
Individuals expose personally identifying information to access a website or qualify for a loan, undermining privacy and security. Firms share proprietary information in dealmaking negotiations; if the deal fails, the negotiating partner may use that information to compete. Regulators that comply with public transparency and oversight requirements can risk subjecting algorithmic governance tools to gaming that destroys their efficacy. Litigants might have to reveal trade secrets in court proceedings to prove a claim or defense. Such “verification dilemmas,” or costly choices between opportunities that require the verification of some fact, and risks of exposing sensitive information in order to perform verification, appear across the legal landscape. Yet, existing legal responses to them are imperfect. Legal responses often depend on ex post litigation remedies that are prohibitively expensive for those most in need, or that fail to address abuses of information entirely. Zero-knowledge proofs (ZKPs)—a class of cryptographic protocols that allow one party to verify a fact or characteristic of secret information without revealing the actual secret—can help solve these verification dilemmas. ZKPs have recently demonstrated their mettle, for example, by providing the privacy backbone for the blockchain. Yet they have received scant notice in the legal literature. This Article fills that gap by providing the first deep dive into ZKPs’ broad relevance for law. It explains ZKPs’ conceptual power and technical operation to a legal audience. It then demonstrates how, and that, ZKPs can be applied as a governance tool to transform verification dilemmas in multiple legal contexts. Finally, the Article surfaces, and provides a framework to address, the policy issues implicated by the potential substitution of ZKP governance tools in place of existing law and practice.
Affinity profiling - grouping people according to their assumed interests rather than solely their personal traits - has become commonplace in the online advertising industry. Online platform providers use behavioural advertisement (OBA) and can infer very sensitive information (e.g. ethnicity, gender, sexual orientation, religious beliefs) about individuals to target or exclude certain groups from products and services, or to offer different prices. OBA and affinity profiling raise at least three distinct legal challenges: privacy, non-discrimination, and group level protection. Current regulatory frameworks may be ill-equipped to sufficiently protect against all three harms. I first examine several shortfalls of the General Data Protection Regulation (GDPR) concerning governance of sensitive inferences and profiling. I then show the gaps of EU non-discrimination law in relation to affinity profiling in terms of its areas of application (i.e. employment, welfare, goods and services) and the types of attributes and people it protects. I propose that applying the concept of ‘discrimination by association’ can help close some of these gaps in legal protection against OBA. This concept challenges the idea of strictly differentiating between assumed interests and personal traits when profiling people. Failing to acknowledge the potential relationship – be it directly or indirectly - between assumed interests and personal traits could render non-discrimination ineffective. Discrimination by association occurs when a person is treated significantly worse than others (e.g. not being shown an advertisement) based on their relationship or association (e.g. assumed gender or affinity) with a protected group. Crucially, the individual does not need to be a member of the protected group to receive protection. Protection does not hinge on whether the measure taken is based on a protected attribute that an individual actually possesses, or on their mere association with a protected group. Discrimination by association would help to overcome the argument that inferring one’s ‘affinity for’ and ‘membership in’ a protected group are strictly unrelated. Not needing to be a part of the protected group, as I will argue, also negates the need for people who are part of the protected group to ‘out’ themselves as members of the group (e.g. sexual orientation, religion) to receive protection, if they prefer. Finally, individuals who have been discriminated against but are not actually members of the protected group (e.g. people who have been misclassified as women) could also bring a claim. Even if these gaps are closed, challenges remain. The lack of transparent business models and practices could pose a considerable barrier to prove non-discrimination cases. Finally, inferential analytics and AI expand the circle of potential victims of undesirable treatment in this context by grouping people according to inferred or correlated similarities and characteristics. These new groups are not accounted for in data protection and non-discrimination law. I close with policy recommendations to address each of these legal challenges for OBA and affinity profiling.
The federal government restricts what former employees can work on after they leave the government, and for good reason. These post-employment conflict restrictions attempt to address the “revolving door” problem, where employees take information learned from their position in government to unfairly advantage industry. But an unintended consequence of overbroad conflict rules is that they impede well-meaning, former federal employees from providing their knowledge and general expertise to other enforcement agencies with similar missions, such as those at the state level. This is playing out right now with FTC technologists, at a time when the agency—and, indeed, consumer protection agencies more broadly— desperately needs greater technical expertise. Three problems result: (1) former FTC technologists find themselves unable to contribute to the enforcement efforts of other agencies and plaintiffs’ attorneys aligned with the mission of the FTC, (2) some current FTC technologists are unwilling to work on important issues before the agency out of fear that doing so will limit their ability to work on related matters in the future, and (3) would-be technologists may be unwilling to take a position at the agency due to these concerns. We explore the impact of federal conflict rules on technologists working with the FTC, consider how this impact has changed alongside changing circumstances and enforcement practices, and discuss policy implications. We conclude that unless the FTC reforms the way it administers its conflict rules, it risks losing the assistance of technological expertise— expertise of which it badly needs more, rather than less.
The development of autonomous vehicles is often presented as a linear trajectory from total human control to total autonomous control, with only technical and regulatory hurdles in the way. But below the smooth surface of innovation-speak lies a battle over competing autonomous vehicle futures with ramifications well beyond driving. Car companies, technology companies, and others are pursuing alternative autonomous vehicle visions, and each involves an entire reorganization of society, politics, and values. Instead of subscribing to the story of inevitable linear development, this paper explores three archetypes of autonomous vehicles—advanced driver-assist systems, fully driverless cars, and connected cars—and the futures they foretell as the ideal endpoints for different classes of actors. We introduce and use the Handoff Model—a conceptual model for analyzing the political and ethical contours of performing a function with different configurations of human and technical actors—in order to expose the political and social reconfigurations intrinsic to those different futures. Using the Handoff Model, we analyze how each archetype both redistributes the task of “driving” across different human and technical actors and imposes political and ethical propositions both on human “users” and society at large. The Handoff Model exposes the baggage each transport model carries and serves as a guide in identifying the desirable and necessary technical, legal, and social dynamics of whichever future we choose.
In Design Patent Law’s Identity Crisis, we traced the origins of design patent law’s ornamentality/non-functionality doctrine and showed how the Federal Circuit, the nation’s de facto design patent emperor over the past four decades, has turned the doctrine on its head: it has upended the 1902 Act’s intent and reversed three-quarters of a century of regional circuit jurisprudence. So much so that the post-1902 Act regional circuit design patent cases invalidating design patents on functionality grounds would come out oppositely under the Federal Circuit’s lax standards. Those standards led to the absurd result that Apple could disgorge Samsung’s profits on its smartphones because they employed rounded rectangular shapes. We showed that the applicable legislation limited design protection to original, ornamental articles of manufacture, and excluded protection for functionality. This Article responds to the practitioners and academics who have defended the Federal Circuit’s interpretation of design patent law in commenting on our article. While none of the commentators question, no less refute, our core finding that the Federal Circuit has flipped the ornamentality/non-functionality doctrine, several offer fig leaves to clothe the Federal Circuit’s lax standards for design patent eligibility and infringement. We discuss the significant areas of agreement and show why the defenses of the Federal Circuit’s interpretation of the design patent standards are mistaken as a matter of statutory interpretation and are bad intellectual property policy. We conclude by addressing ways in which the Supreme Court or the Federal Circuit could faithfully implement the design patent statute, the fundamental intellectual property channeling principle reflected in Baker v. Selden, and sound intellectual property policy.
Courts have long been skeptical about the use of expert witnesses in copyright cases. More than four decades ago, and before Congress extended copyright law to protect computer software, the Ninth Circuit in Krofft Television Prods., Inc. v. McDonald’s Corp., ruled that expert testimony was inadmissible to determine whether Mayor McCheese and the merry band of McDonaldland characters infringed copyright protection for Wilhelmina W. Witchiepoo and the other imaginative H.R. Pufnstuf costumed characters. Since the emergence of software copyright infringement cases in the 1980s, substantially all software copyright cases have permitted expert witnesses to aid juries in understanding software code. As the Second Circuit recognized in Computer Associates Int’l, Inc. v. Altai, Inc., the ordinary observer standard may well have served its purpose when the material under scrutiny was limited to art forms readily comprehensible and generally familiar to the average lay person,” but as to computer programs, district courts must have “discretion . . . to decide to what extent, if any, expert opinion, regarding the highly technical nature of computer programs, is warranted in a given case.” In a shocking departure from the decisions of every other circuit that has confronted software copyright infringement litigation, the Ninth Circuit reaffirmed and applied the bar on expert testimony originating in Krofft Television Prods. to all copyright disputes, including those involving highly technical computer software code. The court in Antonick v. Electronic Arts held that lay juries must decipher and analyze software code—distinct hexadecimal assembly code languages for different processors—without the assistance of expert witnesses, a rule that the authoring judge characterized at the oral argument as “nutty.” The Ninth Circuit’s rule overlooks the key distinction between the use of technical experts to analyze substantial similarity as opposed to enabling lay judges and jurors to perceive the underlying works. Just as it would be absurd to ask a lay jury with no familiarity with Kanji characters to assess whether a translation of HARRY POTTER AND THE PHILOSOPHER’S STONE into Japanese infringed the English original without the aid of a bilingual translator, it makes no sense to ask a non-technical jury to compare computer source codes written in different assembly languages to determine substantial similarity without expert assistance. We contend, consistent with the views of every court outside of the Ninth Circuit that has addressed the issue, that courts should permit the use of technical experts to enable lay judges and juries to perceive the meaning of computer languages and computer code.
In many industries, the arc of our contemporary economy bends towards bigness. The now-ubiquitous digital platform companies such as Amazon, Facebook, and Netflix and (in China) Baidu, Tencent, and Alibaba are the best-known examples. While some concerned onlookers propose structural remedies, our constrained antitrust law plus the logic of natural monopoly means we are likely to be living with this reality for the foreseeable future. In this setting, it is imperative that we preserve multiple sources of rivalrous innovation even as the reach of Big Platforms continues to grow. We need to carve out and preserve a niche for innovative small and medium sized companies. One way to do this is to promote and protect the secondary patent market. Sale of patents is one way small firms can remain viable in the shadow of Big Platforms. I argue that patent markets are superior in some cases to complete acquisition of a small firm by a Big Platform company, because by selling patents a small firm survives as an independent entity. Recent patent system reforms support this pro-secondary market policy: the era of easy, extortionate patent litigation (which has been associated with the secondary patent market) is coming to a close. After these reforms, patent sales and licensing, at times backed by the threat of litigation, can and will promote small company innovation. This is crucial: if history is any guide, though Big Platforms are today young and vigorous, in the long run they will become less innovative. Preserving multiple small innovators – through the patent market and otherwise – is the best way to prepare for this long run reality.
“Paid” digital services have been touted as straightforward alternatives to the ostensibly “free” model, in which users actually face a high price in the form of personal data, with limited awareness of the real cost incurred and little ability to manage their privacy preferences. Yet, the actual privacy behavior of paid services, and consumer expectations about that behavior, remain largely unknown. This Article addresses that gap. It presents empirical data both comparing the true cost of “paid” services as compared to their so-called “free” counterparts, and documenting consumer expectations about the relative behaviors of each. We first present an empirical study that documents and compares the privacy behaviors of 5,877 Android apps that are offered both as free and paid versions. The sophisticated analysis tool we employed, AppCensus, allowed us to detect exactly which sensitive user data is accessed by each app and with whom it is shared. Our results show that paid apps often share the same implementation characteristics and resulting behaviors as their free counterparts. Thus, if users opt to pay for apps to avoid privacy costs, in many instances they do not receive the benefit of the bargain. Worse, we find that there are no obvious cues that consumers can use to determine when the paid version of a free app offers better privacy protections than its free counterpart. We complement this data with a second study: we surveyed 1,000 Android mobile app users as to their perceptions of the privacy behaviors of paid and free app versions. Participants indicated that consumers are more likely to expect the paid version to engage in privacy-protective practices, to demonstrate transparency with regard to its data collection and sharing behaviors, and to offer more granular control over the collection of user data in that context. Together, these studies identify ways in which the actual behavior of apps fails to comport with users’ expectations, and the way that representations of an app as “paid” or “ad-free” can mislead users. They also raise questions about the salience of those expectations for consumer choices. In light of this combined research, we then explore three sets of ramifications for policy and practice. First, our findings that paid services often conduct equally extensive levels of data collection and sale as free ones challenge understandings about how the “pay for privacy” model operates in practice, its promise as a privacy-protective alternative, and the legality of paid app behavior. Second, our findings offer important insights for legal approaches to privacy protection, undermining the legitimacy of legal regimes relying on fictive “notice” and “consent” that do not reflect user understandings as bases for the collection, sale, and processing of information. They fortify demands for a privacy law that focuses on vindicating actual consumer expectations and prohibiting practices that exploit them, and strengthen the argument for ex ante regulation of exploitative data practices where consumers are offered no opportunity for meaningful choice or consent. Third, our work provides technical tools for offering transparency about app behaviors, empowering consumers and regulators, law enforcement, consumer protections organizations, and private parties seeking to remedy undesirable or illegal privacy behavior in the most dominant example of a free vs. paid market—mobile apps—where there turns out to be no real privacy-protective option.
Datamining practices have become greatly enhanced in the interconnected era. What began with the internet now continues through the Internet of Things (IoT), whereby users can constantly be connected to the internet through various means like televisions, smartphones, wearables and computerized personal assistants, among other things. As many of these devices operate in a so-called mode, constantly receiving and transmitting data, the increased use of IoT devices might lead society into an era, where individuals are constantly datafied. As the current regulatory approach to privacy is sectoral in nature, i.e., protects privacy only within a specific context of information gathering or use, and directed only to specific pre-defined industries or a specific cohort, the individual's privacy is at great risk. On the other hand, strict privacy regulation might negatively impact data utility which serves many purposes, and, perhaps mainly, is crucial for technological development and innovation. The tradeoff between data utility and privacy protection is most unlikely to be resolved under the sectoral approach to privacy, but a technological solution that relies mostly on a method called differential privacy might be of great help. It essentially suggests adding noise to data deemed sensitive ex-ante, depending on various parameters further suggested in this Article. In other words, using computational solutions combined with formulas that measure the probability of data sensitivity, privacy could be better protected in the always-on era. This Article introduces legal and computational methods that could be used by IoT service providers and will optimally balance the tradeoff between data utility and privacy. It comprises several stages. The first Part discusses the protection of privacy under the sectoral approach, and estimates what values are embedded in it. The second Part discusses privacy protection in the era. First it assesses how technological changes have shaped the sectoral regulation, then discusses why privacy is negatively impacted by IoT devices and the potential applicability of new regulatory mechanisms to meet the challenges of the era. After concluding that the current regulatory framework is severely limited in protecting individuals' privacy, the third Part discusses technology as a panacea, while offering a new computational model that relies on differential privacy and a modern technique called private coreset. The proposed model seeks to introduce noise to data on the user's side to preserve individual's privacy — depending on the probability of data sensitivity of the IoT device — while enabling service providers to utilize the data.
This paper reports on a set of empirical studies that reveal how people think about location data, how these conceptions relate to expectations of privacy, and, consequently, what this might mean for law, regulation, and technology design. Despite the great debates, published commentary, court action, regulatory activity, and scholarly literature, not enough is known about how people understand location data, and what specifically about location affects people’s judgments about others’ access to their whereabouts. Further, despite efforts to stem location tracking, it remains rampant. Perhaps for the very reasons that people find it abhorrent, the trackers eagerly clutch this revealing window in our lives. Stern rules aimed at curtailing location tracking are a poor match for the ingenuity of seekers of this information who, among other tactics, exploit enormous ambiguity in how location is interpreted and operationalized, to make end runs around these rules. This conceptual ambiguity about location poses challenges even to good faith efforts to regulate location tracking and to represent and enforce it in systems in concert with the ways people conceive, interpret, and value it. In other words, technical and regulatory efforts to protect location privacy may stumble because of a failure to map the meaning that people assign to location with its representations in technical systems. Our studies offer insights into how people think about location data and the factors affecting how we evaluate common location-tracking practices. In so doing these studies may serve the needs of courts, regulators, and systems designers seeking to address diverse challenges without compromising the normative standing of privacy interests in location data. After a series of pilot studies used to test the design of the study, we deployed Knowledge Networks to achieve a nationally representative sample of 1,500 respondents. Using a factorial vignette survey, we asked respondents to rate the appropriateness (a range of ‘Definitely Not OK’ to ‘Definitely OK’) of a series of scenarios, in which contextual elements were systematically varied; these elements included who gathered the location data, how the data was gathered, how long it was stored, and what information was inferred about the subject from the location data. Respondents were placed in one of three conditions determined by vignettes in one of three categories: (1) a baseline category in which they were asked about the collection of location data by different actors, (2) #1 with duration of surveillance added, (3) #2 with inference about the individual included. Our results immediately debunk the idea that people have no expectations of privacy in public. Rather, the findings extend work revealing legitimate privacy interests in erstwhile public locations. The findings reinforce general objections to common practices involving amassing of location data by government and commercial entities, showing that these map onto expressed privacy expectations in systematic and specific ways. Further, the studies reveal that the ways we ask about location in surveys and regulate location in rules makes a difference to how people react. Adding details, such as the duration of collection, the place, and the inferences drawn about the individual decreases the degree to which the vignette are ‘ok.’ The results here show that drawing inferences about an individual's location or identifying the ‘place’ where they are significantly affects how appropriate people judge respective practices to be. This means that tracking an individual's place – home, work, shopping – is seen to violate privacy expectations, even without directly collecting GPS data, that is, standard markers representing location in technical systems. Although our findings, by themselves, do not support specific lines of legal regulation they leave little doubt of a damaging rift between how these beneficiaries of location surveillance communicate their practices and how we, its subjects, understand it. Only when this rift is repaired will it be possible adequately to regulate location surveillance – through policy, law, and technology – to meet privacy expectations and promote privacy’s societal value.
The era of AI-based decision-making fast approaches, and anxiety is mounting about when, and why, we should keep “humans in the loop” (“HITL”). Thus far, commentary has focused primarily on two questions: whether, and when, keeping humans involved will improve the results of decision-making (making them safer or more accurate), and whether, and when, non-accuracy-related values—legitimacy, dignity, and so forth—are vindicated by the inclusion of humans in decision-making. Here, we take up a related but distinct question, which has eluded the scholarship thus far: does it matter if humans appear to be in the loop of decision-making, independent from whether they actually are? In other words, what is stake in the disjunction between whether humans in fact have ultimate authority over decision-making versus whether humans merely seem, from the outside, to have such authority? Our argument proceeds in four parts. First, we build our formal model, enriching the HITL question to include not only whether humans are actually in the loop of decision-making, but also whether they appear to be so. Second, we describe situations in which the actuality and appearance of HITL align: those that seem to involve human judgment and actually do, and those that seem automated and actually are. Third, we explore instances of misalignment: situations in which systems that seem to involve human judgment actually do not, and situations in which systems that hold themselves out as automated actually rely on humans operating “behind the curtain.” Fourth, we examine the normative issues that result from HITL misalignment, arguing that it challenges individual decision-making about automated systems and complicates collective governance of automation.
Despite the increased transparency, connectivity, and search abilities that characterize the digital marketplace, the digital revolution has not always yielded the bargain prices that many consumers expected. What is going on? Some researchers suggest that one factor may be coordination between the algorithms used by suppliers to determine trade terms. Simple coordination-facilitating algorithms are already available off the shelf, and such coordination is only likely to become more commonplace in the near future. This is not surprising. If algorithms offer a legal way to overcome obstacles to profit-boosting coordination, and create a jointly profitable status quo in the market, why should suppliers not use them? In light of these developments, seeking solutions – both regulatory and market-driven – is timely and essential. While current research has largely focused on the concerns raised by algorithmic-facilitated coordination, this article takes the next step, asking to what extent current laws can be fitted to effectively deal with this phenomenon. To meet this challenge, this article advances in three stages. The first part analyzes the effects of algorithms on the ability of competitors to coordinate their conduct. While this issue has been addressed by other researchers, this article seeks to contribute to the analysis by systematically charting the technological abilities of algorithms that may affect coordination in the digital ecosystem in which they operate. Special emphasis is placed on the fact that the algorithms is a “recipe for action”, which can be directly or indirectly observed by competitors. The second part explores the promises as well as the limits of market solutions. In particular, it considers the use of algorithms by consumers and off-the-grid transactions to counteract some of the effects of algorithmic-facilitated coordination by suppliers. The shortcomings of such market solutions lead to the third part, which focuses on the ability of existing legal tools to deal effectively with algorithmic-facilitated coordination, while not harming the efficiencies they bring about. The analysis explores three interconnected questions that stand at the basis of designing a welfare-enhancing policy: What exactly do we wish to prohibit, and can we spell this out clearly for market participants? What types of conduct are captured under the existing antitrust laws? And is there justification for widening the regulatory net beyond its current prohibitions in light of the changing nature of the marketplace? In particular, the article explores the application of the concepts of plus factors and facilitating practices to algorithms. The analysis refutes the Federal Trade Commission’s acting Chairwoman’s claim that current laws are sufficient to deal with algorithmic-facilitated coordination.
Machines, by providing the means of mass production of works of authorship, engendered copyright law. Throughout history, the emergence of new technologies tested the concept of authorship, and courts in response endeavored to clarify copyright’s foundational principles. Today, developments in computer science have created a new form of machine — the “artificially intelligent” system apparently endowed with “computational creativity” — that introduces challenging variations on the perennial question of what makes one an “author” in copyright law: Is the creator of a generative program automatically the author of the works her process begets, even if she cannot anticipate the contents of those works? Does the user of the program become the (or an) author of an output whose content the user has at least in part defined? This article frames these and similar questionsthat generative machines provoke as an opportunity to revisit the concept of copyright authorship in general and to illuminate its murkier corners. This article examines several fundamental relationships (between author and amanuensis, between author and tool, and between author and co-author) as well as several authorship anomalies (including the problem of “accidental” or “indeterminate” authorship) to unearth the basic principles and latent ambiguities which have nourished debates over the meaning of the “author” in copyright. We present an overarching and internally consistent model of authorship based on two basic pillars: a mental step (the conception of a work) and a physical step (the execution of a work), and define the contours of these basic pillars to arrive at a cohesive definition of authorship. We then apply the conception-and-execution theory of authorship to reach a series of conclusions about the question of machine “authorship.” We contend that even the most technologically advanced machines of our era are little more than faithful agents of the humans who design or use them. Asking whether a computer can be an author therefore is the “wrong” question; the “right” question addresses how to evaluate the authorial claims of the humans involved in either preparing or using the machines that “create.” We argue that in many cases, either the upstream human being who programs and trains a machine to produce an output, or the downstream human being who requests the output, is sufficiently involved in the conception and execution of the resulting work to claim authorship. But in some instances, the contributions of the human designer and user will be too attenuated from the work’s creation for either to qualify as “authors” — leaving the work “authorless.”
In deciding what rule-making authority the Copyright Office should have, it may be helpful to take a close and careful look at how the Office has historically exercised its rule-making powers. This article undertakes this task and makes a number of observations: (1) the Office’s rule-making activity increased dramatically after passage of the 1976 Act; (2) the rules issued fall into a number of identifiable categories; (3) by far the largest category consists of rules administering statutory licenses set forth in the Act; and (4) the smallest category consists of precisely the kinds of substantive rules that some commentators propose the Copyright Office issue in the future. While Congress may, of course, change the balance of copyright regulation in the future, this Article argues that any future delegations of substantive rule-making authority must take into account the fact that the Office’s regulatory efforts to date have largely involved a very particular and unique kind of rule-making, one that focuses on administering legislative compromises between large industries rather than on furthering specific copyright policies. Care must be taken to ensure that this unusual regulatory perspective does not unduly influence or affect future substantive rule-making.
Access. A word at the heart of the digital world, fueling debates about how to reconcile education, historical preservation, and personal autonomy with intellectual property protections of copyrighted works. “Freedom or ability to obtain or make use of something” is one definition of access.1 It demonstrates the importance and power of this six-letter word. Much like super computer HAL 9000’s refusal to open the pod bay doors for astronaut David Bowman,2 we now live in a world where the products we buy deny us full access. Our long-held collective assumption that we can tinker with our property is under assault. 3 The reason for this loss of access? Section 1201, the anticircumvention provision of a flawed piece of legislation passed by Congress in 1998, named the Digital Millennium Copyright Act.4 These flaws harm the public in many ways and include the erosion of fair use, unfairly allowing companies to restrict the repair market, chilling free speech, and bottlenecking of innovation. These harms prompted the Copyright Office to conduct two studies published within the last year. One is a comprehensive review of § 1201 requested by Representative John Conyers, Jr.,5 and the other a report on