Open Access. Powered by Scholars. Published by Universities.®

Privacy Law Commons™

Open Access. Powered by Scholars. Published by Universities.®

University of Washington School of Law

Discipline
Keyword
Publication Year
Publication
Publication Type

Articles 1 - 30 of 120

Full-Text Articles in Privacy Law

A Legal Transplant Failure In The Ai Age, Xuan-Thao Nguyen Apr 2026

A Legal Transplant Failure In The Ai Age, Xuan-Thao Nguyen

Articles

Thailand positions itself as the new AI-driven innovation hub in the Southeast Asia region as Big Tech companies invest billions in building new data centers to power the AI transformations in all sectors in Thailand. An integral part of Thailand’s new ambition is the legal transplant of personal data protection law from Europe. The transplant, however, is of form, not substance, as this Article illustrates the failure through in-depth analysis of Thailand’s Personal Data Protection Act and provides evidence of rampant violations and noncompliance by the largest ecommerce conglomerate and SMEs. This Article offers suggestions for Thailand to realign its …


Allocating Data Protection Duties The Chinese Way Jan 2026

Allocating Data Protection Duties The Chinese Way

Washington International Law Journal

Abstract: China has been enacting data protection laws with distinctive features at an unprecedented pace, which makes it necessary to update existing studies on the Chinese approach to data protection. Unlike its predecessors, this Article focuses on developing a structured approach to dissecting the Chinese regime, especially the Personal Information Protection Law and latest case law. It analyzes how the laws allocate responsibilities among the three major parties involved in data protection—individual data subjects, data controllers, and regulators—and draws comparisons with European Union (EU) laws that inspired the Chinese laws. It argues that the way Chinese laws allocate data …


Forget Me Not? Machine Unlearning’S Implications For Privacy Law, Jevan Hutson, Cedric Whitney, Jay T. Conrad Jan 2026

Forget Me Not? Machine Unlearning’S Implications For Privacy Law, Jevan Hutson, Cedric Whitney, Jay T. Conrad

Articles

Generative AI systems are increasingly relied on and are already actively reshaping how we think about privacy and data protection law. Models ingest and process vast amounts of personal and sensitive data, challenging assurances of compliance with legal frameworks like the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) with increasing intensity. Machine unlearning is an emerging tool in practitioners’ attempts to address these challenges: the act of selectively removing or suppressing specific data, such as personal data that a data subject requests be deleted, from AI models as means of complying with legal obligations or …


Shielding Freedoms: State Noncooperation In Hunts For Evidence And People, Mary D. Fan Dec 2025

Shielding Freedoms: State Noncooperation In Hunts For Evidence And People, Mary D. Fan

Washington Law Review

The nation is fracturing into a patchwork of rights and punishment. What some states and localities safeguard as rights, other jurisdictions are criminalizing and punishing. As the divides in rights and punishment deepen, some states are becoming sanctuaries for freedoms penalized elsewhere and enacting shield laws prohibiting cooperation with criminalization and punishment states. A prime example is shield laws protecting people seeking to exercise reproductive rights or obtain gender-affirming care. Major jurisdictions for healthcare and technology-related businesses, such as Washington, California, New York, and Massachusetts, have enacted shield laws that prohibit law enforcement and companies from complying with subpoenas seeking …


Unravelling The Metaverse Matrix: Navigating Privacy Protection Within Modelling And Simulation Platforms, Eugenia Georgiades, James Birt Apr 2025

Unravelling The Metaverse Matrix: Navigating Privacy Protection Within Modelling And Simulation Platforms, Eugenia Georgiades, James Birt

Washington Journal of Law, Technology & Arts

This article examines how personal data are regulated in emerging modelling and simulation environments, including computer games, mobile apps, and digital twin platforms. This article centers on a specific type of simulated and modelling environment, namely the metaverse. This article considers the privacy issues that arise when people subscribe to and participate in modelling and simulation platforms where vast amounts of data are collected, disclosed and stored. Such data may be vulnerable to misuse by the platform and third parties. This article considers Meta’s “horizons metaverse” platform as a case study for an immersive modelling and simulation platform. It examines …


Co-Constructing The Future Of Digital Intimacy, Chris Geeng, Lucy Qin, Allison Mcdonald, Amna Batool, Diana Freed, Oliver L. Haimson, Jevan Hutson, Elissa M. Redmiles, Zahra Stardust, Miranda Wei, Douglas Zytko Jan 2025

Co-Constructing The Future Of Digital Intimacy, Chris Geeng, Lucy Qin, Allison Mcdonald, Amna Batool, Diana Freed, Oliver L. Haimson, Jevan Hutson, Elissa M. Redmiles, Zahra Stardust, Miranda Wei, Douglas Zytko

Articles

The Internet, artificial intelligence, and other emerging technologies have transformed the way humans can interact with each other and express romance, sex, and other forms of intimacy. Digital intimacy, including online dating, sexual/intimate content sharing, online sex work, and romantic chatbots, has grown ubiquitous. This can both be a source of great joy, such as when connecting remote partners and supporting sexual self-expression, and a source of harms, including but not limited to image-based sexual abuse, deepfakes, location privacy violations, and technology-enabled intimate partner violence. As new technologies continue to transform digital intimacy, this workshop aims to create a sex-positive …


The Privacy Act Of 1974: The American Bill Of Rights On Data And Its Unfinished Business, Dongsheng Zang Dec 2024

The Privacy Act Of 1974: The American Bill Of Rights On Data And Its Unfinished Business, Dongsheng Zang

Articles

In the midst of the artificial intelligence (“AI”) revolution and the debates around it in 2023, this Article proposes to revisit the history of the Privacy Act of 1974, a federal statute that attempted to revolutionize the notion of privacy in response to automated data processing in the computer age. By recognizing that an individual should have the right to control data about herself, the 1974 Act went beyond the Warren-Brandeis framework of privacy based on tort law—the 1974 Act was essentially an American Bill of Rights on data.

The Article first tracks the conceptual development of this new idea …


Client Confidentiality As Data Security, Jonah E. Perlin Oct 2024

Client Confidentiality As Data Security, Jonah E. Perlin

Washington Law Review

The duty of confidentiality has been a cornerstone of the attorney-client relationship for more than four centuries. Historically, this duty was not difficult to discharge. All a lawyer had to do to comply was not affirmatively share client information in public without consent. But that has all changed. The same technologies that provide unprecedented benefits of authorized access by lawyers and their clients create unprecedented risks of unauthorized access by others. As a result, although the duty of confidentiality was once synonymous with a duty to keep client confidences secret, today the duty necessitates that lawyers keep client confidences secure …


When Ai Remembers Too Much: Reinventing The Right To Be Forgotten For The Generative Age, Cheng-Chi Chang Jun 2024

When Ai Remembers Too Much: Reinventing The Right To Be Forgotten For The Generative Age, Cheng-Chi Chang

Washington Journal of Law, Technology & Arts

The emergence of generative artificial intelligence (AI) systems poses novel challenges for the right to be forgotten. While this right gained prominence following the 2014 Google Spain v. Gonzalez case, generative AI’s limitless memory and ability to reproduce identifiable data from fragments threaten traditional conceptions of forgetting. This Article traces the evolution of the right to be forgotten from its privacy law origins towards an independent entitlement grounded in self-determination for personal information. However, it contends the inherent limitations of using current anonymization, deletion, and geographical blocking mechanisms to prevent AI models from retaining personal data render forgetting infeasible. Moreover, …


Big Data Searches And The Future Of Criminal Procedure, Mary Fan Apr 2024

Big Data Searches And The Future Of Criminal Procedure, Mary Fan

Articles

This Article proceeds in three parts. Part I illuminates the nostalgic Luddism that influences Fourth Amendment jurisprudence and the challenges posed by evolving technologies to this dominant lens. This Part explains the operation of geofence and keyword warrants and how their power to crack cold cases by unidentified perpetrators both tempt and terrify. The confusion in the courts over the constitutionality of geofence and keyword warrants is emblematic of the larger challenges of the Romantic Luddism in Fourth Amendment originalism that has grown in influence over the decades.

Part II frames and theorizes the concepts of collateral impact and collateral …


Speaking Back To Sexual Privacy Invasions, Brenda Dvoskin Mar 2024

Speaking Back To Sexual Privacy Invasions, Brenda Dvoskin

Washington Law Review

Many big players in the internet ecosystem do not like hosting sexual expression. They often justify these bans as a protection of sexual privacy. For example, Meta states that it removes sexual imagery to prevent the nonconsensual distribution of sexual images. In response, this Article argues that banning digital sexual expression is counterproductive if the aim is to alleviate the harms inflicted by sexual privacy losses.

Contemporary sexual privacy theory, however, lacks analytical tools to explain why nudity bans harm the interests they intend to protect. This Article aims at building those tools. The main contribution is an invitation to …


The Consumer Bundle, Shelly Kreiczer-Levy Mar 2024

The Consumer Bundle, Shelly Kreiczer-Levy

Washington Law Review

Can property law have a consumer protection purpose? One of the most important consumer law concerns today is the limited control consumers have over the digital assets and software-embedded products they purchase. Current proposals for reform focus on classifying the transaction as either license or sale and rely mostly on contract law and consumer protection regulation with a few calls for restoring ownership rights. This Article argues that property law can protect consumers by establishing a minimum bundle of rights for consumers: the “consumer’s bundle.” Working with property theory and an analysis of property values, this Article explains the importance …


The Kids Are Not Alright: Negative Consequences Of Student Device And Account Surveillance, Ashley Peterson Mar 2024

The Kids Are Not Alright: Negative Consequences Of Student Device And Account Surveillance, Ashley Peterson

Washington Law Review

In recent years, student surveillance has rapidly grown. As schools have experimented with new technologies, transitioned to remote and hybrid instruction, and faced pressure to protect student safety, they have increased surveillance of school accounts and school-issued devices. School surveillance extends beyond school premises to monitor student activities that occur off-campus. It reaches students’ most intimate data and spaces, including things students likely believe are private: internet searches, emails, and messages. This Comment focuses on the problems associated with off-campus surveillance of school accounts and school-issued devices, including chilling effects that fundamentally alter student behavior, reinforcement of the school-to-prison pipeline, …


Distinguishing Privacy Law: A Critique Of Privacy As Social Taxonomy, María P. Angel, Ryan Calo Mar 2024

Distinguishing Privacy Law: A Critique Of Privacy As Social Taxonomy, María P. Angel, Ryan Calo

Articles

What distinguishes privacy violations from other harms? This has proven a surprisingly difficult question to answer. For over a century, privacy law scholars labored to define the elusive concept of privacy. Then they gave up. Efforts to distinguish privacy were superseded at the turn of the millennium by a new approach: a taxonomy of privacy problems grounded in social recognition. Privacy law became the field that simply studies whatever courts or scholars talk about as related to privacy.

Decades into privacy as social taxonomy, the field has expanded to encompass a broad range of information-based harms—from consumer manipulation to algorithmic …


Privacy Matters: Data Breach Litigation In Japan, Andrew M. Pardieck Feb 2024

Privacy Matters: Data Breach Litigation In Japan, Andrew M. Pardieck

Washington International Law Journal

In 1890, when Brandeis and Warren wrote The Right to Privacy, Japan did not have a word for privacy. Today, it is closely guarded in Japan: the European Data Protection Board has found privacy protections in Japan “equivalent” to those in the EU. This research explores the evolution of privacy law in Japan, focusing on data breach and the legal rights and obligations associated with it. The writing is broken up into two parts: This article discusses private enforcement of privacy norms, as it is the courts that first established and continue to define privacy rights in Japan. A separate …


America's Next "Stop Model!": Model Deletion, Jevan Hutson, Ben Winters Jan 2024

America's Next "Stop Model!": Model Deletion, Jevan Hutson, Ben Winters

Articles

This Essay explores the emergence of model deletion- the compelled destruction or dispossession of certain data, algorithms, models, and associated work products created or shaped by illegal means- as a remedy, right, and requirement for harmful applications of Al and ML systems. Part I examines model deletion's emergence as a consumer protection remedy and its conception as a positive right and regulatory requirement. Part II considers the constellation of federal and state actors, such as federal and state enforcement agencies and legislative bodies, who might seek model deletion to address particular Al and ML harms. Part III underscores the need …


Safeguarding Taxpayer Data, Michael Hatfield Sep 2023

Safeguarding Taxpayer Data, Michael Hatfield

Articles

The Internal Revenue Service (IRS) collects more information on more individuals than any other government agency. The information is not only financial but personal, potentially including information about health care needs and decisions; the caregivers, disabilities, and foreign birth of children; the educational progress and felony convictions of students; and one’s religious and charitable associations. In acknowledging the vast quantity of information held by the IRS, and the necessity of taxpayers trusting tax administrators with their information, Congress provided greater protection for taxpayer information under the Internal Revenue Code (IRC) than it was provided under the Privacy Act. Congress obligated …


What You Don’T Know Will Hurt You: Fighting The Privacy Paradox By Designing For Privacy And Enforcing Protective Technology, Perla Khattar Jun 2023

What You Don’T Know Will Hurt You: Fighting The Privacy Paradox By Designing For Privacy And Enforcing Protective Technology, Perla Khattar

Washington Journal of Law, Technology & Arts

The persistence of the privacy paradox is proof that current industry regulation is insufficient to protect consumer’s privacy. Although consumer choice is essential, we argue that it should not be the main pillar of modern data privacy legislation. This article argues that legislation should aim to protect consumer’s personal data in the first place, while also giving internet users the choice to opt-in to the processing of their information. Ideally, privacy by design principles would be mandated by law, making privacy an essential component of the architecture of every tech-product and service.


Who Owns Data? Constitutional Division In Cyberspace, Dongsheng Zang Apr 2023

Who Owns Data? Constitutional Division In Cyberspace, Dongsheng Zang

Articles

Privacy emerged as a concern as soon as the internet became commercial. In early 1995, Lawrence Lessig warned that the internet, though giving us extraordinary potential, was “not designed to protect individuals against this extraordinary potential for others to abuse.” The same technology can “destroy the very essence of what now defines individuality.” Lessig urged that “a constitutional balance will have to be drawn between these increasingly important interests in privacy, and the competing interest in collective security.” Lessig envisioned that creating property rights in data would help individuals by giving them control of their data. As utopian as property …


Gone Fishing: Casting A Wide Net Using Geofence Warrants, Ryan Tursi Mar 2023

Gone Fishing: Casting A Wide Net Using Geofence Warrants, Ryan Tursi

Washington Law Review

Technology companies across the country receive requests from law enforcement agencies for cell phone location information near the scenes of crimes. These requests rely on the traditional warrant process and are known as geofence warrants, or reverse location search warrants. By obtaining location information, law enforcement can identify potential suspects or persons of interest who were near the scene of a crime when they have no leads. But the use of this investigative technique is controversial, as it threatens to intrude upon the privacy of innocent bystanders who had the misfortune of being nearby when the crime took place. Innocent …


Privacy And National Politics: Fingerprint And Dna Litigation In Japan And The United States Compared, Dongsheng Zang Jan 2023

Privacy And National Politics: Fingerprint And Dna Litigation In Japan And The United States Compared, Dongsheng Zang

Articles

Drawing cases from two related areas of law-fingerprint and DNA (deoxyribonucleic acid) data-this Article proposes a modified framework, built on the Balkin-Levinson emphasis on national politics: First, national politics understood as partisan rivalry cannot account for what I call doctrinal lock-in in this Article, where I will demonstrate that in different stages of American politics-the Lochner era, the New Deal era, and Civil Rights era-courts across the nation ruled predominantly in favor of public data collectors-state and federal law enforcement in fingerprint cases. From the 1990s, when DNA data became hot targets of law enforcement, the United States Supreme Court …


Beware What You Google: Fourth Amendment Constitutionality Of Keyword Warrants, Chelsa Camille Edano Dec 2022

Beware What You Google: Fourth Amendment Constitutionality Of Keyword Warrants, Chelsa Camille Edano

Washington Law Review

Many Americans have potentially had their privacy rights invaded through invisible, widespread police searches. In recent years, local and federal governments have compelled Google and other search engine companies to produce the personal information of users who have conducted a search query related to a crime. By using keyword warrants, the government can conduct a dragnet search for suspects, imposing suspicion on users and exposing their personal information. The keyword warrant is a symptom of the erosion of the Fourth Amendment protection against suspicionless searches. Not only is scholarship scarce on keyword warrants, but also instances of these warrants are …


Physiognomic Artificial Intelligence, Luke Stark, Jevan Hutson Aug 2022

Physiognomic Artificial Intelligence, Luke Stark, Jevan Hutson

Articles

The reanimation of the pseudosciences of physiognomy and phrenology at scale through computer vision and machine learning is a matter of urgent concern. This Article—which contributes to critical data studies, consumer protection law, biometric privacy law, and antidiscrimination law—endeavors to conceptualize and problematize physiognomic artificial intelligence (“AI”) and offer policy recommendations for state and federal lawmakers to forestall its proliferation.

Physiognomic AI, as this Article contends, is the practice of using computer software and related systems to infer or create hierarchies of an individual’s body composition, protected class status, perceived character, capabilities, and future social outcomes based on their physical …


Why Govern Broken Tools?, Ryan Calo Jan 2022

Why Govern Broken Tools?, Ryan Calo

Articles

In Assessing the Governance of Digital Contact Tracing in Response to COVID-19: Results of a Multi-National Study, Brian Hutler et al. ably compare two approaches to the governance of digital contract tracing (DCT). In this brief essay, I want to examine to what extent governance actually played a meaningful role in the failure of DCT. If DCT failed primarily for other reasons, then the authors’ normative suggestion to pursue “a new governance approach … for designing and implementing DCT technology going forward” may be misplaced.


Self-Control Of Personal Data And The Constitution In East Asia, Dongsheng Zang Jan 2022

Self-Control Of Personal Data And The Constitution In East Asia, Dongsheng Zang

Articles

No abstract provided.


The Hidden Harms Of Privacy Penalties, Mary D. Fan Jan 2022

The Hidden Harms Of Privacy Penalties, Mary D. Fan

Articles

How to frame privacy penalties to protect our personal information is an important question as demands for legislation and proposals proliferate. The predominant assumption in calls for a comprehensive consumer privacy regime is that regulation and penalties arm the consumer David against Goliath businesses. Missing in the focus on powerful companies is attention to the potential harms of expanding privacy penalties for small-fry individuals and entities, especially from disfavored or marginalized groups. This article is the first to illuminate the regressive risks of privacy penalties, showing how broad privacy penalties can become tools for harassment of small businesses and individuals …


You Are Not A Commodity: A More Efficient Approach To Commercial Privacy Rights, Benjamin T. Pardue Dec 2021

You Are Not A Commodity: A More Efficient Approach To Commercial Privacy Rights, Benjamin T. Pardue

Washington Law Review

United States common law provides four torts for privacy invasion: (1) disclosure of private facts, (2) intrusion upon seclusion, (3) placement of a person in a false light, and (4) appropriation of name or likeness. Appropriation of name or likeness occurs when a defendant commandeers the plaintiff’s recognizability, typically for a commercial benefit. Most states allow plaintiffs who establish liability to recover defendants’ profits as damages from the misappropriation under an “unjust enrichment” theory. By contrast, this Comment argues that such an award provides a windfall to plaintiffs and contributes to suboptimal social outcomes. These include overcompensating plaintiffs and incentivizing …


Hacks, Leaks, And Data Dumps: The Right To Publish Illegally Acquired Information Twenty Years After Bartnicki V. Vopper, Erik Ugland, Christina Mazzeo Mar 2021

Hacks, Leaks, And Data Dumps: The Right To Publish Illegally Acquired Information Twenty Years After Bartnicki V. Vopper, Erik Ugland, Christina Mazzeo

Washington Law Review

This Article addresses a fluid and increasingly salient category of cases involving the First Amendment right to publish information that was hacked, stolen, or illegally leaked by someone else. Twenty years ago, in Bartnicki v. Vopper, the Supreme Court appeared to give broad constitutional cover to journalists and other publishers in these situations, but Justice Stevens’s inexact opinion for the Court and Justice Breyer’s muddling concurrence left the boundaries unclear. The Bartnicki framework is now implicated in dozens of new cases— from the extradition and prosecution of Julian Assange, to Donald Trump’s threatened suit of The New York Times …


Revising Reasonableness In The Cloud, Ian Walsh Mar 2021

Revising Reasonableness In The Cloud, Ian Walsh

Washington Law Review

Save everything—just in case––and search for it later. This is a modern mantra fueled by the ubiquity of smartphones, laptops, tablets, and free or low-cost data storage that leads users to store massive amounts of data in the cloud. But when users trust third-party cloud storage providers with private communications, they also surrender Fourth Amendment constitutional certainty. Existing statutory safeguards for these communications are lower than Fourth Amendment warrant and probable cause standards; this permits the government to seize large quantities of users’ private communications stored in the cloud with only minimal justification. Due to the revealing nature of such …


The Right To Benefit From Big Data As A Public Resource, Mary D. Fan Jan 2021

The Right To Benefit From Big Data As A Public Resource, Mary D. Fan

Articles

The information that we reveal from interactions online and with electronic devices has massive value—for both private profit and public benefit, such as improving health, safety, and even commute times. Who owns the lucrative big data that we generate through the everyday necessity of interacting with technology? Calls for legal regulation regarding how companies use our data have spurred laws and proposals framed by the predominant lens of individual privacy and the right to control and delete data about oneself. By focusing on individual control over droplets of personal data, the major consumer privacy regimes overlook the important question of …