Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Internet Law (28)
- Physical Sciences and Mathematics (19)
- Computer Sciences (18)
- Information Security (17)
- Science and Technology Law (16)
-
- Computer Law (15)
- International Law (13)
- Communications Law (9)
- National Security Law (7)
- Consumer Protection Law (6)
- Intellectual Property Law (6)
- First Amendment (5)
- Human Rights Law (5)
- Business (4)
- Business Organizations Law (4)
- Law and Society (4)
- Legislation (4)
- Social and Behavioral Sciences (4)
- Business Law, Public Responsibility, and Ethics (3)
- Constitutional Law (3)
- Health Law and Policy (3)
- Legal Education (3)
- Artificial Intelligence and Robotics (2)
- Civil Rights and Discrimination (2)
- Commercial Law (2)
- Comparative and Foreign Law (2)
- Computer Engineering (2)
- Criminal Law (2)
- Institution
-
- Maurer School of Law: Indiana University (19)
- The Catholic University of America, Columbus School of Law (6)
- Boston University School of Law (3)
- University of Michigan Law School (3)
- American University Washington College of Law (2)
-
- Schulich School of Law, Dalhousie University (2)
- St. John's University School of Law (2)
- University of Colorado Law School (2)
- University of Georgia School of Law (2)
- Chicago-Kent College of Law (1)
- City University of New York (CUNY) (1)
- Duke Law (1)
- Kennesaw State University (1)
- Lewis & Clark Law School (1)
- Loyola Marymount University and Loyola Law School (1)
- Purdue University (1)
- Roger Williams University (1)
- Seattle University School of Law (1)
- Singapore Management University (1)
- St. Mary's University (1)
- University of Florida Levin College of Law (1)
- University of Maine School of Law (1)
- University of New Hampshire (1)
- University of Richmond (1)
- University of San Diego (1)
- University of Washington School of Law (1)
- Vanderbilt University Law School (1)
- Walden University (1)
- Washington University in St. Louis (1)
- West Virginia University (1)
- Publication Year
- Publication
-
- Articles by Maurer Faculty (14)
- Catholic University Journal of Law and Technology (5)
- Faculty Scholarship (3)
- Articles, Book Chapters, & Popular Press (2)
- Indiana Law Journal (2)
-
- Journal of Intellectual Property Law (2)
- Law Faculty Scholarship (2)
- Publications (2)
- St. John's Law Review (2)
- University of Michigan Journal of Law Reform (2)
- 2018–2019 Flyers (1)
- All Faculty Scholarship (1)
- American University Business Law Review (1)
- Articles (1)
- Austen Parrish (2014-2022) (1)
- Catholic University Law Review (1)
- Centre for AI & Data Governance (2019-2025) (1)
- Christiana Ochoa (7/22-10/22 Acting; 11/2022-) (1)
- Duke Law & Technology Review (1)
- Faculty Publications (1)
- Journal of Cybersecurity Education, Research and Practice (1)
- Journal of Educational Research and Practice (1)
- Journal of Law and Mobility (1)
- Keep Up With the Latest News from the Law School (blog) (1)
- Lewis & Clark Law Review (1)
- Loyola of Los Angeles Law Review (1)
- Open Educational Resources (1)
- San Diego International Law Journal (1)
- Scholarly Articles in Law Reviews & Journals (1)
- Scholarship@WashULaw (1)
- Publication Type
Articles 1 - 30 of 63
Full-Text Articles in Privacy Law
The Myth Of Sufficient Technological Barriers: Reevaluating The "Gates-Up-Or-Down" Analogy In Data Scraping, Yucen Zhong
The Myth Of Sufficient Technological Barriers: Reevaluating The "Gates-Up-Or-Down" Analogy In Data Scraping, Yucen Zhong
Duke Law & Technology Review
In Van Buren v. United States, the Supreme Court adopted a “gates-up-or-down” analogy from physical trespass law to define “authorization” under the Computer Fraud and Abuse Act (CFAA). Despite historical shifts in judicial interpretation, courts have recently relied on this binary framework to interpret authorization as it applies to online trespass. But courts have struggled to apply this binary inquiry while still accounting for complications in modern authentication technologies. When pursuing a code-based inquiry based on the gates-up-or-down analogy, courts risk oversimplifying the dynamic nature of online trespass. Such an approach fails to account for how modern authentication measures—such as …
A Proposed Tort To Address The Negligent Enablement Of Cloud Data Breaches, Michael L. Rustad
A Proposed Tort To Address The Negligent Enablement Of Cloud Data Breaches, Michael L. Rustad
American University Business Law Review
[INTRODUCTION] The term “cloud computing” means the remote storage of software applications, tools, and data accessed through the internet. Cloud customers enter into subscription agreements with providers who give 24/7, on-demand, as-needed access to software, storage, and networking services owned and managed by providers through a web browser. “Many businesses are transitioning to the cloud for data storage, remote work, and collaboration.” Cloud providers operate their software as a software-as-a-service (“SaaS”) model, under which customers pay a subscription fee to access the software. Netflix and Amazon Prime Video are examples of subscription services that deliver television programs and videos through …
Corporate Law's Duty Of Data Loyalty, Andy Serwin, Neil Richards, Woodrow Hartzog, Ryan Durrie
Corporate Law's Duty Of Data Loyalty, Andy Serwin, Neil Richards, Woodrow Hartzog, Ryan Durrie
Faculty Scholarship
Privacy law used to be a relatively tidy field, involving a few interesting but discrete topics like press disclosures of private facts, wiretapping, and the processing of personal data by internet companies. But as the digital revolution continues to disrupt area after area of human activity and software “is eating the world,” the core concerns of privacy law such as “when is it appropriate to process personal data?” have similarly entered field after field. Today, most fields of law, including discrimination law, antitrust, and international law, have found it necessary to reckon with the questions of informational harm and power …
School And District Leaders’ Understanding Of Technology Organizations’ Cyber Business Practices, Jayejaye Johnson
School And District Leaders’ Understanding Of Technology Organizations’ Cyber Business Practices, Jayejaye Johnson
Journal of Educational Research and Practice
Educational technology (EdTech) interoperability throughout cyberspace provides the financial opportunity to collect and sell student privacy information in digital learning environments, challenging school leaders to govern schools and keep children safe. School leaders provide the resources, funding, planning, decision making, and administration for EdTech cybersecurity practices and policies, yet little is known about what public school leaders understand. A quantitative study was designed using primary data collected from an online survey. Four research questions guided this study: What are the differences in cybersecurity practices and policy response scores (1) between male and female school leaders; (2) among leaders with different …
Dean's Desk: Finding New Ways To Help Diminish Cybersecurity Threats, Christiana Ochoa
Dean's Desk: Finding New Ways To Help Diminish Cybersecurity Threats, Christiana Ochoa
Christiana Ochoa (7/22-10/22 Acting; 11/2022-)
In an era when cyberattacks can paralyze hospitals, disrupt elections, and compromise the privacy of millions, the need for innovative cybersecurity and privacy protections has never been more urgent. But it is not just a question of new technologies; strong data protection depends as much on motivating people and organizations to use those technologies and make wise choices to diminish data risk.
The Indiana University Maurer School of Law has spent more than 30 years answering cybersecurity and privacy challenges with a distinctive, holistic approach: an interdisciplinary, human-centered legal education that equips students to lead at the intersection of technology, …
"Reasonable [Cybersecurity] Measures" For Digital Trade Secrets: Lessons From Marketing, Raj Sachdev
"Reasonable [Cybersecurity] Measures" For Digital Trade Secrets: Lessons From Marketing, Raj Sachdev
Law Faculty Scholarship
The loss of digital trade secrets in marketing and beyond, often the source of competitive advantage, can have disastrous impacts on brands and companies. Bad actors want to get their digital hands on digital trade secrets, and other actors and factors may also cause a risk to their secrecy. The Defend Trade Secrets Act (DTSA) makes clear that “reasonable measures” must be taken to maintain the secrecy of a trade secret. Likewise, the Uniform Trade Secrets Act (UTSA) requires “reasonable steps.” However, in a digital age, the definition of what is “reasonable” is even more unclear than in offline settings. …
Data Injustice In Global Justice, Asaf Lubin, Cherry Tang
Data Injustice In Global Justice, Asaf Lubin, Cherry Tang
Articles by Maurer Faculty
In May 2020, the United Nations Secretary-General unveiled a sweeping “Data Strategy for Action by Everyone, Everywhere,” seeking to unlock the UN’s “full data potential.” The International Criminal Court’s Office of the Prosecutor followed suit, declaring in 2023 its intent to acquire advanced cyber forensic tools so as to hold the “widest range of digital evidence globally.” Across international institutions, data-driven governance has become the norm, with humanitarian agencies and tribunals transforming into “data hubs and information clearinghouses.” This Article critiques the unfettered datafication of global justice by international courts and organizations. These entities have aggressively expanded their data-driven operations …
Information Accountability Foundation Names Two Maurer Faculty To Leadership Positions, James Owsley Boyd
Information Accountability Foundation Names Two Maurer Faculty To Leadership Positions, James Owsley Boyd
Keep Up With the Latest News from the Law School (blog)
he Information Accountability Foundation (IAF) has appointed two Indiana University Maurer School of Law faculty to lead the organization.
Fred H. Cate, a distinguished professor and C. Ben Dutton Professor of Law, was named the nonprofit think tank’s new executive director, while Stan Crosley, an adjunct faculty member and 1994 graduate of the Law School, was appointed chief policy strategist.
Founded in 2013, the IAF works with global regulators and industry executives to promote organizational accountability, data stewardship, and data ethics. Its mission is to help regulators and responsible companies better understand the challenges around Artificial Intelligence and data governance …
Who Should Be Liable? Examining The Corporate Liability Regime For Cybersecurity Risks, Angel R. Gardner
Who Should Be Liable? Examining The Corporate Liability Regime For Cybersecurity Risks, Angel R. Gardner
Student Journal of Information Privacy Law
The growth of the Internet of Things (IoT) poses new and substantial security risks for individual and national security. The IoT leaves networks susceptible to hacking, a form of unauthorized access into another person’s system or device. All devices that use the IoT are at risk of unauthorized access—a few examples include vehicles or medical devices. Currently, there are no regulations requiring corporations to protect their software from unauthorized intrusions. However, the current tort landscape does not allow for individuals to recover when there are unauthorized network intrusions where there is no tangible harm. This paper discusses why cybersecurity intrusions …
Navigating The Intersection Of Regulation And Vulnerability: The Evolving Landscape Of Cybersecurity In Investment Management And The Imperative For Comprehensive Safeguards, Giezi Rios
Catholic University Journal of Law and Technology
No abstract provided.
Shields Up For Software, Derek E. Bambauer, Melanie J. Teplinsky
Shields Up For Software, Derek E. Bambauer, Melanie J. Teplinsky
UF Law Faculty Publications
This Article contends that the National Cybersecurity Strategy's software liability regime should incorporate two safe harbors. The first would shield software creators and vendors from liability for decisions related to design, implementation, and maintenance, as long as those choices follow enumerated best practices. The second—the “inverse safe harbor”—would have the opposite effect: coders and distributors who engaged in defined worst practices would automatically become liable. This Article explains the design, components, and justifications for these twin safe harbors. The software safe harbors are key parts of the overall design of the new liability regime and work in tandem with the …
Integrating Nist And Iso Cybersecurity Audit And Risk Assessment Frameworks Into Cameroonian Law, Bernard Ngalim
Integrating Nist And Iso Cybersecurity Audit And Risk Assessment Frameworks Into Cameroonian Law, Bernard Ngalim
Journal of Cybersecurity Education, Research and Practice
This paper reviews cybersecurity laws and regulations in Cameroon, focusing on cybersecurity and information security audits and risk assessments. The importance of cybersecurity risk assessment and the implementation of security controls to cure deficiencies noted during risk assessments or audits is a critical step in developing cybersecurity resilience. Cameroon's cybersecurity legal framework provides for audits but does not explicitly enumerate controls. Consequently, integrating relevant controls from the NIST frameworks and ISO Standards can improve the cybersecurity posture in Cameroon while waiting for a comprehensive revision of the legal framework. NIST and ISO are internationally recognized as best practices in information …
Safeguarding Taxpayer Data, Michael Hatfield
Safeguarding Taxpayer Data, Michael Hatfield
Articles
The Internal Revenue Service (IRS) collects more information on more individuals than any other government agency. The information is not only financial but personal, potentially including information about health care needs and decisions; the caregivers, disabilities, and foreign birth of children; the educational progress and felony convictions of students; and one’s religious and charitable associations. In acknowledging the vast quantity of information held by the IRS, and the necessity of taxpayers trusting tax administrators with their information, Congress provided greater protection for taxpayer information under the Internal Revenue Code (IRC) than it was provided under the Privacy Act. Congress obligated …
Securing Patent Law, Charles Duan
Securing Patent Law, Charles Duan
Scholarly Articles in Law Reviews & Journals
A vigorous conversation about intellectual property rights and national security has largely focused on the defense role of those rights, as tools for responding to acts of foreign infringement. But intellectual property, and patents in particular, also play an arguably more important offense role. Foreign competitor nations can obtain and assert U.S. patents against U.S. firms and creators. Use of patents as an offense strategy can be strategically coordinated to stymie domestic innovation and technological progress. This Essay considers current and possible future practices of patent exploitation in this offense setting, with a particular focus on China given the nature …
Small Business Cybersecurity: A Loophole To Consumer Data, Matthew R. Espinosa
Small Business Cybersecurity: A Loophole To Consumer Data, Matthew R. Espinosa
The Scholar: St. Mary's Law Review on Race and Social Justice
Small businesses and small minority owned businesses are vital to our nation’s economy; therefore legislation, regulation, and policy has been created in order to assist them in overcoming their economic stability issues and ensure they continue to serve the communities that rely on them. However, there is not a focus on regulating nor assisting small businesses to ensure their cybersecurity standards are up to par despite them increasingly becoming a victim of cyberattacks that yield high consequences. The external oversight and assistance is necessary for small businesses due to their lack of knowledge in implementing effective cybersecurity policies, the fiscal …
The Rise Of 5g Technology: How Internet Privacy And Protection Of Personal Data Is A Must In An Evolving Digital Landscape, Justin Rabine
The Rise Of 5g Technology: How Internet Privacy And Protection Of Personal Data Is A Must In An Evolving Digital Landscape, Justin Rabine
Catholic University Journal of Law and Technology
No abstract provided.
Privacy Frameworks For Smart Cities, Lindsey Tonsager, Jayne Ponder
Privacy Frameworks For Smart Cities, Lindsey Tonsager, Jayne Ponder
Journal of Law and Mobility
This paper identifies some of the core privacy considerations raised by smart cities – government surveillance and data security in Part I. Then, Part II proposes a set of core principles for smart cities to consider in the development and deployment of smart cities to address privacy concerns. These principles include: (A) human-centric approaches to smart cities design and implementation, (B) transparency for city residents, (C) privacy by design, (D) anonymization and deidentification, (E) data minimization and purpose specification, (F) trusted data sharing, and (G) cybersecurity resilience.
Platforms, Encryption, And The Cfaa: The Case Of Whatsapp V Nso Group, Jonathon Penney, Bruce Schneier
Platforms, Encryption, And The Cfaa: The Case Of Whatsapp V Nso Group, Jonathon Penney, Bruce Schneier
Articles, Book Chapters, & Popular Press
End-to-end encryption technology has gone mainstream. But this wider use has led hackers, cybercriminals, foreign governments, and other threat actors to employ creative and novel attacks to compromise or workaround these protections, raising important questions as to how the Computer Fraud and Abuse Act (CFAA), the primary federal anti-hacking statute, is best applied to these new encryption implementations. Now, after the Supreme Court recently narrowed the CFAA’s scope in Van Buren and suggested it favors a code-based approach to liability under the statute, understanding how best to theorize sophisticated code-based access barriers like end-to-end encryption, and their circumvention, is now …
A Deep Dive Into Technical Encryption Concepts To Better Understand Cybersecurity & Data Privacy Legal & Policy Issues, Anthony Volini
A Deep Dive Into Technical Encryption Concepts To Better Understand Cybersecurity & Data Privacy Legal & Policy Issues, Anthony Volini
Journal of Intellectual Property Law
Lawyers wishing to exercise a meaningful degree of leadership at the intersection of technology and the law could benefit greatly from a deep understanding of the use and application of encryption, considering it arises in so many legal scenarios. For example, in FTC v. Wyndham1 the defendant failed to implement nearly every conceivable cybersecurity control, including lack of encryption for stored data, resulting in multiple data breaches and a consequent FTC enforcement action for unfair and deceptive practices. Other examples of legal issues requiring use of encryption and other technology concepts include compliance with security requirements of GLBA & HIPAA, …
What's The Harm? Federalism, The Separation Of Powers, And Standing In Data Breach Litigation, Grayson Wells
What's The Harm? Federalism, The Separation Of Powers, And Standing In Data Breach Litigation, Grayson Wells
Indiana Law Journal
This Comment will argue that the Supreme Court should analyze standing in data breach litigation under a standard that is deferential to state statutory and common law. Specifically, federal standing analysis should look to state law when determining whether an injury is concrete such that the injury-in-fact requirement is met. Some argue that allowing more data breach cases to proceed to the merits could lead to an explosion of successful litigation and settlements, burdening the federal courts and causing economic losses for the breached businesses. These concerns may be valid. But if state law provides a remedy to the harm …
Eu Privacy Law And U.S. Surveillance: Solving The Problem Of Transatlantic Data Transfers, Peter Margulies
Eu Privacy Law And U.S. Surveillance: Solving The Problem Of Transatlantic Data Transfers, Peter Margulies
Law Faculty Scholarship
No abstract provided.
National Cybersecurity Innovation, Tabrez Y. Ebrahim
National Cybersecurity Innovation, Tabrez Y. Ebrahim
West Virginia Law Review
National cybersecurity plays a crucial role in protecting our critical infrastructure, such as telecommunication networks, the electricity grid, and even financial transactions. Most discussions about promoting national cybersecurity focus on governance structures, international relations, and political science. In contrast, this Article proposes a different agenda and one that promotes the use of innovation mechanisms for technological advancement. By promoting inducements for technological developments, such innovation mechanisms encourage the advancement of national cybersecurity solutions. In exploring possible solutions, this Article asks whether the government or markets can provide national cybersecurity innovation. This inquiry is a fragment of a much larger literature …
Cybersecurity-The Internet Of Things, Amy J. Ramson
Cybersecurity-The Internet Of Things, Amy J. Ramson
Open Educational Resources
With 38.5 billion smart devices in existence in 2020 and increasing every year, the potential for security breaches in the Internet of things is also escalating at a dramatic pace. The goal of this team activity is to facilitate team work, critical thinking, and presentation skills in the area of cybersecurity and the Internet of Things. Students will be grouped into two teams. As a team, they will analyze cases about security cameras and smart dolls through the questions presented in the activity. They will present their analysis to the class.
Regulating Personal Data Usage In Covid-19 Control Conditions, Mark Findlay, Nydia Remolina
Regulating Personal Data Usage In Covid-19 Control Conditions, Mark Findlay, Nydia Remolina
Centre for AI & Data Governance (2019-2025)
As the COVID-19 health pandemic ebbs and flows world-wide, governments and private companies across the globe are utilising AI-assisted surveillance, reporting, mapping and tracing technologies with the intention of slowing the spread of the virus. These technologies have capacity to amass and share personal data for community control and citizen safety motivations that empower state agencies and inveigle citizen co-operation which could only be imagined outside times of real and present personal danger. While not cavilling with the short-term necessity for these technologies and the data they control, process and share in the health regulation mission (provided that the technology …
The (Possibly) Injured Consumer: Standing In Data Breach Litigation, Lauren M. Lozada
The (Possibly) Injured Consumer: Standing In Data Breach Litigation, Lauren M. Lozada
St. John's Law Review
(Excerpt)
This Note will address the question of what factors a prospective plaintiff must display to “push [a] threatened injury of future identity theft beyond the speculative to the sufficiently imminent.” Part I will delve into relevant statistics to identify the characteristics of a data breach that most often lead to eventual identity theft. Part II will explore recent data breach standing cases and analyze the factual differences and legal perspectives that have led to disparate results among the federal circuits. Lastly, Part III will recommend a method for evaluating future data breach standing issues.
The Survival Of Critical Infrastructure: How Do We Stop Ransomware Attacks On Hospitals?, Helena Roland
The Survival Of Critical Infrastructure: How Do We Stop Ransomware Attacks On Hospitals?, Helena Roland
Catholic University Journal of Law and Technology
Our nation’s infrastructure is under an emerging new threat: ransomware attacks. These attacks can cause anything from individual laptops, to entire cities to shut down for a period of time until the victim pays a ransom to the attacker. Unfortunately, these attacks are on the rise and the attackers have a new target: hospitals. Ransomware attacks on hospitals can temporarily shut down operating room technology and limit physician access to patient files, ultimately threatening the safety of hospital patients and the surrounding community. This paper examines how the threat of ransomware attacks on hospitals is on the rise and what …
Internet Of Things For Sustainability: Perspectives In Privacy, Cybersecurity, And Future Trends, Abdul Salam
Internet Of Things For Sustainability: Perspectives In Privacy, Cybersecurity, And Future Trends, Abdul Salam
Faculty Publications
In the sustainability IoT, the cybersecurity risks to things, sensors, and monitoring systems are distinct from the conventional networking systems in many aspects. The interaction of sustainability IoT with the physical world phenomena (e.g., weather, climate, water, and oceans) is mostly not found in the modern information technology systems. Accordingly, actuation, the ability of these devices to make changes in real world based on sensing and monitoring, requires special consideration in terms of privacy and security. Moreover, the energy efficiency, safety, power, performance requirements of these device distinguish them from conventional computers systems. In this chapter, the cybersecurity approaches towards …
Welcome To Cordell Perspectives, Neil M. Richards, Jonathan W. Heusel
Welcome To Cordell Perspectives, Neil M. Richards, Jonathan W. Heusel
Scholarship@WashULaw
The world around us is changing. Let’s talk about it together. Introducing a series of articles and opinions by the world’s leading experts concerning COVID-19 as it relates to precision medicine and data privacy: Welcome to Cordell Perspectives.
Comparative Analysis Of Data Breach Laws: Comprehension, Interpretation, And External Sources Of Legislative Text, Carol M. Hayes
Comparative Analysis Of Data Breach Laws: Comprehension, Interpretation, And External Sources Of Legislative Text, Carol M. Hayes
Lewis & Clark Law Review
Data breach laws in the United States have evolved in waves during the last couple of decades. There are a few federal laws that address aspects of data security and the aftermath of data breaches, but these laws tend to be narrow or sector-specific. This Article instead focuses on state legislative responses. As of 2018, all 50 states have a data breach law that at least addresses notifications. In this Article, the author presents the results of an empirical examination of the language used in these statutes. Examining the statutes side by side highlights the subtle choices of various state …
Protecting Personal Data: A Model Data Security And Breach Notifications Statute, Michael Bloom
Protecting Personal Data: A Model Data Security And Breach Notifications Statute, Michael Bloom
St. John's Law Review
(Excerpt)
This Note argues that current law is inadequate to protect consumers in light of the prevalence and severity of data breaches in recent years, and that a unifying federal legislation combining portions of state law and the DSBNA should be enacted. Part I of this Note analyzes the DSBNA for notification requirements when data breaches occur, the requirements for the implementation of security policies, regulatory mechanisms for monitoring compliance with these requirements, and criminal penalties for failing to comply. Part II summarizes the various state laws that exist for notification of data breaches. Part III proposes a model federal …