information, like personal health information, should never be tradable. Thus, someone within the necessary circle encompassing the doctor–patient relationship would not be able to trade health information, even if it is anonymized, to marketers seeking to create profiles based on health needs. If some information is not tradable but others are, this can still leave room for many different business models to survive, as long as a minimum level of privacy and security are provided.
3. Course-of-Business Data
Recommendations about PII are very common in the privacy literature, but the information disclosed to cloud providers goes far beyond PII. One of the elements that we think deserves more discussion is the control of what we call “course-of-business” data, which consumers store with cloud providers as part of the service. Many cloud services permit customers to store photos, writings, and business data in the cloud. The storage of this information is often the customer’s purpose for using this service to begin with, whereas the transfer of PII is typically incidental to the rendering of service. Because the storage of this information is essential to the service, the terms relating to such storage should be explicit as a condition of the contract between the parties.
In Part II, we noted that many private actors have called for improved transparency and control in the cloud. In the cloud context, the question of data control does not only involve targeted advertising, but also the importance of data mobility so that customers would not lose everything if a service provider became inoperable or if the data had to be moved to a new service provider.539 However, as our analysis of TOS agreements and privacy policies showed, companies often do not address the handling of such data after the contract has terminated.
539. Martin, supra note 44, at 286 (“Any solution needs to incorporate guarantees that data owners would be able to gain control of their data in a usable form should their service providers become inoperable.”).
INFORMATION PRIVACY AND DATA CONTROL 469
Above we emphasized the data withdrawal aspect of data control. The right of withdrawal may have less application to course-of-business data like writings and photos because such data may be protected by intellectual property law (IP law), and therefore a right of withdrawal may be duplicative of IP law protection. However, for course-of-business data entitled to lesser IP law protection, like databases, the right of withdrawal via notice and takedown should be available.
More importantly, the baseline regulations must require a minimum level of protection to ensure data mobility. This means that data must be converted to an acceptable format before being delivered to a departing customer, such that the customer is not locked in to a particular service provider, and could easily move their data from one provider to another. Data mobility focuses on the access and consumer choice aspects of data control and would facilitate market transactions by enabling customers to move their data freely between competing services. What happens if the customer decides for any reason that she wants to use the cloud services of a competing provider? Is a user’s course-of- business data stored in a proprietary format such that the user encounters a “lock-in” problem if she decides she wants to change providers? Currently, privacy policies and TOS agreements often may not address these issues at all. As part of the legal regime that we propose, format transparency would be required, and providers would also be required to include terms addressing end- of-relationship handling of course-of-business data. Under our proposed regime, a company could still store the data in a proprietary format, but would be required to convert the data to a generally accepted format upon account termination to enable the data to be easily moved to a competing service.
Data mobility is important because it allows consumers to more fully participate in the features and services that cloud providers offer. The importance of data mobility in the cloud can be emphasized by analogizing to mobile phone numbers. In November 2003, an FCC regulation became effective that required cell phone carriers to allow numbers to be ported from one carrier to another.540 There was a great deal of resistance on
540. See Telephone Number Portability, First Report and Order and Further
470 70 WASH. & LEE L. REV. 341 (2013)
the part of service providers that claimed that this rule would be too costly to carriers and might not be beneficial to consumers.541 The FCC, however, concluded in 2006 that the number portability requirement did not significantly increase “wireless churn,” and did in fact have a positive impact on service quality due to the need that it created for carriers to devote extra effort to customer retention.542 We expect that a data mobility requirement may be met with the same initial resistance as the wireless number portability requirement, but that like wireless number portability, data mobility requirements will have a net positive effect on both the industry and on consumers. By allowing consumers to “port” their phone numbers into another provider’s system, cellular subscribers are better equipped to participate in the market because such porting greatly reduces costs that might otherwise be associated with switching mobile service providers.543 Similarly, data mobility in the cloud would facilitate consumer participation and reduce transaction costs for consumers when moving from one provider to another.
Protection of course-of-business information could also be achieved through some application of the principles surrounding
Notice of Proposed Rule, 11 FCC Rcd. 8352 (1996). The first compliance date was set for June 30, 1999, but after two requests for forbearance, the agency pushed the deadline for compliance to November 24, 2003. See Cellular Telecommunications & Internet Ass’n v. F.C.C., 330 F.3d 502, 503–04 (D.C. Cir. 2003). 541. See Caron Carlson & Carmen Nobel, Carriers Resist Porting Numbers, EWEEK, Apr. 21, 2003, at 20 (describing how “[w]ireless carriers [were] looking for relief from a requirement that would . . . allow cell phone customers to keep their numbers when they change phone companies”). 542. Implementation of Section 6002(b) of the Omnibus Budget Reconciliation Act of 1993, 21 FCC Rcd. 10,947, 11,006 (2006)
[T]he advent of porting . . . did not lead to a significant increase in wireless churn, but did appear to have had a positive impact on service quality by inducing carriers to engage in aggressive customer retention efforts . . . . Significantly improved retention efforts (better deals on upgrade handsets, incentives for signing longer contracts, better customer service, and higher network spending) following the implementation of local number portability . . . have led to lower churn rates . . . (citations and internal quotations omitted).
543. See Carlson & Nobel, supra note 541 (noting that the extra cost associated with changing a cellular phone number was sometimes viewed as the most important reason to stay with the same provider).
INFORMATION PRIVACY AND DATA CONTROL 471
the law of confidentiality. Confidentiality as a concept is related to privacy, but primarily arises in the context of contracts between private parties. When fiduciary relationships exist, the law often recognizes obligations to keep information confidential. Solove has pointed out the potential application of fiduciary relationships in the privacy context.544 If elements of fiduciary relationships were integrated into the customer–cloud provider relationship, this would impose on the providers an obligation to keep not only the customer’s PII secure, but other data stored on the provider’s servers as well. Consumers could obtain stronger protections by opting into a fiduciary relationship with the service provider for a price. The consumer would thus get a guarantee that if the service provider acts badly, the consumer has a right of action against them. This differs from Solove’s proposal because we are more focused on consumer choice than on making fiduciary relationships into a default rule.
VII. Conclusion
Privacy issues online are not going to disappear overnight. Changes to the law are necessary to facilitate optimal market development that takes into consideration the autonomy of consumers in controlling their personal information. Foucault’s view of Bentham’s Panopticon as a metaphor for power relations in society is even more apt today than when Foucault was originally writing. The market forces peering into private lives may not be doing so with malicious intentions, but the corresponding decrease in consumer control of their personal information is nonetheless harmful.
In this Article, we have examined issues relating to cloud computing through the lens of privacy theories and privacy law. In analyzing a sample of terms of service agreements and privacy policies, we have concluded that these documents have potentially serious implications for the rights of consumers who agree to them without reading the terms.
544. See SOLOVE, DIGITAL PERSON, supra note 2, at 103 (making the “radical proposal” that the law should recognize a fiduciary relationship when a company collects and uses personal information).
472 70 WASH. & LEE L. REV. 341 (2013)
Ultimately, we recommend the implementation of baseline regulations to guarantee some minimum level of protection for consumers in the cloud. These regulations should emphasize the importance of preserving consumer control of their data, and these control mechanisms should focus on data mobility and a right of data withdrawal. Data mobility will require cloud providers to make consumer data available in a generally acceptable format such that consumers can freely move their own data from one provider to another in the interest of maintaining a healthy, competitive marketplace. For data withdrawal, we propose a notice-and-takedown approach patterned after similar provisions in the DMCA, which would permit a consumer to request that entities take down his personal information.
Our proposal raises a number of interesting new research questions. One of the most interesting problems is the effect that our proposals would ultimately have. Once the efficiency of the market is protected and consumers are in control of their data, would there actually be any statistically significant changes in consumer behavior? At the end of the day, if consumers are empowered to control their data, but behavior is largely unaltered, this may indicate that the current state of the market is actually optimal for society. However, the uncertainty that currently exists with regard to data ownership is harmful to consumer autonomy and makes it impossible to conclusively determine the optimality of the current regime. Thus, reduction of this uncertainty is essential to protecting the interests of consumers, and sufficient reduction will likely require some degree of regulatory intervention. We posit, however, that the degree of this regulatory intervention could be very modest, with narrow goals focusing on minimum protections and consumer choice, thus balancing the need to protect consumers with the need to preserve market vitality.
- Washington and Lee Law Review
- 1-1-2013
- Information Privacy and Data Control in Cloud Computing: Consumers, Privacy Preferences, and Market Efficiency
- Jay P. Kesan
- Carol M. Hayes
- Masooda N. Bashir
- Recommended Citation