﻿<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">

<channel>
<title>Law and Tech Research feed - Hoofnagle</title>
<description></description>
<link>http://law.berkeley.edu</link>
<lastBuildDate> 11:12:55 -0400 </lastBuildDate>
<pubDate> 09:00:00 -0400</pubDate>


<item>
<!--/14907.htm-->
    <title>Privacy and Advertising Mail</title>
    <description><![CDATA[
        &nbsp;In
        this paper, we consider why Americans may frame the generation and
        receipt of unsolicited advertising mail as a privacy violation. We then
        present data from our nationwide survey showing that a very large
        majority of Americans, across all ideologies, educational attainment
        levels, age, and income levels, support the creation of a do-not-mail
        mechanism similar to the popular Telemarketing Do Not Call Registry. We
        discuss our results in light of the fact that direct advertising mail
        now makes up more than half of all mailpieces sent by the United States
        Postal Service (USPS).  
    ]]></description>
    <link>http://www.law.berkeley.edu/14907.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/14907.htm</guid>
    <pubDate>Mon, 03 Dec 2012 09:00:00 -0400</pubDate>
</item>

<item>
<!--/14091.htm-->
    <title>Behavioral Advertising: The Offer You Cannot Refuse</title>
    <description><![CDATA[
        <span>At UC
        Berkeley, we are informing political debates surrounding online privacy
        through empirical study of website behaviors. In 2009 and 2011, we
        surveyed top websites to determine how they were tracking consumers. We
        found that advertisers were using persistent tracking technologies that
        were relatively unknown to consumers. Two years later, we found that the
        number of tracking cookies expanded dramatically and that advertisers
        had developed new, previously unobserved tracking mechanisms that users
        cannot avoid even with the strongest privacy settings.<br />
        <br />
        These
        empirical observations are valuable for the political debate surrounding
        online privacy because they inform the framing and assumptions
        surrounding the merits of privacy law.<br />
        <br />
        Our work demonstrates that
        advertisers use new, relatively unknown technologies to track people,
        specifically because consumers have not heard of these techniques.
        Furthermore, these technologies obviate choice mechanisms that consumers
        exercise.  We argue that the combination of disguised tracking
        technologies, choice-invalidating techniques, and models to trick the
        consumers into revealing data suggests that advertisers do not see
        individuals as autonomous beings. Once conceived of as objects,
        preferences no longer matter and can be routed around with tricks and
        technology.<br />
        <br />
        In the political debate, “paternalism” is a
        frequently invoked objection to privacy rules. Our work inverts the
        assumption that privacy interventions are paternalistic while market
        approaches promote freedom. We empirically demonstrate that advertisers
        are making it impossible to avoid online tracking. Advertisers are so
        invested in the idea of a personalized web that they do not think
        consumers are competent to decide to reject it. We argue that
        policymakers should fully appreciate the idea that consumer privacy
        interventions can enable choice, while the alternative, pure marketplace
        approaches can deny consumers opportunities to exercise autonomy. </span>
    ]]></description>
    <link>http://www.law.berkeley.edu/14091.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/14091.htm</guid>
    <pubDate>Tue, 28 Aug 2012 09:00:00 -0400</pubDate>
</item>

<item>
<!--/13759.htm-->
    <title>Mobile Phones and Privacy</title>
    <description><![CDATA[
        <span>Mobile phones are a rich source of personal information about individuals. Both private and public sector actors seek to collect this information. Facebook, among other companies, recently ignited a controversy by collecting contact lists from users’ mobile phones via its mobile app. A recent Congressional investigation found that law enforcement agencies sought access to wireless phone records over one million times in 2011. As these developments receive greater attention in the media, a public policy debate has started concerning the collection and use of information by private and public actors. <br />
        <br />
        To inform this debate and to better understand Americans’ attitudes towards privacy in data generated by or stored on mobile phones, we commissioned a nationwide, telephonic (both wireline and wireless) survey of 1,200 households focusing upon mobile privacy issues. <br />
        <br />
        We found that Americans overwhelmingly consider information stored on their mobile phones to be private — at least as private as information stored on their home computers. They also overwhelmingly reject several types of data collection and use drawn from current business practices. Specifically, large majorities reject the collection of contact lists stored on the phone for the purposes of tailoring social network “friend” suggestions and providing coupons, the collection of location data for tailoring ads, and the use of wireless contact information for telemarketing, even where there is a business relationship between the consumer and merchant. <br />
        <br />
        Respondents evinced strong support for substantial limitations on the retention of wireless phone usage data. Respondents also thought that some prior court oversight is appropriate when police seek to search a wireless phone when arresting an individual. </span>
    ]]></description>
    <link>http://www.law.berkeley.edu/13759.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/13759.htm</guid>
    <pubDate>Tue, 10 Jul 2012 09:00:00 -0400</pubDate>
</item>

<item>
<!--/13351.htm-->
    <title>Mobile Payments: Consumer Benefits &amp; New Privacy Concerns</title>
    <description><![CDATA[
        Payment systems that allow people to pay using their mobile phones are promised to reduce transaction fees, increase convenience, and enhance payment security. New mobile payment systems also are likely to make it easier for businesses to identify consumers, to collect more information about consumers, and to share more information about consumers’ purchases among more businesses. While many studies have reported security concerns as a barrier to adoption of mobile payment technologies, the privacy implications of these technologies have been under examined. To better understand Americans’ attitudes towards privacy in new transaction systems, we commissioned a nationwide, telephonic (wireline and wireless) survey of 1,200 households, focusing upon the ways that mobile payment systems are likely to share information about consumers’ purchases.<br />
        <br />
        We found that Americans overwhelmingly oppose the revelation of contact information (phone number, email address, and home address) to merchants when making purchases with mobile payment systems. Furthermore, an even higher level of opposition exists to systems that track consumers’ movements through their mobile phones.<br />
        <br />
        We explain some advantages of mobile payment systems, some challenges to their adoption in the United States, and then turn to our main finding: Americans overwhelming reject mobile payment systems that track their movements or share identification information with retailers. We then suggest a possible remedy for such information sharing: adapting provisions of California’s Song-Beverly Credit Card Act, which prohibits merchants from requesting personal information at the register when a consumer pays with a credit card, to mobile payments systems. Our survey results suggest that consumers would support limitations on information collection and transfer. Song-Beverly could be adopted to accommodate those who wish to share their transaction data. <br />
        
    ]]></description>
    <link>http://www.law.berkeley.edu/13351.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/13351.htm</guid>
    <pubDate>Tue, 24 Apr 2012 09:00:00 -0400</pubDate>
</item>

<item>
<!--/11598.htm-->
    <title>Flash Cookies and Privacy II: Now with HTML5 and ETag Respawning</title>
    <description><![CDATA[
        In August 2009, we demonstrated that popular websites were using “Flash cookies” to track users. Some advertisers had adopted this technology because it allowed persistent tracking even where users had taken steps to avoid web profiling. We also demonstrated “respawning” on top sites with Flash technology. This allowed sites to reinstantiate HTTP cookies deleted by a user, making tracking more resistant to users’ privacy-seeking behaviors.<br />
        <br />
        In this followup study, we reassess the Flash cookies landscape and examine a new tracking vector, HTML5 local storage and Cache-Cookies via ETags. <br />
        <br />
        We found over 5,600 standard HTTP cookies on popular sites, over 4,900 were from third parties. Google-controlled cookies were present on 97 of the top 100 sites, including popular government websites. Seventeen sites were using HTML5, and seven of those sites had HTML5 local storage and HTTP cookies with matching values. <br />
        <br />
        Flash cookies were present on 37 of the top 100 sites. We found two sites that were respawning cookies, including one site – hulu.com – where both Flash and cache cookies were employed to make identifiers more persistent. The cache cookie method used ETags, and is capable of unique tracking even where all cookies are blocked by the user and “Private Browsing Mode” is enabled.<br />
        <br />
        Our 2009 study is also available at SSRN: http://ssrn.com/abstract=1446862. 
    ]]></description>
    <link>http://www.law.berkeley.edu/11598.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/11598.htm</guid>
    <pubDate>Sat, 30 Jul 2011 09:00:00 -0400</pubDate>
</item>

<item>
<!--/9996.htm-->
    <title>Internalizing Identity Theft</title>
    <description><![CDATA[Why has identity theft remained so prevalent, in light of the development of ever more sophisticated fraud detection tools? Identity theft remains at 2003 levels – 9.9 million Americans fell victim to the crime in 2009.
<P>One faction explains the identity theft as a problem of a lack of control over personal information. Another argues conversely that identity theft may be caused by a lack of access to personal information by credit grantors. This article presents data from a small sample of identity theft victims to explore a different dimension of the crime, one that suggests alternative interventions.</P>
<P>Drawing upon victim and impostor data now accessible because of updates to the Fair Credit Reporting Act, the data show that identity theft impostors supply obviously erroneous information on applications that is accepted as valid by credit grantors. Thus, the problem does not necessarily lie in control nor in more availability of personal information, but rather in the risk tolerances of credit grantors. An analysis of incentives in credit granting elucidates the problem: identity theft remains so prevalent because it is less costly to tolerate fraud. Adopting more aggressive and expensive anti-fraud measures is extremely costly and jeopardizes customer acquisition efforts.</P>
<P>These business decisions leave individuals and merchants with some of the externalities of identity theft. Victims sometimes spend their own money, and more often, valuable personal time dealing with identity theft externalities. This article concludes by reviewing several approaches to internalizing these costs. Popular approaches specify prescriptive rules to address particularly problematic practices in credit granting, such as using the Social Security number as a password for authentication. These approaches may lead to compliance-oriented approaches and reification. Several commentators have suggested negligence actions as a cure to identity theft, but uncertainty surrounding the duty of care would probably leave many consumers unremunerated. A strict liability regime is suggested because credit grantors are the least cost avoiders in the identity theft context, and because consumers cannot control the credit granting process nor insure against identity theft losses efficiently. </P>
<P><EM>UCLA Journal of Law and Technology</EM>, p. 1, 2010 </P>]]></description>
    <link>http://www.law.berkeley.edu/9996.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/9996.htm</guid>
    <pubDate>Wed, 15 Dec 2010 09:00:00 -0400</pubDate>
</item>

<item>
<!--/9993.htm-->
    <title>New Challenges to Data Protection Study - Country Report: United States</title>
    <description><![CDATA[This report is one of 11 country reports produced for the "New Challenges to Data Protection" study, commissioned by the European Commission, and describes the ways in which US law addresses the challenges posed by the new social-technical-political environment.
<P>The hallmark of the US federal approach to privacy is sectoral regulation. A panoply of statutes now regulates specific types of government and business practices, with no broadly-applicable privacy statute governing data collection, use, or disclosure. The Federal Trade Commission has encouraged self-regulation in a number of sectors, and the development of privacy-enhancing technologies. The US approach to privacy is incoherent, sectorally-based, and largely driven by outrage at particular, narrow practices. Still, several innovations from the US approach deserve attention internationally.</P>
<P>First, increasingly, privacy statutes create evolving standards of care, thus encouraging innovation for handling of data and avoiding the reification that can result from prescriptive, detailed regulation. For instance, the Fair Credit Reporting Act mandates an evolving “maximum possible accuracy” standard.</P>
<P>Second, in the direct marketing context, the US has imposed advertiser liability for violations of telemarketing, fax, and spam laws. This is a promising approach to address the use of difficult-to-identify and prosecute service providers that are responsible for illegal marketing campaigns.</P>
<P>Third, audit requirements for access to personal information has had a profound effect in encouraging industry and citizen policing of privacy violations. Audit logs have substantiated long-suspected privacy problems regarding “browsing” of files, and news media access to celebrities’ medical records.</P>
<P>Fourth, the US has briefly experimented with “data provenance,” a requirement that buyers of personal information exercise diligence to ensure against misuse of data. Data provenance responsibilities can create incentives to reduce gray and black market sales of personal information.</P>
<P>Finally, most federal privacy law acts as a floor of protections, allowing states to enact stronger rules. This has created a tension between state and federal governments, resulting in a leveling up of protections, because states (which tend to be more activist on privacy issues) can act where the US Congress is occupied with other issues.</P>
<P>NB: The final report, an executive summary of the final report, both by Douwe Korff and Ian Brown (et al), and one of two working papers, as well as two further country reports (on France and Germany) and a Comparative Chart, all by Douwe Korff, all also produced for the Comparative Study of Different Approaches to New Privacy Challenges in Particular in the Light of Technological Developments, can be found on SSRN. </P>]]></description>
    <link>http://www.law.berkeley.edu/9993.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/9993.htm</guid>
    <pubDate>Wed, 14 Jul 2010 09:00:00 -0400</pubDate>
</item>

<item>
<!--/9994.htm-->
    <title>How Different are Young Adults from Older Adults When it Comes to Information Privacy Attitudes and Policies? </title>
    <description><![CDATA[Study by:
<P><STRONG>Chris Jay Hoofnagle<BR></STRONG>University of California, Berkeley - School of Law, Berkeley Center for Law &amp; Technology</P>
<P><STRONG>Jennifer King<BR></STRONG>UC Berkeley School of Information; Berkeley Center for Law &amp; Technology</P>
<P><STRONG>Su Li<BR></STRONG>University of California, Berkeley- School of Law, Center for the Study of Law and Society</P>
<P><STRONG>Joseph Turow<BR></STRONG>University of Pennsylvania - Annenberg School for Communication<BR></P>
<P>Media reports teem with stories of young people posting salacious photos online, writing about alcohol-fueled misdeeds on social networking sites, and publicizing other ill-considered escapades that may haunt them in the future. These anecdotes are interpreted as representing a generation-wide shift in attitude toward information privacy. Many commentators therefore claim that young people “are less concerned with maintaining privacy than older people are.” Surprisingly, though, few empirical investigations have explored the privacy attitudes of young adults. This report is among the first quantitative studies evaluating young adults’ attitudes. It demonstrates that the picture is more nuanced than portrayed in the popular media.</P>
<P>In this telephonic (wireline and wireless) survey of internet using Americans (N=1000), we found that large percentages of young adults (those 18-24 years) are in harmony with older Americans regarding concerns about online privacy, norms, and policy suggestions. In several cases, there are no statistically significant differences between young adults and older age categories on these topics. Where there were differences, over half of the young adult-respondents did answer in the direction of older adults. There clearly is social significance in that large numbers of young adults agree with older Americans on issues of information privacy.</P>
<P>A gap in privacy knowledge provides one explanation for the apparent license with which the young behave online. 42 percent of young Americans answered all of our five online privacy questions incorrectly. 88 percent answered only two or fewer correctly. The problem is even more pronounced when presented with offline privacy issues – post hoc analysis showed that young Americans were more likely to answer no questions correctly than any other age group.</P>
<P>We conclude then that that young-adult Americans have an aspiration for increased privacy even while they participate in an online reality that is optimized to increase their revelation of personal data. </P>]]></description>
    <link>http://www.law.berkeley.edu/9994.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/9994.htm</guid>
    <pubDate>Sat, 17 Apr 2010 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10131.htm-->
    <title>Beyond Google and Evil: How Policy Makers, Journalists and Consumers Should Talk Differently About Google and Privacy </title>
    <description><![CDATA[Google has come to symbolize the tensions between the benefits of innovative, information-dependent new services and the desire of individuals to control the contexts in which personal information is used. This essay reviews hundreds of newspaper articles where Google speaks about privacy in an effort to characterize the company’s handling of these tensions, to provide context explaining the meaning of the company’s privacy rhetoric, and to advance the privacy dialogue among policy makers, journalists, and consumers.
<P>The dialogue surrounding these tensions is unfocused because many policy makers, journalists, and consumers concentrate the debate on whether the company violates its “you can make money without doing evil” corporate motto. This first observation flows to a second: Google’s conception of “evil” is tied to the revolution the company brought about in advertising practices, practices that many think are mainstream now. Google is thus missing opportunities to remind the public that its advertising policies have several strong pro-consumer aspects, many of which are lost when “evil talk” is employed. Third, vague privacy rhetoric signals a weak commitment to technical or legal safeguards. Journalists are well suited to remedy this by exercising greater inquiry and skepticism in contexts where Google’s privacy representations are non-substantive. Finally, Google heavily relies upon appeals to competition, arguing that those who adopt the company’s services engage in meaningful tradeoffs. Quietly shifting practices, lock in, and lengthy data retention periods, however, mean that these tradeoffs must be continually reevaluated. Google should give voice to its competition and tradeoff rhetoric by creating data portability and deletion rights for consumers. </P>]]></description>
    <link>http://www.law.berkeley.edu/10131.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10131.htm</guid>
    <pubDate>Tue, 16 Mar 2010 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10134.htm-->
    <title>Towards a Market for Bank Safety </title>
    <description><![CDATA[Imagine shopping for a car in 1960. Safety is important to you. How do you assess a car's performance in surviving a crash? What tools were available then to take an informed decision?
<P>The modern consumer of financial services is in a similar position as the car shopper of the 1960s. How does the modern consumer choose a bank that is relatively safe from identity thieves and other malicious individuals? Perhaps she chooses the larger institution, because it has more resources to address fraud. Or perhaps a smaller institution offers more protection, because it is more obscure. There is no way to know for sure, and thus, consumers cannot make an informed decision.</P>
<P>This article attempts to actuate a market for bank safety by comparing identity theft victim data with government statistics used to measure the relative size of financial institutions. It envisions a future when this market incentivizes financial services firms to explicitly compete to reduce the likelihood that customers will become victims of identity theft or other frauds. In a world of competition in bank safety, consumers who put a premium on avoiding fraud could reward the most proficient firms with their loyalty.</P>
<P>This article concludes that the available data, while weakened by several methodological concerns, do show that certain banks, large and small, have different identity theft footprints. Other discoveries were made as well. First, if present trends continue, there will be a substantial upswing in identity theft complaints to the Federal Trade Commission in 2008. Second, over a three-year period, a small group of companies accounted for almost 50 percent of identity theft incidents. Focusing interventions on this small group of companies could have a profound effect on incidence of identity theft. Finally, non-banking institutions, such as telecommunications companies, have an enormous identity theft footprint; in our highly dependent credit markets, impostors may be using these companies as stepping stones for attacks against banks. </P>]]></description>
    <link>http://www.law.berkeley.edu/10134.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10134.htm</guid>
    <pubDate>Tue, 05 Jan 2010 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10043.htm-->
    <title>Americans Reject Tailored Advertising and Three Activities that Enable It </title>
    <description><![CDATA[This nationally representative telephone (wire-line and cell phone) survey explores Americans' opinions about behavioral targeting by marketers, a controversial issue currently before government policymakers. Behavioral targeting involves two types of activities: following users' actions and then tailoring advertisements for the users based on those actions. While privacy advocates have lambasted behavioral targeting for tracking and labeling people in ways they do not know or understand, marketers have defended the practice by insisting it gives Americans what they want: advertisements and other forms of content that are as relevant to their lives as possible.
<P>Contrary to what many marketers claim, most adult Americans (66%) do not want marketers to tailor advertisements to their interests. Moreover, when Americans are informed of three common ways that marketers gather data about people in order to tailor ads, even higher percentages - between 73% and 86% - say they would not want such advertising. Even among young adults, whom advertisers often portray as caring little about information privacy, more than half (55%) of 18-24 years-old do not want tailored advertising. And contrary to consistent assertions of marketers, young adults have as strong an aversion to being followed across websites and offline (for example, in stores) as do older adults.</P>
<P>This survey finds that Americans want openness with marketers. If marketers want to continue to use various forms of behavioral targeting in their interactions with Americans, they must work with policymakers to open up the process so that individuals can learn exactly how their information is being collected and used, and then exercise control over their data. We offer specific proposals in this direction. An overarching one is for marketers to implement a regime of information respect toward the public rather than to treat them as objects from which they can take information in order to optimally persuade them. </P>]]></description>
    <link>http://www.law.berkeley.edu/10043.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10043.htm</guid>
    <pubDate>Tue, 29 Sep 2009 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10044.htm-->
    <title>Exploring Information Sharing through California’s 'Shine the Light' Law </title>
    <description><![CDATA[Consumers have a dim understanding of how companies share personal information. To "shine a light" on information sharing practices, the authors employed a unique California law to survey the information sharing practices of 112 businesses. This follow-on study to a similar, smaller survey in 2007, found that four years after the law took effect, compliance is uneven. Fifty-three companies did not respond to the request at all. Only six companies disclosed how they shared information with third parties for their direct marketing purposes. Thirty-nine companies informed us that they do not share information, 5 provided an opt-out option for third party sharing, and 9 responses were categorized as "other." ]]></description>
    <link>http://www.law.berkeley.edu/10044.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10044.htm</guid>
    <pubDate>Sun, 16 Aug 2009 09:00:00 -0400</pubDate>
</item>

<item>
<!--/12844.htm-->
    <title>An Economic Map of Cybercrime</title>
    <description><![CDATA[The rise of cybercrime in the last decade is an economic case of individuals responding to monetary and psychological incentives. Two main drivers for cybercrime can be identified: the potential gains from cyberattacks are increasing with the growth of importance of the Internet, and malefactors' expected costs (e.g., the penalties and the likelihood of being apprehended and prosecuted) are frequently lower compared with traditional crimes. In short, computer-mediated crimes are more convenient, and protable, and less expensive and risky than crimes not mediated by the Internet. The increase in cybercriminal activities, coupled with ineffective legislation and ineffective law enforcement pose critical challenges for maintaining the trust and security of our<BR>computer infrastructures.<BR><BR>Modern computer attacks encompass a broad spectrum of economic activity, where various malfeasants specialize in developing specific goods (exploits, botnets, mailers) and services (distributing malware, monetizing stolen credentials, providing web hosting, etc.). A typical Internet fraud involves the actions of many of these individuals, such as malware writers, botnet herders, spammers, data brokers, and money launderers.<BR><BR>Assessing the relationships among various malfeasants is an essential piece of information for discussing economic, technical, and legal proposals to address cybercrime. This paper presents a framework for understanding the interactions between these individuals and how they operate. We follow three steps.<BR><BR>First, we present the general architecture of common computer attacks, and discuss the flow of goods and services that supports the underground economy. We discuss the general flow of resources between criminal groups and victims, and the interactions between different specialized cybercriminals.<BR><BR>Second, we describe the need to estimate the social costs of cybercrime and the profits of cybercriminals in order to identify optimal levels of protection. One of the main problems in quantifying the precise impact of cybercrime is that computer attacks are not always detected, or reported. Therefore we propose the need to develop a more systematic and transparent way of reporting computer breaches and their effects.<BR><BR>Finally, we propose some possible countermeasures against criminal activities. In particular, we analyze the role private and public protection, and the incentives of multiple stake holders. ]]></description>
    <link>http://www.law.berkeley.edu/12844.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/12844.htm</guid>
    <pubDate>Sat, 15 Aug 2009 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10109.htm-->
    <title>Flash Cookies and Privacy</title>
    <description><![CDATA[This is a pilot study of the use of 'Flash cookies' by popular websites. We find that more than 50% of the sites in our sample are using flash cookies to store information about the user. Some are using it to 'respawn' or re-instantiate HTTP cookies deleted by the user. Flash cookies often share the same values as HTTP cookies, and are even used on government websites to assign unique values to users. Privacy policies rarely disclose the presence of Flash cookies, and user controls for effectuating privacy preferences are lacking. ]]></description>
    <link>http://www.law.berkeley.edu/10109.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10109.htm</guid>
    <pubDate>Tue, 11 Aug 2009 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10120.htm-->
    <title>What Californians Understand about Privacy Online </title>
    <description><![CDATA[The volume of online commerce grows every year, in absence of a federal law setting baseline protections for the collection, use, and disclosure of personal information. Instead, information collected by websites are governed by individual privacy policies.
<P>In order to gauge Californians' understanding of privacy policies and default rules in the online environment, we commissioned a representative survey of adults in the State (N=991). The telephonic survey of Spanish and English speakers was conducted by the Survey Research Center of University of California, Berkeley.</P>
<P>A gulf exists between California consumers' understanding of online rules and common business practices. For instance, Californians who shop online believe that privacy policies prohibit third-party information sharing. A majority of Californians believes that privacy policies create the right to require a website to delete personal information upon request, a general right to sue for damages, a right to be informed of security breaches, a right to assistance if identity theft occurs, and a right to access and correct data.</P>
<P>These findings show that California consumers overvalue the mere fact that a website has a privacy policy, and assume that websites carrying the label have strong, default rules to protect personal data. In a way, consumers interpret "privacy policy" as a quality seal that denotes adherence to some set of standards. Website operators have little incentive to correct this misperception, thus limiting the ability of the market to produce outcomes consistent with consumers' expectations. Drawing upon earlier work, we conclude that because the term "privacy policy" has taken on a specific meaning in the minds of consumers, its use should be limited to contexts where businesses provide a set of protections that meet consumers' expectations. </P>]]></description>
    <link>http://www.law.berkeley.edu/10120.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10120.htm</guid>
    <pubDate>Wed, 03 Sep 2008 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10124.htm-->
    <title>Measuring Identity Theft (Version 2.0) </title>
    <description><![CDATA[There is no reliable way for consumers, regulators, and businesses to assess the relative rates of identity fraud at major financial institutions. This lack of information prevents a consumer market for bank safety from emerging. As part of a multiple strategy approach to obtaining more actionable data on identity theft, the Freedom of Information Act was used to obtain complaint data submitted by victims in 2006 and 2007 to the Federal Trade Commission. This complaint data identifies the institution where impostors established fraudulent accounts or affected existing accounts in the name of the victim. The data were aggregated and used to create comparative fraud ranks at leading banks.
<P>This analysis faces several challenges that are described in the methods section. This version incorporates and is substantially improved by comments provided on versions 1.0 and 1.5 of this report, incorporates new data from 2007, and shifts focus from identity theft at top banks to events at all types of companies.</P>
<P>In 2007, fraud events where the victim could identify the institution associated with the incident, were concentrated among a relatively small number of companies. Just ten companies accounted for 30% of events. Verizon was identified by victims more than any other company as being targeted by impostors to commit fraud. AFNI, a collections agency, was next in total number of events. Bank of America improved dramatically over its 2006 numbers, while ING Bank and American Express remained top performers among large institutions. </P>]]></description>
    <link>http://www.law.berkeley.edu/10124.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10124.htm</guid>
    <pubDate>Mon, 30 Jun 2008 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10123.htm-->
    <title>Consumer Information Sharing: Where the Sun Still Don't Shine </title>
    <description><![CDATA[In late 2007, the popular social networking site Facebook.com adopted "Beacon," an application that informs Facebook users' friends about purchases made and activities on other websites. For example, if a Facebook user bought a movie ticket on Fandango.com, that user's friends would be informed of that fact through a news "feed" on Facebook. Some users objected vigorously to the Beacon application, because their activities were reported on an opt-out basis, meaning that the user had to take affirmative action to prevent others from learning about their activities. An activism website, Moveon.org, organized a protest, calling users to action by asking, "When you buy a book or movie online - do you want that information automatically shared with the world on Facebook?" Facebook responded to these critiques by changing its policy to obtain express approval before activities on other sites would be shared with friends.
<P>The Facebook folly demonstrates how intensely consumers reject the "sharing" of personal information for marketing purposes. In this instance, consumers learned of Facebook's strategy because it was transparent and obvious to the individual. But what most do not realize is that, in the absence of a specific law prohibiting information sharing, businesses are generally free to monetize their customer databases by selling, renting, or trading them to others. In fact, the sale of customer information is a common, albeit opaque practice that, if disclosed at all, is usually mentioned in a "privacy policy." Facebook's Beacon simply made information sharing obvious to users.</P>
<P>Studies have shown that most consumers oppose the sale of personal information. Unfortunately, most consumers are under the misimpression that a company with a "privacy policy" is barred from selling data. To learn more about information selling, the authors, using a California privacy law, made requests to 86 companies for a disclosure of information sharing practices. The results show that while many companies have voluntarily adopted a policy of not sharing personal information with third parties, many still operate under an opt-out model that is inconsistent with consumer expectations, and others simply did not respond to the request. Based on these results, the authors propose several public policy approaches to bringing business practices in information sharing in line with consumer expectations. </P>]]></description>
    <link>http://www.law.berkeley.edu/10123.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10123.htm</guid>
    <pubDate>Tue, 27 May 2008 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10129.htm-->
    <title>A Supermajority of Californians Supports Limits on Law Enforcement Access to Cell Phone Location Information </title>
    <description><![CDATA[While law enforcement increasingly locates individuals by gaining access to wireless phone records, a supermajority of Californians supports judicial intervention and informing suspects before law enforcement acquires retrospective (historical) location data on individuals from wireless phone companies. A majority of Californians understands that wireless phones can track their location, and that there is broad support for location tracking in emergency situations. When compared with Professor Alan Westin's three privacy segments, "Fundamentalists," "Pragmatists," and the "Unconcerned," Californians are more likely to be privacy pragmatists or fundamentalists, and less likely to be unconcerned about privacy. Generally, Westin's segmentation was not predictive of Californians' attitudes towards law enforcement access to wireless location data. ]]></description>
    <link>http://www.law.berkeley.edu/10129.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10129.htm</guid>
    <pubDate>Tue, 27 May 2008 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10122.htm-->
    <title>Research Report: What Californians Understand About Privacy Offline </title>
    <description><![CDATA[Many online privacy problems are rooted in the offline world, where businesses are free to sell consumers' personal information unless they voluntarily agree not to or where a specific law prohibits the practice. In order to gauge Californians' understanding of business practices with respect to the selling of customer data, we asked a representative sample of Californians about the default rules for protecting personal information in nine contexts. In six of those contexts (pizza delivery, donations to charities, product warranties, product rebates, phone numbers collected at the register, and catalog sales), a majority either didn't know or falsely believed that opt-in rules protected their personal information from being sold to others. In one context - grocery store club cards - a majority did not know or thought information could be sold when California law prohibited the sale. Only in two contexts - newspaper and magazine subscriptions and sweepstakes competitions - did our sample of Californians understand that personal information collected by a company could be sold to others.
<P>Respondents who shopped online were less likely to say that they didn't know the answer to the nine questions asked than those who never shopped online. In about half of the cases, those who shopped online answered correctly more often than those who do not shop online.</P>
<P>Professor Alan Westin has pioneered a popular "segmentation" to describe Americans as fitting into one of three subgroups concerning privacy: privacy "fundamentalists" (high concern for privacy), "pragmatists" (mid-level concern), and the "unconcerned" (low or no privacy concern). When compared with these segments, Californians are more likely to be privacy pragmatists or fundamentalists, and less likely to be unconcerned about privacy. Fundamentalists were much more likely to be correct in their views of privacy rules. In light of this finding, we question Westin's conclusion that privacy pragmatists are well served by self-regulatory and opt-out approaches, as we found this subgroup of consumers is likely to misunderstand default rules in the marketplace. </P>]]></description>
    <link>http://www.law.berkeley.edu/10122.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10122.htm</guid>
    <pubDate>Thu, 15 May 2008 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10116.htm-->
    <title>Identity Theft: Making the Known Unknowns Known </title>
    <description><![CDATA[There is widespread agreement that identity theft causes financial damage to consumers, lending institutions, retail establishments, and the economy as a whole. Surprisingly, there is little good public information available about the scope of the crime and the actual damages it inflicts. The publicly available data on identity theft come mainly from survey research. Methodologically, these survey polls of the public suffer from being both under and over-inclusive in measuring the problem. As a result, low estimates attribute tens of billions of dollars in costs to the economy and consumers, the highest estimates place losses in the hundreds of billions.
<P>To identify proper interventions and appropriately allocate resources we need comprehensive, hard data on the scope and effect of identity theft. One way to provide concrete data is to require lending institutions to publicly report figures on identity theft. Such public reporting will help identify the relative need for intervention and the likely efficacy of interventions. These disclosures are necessary to provide a sound baseline for investment by businesses and action by regulators. They are also warranted because the public pays the price of identity theft directly when they are the victim, and indirectly through higher fees, interest rates, and because the losses are tax subsidized.</P>
<P>The author hypothesizes that if lending institutions reported limited information about identity theft, it would reveal that identity theft is both more prevalent and economically damaging than currently acknowledged, in part because of the rise of synthetic identity theft, a form that cannot be measured by victim surveys because they are unaware of the crime. Furthermore, the disclosure requirement would birth an anti-identity theft market, and the prevalence and severity of the crime would decrease dramatically as institutions compete to offer the safest financial products to consumers. </P>]]></description>
    <link>http://www.law.berkeley.edu/10116.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10116.htm</guid>
    <pubDate>Fri, 09 May 2008 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10118.htm-->
    <title>Big Brother's Little Helpers: How Choicepoint and Other Commercial Data Brokers Collect, Process, and Package Your Data for Law Enforcement </title>
    <description><![CDATA[The shift to a digital information environment has brought many changes to law enforcement access to personal data. Now, by visiting a single website, such as <A href="http://www.cpgov.com">www.cpgov.com</A>, law enforcement can obtain a comprehensive dossier on almost any adult. That website was custom-tailored for law enforcement by ChoicePoint, Inc., a commercial data broker (CDB).
<P>CDBs make available a wide variety of personal information, from arrest and court records to notice that a suspect has opened a private mailbox. Access to private sector databases has significantly altered the balance of power between law enforcement and the individual. This new power has been made possible by the confluence of fast network connections; the availability of public records, both electronic and paper, that are rich with personal information; a regulatory environment that has turned a blind eye to private sector collection of personal information for marketing and other purposes; and the alacrity of companies that have become very profitable from selling personal data to the government.</P>
<P>This article summarizes the findings of three years of research into the relationship between CDBs and the federal government. The federal Freedom of Information Act was employed to obtain over 1,500 documents from nine federal agencies concerning ChoicePoint and other CDBs. Findings are presented from the requests, and concerns are raised regarding law enforcement access to personal information.</P>
<P>The documents led to six major findings. First, the documents show that law enforcement can quickly obtain a broad array of personal information about individuals. Second, although broad requests for documents were filed, there was almost no evidence of controls to prevent agency employees from misusing the databases. It appears as though auditing employee use of the databases is either impossible or simply not done. Third, the database companies are extremely solicitous to the government and actually design the databases for law enforcement use. Fourth, ChoicePoint expanded significantly in 2000 by starting to acquire and sell personal information of non-citizens. That discovery has led to strong international dissent. Fifth, many of the contracts with CDBs are sole-sourced, meaning the contracts are not open to competitive bidding. Sixth, the FBI has a secret, sole-source contract with ChoicePoint to develop an information service prototype.</P>
<P>Based on these documents, the author concludes that the Privacy Act should apply to CDBs. The Privacy Act of 1974 establishes a comprehensive set of Fair Information Practices for government collection of personal information, but does not substantially affect the data practices of these private companies. Because of this lack of coverage, government entities have performed an end-run around the protections of the Privacy Act by allowing the private sector to amass troves of personal information that the government would ordinarily not be allowed to collect. Essentially, commercial data brokers are big brother's little helpers - private sector companies that have escrowed personal information that is customized for law enforcement and other government agencies.</P>
<P>The author also concludes that public policy makers should not draw distinctions between commercial and government collection of personal information. Libertarians and conservatives have employed persuasive arguments to stave off privacy regulation that affects the commercial sector. They have argued that government collection, use, and disclosure of information presents more risk than commercial collection because the government has the power to arrest, imprison, and even to execute citizens. But this article shows that this distinction between the risks of government and commercial privacy risk is no longer tenable. Commercial actors provide personal information to the government in a number of contexts, and often with astonishing alacrity.</P>
<P>Finally, policymakers should revisit policies surrounding access to public records. Much of the personal information made available to law enforcement originates from public records. In a variety of contexts, the government compels individuals to reveal their personal information, and then pours it into the public record for anyone to use for any purpose. The private sector has collected the information, repackaged it, and brought it back to the government full circle. While public records are supposed to provide a window for a citizen to check abusive government activities, increasingly, they are used to leverage more control for powerful institutions against the common man. </P>]]></description>
    <link>http://www.law.berkeley.edu/10118.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10118.htm</guid>
    <pubDate>Fri, 09 May 2008 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10119.htm-->
    <title>Privacy Self Regulation: A Decade of Disappointment </title>
    <description><![CDATA[The Federal Trade Commission's Do-Not-Call Registry, a government-created protection for privacy, is a stellar success. With over 80 million numbers enrolled, Americans now have a easy to use and effective shield against telemarketing. The government's creation quickly superceded and made irrelevant self-regulatory solutions, which were difficult to use, did not apply to all telemarketers, and were unenforceable.
<P>This article argues that, like self-regulatory solutions to the 20th century problem of telemarketing, market approaches to protecting consumers from 21st century problems have failed. The FTC embraced self-regulation to protect privacy on the Internet in 1995. That decision stalled Congress and anesthetized the public, as privacy practices worsened for a decade. Self-regulation has allowed the development of new tracking technologies, and the continued employment of old ones. Self-regulation allows companies to obfuscate their practices, leaving consumers in the dark. Emerging technologies represent serious threats to privacy and are not addressed by self-regulation or law. Self regulation has failed to produce usable anonymous payment mechanisms. We now know (as a result of California consumer protection regulation) that self-regulation failed to address security.</P>
<P>And finally, the worst identification and tracking policies from the online world are finding their way into the offline world. In other words, online self-regulatory approaches have encouraged a more invasive web environment, and have dragged down the practices of ordinary, offline retailers. This paper argues that the FTC and Congress should reevaluate their commitment to market approaches, and empower consumers with privacy law that incorporates Fair Information Practices. </P>]]></description>
    <link>http://www.law.berkeley.edu/10119.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10119.htm</guid>
    <pubDate>Fri, 09 May 2008 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10127.htm-->
    <title>Measuring Identity Theft at Top Banks (Version 1.5) </title>
    <description><![CDATA[There is no reliable way for consumers, regulators, and businesses to assess the relative rates of identity fraud at major financial institutions. This lack of information prevents a consumer market for bank safety from emerging. As part of a multiple strategy approach to obtaining more actionable data on identity theft, the Freedom of Information Act was used to obtain complaint data submitted by victims in 2006 to the Federal Trade Commission. This complaint data identifies the institution where impostors established fraudulent accounts or affected existing accounts in the name of the victim. The data were aggregated and used to create comparative fraud ranks at leading banks. This analysis faces several challenges that are described in the methods section. This version incorporates and is substantially improved by comments provided on version 1.0, released in February 2008 and downloaded over 7,000 times.
<P>Unlike version 1.0, this version provides actionable information to consumers on relative rates of identity theft in 2006. According to the measures in this report, American Express, USAA, and Citibank have the lowest rate of identity theft events among top credit card issuers. Among consumer banks, ING Bank and World Savings Bank performed well under every measure. Correlations were calculated for all the statistics the Federal Deposit Insurance Corporation maintains on top banks; generally the number of identity theft events correlates most strongly with measures of institutions size. </P>]]></description>
    <link>http://www.law.berkeley.edu/10127.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10127.htm</guid>
    <pubDate>Thu, 08 May 2008 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10112.htm-->
    <title>A Model Regime of Privacy Protection (Version 3.0) </title>
    <description><![CDATA[A series of major security breaches at companies with sensitive personal information has sparked significant attention to the problems with privacy protection in the United States. Currently, the privacy protections in the United States are riddled with gaps and weak spots. Although most industrialized nations have comprehensive data protection laws, the United States has maintained a sectoral approach where certain industries are covered and others are not. In particular, emerging companies known as "commercial data brokers" have frequently slipped through the cracks of U.S. privacy law. In this article, the authors propose a Model Privacy Regime to address the problems in the privacy protection in the United States, with a particular focus on commercial data brokers. Since the United States is unlikely to shift radically from its sectoral approach to a comprehensive data protection regime, the Model Regime aims to patch up the holes in existing privacy regulation and improve and extend it. In other words, the goal of the Model Regime is to build upon the existing foundation of U.S. privacy law, not to propose an alternative foundation. The authors believe that the sectoral approach in the United States can be improved by applying the Fair Information Practices - principles that require the entities that collect personal data to extend certain rights to data subjects. The Fair Information Practices are very general principles, and they are often spoken about in a rather abstract manner. In contrast, the Model Regime demonstrates specific ways that they can be incorporated into privacy regulation in the United States.
<P>This is the final version of this paper (Version 3.0), earlier versions of which are also available on SSRN. This version of the paper is published in the Illinois Law Review. </P>]]></description>
    <link>http://www.law.berkeley.edu/10112.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10112.htm</guid>
    <pubDate>Mon, 05 May 2008 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10110.htm-->
    <title>Denialists' Deck of Cards: An Illustrated Taxonomy of Rhetoric Used to Frustrate Consumer Protection Efforts </title>
    <description><![CDATA[The Denalists' Deck of Cards is a humorous illustration of how libertarian policy groups use denialism. In this context, denialism is the use of rhetorical techniques and predictable tactics to erect barriers to debate and consideration of any type of reform, regardless of the facts. Giveupblog.com has identified five general tactics used by denialists: conspiracy, selectivity, the fake expert, impossible expectations, and metaphor.
<P>The Denialists' Deck of Cards builds upon this description by providing specific examples of advocacy techniques. The point of listing denialists' arguments in this fashion is to show the rhetorical progression of groups that are not seeking a dialogue but rather an outcome. As such, this taxonomy is extremely cynical, but it is a reflection of and reaction to how poor the public policy debates in Washington have become.</P>
<P>The Deck is drawn upon my experience as a lawyer working on consumer protection in Washington, DC. Where possible, I have provided specific examples of denialism, but in many cases, these arguments are used only in closed negotiations. Some who read them find the examples humorous, while others find it troubling. But all who read the Washington Post will recognize these tactics; they are ubiquitous and quite effective.</P>
<P>This taxonomy provides a roadmap for consumer advocates to understand the resistance they will face with almost any form of consumer reform. I hope to expand it to include retorts to each argument in the future. </P>]]></description>
    <link>http://www.law.berkeley.edu/10110.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10110.htm</guid>
    <pubDate>Sun, 11 Feb 2007 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10111.htm-->
    <title>A Model Regime of Privacy Protection (Version 2.0) </title>
    <description><![CDATA[This version incorporates and responds to the many comments that we received to Version 1.1, which we released on March 10, 2005.
<P>Privacy protection in the United States has often been criticized, but critics have too infrequently suggested specific proposals for reform. Recently, there has been significant legislative interest at both the federal and state levels in addressing the privacy of personal information. This was sparked when ChoicePoint, one of the largest data brokers in the United States with records on almost every adult American citizen, sold data on about 145,000 people to fraudulent businesses set up by identity thieves. Other companies announced security breaches, including LexisNexis, from which personal information about 32,000 people was improperly accessed. Senator Schumer criticized Westlaw for making available to certain subscribers personal information including Social Security Numbers (SSNs).</P>
<P>In the aftermath of the ChoicePoint debacle and other major information security breaches, both of us have been asked by Congressional legislative staffers, state legislative policymakers, journalists, academics, and others about what specifically should be done to better regulate information privacy. In response to these questions, we believe that it is imperative to have a discussion of concrete legislative solutions to privacy problems.</P>
<P>What appears below is our attempt at such an endeavor. Privacy experts have long suggested that information collection be consistent with Fair Information Practices. This Model Regime incorporates many of those practices and applies them specifically to the context of commercial data brokers such as ChoicePoint. We hope that this will provide useful guidance to legislators and policymakers in crafting laws and regulations. We also intend this to be a work-in-progress in which we collaborate with others. We have welcomed input from other academics, policymakers, journalists, and experts as well as from the industries and businesses that will be subject to the regulations we propose. We have incorporated criticisms and constructive suggestions, and we will continue to update this Model Regime to include the comments we find most helpful and illuminating.</P>
<P>Notice, Consent, Control, and Access</P>
<P>1. Universal Notice<BR>2. Meaningful Informed Consent<BR>3. One-Step Exercise of Rights<BR>4. Individual Credit Management<BR>5. Access to and Accuracy of Personal Information</P>
<P>Security of Personal Information</P>
<P>6. Secure Identification<BR>7. Disclosure of Security Breaches</P>
<P>Business Access to and Use of Personal Information</P>
<P>8. Social Security Number Use Limitation<BR>9. Access and Use Restrictions for Public Records<BR>10. Curbing Excessive Uses of Background Checks<BR>11. Private Investigators</P>
<P>Government Access to and Use of Personal Data</P>
<P>12. Limiting Government Access to Business and Financial Records<BR>13. Government Data Mining<BR>14. Control of Government Maintenance of Personal Information</P>
<P>Privacy Innovation and Enforcement</P>
<P>15. Preserving the Innovative Role of the States<BR>16. Effective Enforcement of Privacy Rights<BR></P>]]></description>
    <link>http://www.law.berkeley.edu/10111.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10111.htm</guid>
    <pubDate>Wed, 06 Apr 2005 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10117.htm-->
    <title>Putting Identity Theft on Ice: Freezing Credit Reports to Prevent Lending to Impostors </title>
    <description><![CDATA[Identity theft is a growing problem. In any given identity theft situation, there are three actors - the victim, the impostor, and an institution, such as a bank or credit card company. Thus far, policymakers have attempted to address the crime by focusing on victims and impostors; victims are told to try to shield their personal information and impostors are increasingly subject to stiffened penalties for committing identity theft. Neither approach has been effective.
<P>This article argues that the third actor, credit granting institutions, are culpable for a large number of identity theft cases. Institutions enable identity theft by maintaining lax credit granting practices, ones that make it easy for impostors to get credit in victims' names.</P>
<P>This article proposes a fix to address lax credit granting practices. It takes the form of a change in the default state of credit reports from their current liquid state to a frozen one. That is, our current credit system allows our personal information to flow like water to almost anyone who requests it. Once credit information is released, credit grantors who are operating in an extremely competitive market, race to issue new accounts. This makes it simple for impostors to commit identity theft by obtaining new credit accounts.</P>
<P>Under the proposed system, credit reports would be sealed or frozen, available only when the individual thaws her file, and specifies to whom, when, or in what contexts it should be released. Creditors will not extend tradelines without a credit report, and thus under a frozen credit report system, impostors would have great difficulty in obtaining new accounts. A simple barrier to obtaining a credit report will provide a shield for all individuals against most identity thieves.</P>
<P>This article is a short book chapter in a forthcoming book to be published by Stanford University Press of papers presented at a March 2004 symposium on privacy and security at Stanford Law School. </P>]]></description>
    <link>http://www.law.berkeley.edu/10117.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10117.htm</guid>
    <pubDate>Wed, 30 Mar 2005 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10115.htm-->
    <title>A Model Regime of Privacy Protection (Version 1.1) </title>
    <description><![CDATA[Privacy protection in the United States has often been criticized, but critics have too infrequently suggested specific proposals for reform. Recently, there has been significant legislative interest at both the federal and state levels in addressing the privacy of personal information. This was sparked when ChoicePoint, one of the largest data brokers in the United States with records on almost every adult American citizen, sold data on about 145,000 people to fraudulent businesses set up by identity thieves.
<P>In the aftermath of the ChoicePoint debacle, both of us have been asked by Congressional legislative staffers, state legislative policymakers, journalists, academics, and others about what specifically should be done to better regulate information privacy. In response to these questions, we believe that it is imperative to have a discussion of concrete legislative solutions to privacy problems.</P>
<P>What appears below is our attempt at such an endeavor. Privacy experts have long suggested that information collection be consistent with Fair Information Practices. This Model Regime incorporates many of those practices and applies them specifically to the context of commercial data brokers such as Choicepoint. We hope that this will provide useful guidance to legislators and policymakers in crafting laws and regulations. We also intend this to be a work-in-progress in which we collaborate with others. We welcome input from other academics, policymakers, journalists, and experts as well as from the industries and businesses that will be subject to the regulations we propose. We invite criticisms and constructive suggestions, and we will update this Model Regime to incorporate the comments we find most helpful and illuminating. We also aim to discuss some of the comments we receive in a commentary section. To the extent to which we incorporate suggestions and commentary, and if those making suggestions want to be identified, we will graciously acknowledge those assisting in our endeavor.</P>
<P>Notice, Consent, Control, and Access</P>
<P>1. Universal Notice<BR>2. Meaningful Informed Consent<BR>3. One-Step Exercise of Rights<BR>4. Individual Credit Management<BR>5. Access to and Accuracy of Personal Information</P>
<P>Security of Personal Information</P>
<P>6. Secure Identification<BR>7. Disclosure of Security Breaches</P>
<P>Business Access to and Use of Personal Information</P>
<P>8. Social Security Number Use Limitation<BR>9. Access and Use Restrictions for Public Records<BR>10. Curbing Excessive Uses of Background Checks<BR>11. Private Investigators</P>
<P>Government Access to and Use of Personal Data</P>
<P>12. Limiting Government Access to Business and Financial Records<BR>13. Government Data Mining<BR>14. Control of Government Maintenance of Personal Information</P>
<P>Privacy Innovation and Enforcement</P>
<P>15. Preserving the Innovative Role of the States<BR>16. Effective Enforcement of Privacy Rights </P>]]></description>
    <link>http://www.law.berkeley.edu/10115.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10115.htm</guid>
    <pubDate>Fri, 11 Mar 2005 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10121.htm-->
    <title>Consumer Privacy in the E-Commerce Marketplace 2002 </title>
    <description><![CDATA[The author reviews 2002 developments in privacy and e-commerce, and concludes by arguing that a framework of fair information principles should govern the collection, maintenance, and dissemination of personal information. Proposed online privacy, computer security, and student privacy legislation is reviewed. The role of the Federal Trade Commission in handling privacy complaints is analyzed, and the author finds that the agency tends only to take action in cases with strong merits or where children's privacy is involved. The agency tends not to levy monetary fines for privacy violations, unless children's privacy is involved. The author reviews two landmark privacy lawsuits, Trans Union v. FTC and IRSG v. FTC, and the status of several privacy issues, including the role of self-regulation, consumer profiling, national identification, wireless privacy, digital rights management, authentication systems, and customer proprietary network information. ]]></description>
    <link>http://www.law.berkeley.edu/10121.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10121.htm</guid>
    <pubDate>Thu, 04 Mar 2004 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10125.htm-->
    <title>Matters of Public Concern and the Public University Professor </title>
    <description><![CDATA[The matter of public concern test is the threshold inquiry courts use to determine whether a public employee's expression falls within the bounds of constitutionally protected speech. This test has been extended into the realm of academia, and it is now used to determine the First Amendment value of professors' expression as well. Under the test, a professor's expression must relate to a matter of political, social, or other concern to the community to gain protection under the First Amendment.
<P>What expression qualifies as a matter of political, social, or other concern to the community? For many reasons, this is a difficult question to answer both in ordinary public employment situations and in academia. Indeed, this article includes many cases where different courts (and different Justices) view the same set of facts, and come to opposite conclusions on whether the expression at issue pertained to a matter of public concern. This article will trace these free speech cases arising in the academic environment in order to determine what expression falls within the ambit of public concern and what expression does not. Despite the gray areas between public and private concern, an analysis of these cases can elucidate trends and provide insight for the professor-plaintiff attempting to evaluate a free speech case.</P>
<P>Public concern cases involving professors tend to arise in one of four different contexts: faculty expression concerning the internal affairs of the institution; faculty expression motivated by personal interest; faculty expression made in private and not shared with the public; and vulgar or derogatory language employed by faculty in the classroom. In this article I will argue that, in each of the four contexts, courts have not always been sensitive to the special differences between ordinary public employment and employment at an institution of higher education. Also, in all four contexts, it is clear that the matter of public concern test does not encompass the traditional notions of protection offered by academic freedom.</P>
<P>To explain the trends in public concern jurisprudence, it is helpful to review the history of constitutional protection for public employee free expression. Part II of this article will review the rise of First Amendment protection for academic freedom, the development of the public concern test, and academic standards for free expression. Part III will describe the current procedural hurdles that plaintiffs and defendants must maneuver when a professor's free speech rights are being litigated. Part IV contains an analysis of public concern cases in terms of the four categories listed above. Finally, Part V presents academic criticism of the matter of public concern test and alternative legal standards for determining the First Amendment value of professors' expression.</P>
<P>Professors must exercise caution when relying on the First Amendment or academic freedom to shield their expression from retaliation because the only academic speech likely to enjoy protection under the Constitution is speech on matters of public concern. The matter of public concern test does not encompass the traditional notions of protection offered by academic freedom. And, even if a professor is successful in showing that the speech in question pertains to a matter of public concern, the professor's case must still survive Pickering balancing, qualified immunity challenges, and other procedural hurdles. Courts applying the matter of public concern test to faculty speech sometimes are insensitive to the special context of higher education. As a result, professors must consider that important expression in the academic environment may appear as inconsequential to a judge. This insensitivity and difference in worldviews results in less protection for free speech, and as a result, it endangers academic freedom.</P>
<P>Cases applying the matter of public concern test to faculty speech are highly fact-sensitive. But some generalizations can be made about public concern cases to help faculty evaluate their free speech rights:</P>
<P>(1) Many important internal affairs issues are not matters of public concern. To be protected, expression on internal affairs issues must directly affect the public's perception of quality of education. As a result, faculty speech on many important, quality-affecting issues is not protected by the First Amendment.</P>
<P>(2) Faculty expression that is motivated by purely personal interest will not enjoy First Amendment protection. Courts will also reject First Amendment claims by faculty who use public issues as a pretense to air their personal grievances. However, faculty who have mixed motives of personal and sincere public interest may have their speech protected.</P>
<P>(3) Professors do not have to publicize their expression in order to enjoy First Amendment protection. Private expression on matters of public concern is protected by the First Amendment.</P>
<P>(4) Professors who use vulgar or derogatory language should exercise caution because an institution or court might not consider the context or speaker's intent carefully. As a result, professors cannot rely on First Amendment protection for vulgar or derogatory speech. Sexually-explicit expression that is motivated by pedagogical purposes has, however, been found to relate to a matter of public concern. </P>]]></description>
    <link>http://www.law.berkeley.edu/10125.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10125.htm</guid>
    <pubDate>Thu, 04 Mar 2004 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10126.htm-->
    <title>Debunking the Commercial Profilers' Claims: A Skeptical Analysis of the Benefits of Personal Information Flows </title>
    <description><![CDATA[In comments to the Federal Trade Commission, the authors propose a model for evaluating the costs to personal privacy imposed by uses of personal information. Under this proposal, the costs of information flows would be measured against Fair Information Practices, principles that set out the rights and responsibilities of data subjects and data collectors. The authors argue that many economic assumptions regarding the benefits of information flows have not come to fruition, especially in the financial services arena. The authors challenge five specious claims of the information industry: that information flows reduce prices, that customers want personalization, that profiling reduces the number of solicitations that individuals receive; that personal information allows companies to extend consumers more choices, and that information flows reduce fraud. ]]></description>
    <link>http://www.law.berkeley.edu/10126.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10126.htm</guid>
    <pubDate>Fri, 20 Feb 2004 09:00:00 -0400</pubDate>
</item>

<item>
<!--/10128.htm-->
    <title>Privacy Practices Below the Lowest Common Denominator: The Federal Trade Commission's Initial Application of Unfair and Deceptive Trade Practices Authority to Protect Consumer Privacy (1997-2000) </title>
    <description><![CDATA[In this paper, the author reviews the first six actions taken by the Federal Trade Commission (FTC) to safeguard consumers' privacy under the agency's authority to prosecute unfair or deceptive trade practices. Six conclusions can be made from these cases: First, the FTC has chosen to take enforcement actions only in cases with strong merits. Second, the protection of children's online activities is a priority of the FTC. Third, deception is the principal theory on which the FTC has relied to enforce violations of the FTCA against online businesses. Fourth, it is possible for the FTC to pursue a privacy claim under an unfairness theory. However, the unfairness theory is more likely to be successful when pursuing violations of children's privacy. Fifth, a strong showing of consumer harm is not required for an action based on unfairness. Merely misrepresenting privacy practices or violating a guarantee of privacy is sufficient to actuate agency action. Under the deception theory, there is no requirement to demonstrate harm. Last, monetary damages have not been assessed in FTC privacy actions against online businesses. ]]></description>
    <link>http://www.law.berkeley.edu/10128.htm</link>
    <guid isPermaLink="true">http://www.law.berkeley.edu/10128.htm</guid>
    <pubDate>Mon, 01 Jan 2001 09:00:00 -0400</pubDate>
</item>


</channel>
</rss>