Wednesday, March 30, 2011

Geolocation Bill Seeks to Unify Fourth Amendment Protections

The following guest post is provided by Sonya Ziaja, J.D. Sonya is the co-owner of Ziaja Consulting LLC, a California based consulting group. She writes regularly for LegalMatch's Law Blog and Ziaja Consulting's blog, Shark. Laser. Blawg.

Senator Ron Wyden (D-Oregon) is in the process of crafting a bill to place legal limitations on the use of geolocation technologies.

Geolocation is commonplace nowadays. People play geolocation games (Foursquare, etc.). And geolocation technologies are encouraged to protect public safety (FCC’s Enhanced 911 rule). To some extent we are comfortable with broadcasting our location, which is well and good so long as doing so is harmless. There is, however, a less carefree side to geolocation--especially where it comes into conflict with the protections of the fourth amendment against unreasonable searches.

Over the past few years, law enforcement has increasing relied on geolocation techniques to track citizens without first obtaining a warrant. Doing so is at least questionably constitutional, if not outright illegal. Law enforcement makes use of both cell phone tracking and secretly tagging vehicles with GPS devices, all without court authorization.

The courts are split on the fourth amendment issues this issue raises. The Ninth Circuit in US v. Pineda-Moreno, for example, held that surreptitiously tagging a vehicle with a GPS device does not require a warrant because it is a substitute for “following a car on a public street, that is unequivocally not a search within the meaning of the [fourth] amendment.” The D.C. Circuit, however, takes the opposite view. In US v. Maynard, the D.C. Circuit held that a warrant is constitutionally necessary before police attach a GPS device to a suspect’s car. The court also specifically rejected the automobile exception argument, stating that

the automobile exception permits the police to search a car without a warrant if they have reason to believe it contains contraband; the exception does not authorize them to install a tracking device on a car without the approval of a neutral magistrate.

A recent case highlights the split. Earlier this March, a twenty-year old college student from San Jose, California brought suit against the FBI for secretly tagging his car without a warrant. Not surprisingly, he has decided to file in Washington D.C., rather than in California.

This circuit split is part of the impetus behind Senator Wyden’s bill--the Geolocational Privacy and Surveillance Act, or GPS Act. The bill aims to clarify the law, addressing multiple forms of geolocation, covering both information gained through cell phone use and covertly tagging vehicles. The hope is that the bill will create a uniform policy that protects both privacy and public safety.

To balance privacy and safety, the bill provides exemptions for emergency cases--for example in cases of national security of when the user’s life is at risk--when police would not need to obtain a warrant. These exemptions have been the most contentious aspect of the bill. Paul Wormelli, executive of the Integrated Justice Information Systems Institute, has been particularly vocal about his concerns that the bill’s exceptions are too vague and would have a chilling effect on officers.

The bill is still in the early stages, however, and has not been formally introduced in the Senate. The language may need clarifying, but at the moment, the GPS bill looks to be our best bet to address the constitutional issues raised by widespread use of geolocation technologies.

Thursday, January 20, 2011

Use of the Stored Communications Act to Get Email Without a Warrant Violates Fourth Amendment

Most modern email services allow people to keep messages indefinitely, and provide their users with enough space that doing so is actually an option. As a result, many people use their email accounts as a long term data archive, storing messages going back years.

So what does this have to do with privacy? Well, the stored communications act was written back in the days when email was much more akin to a mailbox. Because of this, it treats old email in a manner which is similar to how one might treat abandoned mail, and provides a mechanism in 18 U.S.C. 2703(d) to allow the government to get access to it without a warrant.

Actually, it provided a mechanism to allow the government to get access without a warrant. That changed with the case of U.S. v. Warshak, which found the government's use of section 2703(d) to obtain incriminating emails without a warrant violated the fourth amendment.

The facts of the case are extreme, and make for entertaining reading. The main defendant, Steven Warshak, owned Berkeley Premium Neutraceuticals, the company behind the once ubiquitous commercials for Enzyte. According to the opinion, Warshak had owned a number of other businesses. However, Berkeley stood out, both because of the success of Enzyte, and because of its extremely slimy business practices. A sample:

in November 2003, Berkeley hired a company called West to handle “sales calls that were from . . . Avlimil or Enzyte advertisements.” During the calls, West’s representatives asked customers if they wanted to be enrolled in the auto-ship program, and over 80% of customers declined. When Warshak learned what was happening, he issued instructions to “take those customers, even if they decline[d], even if they said no to the Auto-Ship program, go ahead and put them on the Auto-Ship program.” A subsequent email between Berkeley employees indicated that “all [West] customers, whether they know it or not, are going on [auto-ship].” As a result, numerous telephone orders resulted in unauthorized continuity shipments.

Those practices eventually led to a 112 count indictment, and the government obtaining thousands of incriminating emails from Warshak's service provider without a warrant under section 2703(d) of the stored communications act. After his conviction, Warshak appealed to the Sixth Circuit court of appeals arguing (among other things) that the emails were obtained in violation of the 4th amendment, and therefore should have been excluded as evidence.

While the Sixth Circuit upheld Warshak's conviction, it agreed that the warrantless search of Warshak's emails violated the fourth amendment. First, it established that Warshak had a subjective expectations that his emails would remain private. Indeed, the court said the very fact that the emails contained so much incriminating information was evidence that Warshak saw them as private correspondence. Next, the court asked whether the expectation of privacy in emails was one society was prepared to recognize as reasonable. To answer, the court addressed the heavy reliance of modern society on email, and analogized it to other types of communication that were traditionally protected under the fourth amendment. In the end, it concluded that

because they did not obtain a warrant, the government agents violated the Fourth Amendment when they obtained the contents of Warshak’s emails. Moreover, to the extent that the SCA purports to permit the government to obtain such emails warrantlessly, the SCA is unconstitutional.

The decision didn't do much for Warshak. The court also held that the government had been relying in good faith on the act, and so the emails shouldn't be excluded. However, it will help everyone else down the line, because the good faith rule can't be used to justify actions that are clearly inconsistent with the court's holding.

Tuesday, November 23, 2010

DJ Hero

I got an anonymous comment to my last post on the TSA's new security procedures saying that there has to be something we can do, rather than just submitting to whatever is advanced under the name of security. As it happens, there are several things that people can do to react to the TSA's new procedures.

The most well publicized protest is probably National Opt Out Day (warning - page includes naked picture taken with TSA's new scanners), wherein people will opt for being groped by a TSA agent to slow down processing of fliers on November 24 - the busiest flying day of the year. If that's your cup of tea, then it's certainly your right to opt out of the scanning (which you might want to do anyway, for both health and privacy reasons). For me though, I'm not at all interested in being groped by the TSA, even for the noble purpose of protest.

If you're more interested in an ineffectual protest with a touch of humor, you can try radiation shielding undergarments, or a bill or rights luggage tag (all of which are described in this article). My guess is that the bill of rights tag would just be ignored (much like the actual bill of rights), and that the metal undergarments would result in a referral for one of the TSA's special enhanced pat downs. Still, if you want to make a statement, those are another way to do it.

As a lawyer, my first thought was a declaratory judgment action seeking to preliminarily and permanently enjoin the TSA from implementing the new security measures. My next thought was that that was so obvious that someone must have already done it. However, a quick Google search didn't turn up much more than this thread, so maybe that's still available. The problem with this approach is that these types of DJ actions are really hard to win, and you may get bumped on procedural grounds before the judge ever reaches the merits of the case.

In the end though, my guess is that what will be necessary to reverse these new procedures is people (finally) taking a stand for privacy, and bringing enough bad press to the TSA and pressure on their elected representatives, that the TSA's current policies become radioactive. I'm not thrilled that we've reached that point, but it is a free country, and if our elected representatives make enough intrusive laws, sometimes the only way to respond is by replacing them with people who aren't so keen to invade people's privacy.

Sunday, November 14, 2010

Fighting the TSA

The Internet is currently burning up with a story about a man who would rather not fly than submit to the TSA's intrusive screening procedures, and how the TSA reacted to him. To make a long story short, once he decided to leave the security area and ask for a ticket refund, a TSA agent told him he had to return to the security area or would be subject to a civil fine of up to $10,000. A normal person's reaction to reading this story might be outrage at this sort of petty tyranny. As a lawyer, my first reaction was to question whether the threat was real. That is, is this a case of abuse of power by a misguided TSA employee acting outside his authority, or is it a case of abuse of power by a misguided TSA employee enforcing an egregiously bad law?

After about an hour of searching, I strongly suspect that this is a case of abuse of power by a misguided TSA employee acting outside his authority, though I have not been able to convince myself of that fact, and so the normal disclaimers about nothing on this blog being legal advice should go at least double for this post.

The reason I strongly suspect that this is a case of abuse of power by a misguided TSA employee acting outside his authority is that the regulations on penalties and prohibitions mostly focus on making sure that you can't get certain things into secure areas. For example, 49 C.F.R. 1540.107 says that no one can enter the sterile area or board an aircraft without going through a screening. However, in this case, the putative flyer wasn't trying to get into the sterile area or an aircraft without going through a screening - he made a conscious decision to avoid a screening by not entering the sterile area or boarding an aircraft. Similarly, 49 C.F.R. 1540.109 prohibits threatening, interfering with, assaulting or intimidating screening personnel. However, in this case, the putative flyer wasn't interfering at all. Indeed, the screening personnel could have done their jobs more easily if they had simply let him leave the airport. Because there is no evidence that leaving the airport had any adverse effect on security, or on the ability of the screening personnel to screen other passengers, it seems to fall outside of the general scope of the regulations, and so I suspect that the threat of a $10,000 civil penalty was not supported by law.

However, the reason I haven't been able to convince myself of the fact that a civil penalty couldn't have been imposed is that the relevant law is more than a little bit difficult to wade through, and the regs have previously been applied in ways that seem patently unjust. In terms of difficulty wading through the regs, I will give one example: 49 U.S.C. 46301(a)(5):

(A) An individual (except an airman serving as an airman) or small business concern is liable to the Government for a civil penalty of not more than $10,000 for violating—
(i) chapter 401 (except sections 40103 (a) and (d), 40105, 40106 (b), 40116, and 40117), section 44502 (b) or (c), chapter 447section 44502 (b) or (c), chapter 447 (except sections 44717–44723), or chapter 449 (except sections 44902, 44903 (d), 44904, and 44907–44909) of this title; or
(ii) a regulation prescribed or order issued under any provision to which clause (i) applies.

And that's just one example. As a lawyer, I can wade through that, cross checking sections, examining applicability to a given situation, etc. However, as a human being, I don't do that sort of thing for fun, and no one is paying me to write this blog. In terms of unjust application of the regs in the past, I refer readers to Rendon v. TSA an unhappy case where a civil fine imposed for asking some rather profane (but not unreasonable) questions about security procedures was upheld under the prohibition on interfering with screening personnel. While I think imposing a fine for trying to leave an airport is even worse than the situation in Rendon, given the result in Rendon, it wouldn't surprise me terribly if a fine, in fact, were imposed.

So what will happen in this particular case? Probably nothing. I doubt the TSA will seek penalties, given that the whole incident was video taped, and a trial would only lead to bad press and the possibility of their powers being curtailed. In the end, my guess is the whole thing will blow over, the TSA will keep their current security policies in place, and most people (e.g., me) who can't afford to skip flights just because we might not want to be molested by the TSA will end up being subjected to whatever form of invasive screening the TSA thinks is warranted without any realistic avenue for recourse.

Friday, October 1, 2010

I know I've written this post before

Here's the wired headline: Scribd Facebook Instant Personalization Is a Privacy Nightmare. The article is about what you'd expect. There are complaints about automatically generated spam emails to your automatically created friends and confusing or non-existent opportunities to opt out. There's a Scribd PR person explaining how privacy is really very important to the company. There's the author suggesting that one way to fix the problem is to delete your Scribd profile, but characterizing that as extreme. I'm not 100% sure why I read the article. True, I don't use Scribd, and have never run across this particular feature. However, just seeing Facebook in the title gave me a pretty good idea what to expect. Someone in marketing wants to take advantage of the tremendous amount of data on Facebook (and get in on the whole "social media" bandwagon) and so they make it really easy to share data, and relatively difficult not to so do.

So what should people do instead of this? Well, there's always the possibility of not integrating with Facebook. Frankly, regardless of what they've been forced to do by public pressure, I will always distrust a company who's CEO famously doesn't believe in privacy. In the event that you must integrate with Facebook, you could always try little things like opt in rather than opt out participation, not automatically spamming Facebook friends, and sending making sure it's clear for someone how to opt out if they decide they don't like the program. There are also guidelines for interactive and behavioral advertising put out by organizations like the FTC and the IAB (though I consider those to be a bit outside the scope of this post). Whatever you do though, if you're going to move into the world of social media, you need to do it with your eyes open, or your company is likely to be integrated with Facebook in a headline that also includes unpleasant words like "nightmare" or "disaster."

Monday, August 23, 2010

July/August Privacy Catch Up

So...the blog has been uncharacteristically quiet for the last month or so. This is not because nothing privacy related has happened in the legal world. For example, the FBI and federal prosecutors announced that they will not be filing criminal charges related to the Lower Merion Spy Cam Scandal (link here), something I wrote about hereas possibly being the creepiest privacy violation of 2009. Also, it turns out that the millimeter wave scanners used to see through clothes to catch those ever-elusive terrorists can store and transmit images, despite assurances from the TSA that that was not the case (link. In more positive news, the appeals court for the District of Columbia circuit has rejected a claim by the government that round the clock warrantless GPS surveillance is ok (article here). There was also some legislative action, as internet advertisers warned that a new privacy bill, the "best practices act" would "would turn the Internet from a fast-moving information highway to a slow-moving toll-road." Also, speaking of slow-moving toll-roads, Google and Verizon came together to formally announce that net neutrality (i.e., the concept that all traffic on the internet should be treated equally) is a rather quaint notion that shouldn't apply to wireless networks. All in all, it's been a relatively busy month or so.

So why no posts? Well, in addition to all of these privacy events, we also got a huge non-privacy decision - Bilski v. Kappos - which basically upended a decade's worth of precedent on whether you can get patents on novel software or business methods. Since software and business method patents are a big part of my practice, a good deal of the time that I would have spent on privacy was spent on patent stuff instead. To make matters worse, at least time-wise, I also got a copy of Starcraft II, which turned out to be a huge time suck. Happily, rather than releasing a full game, with three playable races and campaigns for each (the approach taken with the original), Blizzard decided to only release a human campaign, which turned out to be approximately a third of a game's worth of play for a full game's price. As a result, I not only get to get back to blogging sooner, I also get to know to avoid new releases from Blizzard in the future, which I guess means that everyone wins.

Sunday, July 11, 2010

Why Do People Keep Thinking This is a Good Idea?

Earlier this month, Blizzard Entertainment (makers of World of Warcraft, among other successful computer games) decided that they would change their game forums from anonymous forums (i.e., you can't tell the identity of someone posting to the forums unless they tell you) to forums where comments are connected with a person's real name. After a firestorm of criticism (e.g., here) Blizzard spiked the program, at least for now. And the reason for going down this path, with its utterly predictable and embarrassing trajectory? Two words: Facebook Integration. Actually (as explained here) it's slightly more complicated than that, but what it boils down to is that Blizzard wanted to get in on some of that social networking magic, and giving everyone a single ID that was consistent across all of Blizzard's forums (and Facebook) seemed to be a good way to do it.

This is an old story, and one that often ends in class action lawsuits (e.g., Google Buzz, Facebook Beacon). Why do people keep doing this? My guess is because they see their existing user data as an asset, and they hate letting an asset go unexploited. However, that's the wrong mindset. The safest way to think of user data is as something that actually belongs to users, which they have allowed you to temporarily safeguard. The point of the user data isn't to exploit it, it's to allow a business to maintain its relationship with its users. If you want to integrate with Facebook - fine. However, the way to do so is going forward, collecting new data (with a clear explanation of what you're collecting the data for), and without degrading or changing the services provided for old users. True, at the outset, this seems much harder than leveraging an existing user base. On the other hand, many existing user bases don't like being leveraged, and going about things the hard way can take that into account, and avoid turning an existing base into a historical user base.