Congress and state legislatures are showing renewed interest in youth addiction, manipulation, and more. Almost all of their proposals, and youth privacy law in general, follow what we call the parental control model. The model is erected in the name of children, but it mostly ignores their expressed privacy interests. Under the model, parents are asked to provide consent for the collection of children's data, to check on the handling of that data, and to protect children from danger. Because parental control dominates policymaking and scholarly discourse, it goes unquestioned. This Article challenges the status quo. Parental control risks harm to vulnerable children, overburdens caregivers (who are more often women), and denies youth the intimate privacy that they need to grow and develop close relationships, including, ironically, relationships with their parents. The parental control model disserves nearly everyone involved except companies that press for its adoption because it earns them massive advertising profits without costly responsibilities for youth safety and privacy. The time is now to reimagine the youth privacy project. We need to shed the yoke of exclusive parental control and to protect the intimate privacy that youth want, expect, and deserve. Our proposal foregrounds youth
Content moderation is typically viewed as an affront to free expression. When companies remove online abuse, they face accusations of censorship. Lost in the discussion is the fact that victims of intimate privacy violations and cyberstalking typically-and regrettably-withdraw from on- and offline activities. Online assaults chase targeted individuals offline; they silence victims. Content moderation can secure opportunities for people to speak. Legal and corporate prohibitions against intimate privacy violations and cyberstalking can help provide the reassurance that victims need to stay online. They can endow individuals with a sense of trust so they continue to use networked technologies to express themselves. Those prohibitions are consonant with First Amendment doctrine and free speech values. Combating online abuse isn't a zero-sum game with free speech as the loser. Rather, it can free us to speak by changing the culture that rewards abuse and encourages self-censorship.
Fifty years ago, federal and state lawmakers called for the regulation of a criminal justice "databank" connecting federal, state, and local agencies. There was bipartisan concern that the system imperiled constitutional commitments and people's crucial life opportunities, including jobs, education, housing, and licenses. Bipartisan congressional concerns of the 1970s should be cause for reinvigoration, not resignation. Recounting the insights of members of the 93rd and 94th Congresses should embolden us. Their concerns clarify the headwinds that reformers face. Then, as now, powerful interests want us to think that privacy and public safety are incompatible. They want us to view diminished expectations of privacy as acceptable, even valuable. Revisiting this history should remind the public that totalizing surveillance is neither acceptable nor desirable. Privacy can and should be ours.
Working hand-in-hand with the private sector, largely in a regulatory vacuum, policing agencies at the federal, state, and local levels are acquiring and using vast reservoirs of personal data. They are doing so indiscriminately, which is to say without any reason to suspect the individuals whose data they are collecting are acting unlawfully. And they are doing it in bulk. People are unlikely to want this personal information shared with anyone, let alone law enforcement. And yet today, private companies are helping law enforcement gather it by the terabyte. On all of us. Our thesis is straightforward: the unregulated collection of this data must cease, at least until basic rule-of-law requisites are met. Any collection must be authorized by democratically accountable bodies. It must be transparent. It must be based on clear proof of efficacy (that a legitimate purpose actually is being served). There must be protections that minimize or avoid harms to individuals and society. And, of course, there must be judicial review of whether indiscriminate bulk data collection is constitutional, either at all or with regard to specific programs. The basis for this thesis is a first-of-its-kind review of instances, from the dawn of the Information Age, in which Congress acted on these very issues. Much of that history involves indiscriminate collection of data on Americans for reasons of national and domestic security, because national security represents the outer bounds of what law enforcement and intelligence agencies are permitted to do, and much of what is done in the name of national security is inappropriate for domestic policing. Yet, in incident after incident, Congress made clear that indiscriminate bulk collection of Americans' data is unacceptable, unlawful, and of dubious constitutionality. To the extent that such collection was permitted at all, Congress demanded the very requisites specified above. Today's indiscriminate bulk surveillance by federal, state, and local policing agencies violates virtually all of these congressionally established norms. It should cease, at least until the rule-of-law requisites are met.
Section 230 is finally getting the clear-eyed attention that it deserves. No longer is it naive to suggest that we revisit the law that shields online platforms from liability for enabling illegality. The harm wrought is now undeniable for victims of online assaults and intimate privacy violations. The market has not fixed this problem. Content platforms lack sufficient incentive to combat online abuse because they generate significant profits from our likes, clicks, and shares. Victims can't sue sites that earn advertising fees from their suffering. The status quo is particularly costly for women, children, and minorities who lose their ability to speak, work, and love. Inaction signals our society's indifference to vulnerable people enduring online abuse that robs them of their civil rights and civil liberties. We need to fix 230. Reform must be approached with humility and care, lest it spur platforms to over-or under-moderate in ways that do more harm than good. The legislative solutions offered here grow out of a decade of experience working with tech companies, online abuse victims, and legislative staff. While the over-filtering provision, 230(c)(2), should be preserved, the under-filtering provision, 230(c)(1), should be revised. Sites that deliberately encourage, solicit, or maintain intimate privacy violations, cyber stalking, or cyber harassment should not enjoy immunity from liability. Beyond carving out those bad actors, the under-filtering provision should be conditioned on a duty of care when claims involve intimate privacy violations, cyber stalking, or cyber harassment. Rather than an unguided duty of care, lawmakers should specify the obligations involved, drawing on key lessons from the trust and safety field. Under my proposal, companies would have to show that they took steps to address abuse that inhibits self-expression and ruins livelihoods.
Privacy violations are destructive, no matter the perpetrator, but gov-ernmental privacy violations cast a particularly long and destructive shadow. A recent illustration began in 2017, when the Department of Jus-tice revealed the texts and extramarital affair of public servants to the press. The President amplified that information in a years-long smear campaign. To the public servants, the wreckage included job losses, stained reputa-tions, physical danger, and emotional suffering. To the public, the damage included a further loss of trust in the government's ability to handle per-sonal data with care. In the wake of privacy violations at the hands of pow-erful government actors, we must recognize the wrongs done to individuals and the public. Existing law provides some relief, but the government's own actions must play a part. At every branch and level, local, state, and federal, the government must work to restore public confidence in its data-handling practices. A key step would be to recognize intimate privacy as a founda-tional right.
Through the standing doctrine, the U.S. Supreme Court has taken a new step toward severely limiting the effective enforcement of privacy laws. The recent Supreme Court decision, TransUnion v. Ramirez (U.S. June 25, 2021) revisits the issue of standing and privacy harms under the Fair Credit Reporting Act (FCRA) that began with Spokeo v. Robins, 132 S. Ct. 1441 (2012). In TransUnion, a group of plaintiffs sued TransUnion under FCRA for falsely labeling them as potential terrorists in their credit reports. The Court concluded that only some plaintiffs had standing – those whose credit reports were disseminated. Plaintiffs whose credit reports weren’t disseminated lacked a “concrete” injury and accordingly lacked standing – even though Congress explicitly granted them a private right of action to sue for violations like this and even though a jury had found that TransUnion was at fault. In this essay, Professors Daniel J. Solove and Danielle Keats Citron engage in an extensive critique of the TransUnion case. They contend that existing standing doctrine incorrectly requires concrete harm. For most of U.S. history, standing required only an infringement on rights. Moreover, when assessing harm, the Court has a crabbed and inadequate understanding of privacy harms. Additionally, allowing courts to nullify private rights of action in federal privacy laws is a usurpation of legislative power that upends the compromises and balances that Congress establishes in laws. Private rights of action are essential enforcement mechanisms.
The legitimacy of the administrative state is premised on our faith in agency expertise. Despite their extra-constitutional structure, administrative agencies have been on firm footing for a long time in reverence to their critical role in governing a complex, evolving society. They are delegated enormous power because they respond expertly and nimbly to evolving conditions. In recent decades, state and federal agencies have embraced a novel mode of operation: automation. Agencies rely more and more on software and algorithms in carrying out their delegated responsibilities. The automated administrative state, however, is demonstrably riddled with concerns. Legal challenges regarding the denial of benefits and rights — from travel to disability — have revealed a pernicious pattern of bizarre and unintelligible outcomes. Scholarship to date has explored the pitfalls of automation with a particular frame, asking how we might ensure that automation honors existing legal commitments such as due process. Missing from the conversation are broader, structural critiques of the legitimacy of agencies that automate. Automation throws away the expertise and nimbleness that justify the administrative state, undermining the very case for the existence and authority of agencies. Yet the answer is not to deny agencies access to technology. This article points toward a positive vision of the administrative state that adopts tools only when they enhance, rather than undermine, the underpinnings of agency legitimacy.
The requirement of harm has significantly impeded the enforcement of privacy law. In most tort and contract cases, plaintiffs must establish that they have suffered harm. Even when legislation does not require it, courts have taken it upon themselves to add a harm element. Harm is also a requirement to establish standing in federal court. In Spokeo, Inc. v. Robins and TransUnion LLC v. Ramirez, the Supreme Court ruled that courts can override congressional judgment about cognizable harm and dismiss privacy claims. Case law is an inconsistent, incoherent jumble with no guiding principles. Countless privacy violations are not remedied or addressed on the grounds that there has been no cognizable harm. Courts struggle with privacy harms because they often involve future uses of personal data that vary widely. When privacy violations result in negative consequences, the effects are often small-frustration, aggravation, anxiety, inconvenience-and dispersed among a large number of people. When these minor harms are suffered at a vast scale, they produce significant harm to individuals, groups, and society. But these harms do not fit well with existing cramped judicial understandings of harm. This Article makes two central contributions. The first is the construction of a typology for courts to understand harm so that privacy violations can be tackled and remedied in a meaningful way. Privacy harms consist of various different types that have been recognized by courts in inconsistent ways. Our typology of privacy harms elucidates why certain types of privacy harms should be recognized as cognizable. This Article's second contribution is providing an approach to when privacy harm should be required. In many cases, harm should not be required because it is irrelevant to the purpose of the lawsuit. Currently, much privacy litigation suffers from a misalignment of enforcement goals and remedies. We contend that the law should be guided by the essential question: When and how should privacy regulation be enforced? We offer an approach that aligns enforcement goals with appropriate remedies.
Intimate life is under constant surveillance. Firms track people’s periods, hot flashes, abortions, sexual assaults, sex toy use, sexual fantasies, and nude photos. Individuals hardly appreciate the extent of the monitoring, and even if they did, little can be done to curtail it. What is big business for firms is a big risk for individuals. Corporate intimate surveillance undermines sexual privacy—the social norms that manage access to, and information about, human bodies, sex, sexuality, gender, and sexual and reproductive health. At stake is sexual autonomy, self-expression, dignity, intimacy, and equality. So are people’s jobs, housing, insurance, and other life opportunities. Women and minorities shoulder a disproportionate amount of that burden. Privacy law is failing us. Not only is the private-sector’s handling of intimate information largely unrestrained by American consumer protection law, but it is treated as inevitable and valuable. This Article offers a new compact for sexual privacy. Reform efforts should focus on stemming the tidal wave of collection, restricting uses of intimate data, and expanding the remedies available in court to include orders to stop processing intimate data.
In Section 230 of the Communications Decency Act, lawmakers thought they were devising a safe harbor for online providers engaged in self-regulation. The goal was to encourage platforms to “clean up” offensive material online. Yet Section 230’s immunity has been stretched far beyond that purpose to immunize platforms that solicit or deliberately host illegality. As Olivier Sylvain’s thoughtful essay shows, it has been invoked to shield from liability platforms whose architectural choices lead ineluctably to illegal discrimination. Section 230’s immunity provision has secured important breathing space for innovative new ways to work, speak, and engage with the world. But the law’s overbroad interpretation has been costly to expression and equality, especially for members of traditionally subordinated groups. This response piece highlights Sylvain’s important normative contributions to the debate over Section 230. It provides some practical reinforcements for his reading of Section 230. Our central disagreement centers on the way forward. Congress should revise Section 230’s safe harbor to apply only to platforms that take reasonable steps to address unlawful activity. I end with thoughts about why it is time for platforms to pair their power with responsibility.
Fiction and visual representations can alter our understanding of human experiences and struggles. They help us understand human frailties and suffering in a visceral way. Nick Drnaso’s graphic novel Sabrina does that in spades. In Sabrina, a woman is murdered by a misogynist, and a video of her execution is leaked. Conspiracy theorists deem her murder a hoax. A cyber mob smears the woman’s loved ones as crisis actors, posts death threats, and spreads their personal information. The attacks continue until a shooting massacre redirects the cyber mob’s wrath to other mourners. Sabrina captures the breathtaking velocity of disinformation online and the rapid escalation to terroristic threats.Every day, people are radicalized online to wreak havoc and violence. On August 3, 2019, in El Paso, Texas, a twenty-one-year old man posted a racist manifesto on 8chan and then walked into a Wal Mart with a powerful rifle, killing 20 people and injuring many others. The killer trafficked in and engaged with others in hateful conspiracy theories. Drnaso invites a conversation about cyber mobs, conspiracy theories, and death videos and the norms, attitudes, and laws enabling them. Right now, it is cheap and easy to wreak havoc online and for that havoc to go viral. Platforms act rationally — some might say responsibly to their shareholders — when they tolerate abuse that earns them advertising revenue and costs them nothing in legal liability. Combatting cyber-mob attacks must be a priority. Law should raise the cost of cyber-mob attacks. It is time for tech companies to redress some of the negative externalities of their business model. Platforms should not enjoy immunity from liability for user-generated content unless they have earned that immunity with reasonable content moderation practices. Education should play a role as well. As digital citizens, we need to do better.
A robust public debate is currently underway about the responsibility of online platforms. We have long called for this discussion, but only recently has it been seriously taken up by legislators and the public. The debate begins with a basic question: should platforms should be responsible for user-generated content? If so, under what circumstances? What exactly would such responsibility look like? Under consideration is Section 230 of the Communications Decency Act—a provision originally designed to encourage tech companies to clean up “offensive” online content. The public discourse around Section 230, however, is riddled with misconceptions. As an initial matter, many people who opine about the law are unfamiliar with its history, text, and application. This lack of knowledge impairs thoughtful evaluation of the law’s goals and how well they have been achieved. Accordingly, Part I of this Article sets the stage with a description of Section 230—its legislative history and purpose, its interpretation in the courts, and the problems that current judicial interpretation raises. A second, and related, major source of misunderstanding is the conflation of Section 230 and the First Amendment. Part II details how this conflation distorts discussion in three ways: it assumes all Internet activity is protected speech; it treats private actors as though they were government actors; and it presumes that regulation will inevitably result in less speech. These distortions must be addressed in order to pave the way for clear-eyed policy reform. Part III offers potential solutions to help Section 230 achieve its legitimate goals.
The fight for civil rights in the United States has historically focused on equal access to physical spaces: schools, workplaces, lunch counters, hotels, voting booths. This emphasis is understandable, because these were the places where people learned, worked, socialized, and voted. Civil rights activists made clear that people who are excluded from, or exploited in, these spaces cannot fully participate in civic life. But as the role of technology in our daily lives has increased, it has become clear that civil rights protections are as necessary in virtual spaces as in physical ones. This reality has perhaps never been more apparent than today, as so many of our crucial activities shift online in the wake of the COVID-19 pandemic.
Every generation’s intimates have their preferred modes of self-disclosure. Not long ago, intimate partners exchanged love letters and mixed tapes. They spent hours on the phone. Today, they text their innermost thoughts, beliefs, and wishes, sometimes with nude photos attached. They engage in sexually-explicit activity via FaceTime and SnapChat. Now, as then, the success and integrity of intimate relationships depends upon sexual privacy. Intimate relationships develop as partners grow to trust one another to treat their nakedness, deepest secrets, and sexual desires as they hope rather than as they fear. Handling partners’ personal information with discretion lays the foundation for trust that is crucial to intimacy. My previous work conceptualized sexual privacy as a distinct privacy interest that deserves comprehensive legal protection. In this Article, I drill down on a crucial reason why sexual privacy matters—as a precondition to intimate relationships. Sexual privacy invasions wreak havoc on the project of intimacy. When individuals secretly videotape others undressing or having sex or when they post former intimates’ nude photos online, victims find it difficult to trust others. Victims fear that revealing their naked bodies and intimate information will end in unwanted exhibition and exploitation. Law and technology have potential to reinforce trust and sexual privacy in intimate relationships, but they require careful assessment to ensure that they do not undermine them.