Surveillance Mitigation: Identify a form of surveillance that you encounter in your everyday life

profilegracedeng
KesanBashirPrivacyCloudSectionsIandII.pdf

Washington and Lee Law Review

Volume 70 | Issue 1 Article 6

1-1-2013

Information Privacy and Data Control in Cloud Computing: Consumers, Privacy Preferences, and Market Efficiency Jay P. Kesan

Carol M. Hayes

Masooda N. Bashir

Follow this and additional works at: http://scholarlycommons.law.wlu.edu/wlulr Part of the Computer Law Commons

This Article is brought to you for free and open access by the Law School Journals at Washington & Lee University School of Law Scholarly Commons. It has been accepted for inclusion in Washington and Lee Law Review by an authorized administrator of Washington & Lee University School of Law Scholarly Commons. For more information, please contact [email protected].

Recommended Citation Jay P. Kesan, Carol M. Hayes, and Masooda N. Bashir, Information Privacy and Data Control in Cloud Computing : Consumers, Privacy Preferences, and Market Efficiency, 70 Wash. & Lee L. Rev. 341 (2013), http://scholarlycommons.law.wlu.edu/wlulr/vol70/iss1/6

341

Information Privacy and Data Control in Cloud Computing: Consumers,

Privacy Preferences, and Market Efficiency

Jay P. Kesan∗ Carol M. Hayes∗∗

Masooda N. Bashir∗∗∗

Abstract

So many of our daily activities now take place “in the cloud,” where we use our devices to tap into massive networks that span the globe. Virtually every time that we plug into a new service, the service requires us to click the seemingly ubiquitous box indicating that we have read and agreed to the provider’s terms of service (TOS) and privacy policy. If a user does not click on this box, he is denied access to the service, but agreeing to these terms without reading them can negatively impact the user’s legal rights.

As part of this work, we analyzed and categorized the terms of TOS agreements and privacy policies of several major cloud services to aid in our assessment of the state of user privacy in the cloud. Our empirical analysis showed that providers take similar approaches to user privacy and were consistently more detailed when describing the user’s obligations to the provider than when describing the provider’s obligations to the user. This asymmetry, combined with these terms’ nonnegotiable nature, led us to ∗ Professor and H. Ross & Helen Workman Research Scholar, University of Illinois College of Law. ∗∗ Research Associate, University of Illinois College of Law; Fall 2010 Fellow in the Christine Mirzayan Science and Technology Policy Graduate Fellowship program at the National Academy of Sciences. ∗∗∗ Assistant Director for Social Trust Initiatives, Information Trust Institute, University of Illinois. The authors also wish to acknowledge the excellent research assistance of Robert Zielinski in preparing this work.

342 70 WASH. & LEE L. REV. 341 (2013)

conclude that the current approach to user privacy in the cloud is in need of serious revision.

In this Article, we suggest adopting a legal regime that requires companies to provide baseline protections for personal information and also to take steps to enhance the parties’ control over their own data. We emphasize the need for a regime that allows for “data control” in the cloud, which we define as consisting of two parts: (1) the ability to withdraw data and require a service provider to stop using or storing the user’s information (data withdrawal); and (2) the ability to move data to a new location without being locked into a particular provider (data mobility). Ultimately, our goal with this piece is to apply established law and privacy theories to services in the cloud and set forth a model for the protection of information privacy that recognizes the importance of informed and empowered users.

Table of Contents

I. Introduction ..................................................................... 344 II. Cloud Computing Fundamentals .................................... 347

A. Background Technology ............................................ 347 1. The Internet ......................................................... 349 2. Mobile Computing ............................................... 351 3. Security ................................................................ 352 4. Related Regulations ............................................. 353

B. What Is Cloud Computing? ....................................... 354 1. Defining Cloud Computing .................................. 355 2. Growth of Cloud Computing ................................ 356 3. Uses of Cloud Computing .................................... 358 4. Types of Cloud Computing Services .................... 360

C. Advantages and Disadvantages of Cloud Computing ................................................................. 362

D. Cloud Computing Legal Issues ................................. 365 1. Privacy ................................................................. 366 2. Jurisdiction .......................................................... 368

E. Calls for Action in the Cloud ..................................... 371 1. Transparency and Control ................................... 372

F. Cloud Services in Different Industries ..................... 373

INFORMATION PRIVACY AND DATA CONTROL 343

III. Privacy Fundamentals .................................................... 375 A. Privacy Theories ........................................................ 375

1. Warren and Brandeis .......................................... 380 2. Prosser ................................................................. 381

a. Prosser’s Privacy Torts and Information Privacy ............................................................ 383

3. Modern Informational Privacy Theory ................ 384 a. Concepts of Privacy ........................................ 386 b. The First Amendment Critique ..................... 388 c. Privacy as a Commodity ................................. 390

B. Privacy Law ............................................................... 392 1. Steps Toward Regulation of Privacy ................... 393 2. Federal Privacy Statutes and State Laws .......... 395

a. Electronic Communications Privacy Act ....... 399 (1) Stored Communications Act ..................... 401 (2) Applying the SCA to the Cloud ................ 405

3. Case Law .............................................................. 407 a. Fourth Amendment ........................................ 408 b. Stored Communications Act........................... 414 c. Contracts and Privacy .................................... 416

4. European Privacy Law ........................................ 418 a. The Safe Harbor Framework ......................... 419

IV. Companies, Customer Data, and Customer- Company Interactions ..................................................... 421 A. Companies and Customer Data ................................ 421

1. Terms of Service Agreements .............................. 421 a. TOS Agreements as Contracts of Adhesion ......................................................... 424

2. Privacy Policies .................................................... 425 a. Sharing Information with the Government ... 427

3. Effects of Security Breaches ................................ 430 4. Protecting Consumer Data—Who Watches the Watchers? ...................................................... 432 5. Tracking Technologies and Behavioral Marketing ............................................................ 436 6. Personally Identifiable Information and “Anonymous” Information ................................... 440

V. Empirical Analysis of Agreements and Policies in the Cloud .......................................................................... 443

344 70 WASH. & LEE L. REV. 341 (2013)

A. Methodology............................................................... 444 B. Terms of Service Agreements .................................... 446

C. Privacy Policies .......................................................... 449 D. Analysis and Discussion ............................................ 457

E. Implications ............................................................... 459 VI. Recommendations—Building a Baseline for

Facilitating Transactions in the Cloud ........................... 460 A. Building the Baseline ................................................ 460

1. Baseline Regulation ............................................. 462 B. Data Control .............................................................. 464

1. Personally Identifiable Information .................... 465 2. Secondary Use ..................................................... 466 3. Course-of-Business Data ..................................... 468

VII. Conclusion ........................................................................ 471

“You have zero privacy anyway. Get over it.” —Scott McNealy, Chairman and former CEO of Sun

Microsystems, 1999

I. Introduction

What price for your privacy? As social interactions and business activities have shifted online, or into “the cloud,” personal information has become a currency with an undervalued exchange rate. What data are consumers willing to trade in exchange for convenience and services online? Would they be as willing to engage in this trade if their privacy rights were more protected and if they had the ability to exercise meaningful control over their data?

Technological and social changes have stimulated many developments over the last decade as the Internet became ingrained in society and social interactions. Substantial technological changes require the law to adapt. When our perceptions change, policymakers amend the law accordingly to address evolved expectations. In this Article, the perceptions and law that we are concerned about are those associated with privacy, especially privacy in the context of services provided over the cloud.

INFORMATION PRIVACY AND DATA CONTROL 345

This is not the first time that conceptions of privacy have been shaped by technology. The Right to Privacy, published in 1890, was the seminal work of Samuel Warren and Louis Brandeis that substantially influenced privacy law in the United States in the twentieth century.1 The publication of this piece was spurred by the authors’ concerns about intrusions into personal privacy by the press, especially considering the technological improvements that had enabled the production of small, affordable cameras.2

Portable cameras were just the beginning of technology that prompted major changes in privacy law and theory. Around the middle of the twentieth century, computers were becoming more pervasive and powerful, enabling the creation of databases that could hold and process huge amounts of information. The idea of informational privacy developed in greater detail around this time, as people realized that personal privacy could be threatened not just by appropriation of one’s name and likeness, but by access to and use of other information about a person.3

While these informational privacy concerns were becoming more visible, the future of connecting computers in a global telecommunications network was just a glimmer in the eyes of some of the more innovative researchers. Today, in exchange for our personal information, we have access to free e-mail and free data storage, and we can use free services to keep in touch with former classmates and colleagues around the country and around the world. Thanks to Facebook, attendees of modern high school

1. See Neil M. Richards & Daniel J. Solove, Prosser’s Privacy Law: A Mixed Legacy, 98 CAL. L. REV. 1887, 1891–93 (2010) (describing the impact of the article on the landscape of privacy law).

2. DANIEL J. SOLOVE, THE DIGITAL PERSON: TECHNOLOGY AND PRIVACY IN THE INFORMATION AGE 137 (2006) [hereinafter SOLOVE, DIGITAL PERSON]. Recent research posits that the authors’ concern about privacy stemmed from Warren’s experiences with the press when he married Mabel Bayard, the daughter of a politician. See Amy Gajda, What If Samuel D. Warren Hadn’t Married a Senator’s Daughter?: Uncovering the Press Coverage That Led to “The Right to Privacy,” 2008 MICH. ST. L. REV. 35, 43–44 (explaining the suggestion of Warren and Brandeis that everyone has the right to keep the press away).

3. See Paul M. Schwartz & Daniel J. Solove, The PII Problem: Privacy and a New Concept of Personally Identifiable Information, 86 N.Y.U. L. REV. 1814, 1836–37 (2011) (describing the myth of anonymity on the Internet).

346 70 WASH. & LEE L. REV. 341 (2013)

reunions who live on opposite sides of the country can focus on catching up on events of the last week instead of the last ten years.

As with any improvement in technology, however, there are also tradeoffs. Free services online are often funded by advertising revenue, and these ads are made more effective by utilizing the user’s personal information to target ads to their interests. To set up accounts for services online, consumers must typically click the ubiquitous box indicating that they have read and agreed to the website’s terms of service (TOS) and privacy policy. These agreements often contain broad provisions for what the provider is permitted to do with the consumer’s information, while giving the consumer few, if any, options for redress. In the majority of cases in which services are marketed to individual users, there is zero negotiability in these terms, and almost no one reads these terms anyway.

In this Article, we urge the creation of baseline regulations that would guarantee a minimum level of protection of consumer privacy while preserving market vitality. One of the essential elements for this baseline regime would be the protection of the consumer’s right to control his data. People are often denied meaningful control over their personal information and the other information that they store with these services. Companies often do not address beforehand how a consumer can exercise control over their information in the event that the service is terminated, and many companies reserve a nonrevocable license to use the consumer’s intellectual property that is stored with its service. We view this right of data control as consisting of two parts: (1) data mobility, which we summarize as a right to move one’s data and terminate a relationship with a particular service provider, under which providers would be required to provide data to departing customers in a generally accepted file format such that customers do not become “locked in”; and (2) a broader right of data withdrawal that would permit a consumer to withdraw his information from the records of any entity, including a third party, through a notice-and-takedown process.

In Part II, we explain the idea of cloud computing and introduce a number of issues related to it. In Part III, we turn to an examination of privacy fundamentals, first examining different theoretical approaches to privacy before turning to a

INFORMATION PRIVACY AND DATA CONTROL 347

discussion of privacy law in the United States and an examination of statutes and case law. In Part IV, we describe issues relating to companies and customer data, including concerns about TOS agreements, privacy policies, and data security. In Part V, we turn to the results of our empirical analysis of the TOS agreements and privacy policies of a sample of cloud service industry leaders. Finally, in Part VI, we offer our recommendations based on our empirical work, as well as our research into privacy issues and the cloud.

II. Cloud Computing Fundamentals

In examining the legal implications of privacy and cloud computing, it is important to understand some of the background. In this Part, we will examine some of the technical background of the current technologies before discussing cloud computing and its advantages and disadvantages in more detail. We will also introduce some legal issues that arise in the cloud context and briefly review various calls for action that have sounded with respect to the cloud, such as calls for amending legislation, proposing legislation, or calling for standards or increased transparency.

A. Background Technology

Before the World Wide Web (Web) became so prevalent, there were two paradigms of computer use. The first was mainframe computing, and under this paradigm, users worked at “dumb terminals” that were connected to a large mainframe system, which in turn processed the users’ requests.4 As microprocessors became available, the personal computing paradigm took over, and the files and data were under the users’ physical control.5

4. William Jeremy Robison, Note, Free at What Cost?: Cloud Computing Privacy Under the Stored Communications Act, 98 GEO. L.J. 1195, 1197 (2010).

5. Christopher Soghoian, Caught in the Cloud: Privacy, Encryption, and Government Back Doors in the Web 2.0 Era, 8 J. TELECOMM. & HIGH TECH. L. 359, 362 (2010).

348 70 WASH. & LEE L. REV. 341 (2013)

The personal computing paradigm has weaknesses, however, including the low degree of scalability of individual systems, the need for technological expertise to assemble and maintain computer systems, and a low level of redundancy such that data loss through equipment failure is a significant danger.6 Under the traditional model of information technology (IT) management, based on this paradigm, a lot of space and human capital is required to maintain and secure the systems of a large enterprise.7

Moving our technological worlds to the cloud is another paradigm shift that some view as the future of computing.8 Mark Weiser predicted in 1991 that the third wave of computing, after mainframe computing and personal computing, would be ubiquitous computing, where computers become so small, inexpensive, and ubiquitous that they virtually disappear.9 Today, technologies continue to improve, but the truly ubiquitous nature of modern computing is not because of the computer’s size

6. See Robison, supra note 4, at 1200–01 (explaining the inefficiencies that occur when everyone has his or her own computer).

7. Mark H. Wittow & Daniel J. Buller, Cloud Computing: Emerging Legal Issues for Access to Data, Anywhere, Anytime, 14 NO. 1 J. INTERNET L. 1, 5 (2010). Wittow and Buller note that these limitations are mitigated by the use of things like centralized disk storage, the use of more advanced servers with smaller hardware footprints, and system virtualization. Id. Virtualization is one of the major technologies behind some applications of “cloud computing,” where spaces on hard drives are turned into “virtual machines” that segment the processing of different requests. VMWare, Virtualization Basics, http://www.vmware.com/ virtualization/virtualization-basics/how-virtualization-works.html (last visited Feb. 3, 2013) (on file with the Washington and Lee Law Review).

8. See Ilana R. Kattan, Cloudy Privacy Protections: Why the Stored Communications Act Fails to Protect the Privacy of Communications Stored in the Cloud, 13 VAND. J. ENT. & TECH. L. 617, 621 (2011) (noting the transitions between paradigms); Soghoian, supra note 5, at 364 (noting that cloud computing has been deemed by many commentators to be the future of computing). Some suggest that the decentralized cloud computing model has the potential to make such services comparable to utilities, with data centers being the equivalent of power plants in the electrical utility context. Kevin Werbach, The Network Utility, 60 DUKE L.J. 1761, 1817 (2011). If cloud providers are utilities, the argument for regulation of services on the cloud becomes stronger. Id. at 1818.

9. Gary M. Olson & Judith S. Olson, Human-Computer Interaction: Psychological Aspects of the Human Use of Computing, 54 ANN. REV. PSYCHOL. 491, 499 (2003).

INFORMATION PRIVACY AND DATA CONTROL 349

or power. The Internet and high-speed connections allow people to be in touch not only with each other, but with service providers that can essentially rent out processing power and storage space over the Internet. Moving some functions to the cloud can allow users access to high-end services and technology without having to trade quality for mobility.10 This future of computing, however, may challenge the default assumption that a user will be able to control her own data.11

1. The Internet

The history of the Internet is often traced back to the late ’60s and ARPANET.12 Even before ARPANET, however, some recognized the possible future value of computers being connected using communication lines.13 Regardless of how the ideas emerged, there is no doubt that the Internet is a pervasive element of today’s society.

To say that the Internet has become a staple of modern life is an understatement. The Internet has had a substantial effect on the world and how people interact.14 Cyberspace is a major social

10. Additionally, increasingly large networks of computers can be used to create “ad hoc supercomputers” through distributed computing. Paul M. Schwartz, Property, Privacy, and Personal Data, 117 HARV. L. REV. 2055, 2064 (2004) [hereinafter Schwartz, Property].

11. Werbach, supra note 8, at 1820. 12. See J.R. OKIN, THE INTERNET REVOLUTION 318 (2004) (describing the

Advanced Research Projects Agency Network, created in the late 1960s, that eventually became today’s Internet).

13. See J.C.R. Licklider, Man–Computer Symbiosis, 1 IRE TRANSACTIONS ON HUM. FACTORS IN ELECTRONICS 4 (1960), available at http://groups. csail.mit.edu/medg/people/psz/Licklider.html (explaining the benefits of a system with “thinking centers” connected to each other by wide-band communication lines and to individual users); Werbach, supra note 8, at 1793 (explaining that major network operators in the 1960s were cognizant that computers would increasingly become the technical foundation for the telecommunications system itself). Werbach notes that some researchers viewed networked computers as having the potential of being a new class of public utility. Id. at 1793–94.

14. See Katherine J. Strandburg, Home, Home on the Web and Other Fourth Amendment Implications of Technosocial Change, 70 MD. L. REV. 614, 626 (2011) (“It is not just that ‘the Internet is different’; it is that the Internet, like every major advance in infrastructural technology before it, has made

350 70 WASH. & LEE L. REV. 341 (2013)

outlet that is often intertwined with the physical realm.15 People keep in touch through a variety of electronic messaging technologies, including e-mail, text messaging, other instant messaging over the Internet, and social networking websites.16 Research by the Kaiser Family Foundation suggests that the average youth between the ages of eight and eighteen spends every permissible waking moment using electronic devices, many of which are connected to the Internet, like smart phones and computers.17 A study by the Nielsen Company found that across all ages, the average American Internet user is online over fifty- five hours per month.18

The Internet works because computers on the network use identical protocols that enable interconnection so that data can be delivered across the network.19 One of the well-known protocols is the Simple Mail Transfer Protocol (SMTP), which enabled e-mail exchanges in the 1980s in the days before the World Wide Web.20 In the mid-1980s, the transfer of e-mail was fairly fragmented, with communications being transmitted from server to server, stored at various locations temporarily during the trip before being downloaded by the recipient.21 Today, webmail still uses the SMTP protocol, as well as the Internet Message Access

everything different.”). 15. Id. at 639. 16. See John Soma, Melodi Mosley Gates & Michael Smith, Bit-Wise but

Privacy Foolish: Smarter E-Messaging Technologies Call for a Return to Core Privacy Principles, 20 ALB. L.J. SCI. & TECH. 487, 497–502 (2010) (explaining the five technologies, including telephone systems, e-mail, text messaging, instant messaging, and social networking); Strandburg, supra note 14, at 655–56 (explaining how social media promise to change social interactions by supplementing physical interaction or replacing it).

17. Andrea Cascia, Don’t Lose Your Head in the Cloud: Cloud Computing and Directed Marketing Raise Student Privacy Issues in K–12 Schools, 261 WEST’S EDUC. L. REP. 883, 894 (2011).

18. Paul Lanois, Caught in the Clouds: The Web 2.0, Cloud Computing, and Privacy?, 9 NW. J. TECH. & INTELL. PROP. 29, 29 (2010). About half of that time is spent on social networking, e-mails, games, and instant messaging. Id.

19. See Werbach, supra note 8, at 1769 (explaining the functionality and concept of the Internet).

20. OKIN, supra note 12, at 212. 21. See Robison, supra note 4, at 1205–06 (explaining the functionality of

electronic communication services).

INFORMATION PRIVACY AND DATA CONTROL 351

Protocol (IMAP). IMAP allows e-mails to be accessed from anywhere with an Internet connection, with e-mails being perpetually stored on the provider’s servers.22 The ability to access information from anywhere is important for mobility and mobile computing.

2. Mobile Computing

Computers have shrunk in size over the last fifty years, from room-size computers to thirty-pound desktops to five-pound laptops to smart phones weighing just a few ounces. The early 1980s saw the invention of the first laptop and the first cellular phone, and the first personal digital assistant (PDA) was released in 1993.23 This increase in mobility has been helpful for both personal and professional tasks. The Blackberry became a popular office tool after its release in 1999, functioning as both a cell phone and a PDA that permitted remote access to office e- mail.24 Today’s smart phones go beyond the original Blackberry, giving users access to e-mail, the Web, appointment calendars, and even software that allows the users to review word processing files and full color PDFs in the palms of their hands. It is estimated that by 2013, about half of the mobile phone market will be smart phones,25 and many if not all of these are likely to have access to 3G or 4G data networks that do not require a separate wireless connection.26

22. See IMAP & POP, UNIVERSITY OF MINNESOTA E-MAIL AND INTERNET ACCOUNTS GUIDES, http://www.oit.umn.edu/email/imap-pop (last visited Feb. 3, 2013) (on file with the Washington and Lee Law Review).

23. Kimberly L. Rhodes & Brian Kunis, Walking the Wire in the Wireless World: Legal and Policy Implications of Mobile Computing, 16 J. TECH. L. & POL’Y 25, 27–28 (2011). The first laptop computer was invented in 1981, and Motorola invented the first cellular phone in 1983. Id.

24. Id. at 28. 25. Daniel Zamani, Note, There’s an Amendment for That: A

Comprehensive Application of Fourth Amendment Jurisprudence to Smart Phones, 38 HASTINGS CONST. L.Q. 169, 170 (2010).

26. Strategy Analytics: Global LTE Phone Shipments Will Surge Tenfold to 67 Million Units in 2012, BUS. WIRE (Mar. 23, 2012), http://www.virtual- strategy.com/2012/03/23/strategy-analytics-global-lte-phone-shipments-will-surge- tenfold-67-million-units-2012 (last visited Feb. 3, 2013) (on file with the

352 70 WASH. & LEE L. REV. 341 (2013)

The desire for technologies that can go anywhere makes cloud computing more appealing. Even with improvements in personal computing technology, increased mobility generally requires a tradeoff with the hardware abilities of the device. This is where the value of the cloud becomes clearer: there are fewer tradeoffs from having smaller and cheaper end-user devices because these devices can tap into the power of network-based services.27

However, mobile devices are vulnerable to the same sorts of security threats as full-sized computers, including spyware and viruses, and data transmitted using these devices may not be secure.28 For this reason, and because of the significant security concerns that arise in the cloud computing context, we turn to this topic next.

3. Security

The security of any information in the cloud is often unclear. There was an uproar when Scott McNealy of Sun Microsystems dismissed online privacy concerns by proclaiming in 1999, “You have zero privacy anyway. Get over it.”29 But regardless of whether consumers will be persuaded by assertions about the nature or extent of privacy, active efforts by third parties to infringe on privacy should properly raise red flags.

One threat to devices accessing the cloud is spyware. One can define spyware as software that installs itself, runs, and uses its host computer, all without the owner’s permission.30 Similar software has been called “adware,” an example of which was the software produced by Gator, which was ad-supported and sent Washington and Lee Law Review). 27. See Werbach, supra note 8, at 1816 (explaining how cloud computing is changing the way people think about computers and computer networks). 28. See Rhodes & Kunis, supra note 23, at 32–33 (noting the existence of malware that targets mobile devices, worms with the ability to monitor and record cell phone conversations, and the exploitation by hackers of information transmitted using wi-fi hotspots). 29. See Robison, supra note 4, at 1196 (quoting John Schwartz, As Big PC Brother Watches, Users Encounter Frustration, N.Y. TIMES, Sept. 5, 2001, at C6). 30. Schwartz, Property, supra note 10, at 2065.

INFORMATION PRIVACY AND DATA CONTROL 353

information about the user and his computer back to the company.31 In 2004, sources indicated that Gator software was installed on about thirty-five million computers located in the United States.32

4. Related Regulations

The degree to which the Internet is or should be regulated is the subject of much debate.33 Werbach traces the origins of the broadband regulation debate back to the 1960s, when the FCC launched the Computer Inquiries to determine when and how data processing services would become sufficiently intertwined with communications that they would be covered by the Communications Act.34 In the first of the Computer Inquiries, Computer I, the FCC concluded that there was “no public interest requirement for regulation by government of such activities” because of the competitive nature of the market for data processing services.35 However, the FCC did recognize that the communications circuits that carried these services might need to be regulated.36

31. Id. at 2066. 32. Id. at 2065. 33. See Shawn Hess, Research Shows America Hates Gov’t Regulation, WEBPRONEWS (Mar. 8, 2012), http://www.webpronews.com/research-shows- america-hates-govt-regulation-2012-03 (last visited Feb. 3, 2013) (addressing attitudes toward search engine regulation) (on file with the Washington and Lee Law Review). 34. See Communications Act of 1934, Pub. L. No. 73-416, 48 Stat. 1064 (codified as amended in scattered sections of 47 U.S.C.); Werbach, supra note 8, at 1804; see also Regulatory and Policy Problems Presented by the Interdependence of Computer and Communication Services and Facilities (Computer I Final Decision), 28 F.C.C. 2d 267 (1971) (final decision and order). 35. See Regulatory and Policy Problems Presented by the Interdependence of Computer and Communication Services and Facilities (Computer I Tentative Decision), 28 F.C.C. 2d 291, 297 (1970) (tentative decision); see also Werbach, supra note 8, at 1804 (discussing Computer I and the Communications Act). 36. Computer I Final Decision, 28 F.C.C.2d at 269 (“[W]ithout appropriate regulatory safeguards, the provision of data processing services by common carriers could adversely affect the statutory obligation of such carriers to provide adequate communication services under reasonable terms and conditions and impair effective competition in the sale of data processing

354 70 WASH. & LEE L. REV. 341 (2013)

At the turn of the century, questions about regulating these communications circuits came to the fore. The Telecommunications Act of 199637 established a category of services called “information services,” which the Act defines as “the offering of a capability for generating, acquiring, storing, transforming, processing, retrieving, utilizing, or making available information via telecommunications.”38 Information services are not regulated as a common carrier under Title II of the Telecommunications Act. In 2002, the FCC designated cable Internet as an “information service” instead of a “telecommunications service,” a designation that was upheld by the Supreme Court,39 and later expanded to include DSL service.40 The National Cable & Telecommunications Ass’n v. Brand X case was regarded by some as marking a decision to not regulate the Internet, given the lesser degree to which information services were regulated compared to telecommunications services.41

B. What Is Cloud Computing?

Up to this point, we have referenced “the cloud” in the context of cloud computing as a new computing paradigm. In this subpart, we will go into more detail about cloud computing and what it is.

services.”); Werbach, supra note 8, at 1825. 37. See Telecommunications Act of 1996, Pub. L. No. 104-104, 110 Stat. 56

(codified in scattered sections of 47 U.S.C.). 38. 47 U.S.C. § 153(20) (2006). 39. Nat’l Cable & Telecomm. Ass’n v. Brand X, 545 U.S. 967 (2005). 40. In re Appropriate Framework for Broadband Access to the Internet over

Wireline Facilities, 20 F.C.C.R. 14853, 14864 para. 15 (Aug. 5, 2005) (report, order, and notice of proposed rulemaking).

41. Brand X, 545 U.S. at 967; Note, How Chevron Step One Limits Permissible Agency Interpretations: Brand X and the FCC’s Broadband Reclassification, 124 HARV. L. REV. 1016, 1021 (2011) (“The Supreme Court affirmed the FCC’s authority to deregulate cable broadband service in Brand X . . . .”).

INFORMATION PRIVACY AND DATA CONTROL 355

1. Defining Cloud Computing

The term “cloud computing” has become popular and trendy, but there are many concepts behind this idea. On a general level, “cloud” is used as a metaphor for the “ethereal Internet” and the virtual platform that it provides.42 Some view cloud computing abstractly as the result of the convergence of computing and communications,43 or more practically as a “scalable network of servers,”44 as “IT as a service,”45 or as the convenience of being able to access a shared pool of computing resources over a network like the World Wide Web.46

42. See David A. Couillard, Defogging the Cloud: Applying Fourth Amendment Principles to Evolving Privacy Expectations in Cloud Computing, 93 MINN. L. REV. 2205, 2205, 2216 (2009); Wittow & Buller, supra note 7, at 1 (noting that “cloud” is essentially a metaphor for the Internet).

43. Werbach, supra note 8, at 1811. 44. See Konstantinos K. Stylianou, An Evolutionary Study of Cloud

Computing Services Privacy Terms, 27 J. MARSHALL J. COMPUTER & INFO. L. 593, 594–95 (2010) (stating that most business executives, lawyers, and computer technicians understand cloud computing as a scalable network of servers on which users store data that would traditionally reside on a local computer). Werbach also embraces this interpretation. Werbach, supra note 8, at 1811 (“Cloud computing is an approach that places application processing and storage in network-based data centers, rather than in end-user devices such as personal computers.”); see also Timothy D. Martin, Hey! You! Get Off of My Cloud: Defining and Protecting the Metes and Bounds of Privacy, Security, and Property in Cloud Computing, 92 J. PAT. & TRADEMARK OFF. SOC’Y 283, 292–94 (2010) (explaining cloud computing as “Infrastructure-as-a-Service”).

45. See Rhodes & Kunis, supra note 23, at 30 (stating that at its core, cloud computing is an IT service because providers “rent” their services to customers). Wittow and Buller similarly note that definitions of cloud computing typically involve a third party provider who supplies a subscription-based service for computing and storage needs. Wittow & Buller, supra note 7, at 5.

46. See Couillard, supra note 42, at 2216 (“Cloud platforms give users ‘anywhere access’ to applications and data stored on the Internet.”); William R. Denny, Survey of Recent Developments in the Law of Cloud Computing and Software as a Service Agreement, 66 BUS. LAW. 237, 237 (2010) (describing cloud computing as technology that gives users convenient network access to a shared pool of computing resources); Lanois, supra note 18, at 29 (referring to cloud computing as being based on the idea of storing software and data on Internet servers instead of locally); Martin, supra note 44, at 287 (quoting a definition for cloud computing as “a platform for the delivery of software services and other applications through remote file servers” in which the data and software stay on remote servers and are accessible from any computer anywhere); Fernando M. Pinguelo & Bradford W. Muller, Avoid the Rainy Day: Survey of U.S. Cloud

356 70 WASH. & LEE L. REV. 341 (2013)

Denny maintains that there is not a uniform definition of cloud computing.47 On the other hand, many commentators also authoritatively cite the definition of cloud computing put forth by the National Institute for Standards and Technology (NIST), which currently defines it as “a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.”48 For our purposes, we accept the NIST’s definition because it is broad enough to encompass the variety of uses for cloud computing.

2. Growth of Cloud Computing

Cloud computing is a growing segment of technology services, thanks in part to the availability of high speed Internet service.49 A study by the Pew Internet and American Life Project concluded that about 69% of Internet users in the United States already use webmail, other software programs located solely Computing Caselaw, 2011 B.C. INTELL. PROP. & TECH. F. 1, 1 (defining cloud computing as “a computer networking model that gives users on-demand access to shared software applications and data storage.”); Robison, supra note 4, at 1200 (drawing a parallel between “dumb” terminals in the mainframe paradigm and how personal computers are used in the cloud paradigm); Soghoian, supra note 5, at 364 (applying the term “cloud computing” to “software offerings where the application is executed in a web browser, via software code that is downloaded (as needed) from a remote server that also stores users’ files.”); Wittow & Buller, supra note 7, at 1 (defining cloud computing as when “an Internet connection delivers hardware power and software functionality to users regardless of where they are or which computer they are using”). 47. Denny, supra note 46, at 237. 48. See Peter Mell and Tim Grance, The NIST Definition of Cloud Computing, Nat’l Inst. of Standards & Tech. (Sept. 2011), http://csrc.nist.gov/ publications/nistpubs/800-145/SP800-145.pdf; see also David S. Barnhill, Cloud Computing and Stored Communications: Another Look at Quon v. Arch Wireless, 25 BERKELEY TECH. L.J. 621, 638–39 (2010) (discussing the NIST definition of cloud computing); George Jiang, Rain or Shine: Fair and Other Non-Infringing Uses in the Context of Cloud Computing, 36 J. LEGIS. 395, 412 (2010) (discussing the NIST definition of cloud computing); Kattan, supra note 8, at 620–21 (discussing the NIST definition of cloud computing). 49. Robison, supra note 4, at 1201.

INFORMATION PRIVACY AND DATA CONTROL 357

online, or online data storage.50 A survey of technology insiders and critics in 2010 reflected a view by the majority that cloud computing technologies will be heavily used in work environments by 2020, with most expecting the PC model to decrease in importance.51 Some suggest that as cloud computing grows and more activities transition onto the Internet, there will be a greater focus on interoperability between cloud platforms and applications.52

As a result of more people using cloud services, the revenue in this industry is expected to grow substantially. The cloud services industry saw revenue of $58.6 billion in 2009, and some analysts are anticipating that the industry’s revenue will increase between $40 billion and $160 billion over the next few years.53 Because of these large growth forecasts, many companies are pushing to be at the forefront of this movement.54

50. See John B. Horrigan, Cloud Computing Gains in Currency, PEW RES. CTR. (Sept. 12, 2008), http://pewresearch.org/pubs/948/cloud-computing-gains-in- currency (last visited Feb. 3, 2013) (on file with the Washington and Lee Law Review). A majority of those responding in the Pew study also indicated that they were very concerned about the use of their personal data by cloud providers. See id.; see also Martin, supra note 44, at 298 (discussing the Pew Research Center study); Wittow & Buller, supra note 7, at 5 (same). 51. Kattan, supra note 8, at 620. Some have noted that cloud computing has the potential to partially replace the desktop computer. See Stylianou, supra note 44, at 604; see also Werbach, supra note 8, at 1813–14 (discussing how the rise of smart, connected mobile devices will increase incorporation of cloud computing). 52. See Stylianou, supra note 44, at 597 (stating that some platforms and applications will allow interoperability, which will allow users to transfer content easily). 53. See Lanois, supra note 18, at 30 (citing a study anticipating growth to $148.8 billion in revenue by 2014, and a study anticipating over a 20% increase in spending on cloud services by organizational customers); Soghoian, supra note 5, at 361 (citing analyst expectations of industry revenue growth between $40 billion and $160 billion). 54. See Lanois, supra note 18, at 30 (referring to a “recent bidding war between Hewlett-Packard and Dell to acquire cloud storage firm 3PAR”).

358 70 WASH. & LEE L. REV. 341 (2013)

3. Uses of Cloud Computing

There are a lot of uses of cloud computing and a lot of aspects to those uses. One of the earliest forms of cloud computing was server-side e-mail storage.55 There are many companies offering cloud services.56 Webmail in particular is very popular, and sometimes an organization may contract with cloud providers for e-mail in order to save money over running its e- mail system in-house.57 Google provides such services to organizations through its Google Apps service,58 as well as free services to individuals over the Web. Google’s services to the public include webmail through Gmail and Web-based productivity software through Google Docs.59

There are also a number of other uses that are not as immediately visible. Users can take advantage of the cloud to improve the functionality of locally run software, like the Weave add-on for the Firefox Web browser, which allows users to synchronize bookmarks, saved passwords, and cookies across multiple computers by storing this information on Mozilla’s servers.60 Additionally, Ford is working on a system that would bring features of cloud computing and social networking to new cars, perhaps including things like traffic alerts and real-time fuel consumption monitoring.61 Cloud computing could also be useful in education to increase student engagement and provide

55. See Couillard, supra note 42, at 2218 (explaining that server-side e- mail was one of the first iterations of cloud computing); Robison, supra note 4, at 1203 (referring to server-side e-mail storage as one of the first cloud computing services available to the public). 56. See Lanois, supra note 18, at 30 (listing offerings of companies, including Amazon, Microsoft, IBM, and VMWare). 57. Soma, Gates, & Smith, supra note 16, at 516. 58. See Soghoian, supra note 5, at 367–68 (describing services offered by Google Apps). 59. John T. Kivus, Spring Training for Electronic Search: Examining U.S. v. Comprehensive Drug Testing, Inc. with Regards to Evolving Trends in Computing, 11 N.C.J.L. & TECH. ON. 115, 128–29 (2009). 60. See Soghoian, supra note 5, at 397 (explaining the characteristics of Firefox, Mozilla’s browser). 61. Lanois, supra note 18, at 32.

INFORMATION PRIVACY AND DATA CONTROL 359

students with additional tools like online forums and storage space in the cloud.62

The cloud is also leading to many innovations in entertainment. Some gaming services are appearing in the cloud, like OnLive and Gaikai, and some posit that the cloud has the potential to let gamers play games with high-end graphics without having high-end computers.63 Other entertainment uses of the cloud include subscription or ad-supported video streaming services like Netflix and Hulu.64 There are also social networking websites, like Facebook, that behave in ways consistent with the NIST’s definition of cloud computing.65

The providers of cloud services may take a variety of approaches to service provision, differing in areas like cost models, user interfaces, and treatment of user data. Because cloud services are still fairly new, some companies may also seek to ease the transition to the cloud by making their services resemble software that is run locally on a computer.66 In addition to easing the transition by focusing on the user experience, cloud service providers also may make their services more appealing by offering them for free. There are many cloud services that are already provided for free, and these services can remain profitable by relying on ad support.67 Companies that do so often

62. See Cascia, supra note 17, at 884 (discussing the benefits of integrating cloud computing in schools). The Department of Education takes the position that cloud computing, data mining, and data aggregation could play valuable roles in increasing student performance and keeping school districts accountable. Id. at 887.

63. Lanois, supra note 18, at 31. OnLive launched in June 2010, but is said to already be worth $1.1 billion. Id.

64. Netflix, How Netflix Works, https://signup.netflix.com/MediaCenter/ HowNetflixWorks (last visited Feb. 3, 2013) (on file with the Washington and Lee Law Review); Hulu, More About Hulu, http://www.hulu.com/about (last visited Feb. 3, 2013) (on file with the Washington and Lee Law Review).

65. See supra note 48 and accompanying text (discussing the NIST definition of cloud computing).

66. See Soghoian, supra note 5, at 369–70 (explaining single-site browser technology). A cloud service provider, looking to ease the transition between local computing and cloud computing, might also choose to provide support for offline access, such as Google’s Gears browser add-on that allows limited access to Gmail. Id. at 370–71.

67. See Jiang, supra note 48, at 415 (explaining different business models for cloud computing).

360 70 WASH. & LEE L. REV. 341 (2013)

use customer information to generate targeted advertisements, which some criticize as effectively monetizing users’ private data.68

Providers may also take very different approaches to data protection and encryption depending on the service, and we argue that the public should be made aware of data protection issues. Remotely stored data that is not intended for public access is likely to be encrypted, password protected, or have unlisted links.69 Other data, especially data that is not considered “sensitive,” are typically stored in an unencrypted format.70 Because cloud computing technology is still emerging, added features like increased security would cost more for early adopters, and this cost plus the current lack of market demand means that cloud service providers currently do not have much incentive to invest in enhancing security for a lot of the data involved.71 One of the things that current customers demand, however, is reliability, so cloud service providers often go to great lengths to have their services available at least 99.9% of the time.72

4. Types of Cloud Computing Services

Cloud services may be private, public, or some hybrid of the two.73 Private clouds may also be referred to as “internal” clouds, and are located solely within that organization and use only that

68. Soghoian, supra note 5, at 396. 69. Couillard, supra note 42, at 2217. Mozy asserts that it uses encryption

technologies when user data is transmitted and stored, which is different from most other companies that say that they use SSL encryption for the exchange of data but do not specify whether data in storage is encrypted. Stylianou, supra note 44, at 603.

70. Stylianou, supra note 44, at 605. Because Google does not encrypt stored e-mails, for example, Google’s software can scan e-mail content for key words for the purpose of targeted advertising. Id.

71. Id. at 606. 72. Id. at 607. 73. Barnhill, supra note 48, at 640.

INFORMATION PRIVACY AND DATA CONTROL 361

organization’s infrastructure.74 Public clouds are offered over the Internet and are supported by ads or fees.75

There are three primary models for public cloud services: Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS).76 Companies that provide servers and storage for remote use are providing IaaS, while companies that provide platforms on remote servers to run applications are providing PaaS.77 A company that makes software applications available over the Internet, including webmail, is providing SaaS.78 Gmail and Facebook are examples of SaaS cloud services.79 SaaS goes much further, however, and includes services like online gaming and online legal research.80

SaaS is arguably the level that consumers are most familiar with. The other types of cloud computing services may be more appealing to developers and computing professionals. PaaS, for example, gives customers (often software developers) the ability to deliver their own software applications over the Web to end users at a lower cost to the developer since they are using someone else’s servers to do so.81 IaaS, on the other hand, involves cloud providers giving customers access to raw computing resources in a manner similar to a utility service.82 Because this Article focuses on individual consumers, the most relevant category of cloud service for our purposes is SaaS.

74. Couillard, supra note 42, at 2216; Martin, supra note 44, at 287. 75. See Martin, supra note 44, at 287 (explaining how cloud computing works). 76. Barnhill, supra note 48, at 639–40. 77. Id. 78. Id. at 639; Denny, supra note 46, at 237. 79. Rhodes & Kunis, supra note 23, at 31. 80. Martin, supra note 44, at 287–88 (“Under the SaaS model, a user interacts with an online service through the Internet, and the online service’s vendor provides the necessary software applications and remote data storage.”). 81. See id. at 289 (explaining the lower costs of PaaS compared to SaaS); Robison, supra note 4, at 1203 (noting the use of PaaS by third-party developers). 82. Robison, supra note 4, at 1204.

362 70 WASH. & LEE L. REV. 341 (2013)

C. Advantages and Disadvantages of Cloud Computing

Moving more services onto the cloud has many promises and pitfalls. It is possible that the future success of cloud services will depend on how these advantages and disadvantages balance with each other and, more importantly, with the public’s expectations.83

Advantages of the cloud paradigm include data preservation,84 high levels of expertise on the part of cloud service providers,85 scalability,86 affordability,87 and availability.88 Additionally, some studies have shown that businesses that adopt SaaS enjoy a return-on-investment of almost 600%.89 Cloud providers are benefited because they have control over content, can set access terms, and can also monitor usage statistics.90

83. Stylianou, supra note 44, at 606 (“In effect, the combination of the sensitive nature of information that cloud services usually attract, the lack of adequate security from cloud services, and the intensification of governmental intrusiveness, stands as an impediment to the spread of cloud services.”). Stylianou also suggests that if cloud services implemented stronger security measures, like encrypting stored data, such changes could make cloud services more attractive to business customers. Id. at 609.

84. See Martin, supra note 44, at 294 (describing the benefit of being able to access applications and data from anywhere at any time).

85. Id.; Stylianou, supra note 44, at 603. 86. See Cascia, supra note 17, at 888 (citing the Department of Education’s

position that the scalability of cloud-based IT services would help schools cut costs); Jiang, supra note 48, at 413; Martin, supra note 44, at 294 (stating that cloud computing offers rapid and intelligent resource adjustment as well as economies of scale); Wittow & Buller, supra note 7, at 5 (noting that cloud computing allows a system’s capacity and capability to be increased without additional infrastructure or personnel investments). Wittow and Buller cite the example of Animoto, which went from 25,000 users to 250,000 users over the course of just three days and was able to keep pace with this very high rate of growth by acquiring more virtual servers. Id. at 5–6. The scalability advantage works both ways, allowing small companies to easily expand their technological resources, and allowing downsizing companies to easily cut unnecessary IT costs. Rhodes & Kunis, supra note 23, at 31.

87. Barnhill, supra note 48, at 640–41; Martin, supra note 44, at 289; Soghoian, supra note 5, at 366.

88. Jiang, supra note 48, at 413; Soghoian, supra note 5, at 366. 89. Martin, supra note 44, at 289 90. See Jiang, supra note 48, at 413; see also Soghoian, supra note 5, at

364–65 (listing the ability to terminate user access and make sure that users are always running the current software version as two advantages of the cloud

INFORMATION PRIVACY AND DATA CONTROL 363

These additional advantages for cloud providers also make cloud services attractive to copyright holders because the control exercised by the cloud provider can provide additional security and protect the copyright holder from infringement.91

There are also many disadvantages to the cloud paradigm, and many of these disadvantages arise in part because of consumers’ loss of control over data. Because consumers are entrusting their data to a third party, they are relying on that third party to adequately secure the information,92 have the services and data available at all times,93 and allow the consumer to move their information between providers freely,94 all in a context in which it is unclear how modern privacy law (including the Fourth Amendment and laws related to confidentiality) may

to the service provider). 91. See Jiang, supra note 48, at 422; Soghoian, supra note 5, at 364–65

(noting the value of the cloud for helping content owners better protect copyrights and trade secrets).

92. See Soghoian, supra note 5, at 374 (“[N]early all [] leading cloud providers offer products that are by default vulnerable to snooping, account hijacking, and data theft by third parties.”). Soghoian suggests that the reason that hackers are a threat to users of cloud services is because cloud providers have not yet adopted strong encryption technologies. Id. at 361. Businesses are likely to be very concerned about the potential security issues of the cloud, so they will have to balance the financial benefits of moving to the cloud against the costs of data security like encryption and key management. Couillard, supra note 42, at 2217.

93. See Kattan, supra note 8, at 623 (explaining how cloud computing creates dependency); Martin, supra note 44, at 294 (describing the benefit of being able to access applications and data from anywhere at any time). While cloud services strive for reliability, the technology is still developing and thus is still very susceptible to human error and programming bugs, like the leap day bug that caused Microsoft’s Azure service to be unavailable all day on February 29, 2012. Bill Laing, Summary of Windows Azure Service Disruption on Feb 29, 2012, WINDOWS AZURE TEAM BLOG (Mar. 9, 2012, 6:03 PM PST), http://blogs.msdn.com/b/windowsazure/archive/2012/03/09/summary-of- windows-azure-service-disruption-on-feb-29th-2012.aspx (last visited Feb. 3, 2013) (on file with the Washington and Lee Law Review).

94. Martin, supra note 44, at 297–98; see also Kattan, supra note 8, at 623 (noting that a customer who moves data storage and processing onto the cloud may have difficulty if he later decides to revert to the PC model). Martin notes that this lock-in problem is likely to not apply to IaaS because a customer of an IaaS provider will typically have everything on a virtual machine over which the customer can exercise full control. Martin, supra note 44, at 294.

364 70 WASH. & LEE L. REV. 341 (2013)

apply.95 Another disadvantage is related to the risk of loss. If a provider fails to secure data and a consumer’s information is compromised, the risk of loss is likely to fall on the consumer rather than the cloud service provider.96

In this Article, we emphasize the need for data control in the cloud, which we define as consisting of the ability to withdraw data (data withdrawal) and move data to a new location (data mobility). We argue that data control is essential for meaningful consumer choice. Consumers will inherently have less control over data stored in the cloud,97 but being able to choose (and switch to) providers that are more reliable or that offer stronger security measures is important for preserving consumer

95. See Lanois, supra note 18, at 44 (citing a publication of the World Privacy Forum). Privacy is likely to be especially important to consumers in the context of electronic health records. See Colin P. McCarthy, Note, Paging Dr. Google: Personal Health Records and Patient Privacy, 51 WM. & MARY L. REV. 2243, 2253 (2010) (discussing the potential problems of personal health records). These concerns are not just limited to health services. Confidentiality is a significant concern to a number of other professions when considering the adoption of cloud services as well. See Cascia, supra note 17, at 884 (noting that outsourcing IT management to third parties may make it more difficult for schools to make sure that the personal information of students remains private); Martin, supra note 44, at 295. Martin mentions the legal field by name as one industry that should be hesitant at this point when considering whether to use cloud services in support of its practices. Id. at 300. It is also unclear how the Fourth Amendment will apply to information held by third party cloud service providers. See id. at 295–96; see also Soghoian, supra note 5, at 361 (noting that cloud computing leaves users vulnerable to invasions of privacy by the government, resulting in “evisceration of traditional Fourth Amendment protections of a person’s private files and documents”). Martin also notes concerns that the federal statute governing electronic messaging may be difficult or unable to apply to modern technology. Martin, supra note 44, at 295– 96.

96. See Soghoian, supra note 5, at 378–79 (discussing why cloud computing providers have little incentive to protect users); see also infra Part IV.A (discussing contents of TOS agreements, including explicit limitations on providers’ legal liability).

97. See Kattan, supra note 8, at 623 (noting the customer’s dependence on cloud service providers to protect the customer’s data); Martin, supra note 44, at 289 (noting customers’ lack of control over data and the security practices of the cloud vendor); Stylianou, supra note 44, at 595 (explaining that some private data will be transferred away from the user’s immediate physical control); Wittow & Buller, supra note 7, at 6 (noting the lack of control that users have over data in the cloud and the importance that the user be able to trust the cloud service provider).

INFORMATION PRIVACY AND DATA CONTROL 365

autonomy. Currently, there are systemic limitations to meaningful choice. SaaS customers may experience lock-in problems because a cloud provider may store the customer’s information in a format unique to the cloud provider and thus make it difficult for the customer to switch cloud providers later.98 This control over content also leads to some concerns about private censorship. Werbach notes the existence of concerns over cloud services having too much power to censor controversial causes, such as when Amazon Web Services dropped Wikileaks as a customer.99

D. Cloud Computing Legal Issues

For our purposes, there are two important categories of legal issues raised in the context of cloud computing: data use and procedural issues. Data use issues could include the use of both public and private information, thus our use of the term “data use” also includes privacy concerns, examined in more detail below. Procedural issues relating to cloud computing can include E-Discovery and jurisdiction questions. The appropriate degree of regulation is also in controversy, so even if we could identify all of the possible legal issues related to cloud computing, it may prove difficult to effectively regulate the industry.100

One data use issue is the problem of “scraping,” specifically the question of how courts should deal with the unauthorized, automated collection of information by, for example, auction services that list relevant auctions in one search across multiple

98. Martin, supra note 44, at 297–98; see also Kattan, supra note 8, at 623 (noting that a customer who moves data storage and processing onto the cloud may have difficulty if they later decide to revert to the PC model). Martin notes that this lock-in problem is likely to not apply to IaaS because a customer of an IaaS provider will typically have everything on a virtual machine over which the customer can exercise full control. Martin, supra note 44, at 294.

99. See Werbach, supra note 8, at 1820 (“From a broader perspective, though, the rise of cloud computing changes a default assumption that data will be within the control of the user.”). 100. See id. at 1766 (referring to network neutrality as the “final hurrah” of the regulatory framework under the Telecommunications Act, as views of the industry have shifted “from regulated monopoly to managed competition within defined industry segments”).

366 70 WASH. & LEE L. REV. 341 (2013)

auction websites.101 Claims relating to scraping have been brought based on the Computer Fraud and Abuse Act (CFAA),102 the tort of trespass, and a “hot news” theory.103 An analysis of these options and whether they provide adequate means of redress for companies whose data is mined poses an interesting research question for future research. Our concern about the privacy of individual users also makes us question whether recourse for “scraping” might also apply to protect individuals whose data is mined without their consent, though this is outside the scope of our research.

1. Privacy

Our primary focus in this Article is on the implications of cloud computing and corresponding privacy agreements on personal privacy. There are several legal issues relating to privacy and cloud computing, including the uncertain applications of the Health Information Portability and Accessibility Act (HIPAA),104 the Stored Communications Act,105 and the Fourth Amendment, especially the third-party doctrine of Fourth Amendment jurisprudence.106 If a legal regime is put into place to provide stronger privacy protections, it is unclear 101. See Wittow & Buller, supra note 7, at 8–9 (discussing how the scraping issue impacts cloud computing). 102. 18 U.S.C. § 1030 (2006). 103. See id. (discussing how the scraping issue impacts cloud computing). 104. See Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, 110 Stat. 1936 (codified at 29 U.S.C. § 1181 et seq.; 42 U.S.C. §§ 300gg, 1320d et seq. (2006)); Denny, supra note 46, at 239–40 (“Yet another statutory hurdle to cloud computing in the United States is the Health Insurance Portability and Accountability Act (‘HIPAA’).”). 105. See Electronic Communications Privacy Act of 1986, Pub. L. No. 99-508, 100 Stat. 1848 (codified as amended in scattered sections of 18 U.S.C.); Werbach, supra note 8, at 1819 (noting that a search warrant is required to access e-mail stored on a user’s hard drive, but that under the Electronic Communications Privacy Act, a lower standard would be applied if that same e- mail had been stored on Google’s Gmail servers for more than six months). 106. See Stylianou, supra note 44, at 596–97 (“[I]t is still debatable whether access to online stored data should be considered a search . . . or whether by communicating data to a remote server the subject is considered to have knowingly exposed the information.”).

INFORMATION PRIVACY AND DATA CONTROL 367

whether data collection should be addressed based on the quantity collected or the type collected, and there is also a lot of uncertainty about how to address the transfer of data between countries with different privacy laws.107

Many aspects of the privacy debate rely on an understanding of privacy theories. Several things influence privacy protections online, including social norms, website architecture, and the law.108 Some note that there are societal obstacles to strengthening privacy protections online, arguing that the younger generation values the interconnectedness and low cost of cloud services more than they value their personal privacy.109 Werbach asserts that the range of concerns about cloud providers’ information practices goes beyond our current concept of “privacy,” and suggests referring to it as “information governance.”110 In lieu of creating a new category, Solove suggests revising the concept of “privacy” to encompass these concerns.111 It is likely that there will be an increase in public policy activity in this area in the near future,112 underscoring the importance and timeliness of this topic. A significant problem that arises when dealing with technologically sophisticated policy issues, however, is that some judges and other policy makers may be ill-

107. See id. at 595–96 (discussing whether access to cloud data is a search). 108. See Michael Birnhack & Niva Elkin-Koren, Does Law Matter Online? Empirical Evidence on Privacy Law Compliance, 17 MICH. TELECOMM. TECH. L. REV. 337, 339–41 (2011) (“Certain non-legal mechanisms can affect online privacy and shape the power of individuals to control their personal data.”). 109. See Robison, supra note 4, at 1237–38 (“[Y]ounger users are more likely to embrace the Internet’s interconnectedness and convenience by participating in social networking, sharing digital content, and using cloud services.”). But see Chris Hoofnagle, Jennifer King, Su Li, & Joseph Turow, How Different Are Young Adults from Older Adults When It Comes to Information Privacy Attitudes & Policies? 20 (Working Paper Series, 2010), available at http://ssrn.com/abstract=1589864 (noting that their study results failed to show the expected significant differences between the behavior of young adults and older adults online with regard to privacy). 110. Werbach, supra note 8, at 1833. 111. See generally Daniel J. Solove, A Taxonomy of Privacy, 154 U. PA. L. REV. 477 (2006) [hereinafter Solove, Taxonomy] (setting forth a new taxonomy for the understanding of information privacy). 112. See Werbach, supra note 8, at 1835 (“Public policy activity in this area seems bound to increase.”).

368 70 WASH. & LEE L. REV. 341 (2013)

informed about the underlying technology, leading these policy makers to hesitate when faced with current issues.113

There may also be legal harms arising from data gathering practices. Richards discusses the “database problem,” in which there are very large databases that make it efficient and valuable for businesses to use consumer information, but the legal rights of the consumers in these databases are unresolved.114 Stylianou acknowledges that cloud computing does result in more private information being collected and this could be harmful, but concludes that most of this increase in information collection happens voluntarily, and that the compromises in privacy appear to be no greater than necessary for the delivery of cloud services.115 Some were critical of the settlement in Authors Guild v. Google116 for its lack of restrictions concerning data gathering, arguing that privacy issues should be addressed in the settlement to protect people from having their reading choices readily available to third parties.117

2. Jurisdiction

Jurisdiction issues concerning a court’s ability to hear a claim will arise in the context of the cloud for two reasons: (1) the

113. For example, in the oral arguments of City of Ontario v. Quon, Justices Roberts and Scalia noted their confusion as to how wireless communications are transmitted, with both indicating that they were not aware that these messages were inherently processed by a third party. See Transcript of Oral Arguments at 48–50, City of Ontario v. Quon, 130 S. Ct. 2619 (2010) (No. 08-1332), http://www.supremecourt.gov/oral_arguments/argument_transcripts/08-1332. pdf (exemplifying the confusion of Justices Roberts and Scalia as to how wireless communications are transmitted). 114. Neil M. Richards, Reconciling Data Privacy and the First Amendment, 52 UCLA L. REV. 1149, 1150, 1156–65 (2005). 115. See Stylianou, supra note 44, at 594–96 (discussing voluntary information collection).

116. Authors Guild v. Google, Inc., 770 F. Supp. 2d 666 (S.D.N.Y. 2011). 117. See Denny, supra note 46, at 238–39 (“Much of the recent debate surrounding cloud computing and privacy stems from a settlement in Authors Guild v. Google Inc.”); Wittow & Buller, supra note 7, at 7 (“Privacy concerns also have been raised in the context of the pending Authors Guild v. Google [Inc.] book search settlement, which creates a cloud-based database of searchable books.”).

INFORMATION PRIVACY AND DATA CONTROL 369

lack of borders in cyberspace; and (2) the vast differences between privacy laws in different locations.118 If a conflict arises with respect to a cloud service, where could that conflict be resolved? If there is a conflict between a customer and cloud provider within the United States, the customer might be bound by arbitration language in a TOS agreement, or by a choice of law or venue clause.119

But what about more geographically vague situations? Some discussions about jurisdiction assume that the applicable law will be determined by the physical location of the data, but this information is often unknown to the customer.120 Sometimes, a defendant may claim that he has insufficient contacts with the forum state for a particular court to exercise jurisdiction.121 Because of these jurisdictional problems, it is important that the TOS agreements for cloud services specify where data will be stored and which laws will apply.122 Otherwise, the uncertainties related to jurisdiction in the cloud may chill some online activity by discouraging people from engaging in electronic commerce.123

Approaches to informational privacy can vary between nations, and the United States as a whole has a privacy law

118. See Stylianou, supra note 44, at 596 (discussing the transfer of data between countries). 119. See Christopher Kuner, Data Protection Law and International Jurisdiction on the Internet (Part 1), 18 INT’L J. L. & INFO. TECH. 176, 178 (2010) [hereinafter Kuner, Part 1] (noting the overlap between choice of law and jurisdiction). 120. See Lanois, supra note 18, at 44 (“[D]ata that might be secure in one country may not be in another, and in many cases, users of cloud services do not know where their information is being held.”); Stylianou, supra note 44, at 602 (“Because different national laws accord different levels of protection to personal and private information, it is important that users know where their data is stored.”). 121. See Pinguelo & Muller, supra note 46, at 1 (“It is apparent that the use of a cloud can potentially increase the number of ‘contacts’ a party is found to have for personal jurisdiction purposes, and thus raise its exposure to lawsuits in multiple forums.”). 122. See Denny, supra note 46, at 239 (“According to the Privacy Authors, if readers were worried that information about their reading habits could be disseminated to the government, divorcing spouses, or other interested third parties, these readers would be less likely to view books on controversial topics.”). 123. Kuner, Part 1, supra note 119, at 178.

370 70 WASH. & LEE L. REV. 341 (2013)

regime that is much less protective of personal privacy than that of the European Union.124 Can a court in the European Union exercise jurisdiction over a U.S. company that violates the personal privacy of EU citizens? Generally, the answer will be yes, based on principles of jurisdiction.

In the international context, jurisdiction can be described as the right of one country to regulate actions that are not solely conducted within that nation’s borders.125 Three categories of international jurisdiction are legislative jurisdiction, under which a nation’s laws can apply to cases with a foreign element; adjudicative jurisdiction, when the nation’s courts have the power to try cases involving a foreign element; and enforcement jurisdiction, when the nation has the power to act in another nation’s territory to enforce its own laws.126

Exercise of adjudicative jurisdiction may be justified when the acts were committed or completed within the nation’s territory, when the perpetrator or victim was a citizen of that nation, when the act has effects within that nation (a justification that is commonly criticized for its open-endedness), or when the act jeopardizes the nation’s sovereignty.127 Because adjudicative jurisdiction can be found when the victim of a wrong is a citizen of the adjudicating nation, this means that service providers in

124. See Stylianou, supra note 44, at 597 (noting that the use of the Safe Harbor agreement allows U.S companies to process the data of European citizens). This agreement is in lieu of a privacy law overhaul to make the U.S. approach to privacy match the approach of the EU. Id. 125. See Kuner, Part 1, supra note 119, at 178–79 (defining international jurisdiction as “the State’s right under international law to regulate conduct in matters not exclusively of domestic concern.” (citation omitted)). 126. See id. at 184 (discussing categories of jurisdiction). Generally, direct enforcement of one nation’s laws in another nation is not permitted, though a nation may apply its domestic law to conduct that occurs elsewhere, provided recognized legal grounds exist for doing so. Id. at 185. Enforcement jurisdiction, however, is rarely found. See Christopher Kuner, Data Protection Law and International Jurisdiction on the Internet (Part 2), 18 INT’L J. L. & INFO. TECH. 227, 232 (2010) [hereinafter Kuner, Part 2] (“[A] State may not carry out an investigation in another State, if the purpose is to enforce its own administrative, criminal, or fiscal law. These restrictions apply even if the persons or entities in the second State consent to the first State’s enforcement actions.”). 127. See Kuner, Part 1, supra note 119, at 188–90 (examining adjudicative jurisdiction in detail).

INFORMATION PRIVACY AND DATA CONTROL 371

the United States must act carefully to comply with the privacy laws of other jurisdictions when a customer is a foreign citizen.

E. Calls for Action in the Cloud

The current legal regime applicable to cloud computing has drawn a lot of criticism from organizations that want the law to consider current technologies.128 Legislative reform will likely be necessary to address the new environment created by cloud computing, but such reform will need to take into account many different concerns.129 For example, reforms will need to take data protection into consideration because customers are likely to want data stored in the cloud to be protected the same as it would be on the customer’s own tangible storage devices.130

The Electronic Communications Privacy Act (ECPA)131 is examined in detail below in Part III.B.2. Several institutions have urged lawmakers to amend the ECPA. Microsoft proposed the Cloud Computing Advancement Act (CCAA)132 in 2010, and the Center for Democracy and Technology has also recommended

128. See Kattan, supra note 8, at 645 (suggesting revision of the Stored Communications Act and referencing the position of the nonprofit Digital Due Process that the ECPA should be modernized and clarified); Martin, supra note 44, at 286 (noting recommendations made by Microsoft and the Center for Democracy and Technology). Digital Due Process is an organization that is focused on modernizing the approaches of law enforcement to electronic data, and they encourage the reformation of the ECPA to take into account recent and emerging technologies. Lanois, supra note 18, at 45. 129. See Werbach, supra note 8, at 1826 (“The solution to the contemporary challenges of cloud computing likely requires some legislative reform in addition to FCC action.”). 130. See Couillard, supra note 42, at 2205–06 (“Despite the shift in Internet usage, users expect their information to be treated the same on this virtual cloud as it would be if it were stored on their own computer, phone, or iPod.”). 131. See Electronic Commc’n Privacy Act of 1986, Pub. L. No. 99-508, 100 Stat. 1848 (codified at 18 U.S.C. §§ 2510–2522, 2701–2712 (2006)). 132. See Brad Smith, Gen. Counsel, Microsoft Corp., Speech at the Brookings Institute Policy Forum: Cloud Computing for Business and Society (Jan. 20, 2010) available at http://download.microsoft.com/download/C/0/ 0/C00D24A5-A686-4109-9DB8-14A29E058069/Building_Confidence_in_the_Clo ud_General_Counsel_Brad_Smith_Brookings_Speech.docx.

372 70 WASH. & LEE L. REV. 341 (2013)

legislative action to address cloud computing issues.133 The CCAA would strengthen the privacy protections of the ECPA, unifying the concepts of “electronic communications service” and “remote computing service,” and would also enhance the Computer Fraud and Abuse Act (CFAA)134 by presuming a loss of $500 for each count of unauthorized access.135 The CDT proposal, on the other hand, focuses more on civil liberties, urging Congress to amend the ECPA to require probable cause before a seizure of online information can be executed without notice.136

1. Transparency and Control

Other calls for revisions of the system have focused on the need for transparency.137 To say that practices of cloud providers should be transparent about information use means that customers should be well-informed of what companies are doing with the customers’ personal data. In examining Internet issues, the FCC maintains that transparency is important for consumer protection in the telecommunications context.138 Martin suggests that when addressing cloud computing concerns, it will be important to ensure that the practices of cloud providers are understood and that customers have the ability to exercise control over their data.139 Transparency could have additional advantages by encouraging cloud platforms to be more interoperable, allowing for greater data portability.140 If the

133. See Martin, supra note 44, at 286 (discussing recently proposed legislation, standards, and governing principles).

134. 18 U.S.C. § 1030 (2006). 135. Martin, supra note 44, at 309–10.

136. Id. at 310. 137. See, e.g., Werbach, supra note 8, at 1767 (“To achieve its public interest mandates, the FCC must consider . . . [and examine] transparency.”). 138. See id. at 1837 (discussing the FCC’s adoption of a transparency mandate in its Open Internet Order). 139. See Martin, supra note 44, at 286 (“Any solution needs to incorporate guarantees that data owners would be able to gain control of their data in a usable form should their service providers become inoperable.”). 140. See Werbach, supra note 8, at 1839 (noting the ancillary benefits of transparency).

INFORMATION PRIVACY AND DATA CONTROL 373

industry takes an approach to personal data that focuses on the ability of users to control their data, transparency may prove beneficial and alleviate some of the information asymmetry between cloud providers and their customers.141

Industry leaders are conscious of transparency concerns. A consortium of industry leaders put forth the Open Cloud Manifesto, advocating the use of standardization and collaboration to develop an “open cloud.”142 The Open Cloud Manifesto focuses on transparency and interoperability between cloud providers, with one of the goals being to minimize the lock- in issue.143 If implemented, this manifesto might mitigate some of the data control issues that we are concerned about in this Article.

It could also facilitate transparency for users to be proactive about seeking information. The European Network and Information Security Agency (ENISA) suggests that users ask cloud providers about things like the provider’s personnel security procedures, use of subcontractors, operational security procedures, disaster recovery protocol, and miscellaneous legal issues like data location, jurisdiction issues, and how the customer can recover data upon termination of the service.144 We posit that users who are given the right to control their information are likely to be more involved in the process of controlling their own data.

F. Cloud Services in Different Industries

There are a number of professions in which practitioners are required to handle client or patient data with care, making data protection in these sensitive industries very important. One of these industries is the legal field, in which attorneys and their staff

141. Schwartz & Solove, supra note 3, at 1882. 142. Martin, supra note 44, at 286.

143. See id. at 310 (discussing the Open Cloud Manifesto in detail). 144. See id. at 311 (examining the European Network and Information Security Agency report, which recommends a series of user procedures that can be employed for self-protection).

374 70 WASH. & LEE L. REV. 341 (2013)

are required to take great steps to protect client confidentiality.145 Still, some state bar associations may recognize the convenience of cloud services and may be inclined to approve of attorney practices in which client information is stored using public cloud services.146 Martin, however, suggests that the ABA should establish ethical guidelines relating to topics like document storage, e-mail, and confidentiality in the cloud.147

In the health care industry, there has been a shift toward using electronic medical records (EMR) as an alternative to paper records.148 A more recent push is toward maintaining personal health records (PHR) online through services like Epic, Microsoft’s HealthVault, and Google Health, in which the patient will have control over her records.149 However, PHR providers do not fall within one of the statutory categories of “covered entities” under HIPAA, so the storage and transmission of personal health information is not currently regulated by HIPAA or any of the related rules.150

In addition to control, security of health information is also of paramount concern. McCarthy notes that the Health Information Technology for Economic and Clinical Health Act151 requires users to be notified if there is a breach threatening PHR data,

145. MODEL RULES OF PROF’L CONDUCT R. 1.6, 5.3 (1983) (discussing confidentiality and the duties of nonlawyer staff, respectively). 146. See Martin, supra note 44, at 300–01 (citing a New York bar opinion about using e-mail services that scan e-mail content to generate targeted advertising). 147. See id. at 313 (“[T]he ABA should move quickly to establish ethical guidelines for lawyers who use cloud computing services . . . [including] document storage, e-mail, collaboration, due diligence for confidentiality, and breach notification related to cloud services.”). 148. McCarthy, supra note 95, at 2250–51. EMRs, however, are generally limited to that specific provider, with no sharing of information. See id. (“Each health care provider maintains its own EMRs—physician’s offices maintain their EMRs, hospitals maintain their EMRs, and so on.”). 149. See id. at 2245, 2251–54 (“Until now, patients could request a copy of her [sic] medical records from their health care providers but have not had the opportunity to control them in the way that PHRs offer.”).

150. Id. at 2258. 151. Health Information Technology for Economic and Clinical Health Act, Pub. L. 111–5, Div. A, Title XIII, Div. B, Title IV, 123 Stat. 226, 467 (2009) (codified in scattered sections of 42 U.S.C.).

INFORMATION PRIVACY AND DATA CONTROL 375

and that the HHS has also promulgated a rule that requires PHR vendors to comply with notification requirements if a breach occurs.152 The increased vulnerability of data in the cloud necessitates strong protections for PHR, like encryption, password protection, and authentication requirements.153 One of our recommendations for regulating cloud providers focuses on establishing baseline standards for data protection, which could help address some of these issues.

This is the end of the excerpt of this article. The full article can be found on the Moodle.

  • Washington and Lee Law Review
    • 1-1-2013
  • Information Privacy and Data Control in Cloud Computing: Consumers, Privacy Preferences, and Market Efficiency
    • Jay P. Kesan
    • Carol M. Hayes
    • Masooda N. Bashir
      • Recommended Citation