SC Lawyer, Sept. 2004, #7. Privacy policies: is there really a choice anymore?.

AuthorBy Sarah B. Kemble

South Carolina Lawyer

2004.

SC Lawyer, Sept. 2004, #7.

Privacy policies: is there really a choice anymore?

South Carolina LawyerSeptember 2004Privacy policies: is there really a choice anymore?By Sarah B. KembleDue to technology that allows companies and the government to collect, correlate and cross-reference a vast body of personal data about consumers through data mining, the meaning of "private" information is being redefined.

Until very recently, companies had a choice as to whether to assuage concerns about the steady erosion of consumer privacy in e-commerce by adopting policies limiting the free dissemination of information collected from Internet users. Consumers also had a choice as to whether to support comprehensive federal legislation or industry self-regulation as the preferred course of action. Now, a single state - California - appears to have foreclosed any choice by its enactment of the Online Privacy Protection Act (OPPA), which became effective July 1, 2004. The OPPA applies to any commercial Web site operator or online service that collects "personally identifiable information through the Internet about individual consumers residing in California." Cal Bus & Prof Code § 22575(a). Because the geographical location of the operator is irrelevant, for all practical purposes the OPPA has the scope and impact of a federal privacy law. Accordingly, every business across the nation that collects personally identifiable information (PII) from or about California residents must be in compliance with the OPPA.

The redefinition of private information

Due to technology that allows companies and the government to collect, correlate and cross-reference a vast body of personal data about consumers through data mining, the meaning of "private" information is being redefined. Beyond the obvious type of information that is often considered confidential - sexual, medical, financial - is information that would not be considered sensitive in isolation, but that becomes sensitive when aggregated through data mining and profiling. Consumers are all too familiar with the correlation of purchasing habits and income and credit information to create profiles for purposes of targeted marketing by mail, telephone and e-mail. A typical consumer does not care whether someone standing in the check-out line observes the book title or groceries she is about the purchase. The same consumer, however, may be reluctant to have the neighbors know of every single purchase of clothing, drugs, magazines, food and household items made in the past five years. Consumer privacy now demands some measure of control not only over what type of data is disclosed, but over how much and to whom.

State common law privacy torts

State common law invasion of privacy tort actions are of limited utility to consumers concerned with the dissemination of PII or data profiles because such claims are designed largely to protect sensitive information that is obtained surreptitiously or that would be embarrassing if publicly disclosed. South Carolina recognizes three privacy torts: wrongful intrusion into private affairs, wrongful appropriation of personality and wrongful publicizing of private affairs. Snakenberg v. Hartford Casualty Ins. Co., 299 S.C. 164, 170, 383 S.E.2d 2, 5 (1989). Wrongful intrusion means "watching, spying, prying, besetting, overhearing, or other similar [intrusive] conduct" into that which is "private" - meaning those aspects of the plaintiff, "his home, his family, his personal relationships and his communications which one normally expects will be free from exposure to the defendant." 383 S.E.2d at 6. Thus, it appears that in South Carolina this encompasses only wrongful procurement of information, not its wrongful disclosure. See Schuchart v. LA Taberna Del Alabardero, Inc., 365 F.3d 33, 36 (D.C. Cir. 2004) (states are "far from unanimous" about what the wrongful intrusion tort encompasses). As such, selling or sharing even "private" information cannot constitute a wrongful intrusion to the extent that the data was disclosed voluntarily by consumers. Web surfers not only reveal PII by engaging in online transactions, but often provide an information bonanza for data mining and profiling purposes by filling out Web site registration pages and participating in online surveys and contests.

The wrongful appropriation of personality tort stems from "the plaintiff's exclusive right at common law to publicize and profit from his name, likeness, and other aspects of personal identity." Snakenberg, 383 S.E.2d at 5-6. The defendant must appropriate "the reputation, prestige, social or commercial standing, public interest or other values" of the plaintiff's identity. Restatement (Second) of Torts § 652C comment c. The sharing or selling of PII or consumer data profiles does not fall within the appropriation tort because the purpose is commercial and "for the value of the information itself, not to take advantage of the [consumer's] reputation or prestige." Remsburg v. Docusearch, Inc., 149 N.H. 148, 158, 816 A.2d 1001, 1010 (2003). Finally, the dissemination of PII or consumer profiles does not constitute a wrongful publicizing of private affairs because, not only must a publication "bring shame or humiliation to a person of ordinary sensibilities," it must also be communicated to the public at large and not "a small group of people." Swinton Creek Nursery v. Edisto Farm Credit, 334 S.C. 469, 478-79, 514 S.E.2d 126, 131 (1999). Even if the information contained in a consumer profile would be considered highly offensive by a reasonable person, it normally would not be disseminated beyond the corporate marketing community. In the final analysis, common law privacy torts do little to address the unique concerns present in the realm of cyberspace.

The limited federal response

A multiplicity of federal laws address privacy concerns in piecemeal fashion, typically restricting the disclosure of information that is considered private in the conventional sense of that term - meaning sensitive or having a potential for embarrassment. See, e.g., Fair Credit Reporting Act of 1970 (credit histories); Family Educational Rights and Privacy Act of 1974 (student records); Fair Debt Collection Act of 1977 (debts); Right to Financial Privacy Act of 1978 (bank records); Tax Reform Act of 1975 (tax returns); Cable Communications Policy Act of 1984 (viewing habits); Videotape Privacy Protection Act of 1988 (video rentals); Health Insurance Portability and Accountability Act of 1996 (health information). Other privacy laws stem from the well-established notion of privacy as the right to be free from unwanted intrusion. See, e.g., Consumer Fraud and Abuse Act of 2000 (hacking); Do-Not-Call Implementation Act of 2003 (national do-not-call registry); Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003 (unsolicited e-mails).

A more expansive view of the right of privacy is reflected in laws that prohibit the disclosure of information that is not traditionally considered "private," but is nonetheless the type of "personal" information that, when shared, may result in data mining and consumer profiling. See, e.g., Driver's Privacy Protection Act of 1994 (prohibiting state motor vehicle licensing agencies from disclosing personal information); Gramm-Leach-Bliley Act of 1999 (requiring consumer notice and right to opt out of information sharing by financial institutions). Uniquely directed at the dangers posed by collecting data from children on the Internet is the Children's Online Privacy Protection Act of 1998 (requiring parental consent to obtain personal information).

As yet, there is no comprehensive nationwide privacy legislation such as was proposed in 2002 in the Online Personal Privacy Act (S. 2201). That proposed federal Act distinguished between "sensitive" and "non-sensitive" information - with "sensitive" referring to financial and medical information, ethnic, religious and political affiliation and sexual orientation. Consumers would have had to affirmatively "opt in" to the disclosure of sensitive information, and "opt out" of the disclosure of non-sensitive information. Instead, the federal government, through the Federal Trade Commission, has continued to encourage self-regulation.

The FTC set forth four principles of fair information practices in its June 1998 Privacy Online: A Report to Congress, explaining that a privacy policy should include: (1) notice to the consumer as to how personal information is collected and used, including whether it is disclosed to advertisers, in the aggregate or otherwise; (2) consumer choice as to whether to permit such collection and use, by either an opt out or opt in method; (3) notice as to the level of security and encryption standards for personal information; and (4) directions on how to correct, update and remove personal information. Because of lagging self-regulation efforts, in its May 2000 report Privacy Online: Fair Information Practices in the Electronic Marketplace (FTC 2000 Privacy Online), the FTC urged "legislation, in conjunction with self-regulation." With no consensus on the desirable scope of privacy protection, however, federal legislative initiatives have stalled.

The California approach

Under the California OPPA, personally identifiable information is defined to include the consumer's name, address, e-mail address, telephone number, social security number and "any other identifier that permits the physical or online contacting of a specific individual." Cal Bus & Prof Code § 22577. In order to comply with the OPPA, a privacy policy must: (1) identify the categories of PII that the operator collects and the categories of third parties with whom it may share the PII; (2) if the operator maintains a process for consumers to review and request changes to their PII, describe the process by which a consumer may request such changes; (3) describe the process by which an operator notifies consumers of changes to the privacy policy; and (4) identify the effective date of the privacy policy. § 22575(b). An operator notified of non-compliance has 30 days in which to cure the violation. § 22576.

The first OPPA requirement, to identify third parties with whom an operator "may" share PII, conforms to the FTC's view that "an entity that sometimes shares personal information with third parties should clearly state as much, even if information is not always shared." FTC 2000 Privacy Online at 27. There is no OPPA requirement akin to the FTC's third fair information practice principle requiring notice as to the level of security and encryption standards for PII. Also, there is no requirement under the OPPA that operators allow consumers to review and request changes to their PII - unlike the FTC's fourth fair information practice principle, which mandates that consumers be able to access and change data about themselves.

Most notably absent from the OPPA is any parallel to the FTC's second fair information practice principle that consumers must be given the opportunity to choose whether to permit sharing of PII by either affirmatively "opting in" to allow it, or "opting out" to prevent it. Instead, under the OPPA consumers apparently are deemed to have consented to the use of their PII merely by using the Web site or online service. A privacy policy need not state, for example, that "information will not be shared without consent" (opt in policy), or "information will be shared unless you indicate your lack of consent" (opt out" policy). The FTC, meanwhile, stresses the need for choice. Of particular concern to the FTC is suggesting that a privacy policy is of the opt in variety, when in fact the consumer is required to take some affirmative action to demonstrate lack of consent (such as, for example, unclicking a pre-checked consent "click box"). FTC 2000 Privacy Online at 26.

The OPPA does, however, impose an obligation that the FTC does not - namely, identifying the effective date of the privacy policy. This probably relates to the third OPPA requirement, to describe the process by which consumers are notified of changes to the privacy policy - considered by the FTC to be an aspect of accurate "notice" under its first fair information practice principle. The FTC has opined that accurate notice may require not only that a privacy policy notify consumers that the company reserves the right to make policy changes, but also that it explain the effect of any material change on previously collected information. In fact, according to the FTC, in certain circumstances "the application of new information practices to information collected pursuant to different, stated practices may constitute an unfair and/or deceptive practice." Id. at 26. In contrast, the OPPA does not require consent to privacy policy changes, but merely disclosure of the method by which the operator intends to notify consumers of changes to the policy.

The manner in which privacy policies must be posted under the OPPA is considerably more detailed than what the FTC recommends. The FTC explains simply that privacy disclosures should be "clear and conspicuous," and that links to the policy should be "prominently displayed" not only on the Web site's home page but on "every page on which personal information is collected." FTC 2000 Privacy Online at 27. In contrast, the OPPA provides that an operator must "conspicuously post" its privacy policy, § 22575(a), which means: (1) on the homepage; (2) by direct link to the homepage through an icon that contains the word "privacy" and contrasts with the background color; (3) by hypertext link that includes the word "privacy" and is set off from the text by larger or contrasting type, font or color, symbols or other marks; or (4) by functional hyperlink that "is so displayed that a reasonable person would notice it." § 22577(b).

What should Web site operators do?

Before the OPPA was enacted, the challenge for Web site operators was to decide if the benefit of self-regulation outweighed the risk of having a privacy policy that might be considered inadequate according to FTC standards. The FTC had indicated that a company could expose itself to unfair trade practice liability if its representations about information sharing practices were confusing or misleading. For example, the FTC opined that while a company may provide both summary and detailed information regarding its information practices, it is "confusing" for a policy to state that "as a general rule" the company does not disclose PII - and to later describe policy exceptions that allow information sharing. FTC 2000 Privacy Online at 24-25. At the same time, however, disclosures should be "simple and easy to understand," thereby creating a tension between drafting succinct yet exact policies. Id. at 27. Given the difficulty inherent in drafting an accurate privacy policy, it is unsurprising that year 2000 survey results showed only 20 percent of Web sites that collected PII implemented all four FTC fair information practices in their privacy policies. Id. at 12.

In light of the OPPA, self-regulation through compliance with the FTC's four fair information practice principles is no longer an option. The OPPA likely will be enforced through California's Unfair Competition Law, which permits private rights of action. Web site operators who collect PII from California residents have no choice but to implement privacy policies that comply with the OPPA. Because privacy policies are now compulsory for most Web site operators, it makes sense to have a policy that complies both with the OPPA and - to the extent possible - with the FTC's four principles. It would not be surprising to see a constitutional challenge to the OPPA under the dormant Commerce Clause, on the grounds that the burden on interstate commerce and out-of-state businesses is excessive in relation to the benefit to California residents. If Congress eventually passes nationwide online privacy legislation, it would undoubtedly preempt the OPPA under the Supremacy Clause. For the time being, however, the vacuum created by the absence of federal law means that "as goes California, so goes the nation."

Sarah B. Kemble is counsel in the Charlotte office of Hunton & Williams LLP and practices in the area of commercial litigation.

Copyright (c) 2004 by the South Carolina Bar. All rights reserved. No part of this publication may be reproduced without written permission.

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex