You can't question a secret you haven't been told. The criminal legal system depends on fair and open proceedings to expose and regulate unlawful and unconstitutional police conduct through the courts. If police can use claims of secrecy to systematically thwart criminal defendants' access to evidence, judicial review will fail. And yet that is exactly what is happening under a common-law doctrine called the "law enforcement privilege." The privilege empowers police and prosecutors to rely on the results of secret investigative methods while withholding information from the defense about how those methods work. It risks perpetuating unconstitutional conduct, enabling wrongful convictions, and rendering Fourth Amendment, Sixth Amendment, Brady, and statutory discovery laws moot. At the same time, it has a non-frivolous policy rationale. If all police investigative methods were public information, then more people committing crimes could evade detection. How can a better balance be struck? This Article argues that current law enforcement privilege doctrine creates a dangerously boundless police secrecy power because of a subtle conceptual collapse: The policy rationale itself is mistakenly used as the test for assessing claims of privilege. The Article recommends that courts instead evaluate privilege claims by reference to the marginal risk of leaking posed by in-court disclosure. Specifically, judges should demand to know what conditions law enforcement previously imposed on access to the information. The answer to that question can be adjudicated publicly without jeopardizing a legitimate privilege claim and will help judges detect mistaken, exaggerated, pretextual, or fraudulent claims to the privilege. Further, even when law enforcement has taken care with the information, if a court-ordered protective order can match or exceed the safeguards that law enforcement itself previously maintained, then judges should default to ordering disclosure. The Article concludes by suggesting a theory of the role of confidentiality in privilege law.
Abstract This chapter discusses the relationship between reproductive autonomy and data privacies. It documents first the scope of anti-abortion criminal and civil investigations after Dobbs and explains why these investigations will seek to exploit digital personal information, creating new risks to the pregnant and their care providers as well as broad spillover harms to data privacy more generally. It then describes the expansive production of digital personal data in the information economy and explains how such data can put reproductive autonomy at risk. The role of, and risks from, digital data in the coming abortion wars will ultimately be determined by two groups of actors: private tech firms and state actors who will set the rules for anti-abortion investigators’ access to the data. The chapter concludes with a detailed prescriptive account of what tech firms and state actors should do to protect digital privacy after Dobbs.
As the knowledge economy expanded and concerns about trade secret misappropriation mounted in the digital age, federal policymakers undertook efforts to reinforce trade secret protection a decade ago. These efforts came to fruition with passage of the Defend Trade Secrets Act of 2016 (DTSA). This landmark legislation, modeled on the Uniform Trade Secrets Act, elevated and expanded trade secret law's role in the federal intellectual property system. DTSA fully opened the federal courts to trade secret litigation as well as added several new features, including an ex parte seizure remedy and whistleblower immunity.DTSA added to the large and growing federal caseloads. It also exposes more federal judges, relatively few of whom studied or litigated trade secret cases prior to their judicial appointments, to the distinctive challenges of trade secret litigation.As with patent litigation, federal judges have implemented innovative approaches to managing trade secret litigation based on the distinctive features of these intangible resources. As with patent litigation, with its pretrial claim construction process, courts have developed practical strategies for identifying the protected trade secrets at issue. This task is complicated by the need to insulate trade secrets from public disclosure. Moreover, trade secret law often involves requests for pretrial equitable relief, which demands additional intensive case management. Furthermore, unlike patent law, federal trade secret law includes criminal law provisions. The interplay of civil and criminal trade secret cases further complicates case management.Drawing on the PATENT CASE MANAGEMENT JUDICIAL GUIDE (3d ed. 2016)—with chapters organized in the stages of litigation and guided by an early case management checklist—the TRADE SECRET CASE MANAGEMENT JUDICIAL GUIDE provides judges with a comprehensive resource for surveying trade secret law and managing trade secret litigation.
U.S. policymakers' responses to a wave of global data privacy laws are creating a deep structural unfairness in the criminal legal system. In an era of cloud computing, when data about communications and activities occurring anywhere in the world can be stored on servers located anywhere else, access to such data can make the difference between convictions and acquittals. At the same time, new global data privacy laws risk cutting off cross-border access to digital evidence in criminal investigations. Recognizing the threat to law enforcement interests, U.S. policymakers enacted the CLOUD Act of 2018 to create special procedures for law enforcement to circumvent foreign data privacy laws and access cross-border evidence anyway. Yet no one is creating similar procedures for criminal defense investigators.In the U.S. adversarial legal system, criminal defense counsel are the sole actors formally tasked with investigating evidence of innocence. While the prosecution team must disclose exculpatory evidence that it happens to possess, law enforcement officers have no formal duty to actively seek out such evidence. As a result, selectively advantaging law enforcement investigations of guilt without creating parallel procedures for the defense means selectively suppressing evidence of innocence. This asymmetry gets privacy backwards. Privacy protections ostensibly meant to constrain government power may accomplish that goal in an absolute sense, but relatively speaking, they specially empower the government as compared to the defense. They thereby undermine the criminal defense process that is itself supposed to guard against government abuse.This Article exposes this structural anti-defendant bias in U.S. responses to global data privacy laws. It then uses this problem as a case study to examine the constitutionality of a more general category of laws: privacy laws that disadvantage criminal defense investigations as compared to their law enforcement counterparts. It diagnoses why constitutional challenges to these types of laws have failed in the past and proposes a novel definitional argument to strengthen these challenges moving forward. Ironically, the very CLOUD Act procedures that exclude defense investigators also hold a key to advocating on their behalf.
id=4099764 [https://perma.cc/9UDT-8LHY]. Fowler and Michael more generally argue that in a post-Dobbs era portending increased state restrictions on contraception, state intrusion into medical decisions surrounding birth, and more general state surveillance and control over those who may become pregnant, period and fertility tracking apps can provide greater autonomy over pregnancy while at the same time generating data that may end up “in the hands of nefarious actors or facilitate civil and criminal actions[.]” Id. at 27. They suggest ways that app developers can minimize privacy risks by limiting data collection and adopting design choices such as end-to-end encryption, id. at 69–71, and identify a number of ways that users can engage in digital self-defense, id. at 71–75. 42 See, e.g., Albert Fox Cahn & Eleni Manis, Pregnancy Panopticon: Abortion Surveillance After Roe, SURVEILLANCE TECH. OVERSIGHT PROJECT 6–7, 9–13 (May 24, 2022), https://www.stopspying.org/pregnancy-panopticon [https://perma.cc/D9PY-5YNT]; Corynne McSherry & Katharine Trendacosta, What Companies Can Do Now to Protect Digital Rights in a Post-Roe World, ELEC. FRONTIER FOUND.: DEEPLINKS BLOG (May 10, 2022), https://www.eff.org/deeplinks/2022/05/what-companies-can-do-now-protect-digitalrights-post-roe-world [https://perma.cc/RDP5-9259]. 43 See, e.g., Kaste, supra note 33 (describing the use of Facebook messages to prosecute a mother and daughter for violating abortion laws). 45115-nyu_98-2 Sheet No. 82 Side B 05/23/2023 08:33:06 4511nyu_98-2 S heet N o. 82 S de B 053/2023 0833:06 \\jciprod01\productn\N\NYU\98-2\NYU203.txt unknown Seq: 12 22-MAY-23 11:39 566 NEW YORK UNIVERSITY LAW REVIEW [Vol. 98:555 to their persecutors), which makes the digital domain an inconstant friend where reproductive choice is concerned. This map of the informational (or epistemic) landscape on which the new abortion wars will unroll does double duty as a guide for those concerned with their vulnerability to state supervision. Second, we analyze the ethical, legal, and economic dilemmas faced by crucial sets of private actors: technology firms and their users. We show that search firms, social media, data brokers, and platforms—indeed any firm with a digital footprint falls into the scope of what we call a “digital” or a “technology” firm—will have to make fraught choices post-Dobbs. The modal response of tech firms to date has been to suggest they will firmly defend their employees’ access to reproductive services, but not their users’.44 This line is untenable. Worse for tech companies hoping to avoid taking a position, we demonstrate that private firms will not be able to use geographic boundaries to demarcate zones of compliance with law enforcement, as opposed to respect for reproductive choice. Neither patients nor restrictionist enforcement efforts will respect state lines. Digital firms, therefore, will inevitably be forced to choose whether to cooperate with restrictionist efforts turning on persons or data located outside the geographical bounds of states that limit abortion. Similarly, data gathered in restrictionist states can reveal activities by providers and pregnant persons within states where abortion is broadly lawful. The risk of such exposure is likely to have a chilling effect. The comprehensive blurring of geographic lines also means that digital firms must take sides: There is no neutral ground. In light of these dynamics, we canvas the ethical and economic arguments for minimizing, within legal bounds, the extent to which technology firms’ digital architectures and prior actions expose their users to abortion-related investigation and prosecution. We conclude that there are powerful reasons for some (if not all) companies to maximize privacy by design—and even at the margins take on some risk of law-related costs in the defense of reproductive choice—based on their own narrowly conceived commercial interests. 44 And indeed, not all workers. See Caitlin Harrington, Tech Companies Will Cover Abortion Travel, but Not for All Workers, WIRED (July 7, 2022, 7:00 AM), https:// www.wired.com/story/tech-companies-abortion-travel [https://perma.cc/9FUL-DKMJ]. Further, given the speed at which such policies were rolled out, it is reasonable to ask whether they will be durable. See Jacob Kastrenakes, Why Big Tech Companies Are So Quiet on Abortion Rights , THE VERGE (June 30, 2022, 1:56 PM), https:// www.theverge.com/2022/6/30/23189810/abortion-rights-activism-big-tech-employees [https://perma.cc/QKP6-G2JW] (reporting “quick, makeshift policies aligning these companies with the right to choose and granting benefits that supported that stance”). 45115-nyu_98-2 Sheet No. 83 Side A 05/23/2023 08:33:06 4511nyu_98-2 S heet N o. 83 S de A 053/2023 0833:06 \\jciprod01\productn\N\NYU\98-2\NYU203.txt unknown Seq: 13 22-MAY-23 11:39 May 2023] DIGITAL PRIVACY FOR REPRODUCTIVE CHOICE 567 Finally, we shift into a prescriptive gear to ask what can be done—by firms and individuals and even pro-choice states—to maximize digital privacy in relation to reproductive choice.45 To this end, we offer a taxonomy of what we dub “battlefields” in the coming abortion wars. These battlefields are four distinct “quarters” of the digital world in which the abortion wars might unfold: (1) technology firms’ decisions to collect and retain data; (2) technology firms’ responses to regulators’ demands for information; (3) technological infrastructure that empowers individual users to access information privately and securely; and (4) state and federal data privacy and evidentiary privilege regulation or legislation. These four battlefields, for patients and regulators alike, act as substitutes in part and complements in part. Clarifying their interrelationship helps focus on where and how reproductive choice can best be enabled—or repressed. What ensues from this analysis is a manifesto for digital privacy to enable reproductive choice. Lest there be any doubt about the perspective from which we write, we should clarify up front our normative priors. We approach the analysis on the assumption that Dobbs was incorrectly decided as a matter of law and as a moral matter. A view of the fundamental rights to life and liberty under the Fourteenth Amendment should account for all Americans’ experience. It should not be insensitive to the radical political exclusion women have experienced through much American history. So understood, historical inquiry of the sort supposedly deployed in Dobbs would quickly reveal the centrality of reproductive choice to the felt experience of liberty and life. We are further persuaded by the moral case in favor of abortion developed by philosophers such as Judith Jarvis Thompson and Richard Hare.46 Unlike the Dobbs Court, moreover, we are alive to the relation between restrictionist regulation and the marginalization and disempowerment of women as a class even as we are aware of the way in 45 We do not address here the federal administrative state, including the FDA and other agencies. Presumably, the latter’s posture will change radically depending on which party controls the White House. It would be peculiar to plot out choice-enabling regulatory strategies on the (false) assumption that federal policy won’t change. 46 Judith Jarvis Thomson, A Defense of Abortion, 1 PHIL. & PUB. AFFS. 47, 48–49 (1971) (stipulating the personhood of the fetus and developing a counterargument to claims against abortion based on the pregnant person’s autonomy interests). For an illuminating defense of abortion under the “Christian golden rule,” see R.M. Hare, Abortion and the Golden Rule, 4 PHIL. & PUB. AFFS. 201, 221 (1975). On the dearth of religious opposition to abortion as a historical matter until the twentieth century, see Garry Willis, The Bishops Are Wrong About Biden—and Abortion, N.Y. TIMES (June 27, 2021), https://www.nytimes.com/2021/06/27/opinion/biden-bishops-communion-abortion.html [https://perma.cc/9JJH-LA53] (exploring the absence of opposition to abortion in historical Christianity). 45115-nyu_98-2 Sheet No. 83 Side B 05/23/2023 08:33:06 4511nyu_98-2 S heet N o. 83 S de B 053/2023 0833:06 \\jciprod01\productn\N\NYU\98-2\NYU203.txt unknown Seq: 14 22-MAY-23 11:39 568 NEW YORK UNIVERSITY LAW REVIEW [Vol. 98:555 which abortion sweeps in those who do not identify as women while experiencing pregnancy.47 Although we disagree sharply with Dobbs on both legal and moral grounds, we nevertheless stipulate its outcome as a matter of positive (but unjust and incorrect) law for the purposes of analysis here. Our approach is, at the same time, sensitive to the powerful liberty, anti-domination, and equality interests at stake when reproductive choice is curtailed. The Court’s failure to recognize or honor those interests is hardly warrant for the rest of us to do the same. Nor is the bare fact of criminalization enough to squelch the powerful moral and medical interests that the pregnant have in accessing information and care. American history is full of instances in which statelevel criminalization and pendent investigative powers have been used for morally bankrupt ends such as the enforcement of chattel slavery before the Civil War48 or its recreation through “Black Codes” and convict leasing laws in the late eighteenth century.49 Our argument in the balance of the paper proceeds as follows. Part I crisply maps the bilateral economy of digital data flows—to patients and to prosecutors—that works as terrain in the new abortion wars. We draw attention here in particular to epistemic dynamics that, to date, have been understudied or ignored. Part II turns to the ethical and economic choices of technology firms straddling this landscape. We ask here both what would be ethical, and what would be efficient (i.e., wealth-maximizing), for different firms to do. Part III then offers a taxonomy of digital battlefields. It points the way toward complementary choices by private fi
The use of hidden investigative software to collect evidence of crimes presents courts with a recurring dilemma: On the one hand, there is often clear public interest in keeping the software hidden to preserve its effectiveness in fighting crimes. On the other hand, criminal defendants have rights to inspect and challenge the full evidence against them, including law enforcement's investigative methods. In fact, in the U.S. adversarial legal system, the defendant's rights to scrutinize the government's tools are crucial to the truth-seeking process and to keeping law enforcement conduct lawful and constitutional. Presently, courts balance these conflicting interests on a case-by-case basis through evidentiary privilege law, often voicing their frustration with the challenging dilemma they face. We demonstrate how judicious use of a sophisticated cryptographic tool called Zero Knowledge Proofs (ZKPs) could help to mitigate this dilemma: Based on actual court cases where evidence was collected using a modified version of a peer-to-peer software, we demonstrate how law enforcement could, in these cases, augment their investigative software with a ZKP-based mechanism that would allow them to later provide full responses to challenges made by a defense expert -- and allow a defense expert to independently verify law enforcement claims -- while keeping the software hidden. We demonstrate the technical feasibility of our mechanism via a proof-of-concept implementation. We also propose legal analysis that justifies its use, discusses its merits, and considers the legal implications that the very existence of such a mechanism might have, even in cases where it has not been used. Our proof-of-concept may also extend to other verification dilemmas in the legal landscape.
The U.S. criminal legal system increasingly relies on software output to convict and incarcerate people. In a large number of cases each year, the government makes these consequential decisions based on evidence from statistical software -- such as probabilistic genotyping, environmental audio detection, and toolmark analysis tools -- that defense counsel cannot fully cross-examine or scrutinize. This undermines the commitments of the adversarial criminal legal system, which relies on the defense's ability to probe and test the prosecution's case to safeguard individual rights. Responding to this need to adversarially scrutinize output from such software, we propose robust adversarial testing as an audit framework to examine the validity of evidentiary statistical software. We define and operationalize this notion of robust adversarial testing for defense use by drawing on a large body of recent work in robust machine learning and algorithmic fairness. We demonstrate how this framework both standardizes the process for scrutinizing such tools and empowers defense lawyers to examine their validity for instances most relevant to the case at hand. We further discuss existing structural and institutional challenges within the U.S. criminal legal system that may create barriers for implementing this and other such audit frameworks and close with a discussion on policy changes that could help address these concerns.
This Article introduces the phenomenon of “privacy asymmetries,” which are privacy statutes that permit courts to order disclosures of sensitive information when requested by law enforcement, but not when requested by criminal defense counsel. In the United States adversarial criminal legal system, defense counsel are the sole actors tasked with investigating evidence of innocence. Law enforcement has no constitutional, statutory, or formal ethical duty to seek out evidence of innocence. Therefore, selectively suppressing defense investigations means selectively suppressing evidence of innocence. Privacy asymmetries form a recurring, albeit previously unrecognized, pattern in privacy statutes. They likely arise from legislative oversight and not reasoned deliberation. Worse, they risk unnecessary harms to criminal defendants, as well as to the truth-seeking process of the judiciary, by advantaging the search for evidence of guilt over that for evidence of innocence. The number of these harms will only increase in the digital economy as private companies collect immense quantities of data about our heart beats, movements, communications, consumption, and more. Much of that data will be relevant to criminal investigations, and available to the accused solely through the very defense subpoenas that privacy asymmetries block. Moreover, the introduction of artificial intelligence and machine learning tools into the criminal justice system will exacerbate the consequences of law enforcement’s and defense counsel’s disparate access to data. To avoid enacting privacy asymmetries by sheer accident, legislators drafting privacy statutes should include a default symmetrical savings provision for law enforcement and defense investigators alike.
This Article exposes a profound and growing injustice that major technology companies have propagated through every level of the judiciary under the guise of protecting data privacy. The Supreme Court has repeatedly proclaimed that: “In our judicial system, the public has a right to every [person’s] evidence.” Yet, for over a decade, Facebook, Twitter, Google, and Github have leveraged the Stored Communications Act (SCA) — a key data privacy law for the Internet — to bar criminal defendants from subpoenaing the contents of another’s online communications, even when those communications could exonerate the wrongfully accused. Every appellate court to rule on this issue to date has agreed with the companies. This Article argues that all of these decisions are wrong as a matter of binding Supreme Court doctrine and just policy. The Article makes two novel doctrinal claims and then evaluates the policy consequences of those claims. First, when courts read the SCA to block criminal defense subpoenas, they construe the statute as creating an evidentiary privilege. Second, this construction violates a binding rule of privilege law: courts must not construe ambiguous silence in statutory text as impliedly creating a privilege because privileges are “in derogation of the search for truth.” This Article is the first to read the SCA through the lens of evidentiary privilege law. Overturning the conventional wisdom and correcting the erroneous case law on this issue will enhance truth-seeking and fairness in the criminal justice system with minimal cost to privacy.
Individuals expose personally identifying information to access a website or qualify for a loan, undermining privacy and security. Firms share proprietary information in dealmaking negotiations; if the deal fails, the negotiating partner may use that information to compete. Regulators that comply with public transparency and oversight requirements can risk subjecting algorithmic governance tools to gaming that destroys their efficacy. Litigants might have to reveal trade secrets in court proceedings to prove a claim or defense. Such “verification dilemmas,” or costly choices between opportunities that require the verification of some fact, and risks of exposing sensitive information in order to perform verification, appear across the legal landscape. Yet, existing legal responses to them are imperfect. Legal responses often depend on ex post litigation remedies that are prohibitively expensive for those most in need, or that fail to address abuses of information entirely. Zero-knowledge proofs (ZKPs)—a class of cryptographic protocols that allow one party to verify a fact or characteristic of secret information without revealing the actual secret—can help solve these verification dilemmas. ZKPs have recently demonstrated their mettle, for example, by providing the privacy backbone for the blockchain. Yet they have received scant notice in the legal literature. This Article fills that gap by providing the first deep dive into ZKPs’ broad relevance for law. It explains ZKPs’ conceptual power and technical operation to a legal audience. It then demonstrates how, and that, ZKPs can be applied as a governance tool to transform verification dilemmas in multiple legal contexts. Finally, the Article surfaces, and provides a framework to address, the policy issues implicated by the potential substitution of ZKP governance tools in place of existing law and practice.
The National Security Agency (NSA) engages in warrantless "upstream" surveillance of international communications that travel along the Internet’s “backbone” of fiber optic cables. The government has stymied Fourth Amendment challenges on the ground that plaintiffs lack standing because they cannot prove that the NSA has intercepted, copied, or reviewed any of their communications. Of course, the reason plaintiffs have no direct evidence of such surveillance is that the government asserts that the surveillance program is a state secret, and its details are classified.In response to a motion for summary judgment in Wikimedia Foundation v. National Security Agency, the foundation produced expert reports concluding that it is all but certain that the NSA intercepted and opened at least one of Wikimedia's trillions of Internet communications. Treating the expert's opinion as inadmissible under Federal Rule of Evidence 702 as interpreted in Daubert v. Merrell Dow Pharmaceuticals, the district court granted summary judgment.In a pending appeal to the U.S. Court of Appeals for the Fourth Circuit, four evidence law professors filed a brief as amici curiae in support of Wikimedia. The brief, posted here, questions the district court’s abbreviated analysis of Rule 702 and Daubert. It describes the applicable standard for excluding expert testimony. It then argues that the expert’s method of reasoning was sound and that the underlying facts regarding the nature of Internet communications and surveillance technology, together with public information on the goals and needs of the NSA program, were sufficient to justify the receipt of the proposed testimony.
One day in early January, a letter appeared on my desk marked DIN92A5501— an inmate ’s ident i f icat ion number from the Eastern Correctional Facility in upstate New York. The author, Glenn Rodríguez, had drafted it in upright, even letters, perfectly aligned. Here, in broad strokes, is the story he told: Rodríguez was just 16 at the time of his arrest, and was convicted of second-degree murder for his role in an armed robbery of a car dealership that left an employee dead. Now, 26 years later, he was a model of rehabilitation. He had requested a transfer to Eastern, a maximum-security prison, to take college classes. He had spent four and a half years training service dogs for wounded veterans and 11 volunteering for a youth program. A job and a place to stay were waiting for him outside. And he had not had a single disciplinary infraction for the past decade. Yet, last July, the parole board hit him with a denial. It might have turned out differently but, the board explained, a computer system called COMPAS had ranked Code of Silence How private companies hide flaws in the software that governments use to decide who goes to prison and who gets out
The criminal justice system is becoming automated. At every stage, from policing to evidence to parole, machine learning and other computer systems guide outcomes. Widespread debates over the pros and cons of these technologies have overlooked a crucial issue: ownership. Developers often claim that details about how their tools work are trade secrets and refuse to disclose that information to criminal defendants or their attorneys. The introduction of intellectual property claims into the criminal justice system raises under-theorized tensions between life, liberty, and property interests. This Article offers the first wide-ranging account of trade secret evidence in criminal cases, and develops a framework to address the problems that result. In sharp contrast to the general view among trial courts, legislatures, and scholars alike, the Article argues that trade secrets should not be privileged in criminal proceedings. A criminal trade secret privilege is ahistorical; harmful to defendants; and unnecessary to protect the interests of the secret holder. Meanwhile, compared to substantive trade secret law, the privilege overprotects intellectual property. Further, privileging trade secrets in criminal proceedings fails to serve the theoretical purpose of either trade secret law or privilege law. The trade secret inquiry sheds new light on how evidence rules do, and should, function differently in civil and criminal cases.