Showing posts with label privacy rights. Show all posts
Showing posts with label privacy rights. Show all posts

Tuesday, May 13, 2008

More Potential Legal Troubles for Google Streetview

Ever since its introduction, Google Streetview has raised concerns about privacy (see, e.g., here). Now, Streetview is being prepared for Europe, and apparently French law is presenting a problem. According to this article from Computer World, under French law, you are not permitted to publish images of people going about their business without their permission. The article says that that's a problem for Streetview because it could require Google to employ "an army of clipboard-wielding legal assistants asking bystanders to sign release forms as they sip their coffee."

My initial take on it is that something about the article doesn't make sense. While I'm not familiar with French law, it seems unbelievable to me that any country would have regulations that prevent the publication of pictures taken in public. After all, if French law really did include that requirement, it would seem completely incompatible with newspapers publishing pictures of crowds, such as might appear at political rallies and sporting events. In any case though, if the article's portrayal of French law really is correct, then it's an example of where I think giving individuals control over some aspect of their persona (in this case their image) goes too far. The loss of privacy from allowing pictures to be published without permission is slight (if it shows up on Google Streetview it was, by hypothesis, visible to the public). By contrast, the cost is real - loss of a popular product which could spin off potentially interesting follow on technologies. Thus, in this case, assuming the choice is real, I'd have to come down on the side of Google, rather than on the side of individual control of information.

Sunday, March 16, 2008

Problems with U.S. Courts' Treatment of Security Breach Damages

This article from Computer World asks the question "When Does a Privacy Breach Cause Harm?" and then proceeds to take U.S. courts to task for failing to recognize damages from security breaches beyond verifiable damages from identity theft or account fraud. While I agree that U.S. courts have done an atrocious job with respect to protecting privacy (see, e.g., here, describing the 7th Circuit's statement that plaintiffs could not proceed on a action based on a data security breach, despite circumstances showing that the breach was caused by identity thieves), I have to take issue with the analysis offered in the article. The article states that the problem with what courts have done is that they have overlooked "[t]he assault to personality and feelings [that is] is the quintessential privacy injury." That rationale just doesn't work for me. Human feelings are notoriously hard to quantify, which means that damages based on assaults to personality and feelings would likely swing wildly from case to case and judge to judge, even if the actual underlying facts in particular cases are similar. Moreover, basing damages on feelings of loss and assault to personality runs the significant risk that juries will simply decide that those losses are too small to justify compensating, since studies (e.g., here) have shown that most people place little to no value on the privacy of their personal information.
A better option, and one I happen to agree with, is for businesses which suffer a security breach through their own fault (e.g., negligence) should be held responsible for the quantifiable damages caused by that breach, even if there is no subsequent identity theft. For example, time spent by customers replacing credit cards with stolen numbers, or the cost of various identity theft protection services are easily determined, and would serve as a measure of damages that courts could easily compute and assess. Indeed, since limiting damages to those directly caused by identity theft or account fraud provides an incentive for consumers not to prevent identity theft, making companies responsible for quantifiable costs would improve the status quo by increasing the level of protection given to privacy by courts, while avoiding the difficulties of trying to quantify injuries to personality. To me, that's a far superior alternative to relying on damages to personal integrity, which are both hard to quantify, and easy to undermine.

via The Dunning Letter.

PostScript: I am well aware that laws vary tremendously from state to state. My statements regarding the state of current privacy laws reflect the holding in Pisciotta v. Old National Bancorp, in which the 7th circuit addressed the issue of damages for a data security breach in the absence of subsequent identity theft.

Sunday, February 17, 2008

An Interesting Application of Privacy Laws

Here's an interesting article about a consumer who has used a data exposure notification law for an novel purpose: punishing an electronics distributor for bad customer service. What happened was as follows:
1) Raelyn Campbell brings her laptop into Best Buy for service.
2) Best Buy loses laptop.
3) Raelyn contacts best buy asking when her laptop will be ready.
4) Best Buy gives Raelyn the runaround
5) Steps 3-4 repeated for four months.
6) Realyn sues Best Buy...for $54,000,000.
So where's the privacy angle in all this? It turns out, that the sequence of events describes above should have included a step 2a) Tell Raelyn that her laptop, which contained her tax returns, was lost. The reason (other than the fact that it's the right thing to do from a moral and customer relations standpoint) is that such notification seems to be required by the District of Columbia's security breach notification act. That law, which it appears that Best Buy did not comply with, is the basis for Raelyn's $54,000,000 suit.

The next question, of course, how much this is going to end up costing Best Buy. The short answer is: not $54,000,000. The relevant statute does authorize individuals to file suit against entities who have not complied with the statute's requirements (see here). However, it allows a recovery of actual damages plus costs (including attorney's fees), and Raelyn admits that the $54,000,000 figure was pulled out of the air for the purpose of making a statement. However, Best Buy isn't going to get off cheap either. When Raelyn originally learned that the laptop had been lost, she offered to settle with Best Buy for $2,100. As an attorney, I can safely say that Best Buy will spend more (likely much more) in legal fees just dealing with the case. Moreover, there's the cost of actually paying Raelyn's damages (cost of the laptop and any data stored on it, time wasted trying to get the laptop back, attorney's fees, and court costs). All in all, my guess is that before the end of this suit, Best Buy will institute a policy of simply replacing lost laptops for customer in states with security breach notification laws that allow for individual suit.

If that prediction turns out to be correct, it would be a powerful example of how allowing consumers to protect the security of their own data can have beneficial effects beyond consumer privacy (in this case improving customer service); something to consider when people ask why they should care about the privacy of information.

Wednesday, January 9, 2008

Lawsuit Against Sears Attacks Customer Information Sharing Practices

A class action lawsuit against Sears Holdings Corp. filed last week illustrates how far the plaintiff's bar is willing to go to extend the frontier of tort liability for the alleged breach of consumer privacy rights. See Computerworld article
The lawsuit challenges the availability of Sears' customers' purchasing history on its Managemyhome.com website. Besides providing Sears shoppers with the ability to download manuals, find product tips and get home-renovation ideas, it also let customers track purchases and product warranties by entering their name, address and phone number. Since it was not password-protected, anyone could enter any other name and address and obtain others' information as well. The "Find your Products" section of the site has been disabled in the wake of public criticism and the filing of the lawsuit.

While the legal merits of the case may be tenuous, the more important lesson from this case for companies is that it illustrates what NOT to do. First, Sears created a site knowingly giving public access to its customers' personal information. No matter that it did not include account or Social Security numbers -- most laws define "nonpublic personal information" to be a consumer's name and any of that person's address, phone number, Social Security number, account number, etc. So, by definition, this information was considered "private" and should have been password-protected. Secondly, Sears did not inform its customers that they were making this information available on the website. Its privacy policy made no mention of it, and while it may not be required by law, it would have been prudent to give the customers the opportunity to opt out. Finally, Sears learned of the issue weeks before it took any action to rectify the situation. It did not take the feature off the website until after the lawsuit was filed. Even if it was convinced that its behavior did not expose it to legal action, its inaction indicated an insensitivity to public concern for privacy rights. One would hope that given the amount of adverse publicity TJX and others have suffered from their experiences with security breaches, that such insensitivity to consumers' privacy concerns by companies that are the repositories of consumers' personal information would be a faint memory.

At a minimum, the Sears lawsuit should serve as a wake-up call to other companies that a cavalier attitude to consumer privacy will no longer be tolerated by the public.