Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Computer Law (12)
- Internet Law (11)
- Science and Technology Law (10)
- Health Law and Policy (7)
- Communications Law (4)
-
- Comparative and Foreign Law (4)
- Computer Sciences (3)
- Consumer Protection Law (3)
- Physical Sciences and Mathematics (3)
- Commercial Law (2)
- Constitutional Law (2)
- Information Security (2)
- Intellectual Property Law (2)
- Law and Society (2)
- Legal Ethics and Professional Responsibility (2)
- Legal Remedies (2)
- Legislation (2)
- National Security Law (2)
- Asian Studies (1)
- Business (1)
- Business Administration, Management, and Operations (1)
- Business Law, Public Responsibility, and Ethics (1)
- Business Organizations Law (1)
- Civil Rights and Discrimination (1)
- Conflict of Laws (1)
- Contracts (1)
- Criminal Law (1)
- E-Commerce (1)
- Institution
-
- University of Michigan Law School (11)
- Boston University School of Law (8)
- University of Oklahoma College of Law (5)
- Chicago-Kent College of Law (3)
- The Catholic University of America, Columbus School of Law (2)
-
- University of Colorado Law School (2)
- City University of New York (CUNY) (1)
- Cornell University Law School (1)
- Georgetown University Law Center (1)
- Singapore Management University (1)
- St. Mary's University (1)
- University of Miami Law School (1)
- Vanderbilt University Law School (1)
- Washington and Lee University School of Law (1)
- Publication Year
- Publication
-
- Faculty Scholarship (8)
- Michigan Telecommunications & Technology Law Review (6)
- Faculty Articles (4)
- Chicago-Kent Law Review (3)
- Michigan Technology Law Review (3)
-
- Michigan Law Review (2)
- Publications (2)
- Catholic University Journal of Law and Technology (1)
- Catholic University Law Review (1)
- Cornell Law Faculty Publications (1)
- Georgetown Law Faculty Publications and Other Works (1)
- Oklahoma Law Review (1)
- Publications and Research (1)
- Research Collection Yong Pung How School Of Law (1)
- The Scholar: St. Mary's Law Review on Race and Social Justice (1)
- University of Miami Law Review (1)
- Vanderbilt Journal of Entertainment & Technology Law (1)
- Washington and Lee Law Review (1)
- Publication Type
Articles 1 - 30 of 39
Full-Text Articles in Privacy Law
The Great Scrape: The Clash Between Scraping And Privacy, Daniel J. Solove, Woodrow Hartzog
The Great Scrape: The Clash Between Scraping And Privacy, Daniel J. Solove, Woodrow Hartzog
Faculty Scholarship
Artificial intelligence (AI) systems depend on massive quantities of data, often gathered by “scraping”—the automated extraction of large amounts of data from the internet. A great deal of scraped data contains people’s personal information. This personal data provides the grist for AI tools such as facial recognition, deep fakes, and generative AI. Although scraping enables web searching, archiving of records, and meaningful scientific research, scraping for AI can also be objectionable and even harmful to individuals and society.
Organizations are scraping at an escalating pace and scale, even though many privacy laws are seemingly incongruous with the practice. In this …
Client Confidentiality As Data Security, Jonah Perlin
Client Confidentiality As Data Security, Jonah Perlin
Georgetown Law Faculty Publications and Other Works
The duty of confidentiality has been a cornerstone of the attorney-client relationship for more than four centuries. Historically, this duty was not difficult to discharge. All a lawyer had to do to comply was not affirmatively share client information in public without consent. But that has all changed. The same technologies that provide unprecedented benefits of authorized access by lawyers and their clients create unprecedented risks of unauthorized access by others. As a result, although the duty of confidentiality was once synonymous with a duty to keep client confidences secret, today the duty necessitates that lawyers keep client confidences secure …
The Three Laws: The Chinese Communist Party Throws Down The Data Regulation Gauntlet, William Chaskes
The Three Laws: The Chinese Communist Party Throws Down The Data Regulation Gauntlet, William Chaskes
Washington and Lee Law Review
Criticism of the Chinese Communist Party (CCP) runs a wide gamut. Accusations of human rights abuses, intellectual property theft, authoritarian domestic policies, disrespecting sovereign borders, and propaganda campaigns all have one common factor: the CCP’s desire to control information. Controlling information means controlling data. Lurking beneath the People’s Republic of China’s (PRC) tumultuous relationship with the rest of the world is the fight between nations to control their citizens’ data while also keeping it out of the hands of adversaries. The CCP’s Three Laws are its newest weapon in this data war.
One byproduct of the CCP’s emphasis on controlling …
Gauging The Acceptance Of Contact Tracing Technology: An Empirical Study Of Singapore Residents’ Concerns With Sharing Their Information And Willingness To Trust, Ee-Ing Ong, Wee Ling Loo
Gauging The Acceptance Of Contact Tracing Technology: An Empirical Study Of Singapore Residents’ Concerns With Sharing Their Information And Willingness To Trust, Ee-Ing Ong, Wee Ling Loo
Research Collection Yong Pung How School Of Law
In response to the COVID-19 pandemic, governments began implementing various forms of contact tracing technology. Singapore’s implementation of its contact tracing technology, TraceTogether, however, was met with significant concern by its population, with regard to privacy and data security. This concern did not fit with the general perception that Singaporeans have a high level of trust in its government. We explore this disconnect, using responses to our survey (conducted pre-COVID-19) in which we asked participants about their level of concern with the government and business collecting certain categories of personal data. The results show that respondents had less concern with …
Small Business Cybersecurity: A Loophole To Consumer Data, Matthew R. Espinosa
Small Business Cybersecurity: A Loophole To Consumer Data, Matthew R. Espinosa
The Scholar: St. Mary's Law Review on Race and Social Justice
Small businesses and small minority owned businesses are vital to our nation’s economy; therefore legislation, regulation, and policy has been created in order to assist them in overcoming their economic stability issues and ensure they continue to serve the communities that rely on them. However, there is not a focus on regulating nor assisting small businesses to ensure their cybersecurity standards are up to par despite them increasingly becoming a victim of cyberattacks that yield high consequences. The external oversight and assistance is necessary for small businesses due to their lack of knowledge in implementing effective cybersecurity policies, the fiscal …
Individuals As Gatekeepers Against Data Misuse, Ying Hu
Individuals As Gatekeepers Against Data Misuse, Ying Hu
Michigan Technology Law Review
This article makes a case for treating individual data subjects as gatekeepers against misuse of personal data. Imposing gatekeeper responsibility on individuals is most useful where (a) the primary wrongdoers engage in data misuse intentionally or recklessly; (b) misuse of personal data is likely to lead to serious harm; and (c) one or more individuals are able to detect and prevent data misuse at a reasonable cost.
As gatekeepers, individuals should have a legal duty to take reasonable measures to prevent data misuse where they are aware of facts indicating that the person seeking personal data from them is highly …
Healthy Data Protection, Lothar Determann
Healthy Data Protection, Lothar Determann
Michigan Technology Law Review
Modern medicine is evolving at a tremendous speed. On a daily basis, we learn about new treatments, drugs, medical devices, and diagnoses. Both established technology companies and start-ups focus on health-related products and services in competition with traditional healthcare businesses. Telemedicine and electronic health records have the potential to improve the effectiveness of treatments significantly. Progress in the medical field depends above all on data, specifically health information. Physicians, researchers, and developers need health information to help patients by improving diagnoses, customizing treatments and finding new cures.
Yet law and policymakers are currently more focused on the fact that health …
Exploring Lawful Hacking As A Possible Answer To The "Going Dark" Debate, Carlos Liguori
Exploring Lawful Hacking As A Possible Answer To The "Going Dark" Debate, Carlos Liguori
Michigan Technology Law Review
The debate on government access to encrypted data, popularly known as the “going dark” debate, has intensified over the years. On the one hand, law enforcement authorities have been pushing for mandatory exceptional access mechanisms on encryption systems in order to enable criminal investigations of both data in transit and at rest. On the other hand, both technical and industry experts argue that this solution compromises the security of encrypted systems and, thus, the privacy of their users. Some claim that other means of investigation could provide the information authorities seek without weakening encryption, with lawful hacking being one of …
A New Frontier Facing Attorneys And Paralegals: The Promise & Challenges Of Artificial Intelligence As Applied To Law & Legal Decision-Making, Marissa Moran
Publications and Research
Artificial Intelligence/AI invisibly navigates and informs our lives today and may also be used to determine a client’s legal fate. Through executive order, statements by a U.S. Supreme Court justice and a Congressional Commission on AI, all three branches of the United States government have addressed the use of AI to resolve societal and legal matters. Pursuant to the American Bar Association Model Rules of Professional Conduct[i] and New York Rules of Professional Conduct (NYRPC), [ii] the legal profession recognizes the need for competency in technology which requires both substantive knowledge of law and competent use of technology for …
Assumed Compliance, Stacey A. Tovino
Breaches Within Breaches: The Crossroads Of Erisa Fiduciary Responsibilities And Data Security, Gregg Moran
Breaches Within Breaches: The Crossroads Of Erisa Fiduciary Responsibilities And Data Security, Gregg Moran
University of Miami Law Review
Although the drafters of the Employee Retirement Income Security Act of 1974 (“ERISA”) likely could not have anticipated the data security issues of the twenty-first century, ERISA’s duty of prudence almost certainly requires employee benefit plan fiduciaries to protect sensitive participant data in at least some manner. This Article suggests the Department of Labor should issue a regulation clarifying fiduciaries’ data security obligations. Given that fiduciaries are in the best positions to recognize their plans’ individual security needs and capabilities, the regulation should not attempt to micromanage fiduciaries’ substantive data security policies; rather, it should focus on the procedures by …
Going Rogue: Mobile Research Applications And The Right To Privacy, Stacey A. Tovino
Going Rogue: Mobile Research Applications And The Right To Privacy, Stacey A. Tovino
Faculty Articles
This Article investigates whether nonsectoral state laws may serve as a viable source of privacy and security standards for mobile health research participants and other health data subjects until new federal laws are created or enforced. In particular, this Article (1) catalogues and analyzes the nonsectoral data privacy, security, and breach notification statutes of all fifty states and the District of Columbia; (2) applies these statutes to mobile-app-mediated health research conducted by independent scientists, citizen scientists, and patient researchers; and (3) proposes substantive amendments to state law that could help protect the privacy and security of all health data subjects, …
Florida Law, Mobile Research Applications, And The Right To Privacy, Stacey A. Tovino
Florida Law, Mobile Research Applications, And The Right To Privacy, Stacey A. Tovino
Faculty Articles
This Article investigates whether state law contains comprehensive privacy, security, and breach notification standards that could apply to independent scientists who conduct mobile app mediated health research. Focusing only on Florida law, this Article assesses potentially relevant and applicable sources of privacy, security, and breach notification standards for health data of the type obtained during mobile app mediated health research studies. This Article concludes that, with one exception, Florida law tends to fall into one of two categories: (1) the law contains at least one data privacy, security, or breach notification standard, but the standard is limited in application to …
A Timely Right To Privacy, Stacey A. Tovino
A Timely Right To Privacy, Stacey A. Tovino
Faculty Articles
On December 28, 2017, the federal Department of Health and Human Services ("HHS") settled its fiftieth case involving potential violations of the privacy, security, and breach notification rules ("Rules") that implement the Health Insurance Portability and Accountability Act ("HIPAA") and the Health Information Technology for Economic and Clinical Health Act ("HITECH"). This Article catalogues and examines currently available enforcement actions involving the HIPAA and HITECH Rules, including the cases in which HHS has entered into a settlement agreement with a HIPAA covered entity or business associate, the cases in which HHS has imposed a civil money penalty on a HPAA …
Who Are The Real Cyberbullies: Hackers Or The Ftc? The Fairness Of The Ftc’S Authority In The Data Security Context, Jaclyn K. Haughom
Who Are The Real Cyberbullies: Hackers Or The Ftc? The Fairness Of The Ftc’S Authority In The Data Security Context, Jaclyn K. Haughom
Catholic University Law Review
As technology continues to be an integral part of daily life, there lies an ever-increasing threat of the personally identifiable information of consumers being lost, stolen, or accessed without authorization. The Federal Trade Commission (FTC) is the U.S. government’s primary consumer protection agency and the country’s lead enforcer against companies subject to data breaches. Although the FTC lacks explicit statutory authority to enforce against data breaches, the Commission has successfully relied on Section 5 of the FTC Act (FTCA) to exercise its consumer protection power in the data security context. However, as the FTC continues to take action against businesses …
Health Information Equity, Craig Konnoth
Health Information Equity, Craig Konnoth
Publications
In the last few years, numerous Americans’ health information has been collected and used for follow-on, secondary research. This research studies correlations between medical conditions, genetic or behavioral profiles, and treatments, to customize medical care to specific individuals. Recent federal legislation and regulations make it easier to collect and use the data of the low-income, unwell, and elderly for this purpose. This would impose disproportionate security and autonomy burdens on these individuals. Those who are well-off and pay out of pocket could effectively exempt their data from the publicly available information pot. This presents a problem which modern research ethics …
Standing After Snowden: Lessons On Privacy Harm From National Security Surveillance Litigation, Margot E. Kaminski
Standing After Snowden: Lessons On Privacy Harm From National Security Surveillance Litigation, Margot E. Kaminski
Publications
Article III standing is difficult to achieve in the context of data security and data privacy claims. Injury in fact must be "concrete," "particularized," and "actual or imminent"--all characteristics that are challenging to meet with information harms. This Article suggests looking to an unusual source for clarification on privacy and standing: recent national security surveillance litigation. There we can find significant discussions of what rises to the level of Article III injury in fact. The answers may be surprising: the interception of sensitive information; the seizure of less sensitive information and housing of it in a database for analysis; and …
The Privacy Policymaking Of State Attorneys General, Danielle K. Citron
The Privacy Policymaking Of State Attorneys General, Danielle K. Citron
Faculty Scholarship
Accounts of privacy law have focused on legislation, federal agencies, and the self-regulation of privacy professionals. Crucial agents of regulatory change, however, have been ignored: the state attorneys general. This article is the first in-depth study of the privacy norm entrepreneurship of state attorneys general. Because so little has been written about this phenomenon, I engaged with primary sources — first interviewing state attorneys general and current and former career staff, and then examining documentary evidence received through FOIA requests submitted to AG offices around the country.
Much as Justice Louis Brandeis imagined states as laboratories of the law, offices …
Just What The Doctor Ordered: Protecting Privacy Without Impeding Development Of Digital Pills, Amelia R. Montgomery
Just What The Doctor Ordered: Protecting Privacy Without Impeding Development Of Digital Pills, Amelia R. Montgomery
Vanderbilt Journal of Entertainment & Technology Law
Using technology, humans are receiving more and more information about the world around them via the Internet of Things, and the next area of connection will be the inside of the human body. Several forms of "digital pills" that send information from places like the human digestive tract or bloodstream are being developed, with a few already in use. These pills could stand to provide information that could drastically improve the lives of many people, but they also have privacy and data security implications that could put consumers at great risk. This Note analyzes these risks and suggests that short-term …
Taking Trust Seriously In Privacy Law, Neil Richards, Woodrow Hartzog
Taking Trust Seriously In Privacy Law, Neil Richards, Woodrow Hartzog
Faculty Scholarship
Trust is beautiful. The willingness to accept vulnerability to the actions of others is the essential ingredient for friendship, commerce, transportation, and virtually every other activity that involves other people. It allows us to build things, and it allows us to grow. Trust is everywhere, but particularly at the core of the information relationships that have come to characterize our modern, digital lives. Relationships between people and their ISPs, social networks, and hired professionals are typically understood in terms of privacy. But the way we have talked about privacy has a pessimism problem – privacy is conceptualized in negative terms, …
Anonymization And Risk, Ira S. Rubinstein, Woodrow Hartzog
Anonymization And Risk, Ira S. Rubinstein, Woodrow Hartzog
Faculty Scholarship
Perfect anonymization of data sets that contain personal information has failed. But the process of protecting data subjects in shared information remains integral to privacy practice and policy. While the deidentification debate has been vigorous and productive, there is no clear direction for policy. As a result, the law has been slow to adapt a holistic approach to protecting data subjects when data sets are released to others. Currently, the law is focused on whether an individual can be identified within a given set. We argue that the best way to move data release policy past the alleged failures of …
Implications For The Future Of Global Data Security And Privacy: The Territorial Application Of The Stored Communications Act And The Microsoft Case, Russell Hsiao
Catholic University Journal of Law and Technology
No abstract provided.
Exposure Without Redress: A Proposed Remedial Tool For The Victimns Who Were Set Aside, Elizabeth T. Isaacs
Exposure Without Redress: A Proposed Remedial Tool For The Victimns Who Were Set Aside, Elizabeth T. Isaacs
Oklahoma Law Review
No abstract provided.
The Scope And Potential Of Ftc Data Protection, Woodrow Hartzog, Daniel J. Solove
The Scope And Potential Of Ftc Data Protection, Woodrow Hartzog, Daniel J. Solove
Faculty Scholarship
For more than fifteen years, the FTC has regulated privacy and data security through its authority to police deceptive and unfair trade practices as well as through powers conferred by specific statutes and international agreements. Recently, the FTC’s powers for data protection have been challenged by Wyndham Worldwide Corp. and LabMD. These recent cases raise a fundamental issue, and one that has surprisingly not been well explored: How broad are the FTC’s privacy and data security regulatory powers? How broad should they be?
In this Article, we address the issue of the scope of FTC authority in the areas of …
Unfair And Deceptive Robots, Woodrow Hartzog
Unfair And Deceptive Robots, Woodrow Hartzog
Faculty Scholarship
Robots, like household helpers, personal digital assistants, automated cars, and personal drones are or will soon be available to consumers. These robots raise common consumer protection issues, such as fraud, privacy, data security, and risks to health, physical safety and finances. Robots also raise new consumer protection issues, or at least call into question how existing consumer protection regimes might be applied to such emerging technologies. Yet it is unclear which legal regimes should govern these robots and what consumer protection rules for robots should look like.
The thesis of the Article is that the FTC’s grant of authority and …
The Ftc And The New Common Law Of Privacy, Daniel J. Solove, Woodrow Hartzog
The Ftc And The New Common Law Of Privacy, Daniel J. Solove, Woodrow Hartzog
Faculty Scholarship
One of the great ironies about information privacy law is that the primary regulation of privacy in the United States has barely been studied in a scholarly way. Since the late 1990s, the Federal Trade Commission (FTC) has been enforcing companies’ privacy policies through its authority to police unfair and deceptive trade practices. Despite over fifteen years of FTC enforcement, there is no meaningful body of judicial decisions to show for it. The cases have nearly all resulted in settlement agreements. Nevertheless, companies look to these agreements to guide their privacy practices. Thus, in practice, FTC privacy jurisprudence has become …
The Ftc And Privacy And Security Duties For The Cloud, Daniel J. Solove, Woodrow Hartzog
The Ftc And Privacy And Security Duties For The Cloud, Daniel J. Solove, Woodrow Hartzog
Faculty Scholarship
Third-party data service providers, especially providers of cloud computing services, present unique and difficult privacy and data security challenges. While many companies that directly collect data from consumers are bound by the promises they make to individuals in their privacy policies, cloud service providers are usually not a part of this arrangement. It is not entirely clear what, if any, obligations cloud service providers have to protect the data of individuals with whom they have no contractual relationship. This problem is especially acute because many institutions sharing personal data with cloud service providers fail to include significant privacy and security …
Limits Of The Federal Wiretap Act's Ability To Protect Against Wi-Fi Sniffing, Mani Potnuru
Limits Of The Federal Wiretap Act's Ability To Protect Against Wi-Fi Sniffing, Mani Potnuru
Michigan Law Review
Adoption of Wi-Fi wireless technology continues to see explosive growth. However many users still operate their home Wi-Fi networks in unsecured mode or use publicly available unsecured Wi-Fi networks, thus exposing their communications to the dangers of "packet sniffing," a technique used for eavesdropping on a network. Some have argued that communications over unsecured Wi-Fi networks are "readily accessible to the general public" and that such communications are therefore excluded from the broad protections of the Federal Wiretap Act against intentional interception of electronic communications. This Note examines the Federal Wiretap Act and argues that the current Act's treatment of …
Known And Unknown, Property And Contract: Comments On Hoofnagle And Moringiello, James Grimmelmann
Known And Unknown, Property And Contract: Comments On Hoofnagle And Moringiello, James Grimmelmann
Cornell Law Faculty Publications
In addition to gerund-noun-noun titles and a concern with the misaligned incentives of businesses that handle consumers' financial data, Chris Hoofnagle's Internalizing Identity Theft and Juliet Moringiello's Warranting Data Security share something else: hidden themes. Hoofnagle's paper is officially about an empirical study of identity theft, but behind the scenes it's also an exploration of where we draw the line between public information shared freely and secret information used to authenticate individuals. Moringiello's paper is officially a proposal for a new warranty of secure handling of payment information, but under the surface, it invites us to think about the relationship …
There Is A Time To Keep Silent And A Time To Speak, The Hard Part Is Knowing Which Is Which: Striking The Balance Between Privacy Protection And The Flow Of Health Care Information, Daniel J. Gilman, James C. Cooper
There Is A Time To Keep Silent And A Time To Speak, The Hard Part Is Knowing Which Is Which: Striking The Balance Between Privacy Protection And The Flow Of Health Care Information, Daniel J. Gilman, James C. Cooper
Michigan Telecommunications & Technology Law Review
Health information technology (HIT) has become a signal element of federal health policy, especially as the recently enacted American Recovery and Reinvestment Act of 2009 (Recovery Act or ARRA) comprises numerous provisions related to HIT and commits tens of billions of dollars to its development and adoption. These provisions charge various agencies of the federal government with both general and specific HIT-related implementation tasks including, inter alia, providing funding for HIT in various contexts: the implementation of interoperable HIT, HIT-related infrastructure, and HIT-related training and research. The Recovery Act also contains various regulatory provisions pertaining to HIT. Provisions of the …