Open Access. Powered by Scholars. Published by Universities.®

Privacy Law Commons™

Open Access. Powered by Scholars. Published by Universities.®

Data protection

Discipline
Institution
Publication Year
Publication
Publication Type

Articles 1 - 30 of 94

Full-Text Articles in Privacy Law

Think Your Cellphone Data Is Protected Without A Search Warrant? Think Again., Adam M. Gershowitz Jul 2026

Think Your Cellphone Data Is Protected Without A Search Warrant? Think Again., Adam M. Gershowitz

Popular Media

No abstract provided.


Agentizing Privacy Preferences Without Privatizing Data Protection Policy, Frank Pasquale, Vanna Carter Oct 2025

Agentizing Privacy Preferences Without Privatizing Data Protection Policy, Frank Pasquale, Vanna Carter

Cornell Law Faculty Publications

This essay explores how consumers might exercise newly restored agency in a digital environment increasingly shaped by generative AI. Rather than expecting consumers to read privacy-related terms of service, policymakers should encourage the emergence of Automated Consumer Agents (“ACAs”) capable of interpreting privacy provisions and acting on behalf of users according to their stated preferences. These systems could automatically reject objectionable forms of data extraction, translating consumer values into actionable decisions in online transactions.

Despite this promise, the rise of ACAs would also present new problems. Without supportive policy and legal frameworks, agentization of privacy preferences could itself reproduce or …


Standardizing Space Technologies As Admissible Evidence: Legal And Ethical Frameworks For U.S. Courts And The International Criminal Court, Tuana Yazici Apr 2025

Standardizing Space Technologies As Admissible Evidence: Legal And Ethical Frameworks For U.S. Courts And The International Criminal Court, Tuana Yazici

University of Miami International and Comparative Law Review

This paper explores the increasing role of satellite and other space technologies — such as optical satellite imagery, radar, and artificial intelligence (AI) — in legal proceedings both in the U.S. and internationally. It examines relevant Supreme Court and appellate cases, as well as key international rulings, to assess how courts are addressing the legal challenges posed by surveillance technologies. These cases reveal the tension between advancing technology and existing privacy protections, highlighting the need for updated legal frameworks. The analysis also covers federal laws, including the Electronic Communications Privacy Act, alongside proposed legislation like the American Privacy Rights Act …


Dean's Desk: Finding New Ways To Help Diminish Cybersecurity Threats, Christiana Ochoa Mar 2025

Dean's Desk: Finding New Ways To Help Diminish Cybersecurity Threats, Christiana Ochoa

Christiana Ochoa (7/22-10/22 Acting; 11/2022-)

In an era when cyberattacks can paralyze hospitals, disrupt elections, and compromise the privacy of millions, the need for innovative cybersecurity and privacy protections has never been more urgent. But it is not just a question of new technologies; strong data protection depends as much on motivating people and organizations to use those technologies and make wise choices to diminish data risk.

The Indiana University Maurer School of Law has spent more than 30 years answering cybersecurity and privacy challenges with a distinctive, holistic approach: an interdisciplinary, human-centered legal education that equips students to lead at the intersection of technology, …


Erasing Illusions: A Statutory Framework For Deletion In U.S. Data Privacy, Kirsten Worden Mar 2025

Erasing Illusions: A Statutory Framework For Deletion In U.S. Data Privacy, Kirsten Worden

Texas A&M Law Review

Since the passage of the California Consumer Privacy Act in 2018, states have rushed to pass their own consumer data protection laws, filling the glaring absence of comprehensive federal privacy law in the United States. These state privacy statutes are largely modeled after the European Union’s (“EU’s”) General Data Protection Regulation (“GDPR”), which introduced the “right to be forgotten.” This right permits EU residents to request that organizations delete their personal information. U.S. state laws have followed the GDPR by adopting a “right to delete.” Yet these new state laws provide little detail about the right to delete and lack …


Centering The Vulnerable Through Data Protection, Scott Skinner-Thompson Jan 2025

Centering The Vulnerable Through Data Protection, Scott Skinner-Thompson

Publications

No abstract provided.


An American's Guide To The Eu Ai Act, Margot Kaminski, Andrew D. Selbst Jan 2025

An American's Guide To The Eu Ai Act, Margot Kaminski, Andrew D. Selbst

Publications

The EU AI Act entered into force in August 2024. The AI Act is long. It is complicated. It relies on a regulatory framework and institutions unfamiliar to many in the United States. But as the first omnibus AI regulation worldwide, it has the potential to have a vast influence on both practice and lawmaking.

In this Article, we provide the American's Guide to the EU AI Act. This Article breaks down the AI Act for a U.S. law audience, explaining the overall mechanisms, and how the Act interacts with background EU laws and institutions. At its core, the AI …


Don't Call It 'Privacy': Data Protection, From Ideas To Constitutional Law, Raphaël Beauregard-Lacroix Jan 2024

Don't Call It 'Privacy': Data Protection, From Ideas To Constitutional Law, Raphaël Beauregard-Lacroix

SJD Dissertations

Data protection law has been subject to various criticisms, among which is one of a fundamental kind: devoted to procedures, it lost sight of its privacy-bound origins. This dissertation aims to provide a novel historical and comparative account of the transatlantic development of data protection law, from the origins to this day, identifying how it may yet succeed in reaching the policy goals its original proponents imagined, and untangling key legal concepts along the way.

The regulatory concept of data protection was founded on three basic principles: purpose limitation, universality, and institutional supervision and enforcement. These three principles trace their …


U.S. Public Perceptions Of The Sensitivity Of Brain Data, Shenyang Huang, Umika Paul, Shikhar Gupta, Karan Desai, Melinda Guo, Jennifer Jung, Beatrice Capestany, William D. Krenzer, Dylan Stonecipher, Nita A. Farahany Jan 2024

U.S. Public Perceptions Of The Sensitivity Of Brain Data, Shenyang Huang, Umika Paul, Shikhar Gupta, Karan Desai, Melinda Guo, Jennifer Jung, Beatrice Capestany, William D. Krenzer, Dylan Stonecipher, Nita A. Farahany

Faculty Scholarship

As we approach an era of potentially widespread consumer neurotechnology, scholars and organizations worldwide have started to raise concerns about the data privacy issues these devices will present. Notably absent in these discussions is empirical evidence about how the public perceives that same information. This article presents the results of a nationwide survey on public perceptions of brain data, to inform discussions of law and policy regarding brain data governance. The survey reveals that the public may perceive certain brain data as less sensitive than other ‘private’ information, like social security numbers, but more sensitive than some ‘public’ information, like …


The New Eu-Us Data Protection Framework's Implications For Healthcare, Charlotte A. Tschider, Marcelo Corrales Compagnucci, Timo Minssen Jan 2024

The New Eu-Us Data Protection Framework's Implications For Healthcare, Charlotte A. Tschider, Marcelo Corrales Compagnucci, Timo Minssen

Faculty Publications & Other Works

In July 2023, the United States and the European Union introduced the Data Privacy Framework (DPF), introducing the third generation of cross-border data transfer agreements constituting adequacy with respect to personal data transfers under the General Data Protection Regulation (GDPR) between the European Union (EU) and the US. This framework may be used in cross-border healthcare and research relationships, which are highly desirable and increasingly essential to innovative health technology development and health services deployment. A reliable model meeting EU adequacy requirements could enhance the transfer of patient and research participant data. While the DPF might present a familiar terrain …


The Trade Origins Of Privacy Law, Anupam Chander Jan 2024

The Trade Origins Of Privacy Law, Anupam Chander

Georgetown Law Faculty Publications and Other Works

The desire for trade propelled the growth of data privacy law across the world. Countries with strong privacy laws sought to ensure that their citizens’ privacy would not be compromised when their data traveled to other countries. Even before this vaunted Brussels Effect pushed privacy law across the world through the enticement of trade with the European Union, Brussels had to erect privacy law within the Union itself. And as the Union itself expanded, privacy law was a critical condition for accession.

But this coupling of privacy and trade leaves a puzzle: how did the U.S. avoid a comprehensive privacy …


Privacy Law’S Role In An Information Economy, Sari Mazzurco Jan 2024

Privacy Law’S Role In An Information Economy, Sari Mazzurco

Faculty Journal Articles and Book Chapters

What do we lose when we lose our privacy? A slew of recently enacted state laws suggest that the loss of privacy is merely a loss of individual choice in the market exchange of services for personal information. This Article argues that a loss of privacy risks something greater: the collapse of complex and fluid social identity. Without privacy, individuals cannot nurture their own senses of self because they are no longer free to try on different social roles across diverse relationships. Pervasive, private data collection threatens multifaceted selfhood by eliminating the boundaries that make social roles distinct and hindering …


Data In Business & Society, Tabrez Y. Ebrahim Jan 2024

Data In Business & Society, Tabrez Y. Ebrahim

Lewis & Clark Law Review

Data, it is sometimes said, is the world’s new oil. Unlike the days when information was transmitted in print form, data is transmitted at the touch of a fingertip through the click of a mouse or a push of an icon on a phone app. Algorithms and computing systems have drastically expanded the scope, speed, and volume of access and use of data for consumers. Additionally, businesses, in variety of forms, including business-to-business, business-to-consumer, online, and even brick-and-mortar, have employed data to interact with other businesses and with consumers. Data has drastically expanded in use throughout business and society, and …


Against Engagement, Neil Richards, Woodrow Hartzog Jan 2024

Against Engagement, Neil Richards, Woodrow Hartzog

Faculty Scholarship

In this Article, we focus on a key dimension of commercial surveillance by data-intensive digital platforms that is too often treated as a supporting cast member instead of a star of the show: the concept of engagement. Engagement is, simply put, a measure of time, attention, and other interactions with a service. The economic logic of engagement is simple: more engagement equals more ads watched equals more revenue. Engagement is a lucrative digital business model, but it is problematic in several ways that lurk beneath the happy sloganeering of a “free” internet

Our goal in this Article is to isolate …


Do Not Touch My Data: Exploring A Disclosure-Based Framework To Address Data Access, Francis Morency Apr 2023

Do Not Touch My Data: Exploring A Disclosure-Based Framework To Address Data Access, Francis Morency

Washington and Lee Journal of Civil Rights and Social Justice

Companies have too much control over people’s information. In the data marketplace, companies package and sell individuals’ data, and these individuals have little to no bargaining power over the process. Companies may freely buy and sell people’s data in the private sector for targeted marketing and behavior manipulation. In the justice system, an unchecked data marketplace leaves black and brown communities vulnerable to serious data access issues caused by predictive sentencing, for example. Risk assessment algorithms in predictive sentencing rely on data on individuals and run all relevant data points to provide the likelihood that a defendant will recidivate low …


Prescribing Exploitation, Charlotte A. Tschider Jan 2023

Prescribing Exploitation, Charlotte A. Tschider

Faculty Publications & Other Works

Patients are increasingly reliant temporarily, if not indefinitely, on connected medical devices and wearables, many of which use artificial intelligence (“AI”) infrastructures and physical housing that directly interacts with the human body. The automated systems that drive the infrastructures of medical devices and wearables, especially those using complex AI, often use dynamically inscrutable algorithms that may render discriminatory effects that alter paths of treatment and other aspects of patient welfare.

Previous contributions to the literature, however, have not explored how AI technologies animate exploitation of medical technology users. Although all commercial relationships may exploit users to some degree, some forms …


The Gdpr And Uk Gdpr And Its Impact On Us Academic Institutions, Leila Halawi, Alpesh Makwana Jan 2023

The Gdpr And Uk Gdpr And Its Impact On Us Academic Institutions, Leila Halawi, Alpesh Makwana

Publications

This research paper delves into the implications of the General Data Protection Regulation (GDPR) and the United Kingdom (UK) GDPR on academic institutions, shedding light on their significance for organizations and educational establishments handling data from individuals in the European Union (EU) and the UK. Non-compliance with these regulations can lead to substantial penalties. The study focuses specifically on US Higher Education and presents actionable measures that institutions can adopt to enhance compliance, fortify data protection, and safeguard the privacy of individuals.


Data Privacy In The Time Of Plague, Cason Schmit, Brian N. Larson, Hye-Chung Kum Aug 2022

Data Privacy In The Time Of Plague, Cason Schmit, Brian N. Larson, Hye-Chung Kum

Faculty Scholarship

Data privacy is a life-or-death matter for public health. Beginning in late fall 2019, two series of events unfolded, one everyone talked about and one hardly anyone noticed: The greatest world-health crisis in at least 100 years, the COVID-19 pandemic; and the development of the Personal Data Protection Act Committee by the Uniform Law Commissioners (ULC) in the United States. By July 2021, each of these stories had reached a turning point. In the developed, Western world, most people who wanted to receive the vaccine against COVID- 19 could do so. Meanwhile, the ULC adopted the Uniform Personal Data Protection …


Data Privacy, Human Rights, And Algorithmic Opacity, Sylvia Lu Jan 2022

Data Privacy, Human Rights, And Algorithmic Opacity, Sylvia Lu

Fellow, Adjunct, Lecturer, and Research Scholar Works

Decades ago, it was difficult to imagine a reality in which artificial intelligence (AI) could penetrate every corner of our lives to monitor our innermost selves for commercial interests. Within just a few decades, the private sector has seen a wild proliferation of AI systems, many of which are more powerful and penetrating than anticipated. In many cases, AI systems have become “the power behind the throne,” tracking user activities and making fateful decisions through predictive analysis of personal information. Despite the growing power of AI, proprietary algorithmic systems can be technically complex, legally claimed as trade secrets, and managerially …


Responding To Deficiencies In The Architecture Of Privacy: Co-Regulation As The Path Forward For Data Protection On Social Networking Sites, Laurent Cre ́Peau Jan 2022

Responding To Deficiencies In The Architecture Of Privacy: Co-Regulation As The Path Forward For Data Protection On Social Networking Sites, Laurent Cre ́Peau

Canadian Journal of Law and Technology

Social Networking Sites like Facebook, Twitter and the like are a ubiquitous part of contemporary culture. Yet, as exemplified on numerous occasions, most recently in the Cambridge Analytica scandal that shook Facebook in 2018, these sites pose major concerns for personal data protection. Whereas self-regulation has characterized the general regulatory mindset since the early days of the Internet, it is no longer viable given the threat social media poses to user privacy. This article notes the deficiencies of self-regulatory models of privacy and contends jurisdictions like Canada should ensure they have strong data protection regulations to adequately protect the public. …


Delineating The Legal Framework For Data Protection: A Fundamental Rights Approach Or Data Propertization?, Efe Lawrence Ogbeide Jan 2022

Delineating The Legal Framework For Data Protection: A Fundamental Rights Approach Or Data Propertization?, Efe Lawrence Ogbeide

Canadian Journal of Law and Technology

The Charter of Fundamental Rights of the European Union, like other key legal instruments around the globe, grants citizens the right to privacy in Article 7. The Charter, however, further provides for the right to data protection in Article 8. Simply put, the implication of Article 8 of the Charter is that the right to data protection is a fundamental right. The central question in this article is whether data protection indeed qualifies to be categorized as a fundamental right. If not, what other approach(es) to data protection may be implemented?


Use Of Unmanned Aircraft Systems And Regulatory Landscape: Unravelling The Future Challenges In The High Sky, K Kirthan Shenoy, Divya Tyagi Jan 2022

Use Of Unmanned Aircraft Systems And Regulatory Landscape: Unravelling The Future Challenges In The High Sky, K Kirthan Shenoy, Divya Tyagi

International Journal of Aviation, Aeronautics, and Aerospace

The individuals on the ground nowadays often observe objects distantly hover over the sky, which raises the question of who might be operating the object or what the object might record. Unmanned Aircraft Systems (UAS) or Drones today have quickly penetrated civilian, military, and commercial sectors. The drones or UAS, with the advancement of technology, are now capable of traversing long distances, having long endurance, and having multipurpose functionality. The UAS industry is fast expanding, with trade investment touching the billion-dollar mark in flourishing economies. The advent of the Covid 19 pandemic saw a steep rise in the use of …


Legislating Data Loyalty, Woodrow Hartzog, Neil Richards Jan 2022

Legislating Data Loyalty, Woodrow Hartzog, Neil Richards

Faculty Scholarship

Lawmakers looking to embolden privacy law have begun to consider imposing duties of loyalty on organizations trusted with people’s data and online experiences. The idea behind loyalty is simple: organizations should not process data or design technologies that conflict with the best interests of trusting parties. But the logistics and implementation of data loyalty need to be developed if the concept is going to be capable of moving privacy law beyond its “notice and consent” roots to confront people’s vulnerabilities in their relationship with powerful data collectors.

In this short Essay, we propose a model for legislating data loyalty. Our …


The Surprising Virtues Of Data Loyalty, Woodrow Hartzog, Neil M. Richards Jan 2022

The Surprising Virtues Of Data Loyalty, Woodrow Hartzog, Neil M. Richards

Faculty Scholarship

Lawmakers in the United States and Europe are seriously considering imposing duties of data loyalty that implement ideas from privacy law scholarship, but critics claim such duties are unnecessary, unworkable, overly individualistic, and indeterminately vague. This paper takes those criticisms seriously, and its analysis of them reveals that duties of data loyalty have surprising virtues. Loyalty, it turns out, can support collective well-being by embracing privacy’s relational turn; it can be a powerful state of mind for reenergizing privacy reform; it prioritizes human values rather than potentially empty formalism; and it offers solutions that are flexible and clear rather than …


Stealing (Identity) From The Poor, Sara S. Greene Jan 2021

Stealing (Identity) From The Poor, Sara S. Greene

Faculty Scholarship

The law of data breaches is new, dynamic, and evolving. The number and complexity of breaches increases each year and legal scholars, courts, and policymakers scramble to respond. In 2019, 14.4 million consumers became victims of identity theft, the most problematic consequence of data breaches for consumers. Indeed, one-third of all Americans have experienced identity theft at some point in their lives. Yet despite low-income groups comprising at least thirty percent of all identity theft victims, existing discourse and debate on the regulatory regime governing data breaches and identity theft primarily reflects the experiences and concerns of middle- and high-income …


Ai's Legitimate Interest: Towards A Public Benefit Privacy Model, Charlotte A. Tschider Jan 2021

Ai's Legitimate Interest: Towards A Public Benefit Privacy Model, Charlotte A. Tschider

Faculty Publications & Other Works

Health data uses are on the rise. Increasingly more often, data are used for a variety of operational, diagnostic, and technical uses, as in the Internet of Health Things. Never has quality data been more necessary: large data stores now power the most advanced artificial intelligence applications, applications that may enable early diagnosis of chronic diseases and enable personalized medical treatment. These data, both personally identifiable and de-identified, have the potential to dramatically improve the quality, effectiveness, and safety of artificial intelligence.

Existing privacy laws do not 1) effectively protect the privacy interests of individuals and 2) provide the flexibility …


Meaningful Choice: A History Of Consent And Alternatives To The Consent Myth, Charlotte A. Tschider Jan 2021

Meaningful Choice: A History Of Consent And Alternatives To The Consent Myth, Charlotte A. Tschider

Faculty Publications & Other Works

Although the first legal conceptions of commercial privacy were identified in Samuel Warren and Louis Brandeis’s foundational 1890 article, The Right to Privacy, conceptually, privacy has existed since as early as 1127 as a natural concern when navigating between personal and commercial spheres of life. As an extension of contract and tort law, two common relational legal models, U.S. privacy law emerged to buoy engagement in commercial enterprise, borrowing known legal conventions like consent and assent. Historically, however, international legal privacy frameworks involving consent ultimately diverged, with the European Union taking a more expansive view of legal justification for processing …


A Review Of Data Protection Regulations And The Right To Privacy: The Case Of The Us And India, Chrisann Campbell Jan 2021

A Review Of Data Protection Regulations And The Right To Privacy: The Case Of The Us And India, Chrisann Campbell

Dissertations and Theses

Since 1948 and the signing of the Universal Declaration of Human Rights, the concept of privacy has grown more complex with the rise of technology and a shift to the internet. In particular, the unregulated use of technologies that can capture individuals' personal data without their knowledge or consent poses a threat to their right to privacy and other additional human rights. The protection of the collection, storing, and transfer of users' personal data against data breaches also ensures that the right to privacy is guaranteed. Through examining two countries, the U.S. and India, on the idea of privacy, personal …


Catalyzing Privacy Law, Anupam Chander, Margot E. Kaminski, William Mcgeveran Jan 2021

Catalyzing Privacy Law, Anupam Chander, Margot E. Kaminski, William Mcgeveran

Publications

The United States famously lacks a comprehensive federal data privacy law. In the past year, however, over half the states have proposed broad privacy bills or have established task forces to propose possible privacy legislation. Meanwhile, congressional committees are holding hearings on multiple privacy bills. What is catalyzing this legislative momentum? Some believe that Europe’s General Data Protection Regulation (GDPR), which came into force in 2018, is the driving factor. But with the California Consumer Privacy Act (CCPA) which took effect in January 2020, California has emerged as an alternate contender in the race to set the new standard for …


"Slack" In The Data Age, Shu-Yi Oei, Diane M. Ring Jan 2021

"Slack" In The Data Age, Shu-Yi Oei, Diane M. Ring

Faculty Scholarship

This Article examines how increasingly ubiquitous data and information affect the role of “slack” in the law. Slack is the informal latitude to break the law without sanction. Pockets of slack exist for various reasons, including information imperfections, enforcement resource constraints, deliberate nonenforcement of problematic laws, politics, biases, and luck. Slack is important in allowing flexibility and forbearance in the legal system, but it also risks enabling selective and uneven enforcement. Increasingly available data is now upending slack, causing it to contract and exacerbating the risks of unfair enforcement.

This Article delineates the various contexts in which slack arises and …