Showing posts with label private suits. Show all posts
Showing posts with label private suits. Show all posts

Wednesday, April 13, 2011

Data privacy legislation introduced

Per Wired.com, Senators Kerry and McCain have proposed legislation that would give web users the right not to be tracked while on line (the text of the bill can be found here). While this sounds like a step forward for consumer privacy, the legislation has not been well received by privacy advocates. According to the article:

The ACLU and others would prefer what is being touted as a “universal opt-out” in which consumers could one-stop shop and end all tracking by using a national registry of sorts. The Federal Trade Commission suggested such legislation in December.

“Consumers need strong baseline safeguards to protect them from the sophisticated data profiling and targeting practices that are now rampant online and with mobile devices. We cannot support the bill at this time,” Consumer Watchdog, Center for Digital Democracy, Consumer Action Privacy Rights Clearinghouse and Privacy Times wrote McCain and Kerry on Tuesday.


While I have concerns about the proposed legislation, I don't know that I agree with the sentiments expressed by quoted advocacy organizations. True, the bill could do more for privacy. However, the U.S. has generally been slow to enact laws protecting privacy, so letting the perfect be the enemy of the good in this case doesn't seem to make sense. Also, the bill (at least as proposed) does do more than prevent tracking. For example, for example, section 101 requires the FTC to make rules requiring covered entities to establish security measures to protect the data they do collect and section 202(A)(4) requires the FTC to make rules enabling individuals to correct information stored about them. There are also provisions requiring covered entities to design their products with privacy in mind (section 103) and to minimize the data they collect (section 301). These are all potentially helpful provisions, and the fact that they weren't mentioned indicates to me that the bill might not be getting all the credit it deserves.

With that having been said, I do have two problems with the bill that (if anyone were interested in my opinion) would stop me from supporting it. First, as mentioned in the Wired article, it preempts potentially more stringent state laws (section 405). This is a significant problem, as states are generally well ahead of the federal government on privacy issues. Second, it specifically states that it does not create any kind of private right of action (section 406). This is also a significant issue, since giving people the right to sue would likely result in much more vigorous enforcement of the law than simply relying on the FTC.

The bottom line for me is that, while the legislation includes a number of privacy protective features, its incompatibility with stronger state laws, as well as its lack of a private right of action mean that, if passed, it probably wouldn't help (and might even hurt) consumer privacy rights.

Sunday, April 11, 2010

Microsoft v. Waledac

This is a site that all lawyers working in the area of computer security should be aware of and visit. It's a page which contains all the pleadings from Microsoft's current case against John Does 1-27 (aka the "Waledac" botnet). This page is important for two reasons. First, Microsoft's efforts against the botnet are on the cutting edge of legal efforts to shut down hacking operations, and so should be seen as examples of legal theories that can be used in that area. Second, it has some interesting (and probably useful) examples of rhetoric and explanations which can be used to sway a (presumably) technologically unsavvy judge to your side. For example, on pages 3-9 of the PDF of Microsoft's motion for a temporary restraining order against the botnet, there is a non-technical tutorial on what a botnet is, and how issuing the TRO would shut it down, complete with pictures. Similarly, in making the arguments in support of the TRO, Microsoft repeatedly seeks to establish the harm the botnet is causing by explaining how it harms Microsoft's customers. E.g.:
Once customers' computers are infected and become part of the botnet, they are unaware of that fact and may not have the technical resources to solve the problem, allowing their computers to be misused indefinitely. Thus, extrajudicial, technical attempts to remedy the problem alone are insufficient and the injury caused to customers continues.

While this might not be the most relevant argument legally (after all, one is generally not allowed to bring suit based on injuries to third parties) from an emotional standpoint, it almost certainly made the judge more likely to grant Microsoft's requested relief.*

In any case, there's too much there to succinctly summarize here. Further, there's no reason to want to read a summary. The information is valuable enough to be worth the time to read in the original.

*Yes, I am aware that harm to third parties can be used to establish that issuing an injunction is in the public interest. However, Microsoft invoked its customers' interests essentially everywhere, not only when arguing that the public interest would be served by granting a TRO.

Tuesday, February 10, 2009

Even More Limitations on Private Rights of Action

Previously, I've written about problems with protecting privacy through private civil suits, such as transaction costs, difficulty of proving damages, and a generally hostile court system. However, a recent breach notification by Geeks.com as indicated that even when those factors aren't present, people (or, in this case, businesses) still aren't that interested in enforcing their rights. The story, according to this article from Computer World is that the web site was victimized by an SQL injection attack, and the operators eventually entered into a settlement with the FTC wherein they agreed to undergo audits and not to make any further misleading claims about privacy. So far not particularly notable. However, as the article says, unlike most security breaches:

The breach was notable because the Geeks.com site prominently displayed a "Hacker Safe" seal provided to companies by McAfee Inc. as part of its ScanAlert vulnerability scanning service. However, McAfee officials said at the time that the Hacker Safe certification — since renamed McAfee Secure — had been withdrawn from Geeks.com on multiple occasions during 2007 after scans found vulnerabilities in its systems.

To me this is shocking. Not because a supposedly secure site was compromised, but because they were improperly displaying the "Hacker Safe" seal.

Where was McAfee?

Didn't it care about its good name? I would guess that Geeks.com would have taken down the "Hacker Safe" seal if McAfee simply asked them to. I doubt even a sternly worded letter would have been necessary. Still, if it had been, there are any number of attorneys who could have written it, and who would have been happy to go to court to get the seal removed if Geeks.com wouldn't take it down otherwise. Happily, the FTC stepped up in this case. However, it's a little surprising that they were the ones who ended up doing it, rather than the private actor who one would think would have had both the incentive and opportunity to have taken action earlier.

Wednesday, July 16, 2008

Discovery

Unless otherwise limited by court order, the scope of discovery is as follows: Parties may obtain discovery regarding any nonprivileged matter that is relevant to any party's claim or defense — including the existence, description, nature, custody, condition, and location of any documents or other tangible things and the identity and location of persons who know of any discoverable matter.

That's the text of the first sentence of rule 26(b)(1) of the Federal Rules of Civil Procedure. For the non-lawyers out there, I'll unpack it a bit. The first part, about obtaining discovery of any nonprivileged matter, means that, unless information falls into certain narrowly defined categories (e.g., attorney-client, doctor-patient, etc) it is subject to discovery. The next part, about relevant to any party's claim or defense, means (generally) that it has to have some bearing on the subject matter of the litigation. In practice, this means that during pre-trial discovery, litigants can request essentially any records maintained by a business, its principals, and their agents (e.g., vendors). The bottom line is that, if a lawsuit takes place, the parties can request virtually any information, that information has to be provided to them, unless it falls within the narrowly defined (privileged) categories.

While massive security incidents like the TJX breach generate more headlines, these pretrial discovery rules could represent an even bigger threat to consumer privacy. Two instructive cases in this respect are Viacom v. Google and MPAA v. Bunnell. In the Viacom case, Viacom requested, and the judge ordered Google to produce, records showing who watches videos on YouTube and what videos they watch (see article here). This release of data has the potential to be even more damaging to the affected users (including me, since I use YouTube regularly) than the release of information such as social security and credit card numbers, because YouTube viewing records can be used to make out a case for copyright infringement - a charge that can bankrupt all but the super-wealthy (for example, in the case described here the defendant was found liable for almost a quarter million dollars in damages for infringing copyrights on only 24 songs). In the MPAA case, the judge also ordered that user records be turned over - in that case the records showed what users had searched for using the popular bit torrent software. However, there, rather than take an act which it saw as betraying its users privacy expectations, the defendant blocked access to his web site from the U.S. - a radical solution, but the only way the defendant saw to protect his users' privacy.

The cases above showcase a trend which is, to me, highly disturbing. Instead of relying on black hat hackers, businesses can use litigation to obtain consumer information. In the cases above, that result in the exposure of (likely) millions of records from Google, and the complete shutdown of TorrentSpy in the U.S. Those are serious consequences, and they should be considered whenever people think of possible threats to their privacy.

Sunday, April 6, 2008

Hannaford Data Exposure Suit

In a development that can be expected to surprise no one, yet another merchant has announced that a security breach has resulted in the exposure of consumer data. The breach is described in this article from Computer World, as well as this article from the E-Commerce Times. The basic outline of the story is that Hannaford Bros. Co., a Maine based supermarket chain, had their servers compromised by malware which ended up leading to the exposure of somewhere north of 4 million debit and credit card accounts. Now that the breach has surfaced, the inevitable class action suits have been filed in federal court in Maine. While I don't have the facts necessary to comment on the merits, there are a few aspects of this case that could set it apart from the run of the mill data exposure suit. First, according to the E-Commerce Times article, nearly 2000 cases of fraud have been traced to the breach. This, obviously, be helpful to the plaintiffs, as it will help show actual damages, which have often been a stumbling block in similar cases. The second interesting aspect of this case is that Hannaford, rather than being a poster child for bad security practices a la TJX, was apparently in compliance with the PCI standards when the breach took place. This, obviously, could be helpful to the defendants, who could use their compliance with the PCI standards to rebut charges of negligence.

In any case, as I mentioned previously, I don't have the facts necessary to comment on the merits of the case. However, it seems that there are things to be said for both parties, which could make this an interesting case which could help provide guidance for both plaintiffs and defendants in future data exposure cases.

Thursday, March 20, 2008

The Problem of Compensation

In my last post, I addressed what is a proper measure of damages for exposure of a person's private information. In response, the Dunning Letter put up a post responding to it, and providing some interesting statistics about the cost ($5720/victim) and prevalence (top complaint reported by FTC ID theft and consumer fraud survey) of identity theft. At that time, I considered preparing a responsive post, essentially playing devil's advocate and pointing out that providing compensation via lawsuits was really a poor way to combat the problem of information exposure, because, even if you could get the proper measure of damages, most people wouldn't take the trouble to file a lawsuit. Further, even if people did file lawsuits, the transaction costs associated with litigation (i.e., attorneys' fees) mean that, even if you did provide incentives to avoid data exposure, there would be a ton of lost effort involved.
However, this post brings the problem into even sharper focus, by describing the situation of a young woman who states the she reported an identity theft, which took between 20 minutes to an hour, and that she got NOTHING in return. If doesn't think it's worth an hour of her time to report an ID theft (and she's undoubtedly not alone in that), then you can bet there will be very few consumers who would be willing to spend the time (years) and money (thousands of dollars) which are necessary to go to court. The bottom line: while providing compensation is worthwhile, it isn't enough.
So what is enough? My proposal is regulation, clearly written and consistently enforced. Part of the problem is that businesses simply don't know what they need to do to avoid having security breaches. Also, businesses know that, even if there is a breach, there isn't much chance that individual plaintiffs will be able to successfully bring suit for damages. Clear regulation which is consistently enforced could solve those problems, both by providing clear guidance for businesses, and by providing a strong incentive (threat of government penalties) for following that standard. At the moment though, the U.S. model seems to be notification followed by individual litigation, which is, as set forth above, a highly suboptimal solution.

Sunday, March 16, 2008

Problems with U.S. Courts' Treatment of Security Breach Damages

This article from Computer World asks the question "When Does a Privacy Breach Cause Harm?" and then proceeds to take U.S. courts to task for failing to recognize damages from security breaches beyond verifiable damages from identity theft or account fraud. While I agree that U.S. courts have done an atrocious job with respect to protecting privacy (see, e.g., here, describing the 7th Circuit's statement that plaintiffs could not proceed on a action based on a data security breach, despite circumstances showing that the breach was caused by identity thieves), I have to take issue with the analysis offered in the article. The article states that the problem with what courts have done is that they have overlooked "[t]he assault to personality and feelings [that is] is the quintessential privacy injury." That rationale just doesn't work for me. Human feelings are notoriously hard to quantify, which means that damages based on assaults to personality and feelings would likely swing wildly from case to case and judge to judge, even if the actual underlying facts in particular cases are similar. Moreover, basing damages on feelings of loss and assault to personality runs the significant risk that juries will simply decide that those losses are too small to justify compensating, since studies (e.g., here) have shown that most people place little to no value on the privacy of their personal information.
A better option, and one I happen to agree with, is for businesses which suffer a security breach through their own fault (e.g., negligence) should be held responsible for the quantifiable damages caused by that breach, even if there is no subsequent identity theft. For example, time spent by customers replacing credit cards with stolen numbers, or the cost of various identity theft protection services are easily determined, and would serve as a measure of damages that courts could easily compute and assess. Indeed, since limiting damages to those directly caused by identity theft or account fraud provides an incentive for consumers not to prevent identity theft, making companies responsible for quantifiable costs would improve the status quo by increasing the level of protection given to privacy by courts, while avoiding the difficulties of trying to quantify injuries to personality. To me, that's a far superior alternative to relying on damages to personal integrity, which are both hard to quantify, and easy to undermine.

via The Dunning Letter.

PostScript: I am well aware that laws vary tremendously from state to state. My statements regarding the state of current privacy laws reflect the holding in Pisciotta v. Old National Bancorp, in which the 7th circuit addressed the issue of damages for a data security breach in the absence of subsequent identity theft.

Monday, January 14, 2008

Consequences of McCain Pledging his Donor List

According to this story from Politico, John McCain's presidential campaign has pledged its fundraising list as collateral for a loan. The problem is that the campaign's Privacy Policy states that: "John McCain 2008, will not sell your information to third parties or any commercial entities." While the policy does state that "We may share information -- that you voluntarily provide us -- with like-minded organizations committed to the principles or candidates of the Republican party, Republican State Party organizations, local Republican groups and like-minded organizations" it seems unlikely that the commercial banks which made the loan are "like-minded organizations," so there seems to be a conflict between the pledge and the policy.

Unsurprisingly, the comments to the article were mostly focused on the politics of the situation (e.g., "It's just one more example of John McCain's total arrogance.", which was followed by "I think I'll donate more money right now to spite this attack"). However, I'm more interested in the legal implications of the pledge. For example, the Politico article says that McCain's campaign could be sued by its donors for breach of contract. Is that true? Well, I have two words for any donors seeking to sue the campaign: Good Luck. While I'm all for protecting consumer privacy, the courts have previously ruled in In re Northwest Airlines Litigation that Northwest's privacy policy did not create a contract with consumers, and that the data collected by Northwest belonged to Northwest (who could therefore divulge it in violation of the privacy policy) not to consumers (who wanted it maintained in confidence). Whether or not you like the ruling, there's no reason to believe that someone suing McCain's campaign for pledging the list would have better luck. In any case, even if a court were to look more favorably on someone suing the McCain campaign, it's too early to sue the campaign anyway. The list was pledged, but the campaign hasn't defaulted, so the pledge hasn't been redeemed. In other words, there hasn't been a sale, and so, at least for now, there is no breach of the policy for which the McCain campaign could be sued.

Tuesday, November 6, 2007

Emotional Damages for Data Exposure

About a week ago, a friend of mine (whose name will be withheld unless he or she tells me to reveal it) asked what I thought about the approach to damages taken by the plaintiffs in Pisciotta v. Old National Bancorp (previous blog post about that case is here). In that case, the plaintiffs, in addition to asking for damages to cover credit monitoring costs, also requested compensation for emotional damage caused by elevated risk of identity theft. The problem is that, as in most identity exposure cases, the court dismissed the plaintiffs' cause of action saying that they had suffered no present compensable injury because their identities hadn't actually been stolen. The emotional harm the plaintiffs may have suffered was dismissed as being connected to the potential future harm, rather than to any completed present harm.

My guess is that plaintiffs in the future aren't likely to get much mileage out of emotional harm arguments. Courts have uniformly rejected claims for damages based on exposure of data, and the 7th Circuit in Pisciotta v. Old National Bancorp was simply following the trend. Where plaintiffs may be more successful is cases where they can show that they have suffered some direct out of pocket cost (other than credit monitoring) as a result of a security breach. This includes not only individual consumers who are victims of identity theft, but also other commercial entities, such as banks, who are forced to spend money by the breach itself (e.g., by reissuing credit cards).

Friday, August 24, 2007

7th Circuit Says No Private Right of Action for Data Breach

As described in this post on the threat level blog, the seventh circuit court of appeals has ruled against consumer's whose personal data was stolen from a bank database (the opinion can be found here). As described in the opinion, the consumers' data was stolen as the result of an intrusion which was "sophisticated, intentional and malicious." The consumers requested that the court grant them, among other relief, payment for the cost of credit monitoring services - a seemingly reasonable request, given the fact that their personal data was now in the hands of criminals who had likely stolen it for the specific purpose of facilitating identify theft. However, the seventh circuit decided that the harm suffered by the consumers was only potential harm, and therefore was not compensable under the relevant state law. True, the consumers had to pay for credit monitoring, but the court pointed out that they could not show that their identities had been stolen (yet), so the case was thrown out.

What does all this mean for consumers? There are two primary lessons to be drawn. The first is that courts remain an extremely hostile environment for trying to vindicate privacy rights. The (in my opinion) classic case on this subject is In re Northwest Airlines Litigation which found that Northwest's privacy policy was not a contract with customers, and that customer data collected by Northwest belonged to Northwest, not the customers. The new decision from the seventh circuit just confirms what was already clear: consumers should not expect courts to protect privacy. The second lesson to be drawn from the seventh circuit's new decision is that states which wish to provide meaningful privacy protections for their citizens should include private rights of action in their privacy legislation. In finding against the consumers, the seventh circuit referred to the fact that the relevant data breach notification act did not provide a private right of action. Thus, if state legislators want to avoid their citizens being thrown out of court, they should make sure to explicitly create a way (by statute) for the citizens to protect themselves.