Open Access. Powered by Scholars. Published by Universities.®

Privacy Law Commons™

Open Access. Powered by Scholars. Published by Universities.®

Washington and Lee University School of Law

Discipline
Keyword
Publication Year
Publication
Publication Type

Articles 31 - 60 of 71

Full-Text Articles in Privacy Law

Comment: The Necessary Evolution Of State Data Breach Notification Laws: Keeping Pace With New Cyber Threats, Quantum Decryption, And The Rapid Expansion Of Technology, Beth Burgin Waller, Elaine Mccafferty Jan 2022

Comment: The Necessary Evolution Of State Data Breach Notification Laws: Keeping Pace With New Cyber Threats, Quantum Decryption, And The Rapid Expansion Of Technology, Beth Burgin Waller, Elaine Mccafferty

Washington and Lee Law Review

The legal framework that was built almost two decades ago now struggles to keep pace with the rapid expansion of technology, including quantum computing and artificial intelligence, and an ever-evolving cyber threat landscape. In 2002, California passed the first data breach notification law, with all fifty states following suit to require notice of unauthorized access to and acquisition of an individual’s personal information.1 These data breach notification laws, originally designed to capture one-off unauthorized views of data in a computerized database, were not built to address PowerShell scripts by cyber terrorists run across thousands of servers, leaving automated accessed data …


The “P” Isn’T For Privacy: The Conflict Between Bankruptcy Rules And Hipaa Compliance, Sophie R. Rogers Churchill Apr 2021

The “P” Isn’T For Privacy: The Conflict Between Bankruptcy Rules And Hipaa Compliance, Sophie R. Rogers Churchill

Washington and Lee Law Review

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) included a now-ubiquitous provision designed to protect the privacy of patients’ protected health information. The provision prohibits covered entities, including health care providers and their agents, from disclosing any demographic information that may identify a patient and that relates to that patient’s medical care. The provision is broad and can include such simple information as which doctor a patient consults or the date of a patient’s consultation with a physician.

Unfortunately, such protections become impracticable in the bankruptcy setting. When a health care provider files bankruptcy, it files a host …


#Audited: Social Media And Tax Enforcement, Michelle Lyon Drumbl Jan 2021

#Audited: Social Media And Tax Enforcement, Michelle Lyon Drumbl

Scholarly Articles

With limited resources and a diminished budget, it is not surprising that the Internal Revenue Service would seek new tools to maximize its enforcement efficiency. Automation and technology provide new opportunities for the IRS, and in turn, present new concerns for taxpayers. In December 2018, the IRS signaled its interest in a tool to access publicly available social media profiles of individuals in order to “expedite IRS case resolution for existing compliance cases.” This has important implications for taxpayer privacy.

Moreover, the use of social media in tax enforcement may pose a particular harm to an especially vulnerable population: low-income …


Bad Actors: Authenticity, Inauthenticity, Speech, And Capitalism, Sarah C. Haan Jan 2020

Bad Actors: Authenticity, Inauthenticity, Speech, And Capitalism, Sarah C. Haan

Scholarly Articles

“Authenticity” has evolved into an important value that guides social media companies’ regulation of online speech. It is enforced through rules and practices that include real-name policies, Terms of Service requiring users to present only accurate information about themselves, community guidelines that prohibit “coordinated inauthentic behavior,” verification practices, product features, and more.

This Article critically examines authenticity regulation by the social media industry, including companies’ claims that authenticity is a moral virtue, an expressive value, and a pragmatic necessity for online communication. It explains how authenticity regulation provides economic value to companies engaged in “information capitalism,” “data capitalism,” and “surveillance …


Bytes Bite: Why Corporate Data Breaches Should Give Standing To Affected Individuals, Caden Hayes Mar 2019

Bytes Bite: Why Corporate Data Breaches Should Give Standing To Affected Individuals, Caden Hayes

Washington and Lee Journal of Civil Rights and Social Justice

High-profile data hacks are not uncommon. In fact, according to the Privacy Rights Clearinghouse, there have been at least 7,961 data breaches, exposing over 10,000,000,000 accounts in total, since 2005. These shocking numbers are not particularly surprising when taking into account the value of information stolen. For example, cell phone numbers, as exposed in a Yahoo! hack, are worth $10 a piece on the black market, meaning the hackers stood to make $30,000,000,000 from that one hack. That dollar amount does not even consider copies the hackers could make and later resell. Yet while these hackers make astronomical payoffs, the …


The Ironic Privacy Act, Margaret Hu Jan 2019

The Ironic Privacy Act, Margaret Hu

Scholarly Articles

This Article contends that the Privacy Act of 1974, a law intended to engender trust in government records, can be implemented in a way that inverts its intent. Specifically, pursuant to the Privacy Act's reporting requirements, in September 2017, the U.S. Department of Homeland Security (DHS) notified the public that record systems would be modified to encompass the collection of social media data. The notification justified the collection of social media data as a part of national security screening and immigration vetting procedures. However, the collection will encompass social media data on both citizens and noncitizens, and was not explicitly …


Hardware, Heartware, Or Nightmare: Smart-City Technology And The Concomitant Erosion Of Privacy, Leila Lawlor Jan 2019

Hardware, Heartware, Or Nightmare: Smart-City Technology And The Concomitant Erosion Of Privacy, Leila Lawlor

Scholarly Articles

Smart-city technology is being adopted in cities all around the world to simplify our lives, save us time, ease traffic, improve education, reduce energy usage, and keep us healthy and safe. Its adoption is necessary because of changes that are predicted for urban dwellers over the next three decades; urban population and travel are predicted to increase dramatically and our population is graying, meaning the population will include a much greater number of elderly citizens. As these changes occur, smart-city technology can have a huge impact on public safety, improving the ability of law enforcement to investigate crimes, both with …


Information And The Regulatory Landscape: A Growing Need To Reconsider Existing Legal Frameworks, Anjanette H. Raymond Apr 2018

Information And The Regulatory Landscape: A Growing Need To Reconsider Existing Legal Frameworks, Anjanette H. Raymond

Washington and Lee Journal of Civil Rights and Social Justice

No abstract provided.


Bulk Biometric Metadata Collection, Margaret Hu Jan 2018

Bulk Biometric Metadata Collection, Margaret Hu

Scholarly Articles

Smart police body cameras and smart glasses worn by law enforcement increasingly reflect state-of-the-art surveillance technology, such as the integration of live-streaming video with facial recognition and artificial intelligence tools, including automated analytics. This Article explores how these emerging cybersurveillance technologies risk the potential for bulk biometric metadata collection. Such collection is likely to fall outside the scope of the types of bulk metadata collection protections regulated by the USA FREEDOM Act of 2015. The USA FREEDOM Act was intended to bring the practice of bulk telephony metadata collection conducted by the National Security Agency (“NSA”) under tighter regulation. In …


Data Flow Maps—Increasing Data Processing Transparency And Privacy Compliance In The Enterprise, Jeremy Berkowitz, Michael Mangold, Stephen Sharon May 2017

Data Flow Maps—Increasing Data Processing Transparency And Privacy Compliance In The Enterprise, Jeremy Berkowitz, Michael Mangold, Stephen Sharon

Washington and Lee Law Review Online

In recent years, well-known cyber breaches have placed growing pressure on organizations to implement proper privacy and data protection standards. Attacks involving the theft of employee and customer personal information have damaged the reputations of well-known brands, resulting in significant financial costs. As a result, governments across the globe are actively examining and strengthening laws to better protect the personal data of its citizens. The General Data Protection Regulation (GDPR) updates European privacy law with an array of provisions that better protect consumers and require organizations to focus on accounting for privacy in their business processes through “privacy-by-design” and “privacy …


The Market’S Law Of Privacy: Case Studies In Privacy/Security Adoption, Chetan Gupta May 2017

The Market’S Law Of Privacy: Case Studies In Privacy/Security Adoption, Chetan Gupta

Washington and Lee Law Review Online

This paper examines the hypothesis that it may be possible for individual actors in a marketplace to drive the adoption of particular privacy and security standards. It aims to explore the diffusion of privacy and security technologies in the marketplace. Using HTTPS, Two-Factor Authentication, and End-to-End Encryption as case studies, it tries to ascertain which factors are responsible for successful diffusion which improves the privacy of a large number of users. Lastly, it explores whether the FTC may view a widely diffused standard as a necessary security feature for all actors in a particular industry.

Based on the case studies …


Privacy In The Age Of Autonomous Vehicles, Ivan L. Sucharski, Philip Fabinger Apr 2017

Privacy In The Age Of Autonomous Vehicles, Ivan L. Sucharski, Philip Fabinger

Washington and Lee Law Review Online

To prepare for the age of the intelligent, highly connected, and autonomous vehicle, a new approach to concepts of granting consent, managing privacy, and dealing with the need to interact quickly and meaningfully is needed. Additionally, in an environment where personal data is rapidly shared with a multitude of independent parties, there exists a need to reduce the information asymmetry that currently exists between the user and data collecting entities. This Article rethinks the traditional notice and consent model in the context of real-time communication between vehicles or vehicles and infrastructure or vehicles and other surroundings and proposes a re-engineering …


From The National Surveillance State To The Cybersurveillance State, Margaret Hu Jan 2017

From The National Surveillance State To The Cybersurveillance State, Margaret Hu

Scholarly Articles

This article anchors the phenomenon of bureaucratized cybersurveillance around the concept of the National Surveillance State, a theory attributed to Professor Jack Balkin of Yale Law School and Professor Sanford Levinson of the University of Texas School of Law. Pursuant to the theory of the National Surveillance State, because of the routinized and administrative nature of government-led surveillance, normalized mass surveillance is viewed as justified under crime and counterterrorism policy rationales. This article contends that the Cybersurveillance State is the successor to the National Surveillance State. The Cybersurveillance State harnesses technologies that fuse biometric and biographic data for risk assessment, …


Peeling Back The Student Privacy Pledge, Alexi Pfeffer-Gillett Jan 2017

Peeling Back The Student Privacy Pledge, Alexi Pfeffer-Gillett

Scholarly Articles

Education software is a multi-billion dollar industry that is rapidly growing. The federal government has encouraged this growth through a series of initiatives that reward schools for tracking and aggregating student data. Amid this increasingly digitized education landscape, parents and educators have begun to raise concerns about the scope and security of student data collection.

Industry players, rather than policymakers, have so far led efforts to protect student data. Central to these efforts is the Student Privacy Pledge, a set of standards that providers of digital education services have voluntarily adopted. By many accounts, the Pledge has been a success. …


Beyond Irbs: Ethical Guidelines For Data Research, Omer Tene, Jules Polonetsky Jun 2016

Beyond Irbs: Ethical Guidelines For Data Research, Omer Tene, Jules Polonetsky

Washington and Lee Law Review Online

No abstract provided.


Clapper Dethroned: Imminent Injury And Standing For Data Breach Lawsuits In Light Of Ashley Madison, Arthur R. Vorbrodt Jun 2016

Clapper Dethroned: Imminent Injury And Standing For Data Breach Lawsuits In Light Of Ashley Madison, Arthur R. Vorbrodt

Washington and Lee Law Review Online

No abstract provided.


Elements Of A New Ethical Framework For Big Data Research, Effy Vayena, Urs Gasser, Alexandra Wood, David R. O'Brien, Micah Altman Mar 2016

Elements Of A New Ethical Framework For Big Data Research, Effy Vayena, Urs Gasser, Alexandra Wood, David R. O'Brien, Micah Altman

Washington and Lee Law Review Online

Emerging large-scale data sources hold tremendous potential for new scientific research into human biology, behaviors, and relationships. At the same time, big data research presents privacy and ethical challenges that the current regulatory framework is ill-suited to address. In light of the immense value of large-scale research data, the central question moving forward is not whether such data should be made available for research, but rather how the benefits can be captured in a way that respects fundamental principles of ethics and privacy.

In response, this Essay outlines elements of a new ethical framework for big data research. It argues …


Big Data Sustainability: An Environmental Management Systems Analogy, Dennis D. Hirsch, Jonathan H. King Mar 2016

Big Data Sustainability: An Environmental Management Systems Analogy, Dennis D. Hirsch, Jonathan H. King

Washington and Lee Law Review Online

Today, organizations globally wrestle with how to extract valuable insights from diverse data sets without invading privacy, causing discrimination, harming their brand, or otherwise undermining the sustainability of their big data projects. Leaders in these organizations are thus asking: What management approach should businesses employ sustainably to achieve the tremendous benefits of big data analytics, while minimizing the potential negative externalities?

This Paper argues that leaders can learn from environmental management practices developed to manage the negative externalities of the industrial revolution. First, it shows that, along with its many benefits, big data can create negative externalities that are structurally …


The Regulation Of Commercial Profiling — A Comparative Analysis, Indra Spiecker, Olivia Tambou, Paul Bernal, Margaret Hu, Carlos Alberto Molinaro Jan 2016

The Regulation Of Commercial Profiling — A Comparative Analysis, Indra Spiecker, Olivia Tambou, Paul Bernal, Margaret Hu, Carlos Alberto Molinaro

Scholarly Articles

The authors, all data protection experts, discuss the status of the relevant data protection regulatory framework on profiling in the business sector in sev eral countries worldwide, from the constitutional level to some individual regulation including the general attitude towards the topic. The EU perspective is presented on the basis of the present directives as well as the General Data Protection Regulation. The United Kingdom, Germany and France, as three of the largest EU Member States with partly highly differing regulatory approaches represent Member State law. Australia, Brazil and the US regulation exemplify the different integration of data protection standards …


Taxonomy Of The Snowden Disclosures, Margaret Hu Sep 2015

Taxonomy Of The Snowden Disclosures, Margaret Hu

Washington and Lee Law Review

This brief Essay offers a proposed taxonomy of the Snowden Disclosures. An informed discussion on the legality and constitutionality of the emerging cybersurveillance and mass dataveillance programs revealed by former NSA contractor Edward Snowden necessitates the furtherance of cybersurveillance aptitude. This Essay contends, therefore, that a detailed examination of the Snowden disclosures requires not just a careful inquiry into the legal and constitutional framework that guides the oversight of these programs. A close interrogation also requires a careful inquiry into the big data architecture that guides them. This inquiry includes examining the underlying theories of data science and the rationales …


The Fisa Court And Article Iii, Stephen I. Vladeck Jun 2015

The Fisa Court And Article Iii, Stephen I. Vladeck

Washington and Lee Law Review

No abstract provided.


Cybersurveillance In A Free Society, Russell L. Weaver Jun 2015

Cybersurveillance In A Free Society, Russell L. Weaver

Washington and Lee Law Review

No abstract provided.


Spying Inc., Danielle Keats Citron Jun 2015

Spying Inc., Danielle Keats Citron

Washington and Lee Law Review

The latest spying craze is the “stalking app.” Once installed on someone’s cell phone, the stalking app can provide continuous access to the phone owner’s calls, texts, snapchats, photos, calendar updates, and movements. Stalking apps destroy the privacy and confidentiality of cell phone activities. Domestic abusers and stalkers frequently turn to stalking apps because they are undetectable even to sophisticated phone owners.

Business is booming for stalking app providers, even though their entire enterprise is arguably illegal. Federal and state wiretapping laws ban the manufacture, sale, or advertisement of devices knowing their design makes them primarily useful for the surreptitious …


Defining "Foreign Affairs" In Section 702 Of The Fisa Amendments Act: The Virtues And Deficits Of Post-Snowden Dialogue On U.S. Surveillance Policy, Peter Margulies Jun 2015

Defining "Foreign Affairs" In Section 702 Of The Fisa Amendments Act: The Virtues And Deficits Of Post-Snowden Dialogue On U.S. Surveillance Policy, Peter Margulies

Washington and Lee Law Review

No abstract provided.


Surveillance As Loss Of Obscurity, Woodrow Hartzog, Evan Selinger Jun 2015

Surveillance As Loss Of Obscurity, Woodrow Hartzog, Evan Selinger

Washington and Lee Law Review

No abstract provided.


State Labs Of Federalism And Law Enforcement "Drone" Use, Chris Jenks Jun 2015

State Labs Of Federalism And Law Enforcement "Drone" Use, Chris Jenks

Washington and Lee Law Review

No abstract provided.


Banning Bulk: Passage Of The Usa Freedom Act And Ending Bulk Collection, Bart Forsyth Jun 2015

Banning Bulk: Passage Of The Usa Freedom Act And Ending Bulk Collection, Bart Forsyth

Washington and Lee Law Review

No abstract provided.


I Spy: The New Self-Cybersurveillance And The "Internet Of Things", Steven I. Friedland Jun 2015

I Spy: The New Self-Cybersurveillance And The "Internet Of Things", Steven I. Friedland

Washington and Lee Law Review

Prior to the digital age, surveillance generally meant a government agent or private investigator engaged in a stakeout or observation detail that involved physical work, expense, and time. The digital age changed surveillance fundamentally. Today, we not only generate mountains of data for others, we also effectively surveil ourselves through digitally-connected, multifunctional smart devices, collectively described as the “Internet of Things.”

Cybersurveillance accessed by the government, even when started as self-surveillance, raises complex and uncertain legal issues, especially when related to the Constitution. In United States v. Kyllo, the Supreme Court was reticent to allow government agents to use …


Putting The Brakes On Driver Privacy: Black Boxes, Data Collection, And The Fourth Amendment, Thayer Case Sep 2014

Putting The Brakes On Driver Privacy: Black Boxes, Data Collection, And The Fourth Amendment, Thayer Case

Washington and Lee Journal of Civil Rights and Social Justice

No abstract provided.


Anonymous Speech On The Internet, In Amateur Media: Social, Cultural And Legal Perspectives (Dan Hunter Et Al. Eds., 2013), Brian C. Murchison Jan 2013

Anonymous Speech On The Internet, In Amateur Media: Social, Cultural And Legal Perspectives (Dan Hunter Et Al. Eds., 2013), Brian C. Murchison

Books and Chapters

The U.S. legal community is engaged in a serious but inconclusive dialogue on issues relating to anonymous speech on the Internet. To be sure, several basic questions relevant to Internet speech have been settled: in a 1997 case; the Supreme Court determined that strict scrutiny applies to Internet content regulation, and in a 1995 case, the Court recognized a First Amendment right of anonymous speech. Yet the 1995 case did not arise in an Internet setting, and the scope of expressive freedom in certain Internet scenarios remains disputed. Over the past ten years, courts and commentators have grappled with anonymous …