{"id":13221,"date":"2021-03-29T10:08:12","date_gmt":"2021-03-29T15:08:12","guid":{"rendered":"http:\/\/sites.law.duq.edu\/juris\/?p=13221"},"modified":"2021-04-05T17:21:28","modified_gmt":"2021-04-05T22:21:28","slug":"do-we-need-data-privacy","status":"publish","type":"post","link":"https:\/\/sites.law.duq.edu\/juris\/2021\/03\/29\/do-we-need-data-privacy\/","title":{"rendered":"Do We Need Data Privacy?"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-13222\" src=\"http:\/\/sites.law.duq.edu\/juris\/wp-content\/uploads\/2021\/03\/Pagana-Privacy.jpg\" alt=\"\" width=\"1000\" height=\"667\" \/><\/p>\n<p style=\"text-align: center;\">Photo provided courtesy by Unsplash.com.<br \/>\nBy Daniel Pagana, Staff Writer<\/p>\n<p>Many industries are subject to privacy laws.\u00a0 Often times, privacy law violations indicate potential criminal conduct because of the nature of certain sensitive information.\u00a0 For example, sensitive data held by the banking industry is subject to the Right to Financial Privacy Act, which \u201cprotects the confidentiality of personal financial records.\u201d<a href=\"#_ftn1\" name=\"_ftnref1\"><sup>[1]<\/sup><\/a>\u00a0 The Act is viewed as congressional backlash to the Supreme Court decision in <u>United States v. Miller<\/u>. \u00a0In that case, the Court held that individuals have no reasonable privacy expectations in banking records after voluntarily turning such sensitive information over to third parties such as financial institutions.<a href=\"#_ftn2\" name=\"_ftnref2\"><sup>[2]<\/sup><\/a>\u00a0 The Court has also weighed in, regarding sensitive information handled by other heavily regulated industries such as health care. In a string of decisions, the Supreme Court has protected individual privacy relating to contraceptives and abortion. In other instances, the Court has limited privacy interests in health related information like the use of controlled substances<a href=\"#_ftn3\" name=\"_ftnref3\"><sup>[3]<\/sup><\/a>\u00a0 And of course, Congress has regulated privacy for nearly all involved in healthcare through The Health Insurance Portability and Accountability Act or (\u201cHIPPA\u201d).<a href=\"#_ftn4\" name=\"_ftnref4\"><sup>[4]<\/sup><\/a>\u00a0 Healthcare and banking are two of the largest industries in the US, contributing trillions of dollars to the economy, so it is unsurprising to most that they are also two of the most regulated in terms of privacy.<a href=\"#_ftn5\" name=\"_ftnref5\"><sup>[5]<\/sup><\/a><\/p>\n<p>Privacy in the technology sector, specifically regarding data controlled by big tech, is the new heated debate in partisan politics,<a href=\"#_ftn6\" name=\"_ftnref6\"><sup>[6]<\/sup><\/a>\u00a0 It is also the area that has changed substantially over the past 20 years.<a href=\"#_ftn7\" name=\"_ftnref7\"><sup>[7]<\/sup><\/a>\u00a0 For example Google\u2019s privacy policy used to be only a paragraph long. That same policy is currently over 4,000 words long.<a href=\"#_ftn8\" name=\"_ftnref8\"><sup>[8]<\/sup><\/a>\u00a0 This is due to a change in how the company employs user data.\u00a0 Early on, the company considered use of such data only in the aggregate, but now google uses a much more sophisticated method of isolating user data.<a href=\"#_ftn9\" name=\"_ftnref9\"><sup>[9]<\/sup><\/a>\u00a0 Through a combination of gps data, user searches\u2014even data specific to a particular users\u2019 device\u2014google has become much better at selling its users to advertisers.<a href=\"#_ftn10\" name=\"_ftnref10\"><sup>[10]<\/sup><\/a><\/p>\n<p>The debate in Congress on how to regulate tech giants is currently at a standstill, with no real comprehensive legislation materializing.<a href=\"#_ftn11\" name=\"_ftnref11\"><sup>[11]<\/sup><\/a> While Congress has been flat footed on the issue, the courts have been active in regulating data privacy.\u00a0 The courts dismissed alleged wiretap act claims against Google for storing and listening to user audio data.<a href=\"#_ftn12\" name=\"_ftnref12\"><sup>[12]<\/sup><\/a> The courts have also decided that money gained by a company that shares user data is not the same as the plaintiff losing money. <a href=\"#_ftn13\" name=\"_ftnref13\"><sup>[13]<\/sup><\/a>These decisions are important but not comprehensive, both decisions rely on law that does not directly apply to user data.<\/p>\n<p>Many of these cases are being brought under the California Unfair Competition Law (\u201cUCL\u201d).<a href=\"#_ftn14\" name=\"_ftnref14\"><sup>[14]<\/sup><\/a>\u00a0 The UCL has been cited by plaintiffs broadly because the law \u201cprohibits business practices that are unlawful, unfair, or fraudulent.\u201d<a href=\"#_ftn15\" name=\"_ftnref15\"><sup>[15]<\/sup><\/a>\u00a0 However, lawsuits seeking protection from alleged data privacy violations under UCL have had little success since the law requires plaintiffs to allege money or property damages to have standing.<a href=\"#_ftn16\" name=\"_ftnref16\"><sup>[16]<\/sup><\/a>\u00a0 Plaintiffs thus far have not been able to convince the courts that user data constitutes either money or property.<\/p>\n<p>The European Union has passed a comprehensive data privacy program under the General Data Protection Regulation (\u201cGDPR\u201d).\u00a0 GDPR is a \u201cregulation that requires businesses to protect the personal data and privacy of EU citizens for transactions that occur within EU member states.\u201d<a href=\"#_ftn17\" name=\"_ftnref17\"><sup>[17]<\/sup><\/a>\u00a0The GDPR has provided a regulatory framework that big tech companies have been forced to acknowledge.<a href=\"#_ftn18\" name=\"_ftnref18\"><sup>[18]<\/sup><\/a>\u00a0 In <u>Facebook, Inc. Sec. Litig.<\/u>, executives claimed that Facebook was almost compliant with the data privacy restrictions that the GDPR was ready to enforce.<a href=\"#_ftn19\" name=\"_ftnref19\"><sup>[19]<\/sup><\/a>\u00a0 Facebooks made a number of claims most notably that they do not sell data to third parties and that the user owns what they post to Facebook and control how it is being shared.<a href=\"#_ftn20\" name=\"_ftnref20\"><sup>[20]<\/sup><\/a> In contrast, at the time of the GDRP rollout in the EU, Facebook was engaged in the Cambridge Analytica scandal in the US which was a blatant example of Facebook selling user data to third parties.<a href=\"#_ftn21\" name=\"_ftnref21\"><sup>[21]<\/sup><\/a><\/p>\n<p>Comprehensive legislation in the US has yet to come, but there have been efforts by states like California to get a data privacy bill done.\u00a0 The California Consumer Privacy Act (\u201cCCPA\u201d) is such a bill, and is modeled after the GDPR.<a href=\"#_ftn22\" name=\"_ftnref22\"><sup>[22]<\/sup><\/a> The CCPA requires that businesses disclose to Californians how their data is to be used.<a href=\"#_ftn23\" name=\"_ftnref23\"><sup>[23]<\/sup><\/a>\u00a0 It allows Californians to request that collected data be deleted and even \u201cgrants consumers the right to control selling their information to third parties via a \u2018Do Not Sell My Personal Information\u2019 link in their privacy policies.\u201d<a href=\"#_ftn24\" name=\"_ftnref24\"><sup>[24]<\/sup><\/a> The legislation does have its short comings. Most notably, the CCPA has been criticized as being far too broad.<a href=\"#_ftn25\" name=\"_ftnref25\"><sup>[25]<\/sup><\/a> It will be interesting to see how much of this legislation will be used by Congress, other states, or simply thrown out by the courts.<\/p>\n<h3><\/h3>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\">[1]<\/a>https:\/\/epic.org\/privacy\/rfpa\/#:~:text=The%20Right%20to%20Financial%20Privacy%20Act%20of%201978%20protects%20the,ruling%20in%20United%20States%20v.&amp;text=%C2%A7%203401%2D342.-,United%20States%20v.,425%20U.S.%20435%20(1976).<\/p>\n<p><a href=\"#_ftnref2\" name=\"_ftn2\">[2]<\/a> <u>United States v. Miller<\/u>, 425 U.S. 435, 96 S. Ct. 1619 (1976)<\/p>\n<p><a href=\"#_ftnref3\" name=\"_ftn3\">[3]<\/a> <u>Whalen v. Roe<\/u>, 429 U.S. 589, 97 S. Ct. 869 (1977)<\/p>\n<p><a href=\"#_ftnref4\" name=\"_ftn4\">[4]<\/a> https:\/\/www.hhs.gov\/hipaa\/for-individuals\/guidance-materials-for-consumers\/index.html<\/p>\n<p><a href=\"#_ftnref5\" name=\"_ftn5\">[5]<\/a> https:\/\/www.statista.com\/statistics\/247991\/value-added-to-the-us-gdp-by-industry\/<\/p>\n<p><a href=\"#_ftnref6\" name=\"_ftn6\">[6]<\/a> https:\/\/www.csoonline.com\/article\/3429608\/11-new-state-privacy-and-security-laws-explained-is-your-business-ready.html<\/p>\n<p><a href=\"#_ftnref7\" name=\"_ftn7\">[7]<\/a> https:\/\/www.nytimes.com\/interactive\/2019\/07\/10\/opinion\/google-privacy-policy.html?mtrref=www.google.com&amp;gwh=CC342D0A46F2C37D3BBFC548A2746984&amp;gwt=regi&amp;assetType=REGIWALL<\/p>\n<p><a href=\"#_ftnref8\" name=\"_ftn8\">[8]<\/a> <em>Id<\/em>.<\/p>\n<p><a href=\"#_ftnref9\" name=\"_ftn9\">[9]<\/a> <em>Id<\/em>.<\/p>\n<p><a href=\"#_ftnref10\" name=\"_ftn10\">[10]<\/a> <em>Id<\/em>.<\/p>\n<p><a href=\"#_ftnref11\" name=\"_ftn11\">[11]<\/a> <em>Id<\/em>.<\/p>\n<p><a href=\"#_ftnref12\" name=\"_ftn12\">[12]<\/a> I<u>n re Google Assistant Privacy Litig.<\/u>, 457 F. Supp. 3d 797 (N.D. Cal. 2020)<\/p>\n<p><a href=\"#_ftnref13\" name=\"_ftn13\">[13]<\/a> <u>In re Facebook, Inc.<\/u>, 402 F. Supp. 3d 767 (N.D. Cal. 2019)<\/p>\n<p><a href=\"#_ftnref14\" name=\"_ftn14\">[14]<\/a> https:\/\/www.csoonline.com\/article\/3429608\/11-new-state-privacy-and-security-laws-explained-is-your-business-ready.html<\/p>\n<p><a href=\"#_ftnref15\" name=\"_ftn15\">[15]<\/a> <u>In re Facebook, Inc.<\/u>, 402 F. Supp. 3d 767 (N.D. Cal. 2019)<\/p>\n<p><a href=\"#_ftnref16\" name=\"_ftn16\">[16]<\/a> <em>Id<\/em>.<\/p>\n<p><a href=\"#_ftnref17\" name=\"_ftn17\">[17]<\/a> https:\/\/www.csoonline.com\/article\/3202771\/general-data-protection-regulation-gdpr-requirements-deadlines-and-facts.html<\/p>\n<p><a href=\"#_ftnref18\" name=\"_ftn18\">[18]<\/a> <u>In re Facebook, Inc. Sec. Litig.<\/u>, 405 F. Supp. 3d 809 (N.D. Cal. 2019)<\/p>\n<p><a href=\"#_ftnref19\" name=\"_ftn19\">[19]<\/a> <em>Id<\/em>.<\/p>\n<p><a href=\"#_ftnref20\" name=\"_ftn20\">[20]<\/a> <em>Id<\/em>.<\/p>\n<p><a href=\"#_ftnref21\" name=\"_ftn21\">[21]<\/a> https:\/\/www.nytimes.com\/2018\/04\/04\/us\/politics\/cambridge-analytica-scandal-fallout.html<\/p>\n<p><a href=\"#_ftnref22\" name=\"_ftn22\">[22]<\/a> https:\/\/www.csoonline.com\/article\/3429608\/11-new-state-privacy-and-security-laws-explained-is-your-business-ready.html<\/p>\n<p><a href=\"#_ftnref23\" name=\"_ftn23\">[23]<\/a> <em>Id<\/em>.<\/p>\n<p><a href=\"#_ftnref24\" name=\"_ftn24\">[24]<\/a> <em>Id<\/em>.<\/p>\n<p><a href=\"#_ftnref25\" name=\"_ftn25\">[25]<\/a> https:\/\/abovethelaw.com\/2019\/10\/some-big-reasons-why-the-ccpa-is-more-of-a-problem-than-you-think\/<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Photo provided courtesy by Unsplash.com. By Daniel Pagana, Staff Writer Many industries are subject to privacy laws.\u00a0 Often times, privacy law violations indicate potential criminal conduct because of the nature of certain sensitive information.\u00a0 For example, sensitive data held by the banking industry is subject to the Right to Financial [\u2026] <\/p>\n<div class=\"clear\"><\/div>\n<p><a class=\"more_link clearfix\" href=\"https:\/\/sites.law.duq.edu\/juris\/2021\/03\/29\/do-we-need-data-privacy\/\" rel=\"nofollow\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":13222,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,8],"tags":[3279,80,48,3278,3280,477,57],"class_list":["post-13221","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-juris-blog","category-juris-issues","tag-california-consumer-privacy-act","tag-congress","tag-duquesne-law","tag-facebook-ccpa","tag-financial-privacy-act","tag-juris","tag-privacy"],"_links":{"self":[{"href":"https:\/\/sites.law.duq.edu\/juris\/wp-json\/wp\/v2\/posts\/13221","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sites.law.duq.edu\/juris\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.law.duq.edu\/juris\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.law.duq.edu\/juris\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.law.duq.edu\/juris\/wp-json\/wp\/v2\/comments?post=13221"}],"version-history":[{"count":4,"href":"https:\/\/sites.law.duq.edu\/juris\/wp-json\/wp\/v2\/posts\/13221\/revisions"}],"predecessor-version":[{"id":13226,"href":"https:\/\/sites.law.duq.edu\/juris\/wp-json\/wp\/v2\/posts\/13221\/revisions\/13226"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sites.law.duq.edu\/juris\/wp-json\/wp\/v2\/media\/13222"}],"wp:attachment":[{"href":"https:\/\/sites.law.duq.edu\/juris\/wp-json\/wp\/v2\/media?parent=13221"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.law.duq.edu\/juris\/wp-json\/wp\/v2\/categories?post=13221"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.law.duq.edu\/juris\/wp-json\/wp\/v2\/tags?post=13221"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}