隐私危害与通知与选择框架的有效性

J. Reidenberg, N. C. Russell, Alexander J. Callen, S. Qasir, Thomas B. Norton
{"title":"隐私危害与通知与选择框架的有效性","authors":"J. Reidenberg, N. C. Russell, Alexander J. Callen, S. Qasir, Thomas B. Norton","doi":"10.2139/SSRN.2418247","DOIUrl":null,"url":null,"abstract":"In the last fifteen years, the Federal Trade Commission and the White House have promoted notice and choice as the preferred mechanism for protecting consumers’ privacy online. But law and policy scholars doubt the efficacy of this mechanism. Research shows that consumers rarely read website privacy policies, that such policies are often too complex for users to understand, and that website policy statements do not match consumers’ privacy expectations. Efforts to ameliorate theses issues through technological tools, such as privacy filters and do-not-track codes, have been unsuccessful. Further, these tools do not address whether notice and choice theory aligns with the actual privacy harms that consumers experience. This alignment remains unexplored. This article, thus, proposes to examine the relationship between the notice and choice theory and users’ actual privacy concerns. The article takes a novel approach that examines privacy litigation and FTC enforcement actions. This focus on the wrongs litigated in the real world reveals the most important harms that consumers experience and provides a better understanding of the efficacy of the notice and choice framework.The data set compiled to support the research for the article consists of all federal class action complaints alleging online privacy violations filed during the last ten years and the Federal Trade Commission complaints and settlements addressing online privacy. The article next addresses the roles that jurisdiction and competence play in framing claims and identifies a typology of the wrongful acts experienced by consumers. The research shows that four types of claims appear in both private litigation and public enforcement with respect to personal information: (1) unauthorized disclosure, (2) surreptitious collection, (3) failure to secure, and (4) undue retention. The article then applies this typology to map “zones of effectiveness” for the notice and choice regime. The article identifies which wrongs a proper notice and choice regime can and cannot address. The research demonstrates that while some wrongful practices might be avoided by the inclusion of specific statements in a notice, others will be incurable through notice. The latter set of wrongs is, thus, outside the “zone of effectiveness” of a notice and choice regime. Lastly, the article concludes with a discussion of whether and how the harms that consumers experience match the outcomes of litigation and FTC settlement orders.This research is supported by the National Science Foundation grant 1330214 “TWC SBE: Option: Frontier: Collaborative: Towards Effective Web Privacy Notice and Choice: A Multi-Disciplinary Prospective.”","PeriodicalId":179517,"journal":{"name":"Information Privacy Law eJournal","volume":"875 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-03-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"70","resultStr":"{\"title\":\"Privacy Harms and the Effectiveness of the Notice and Choice Framework\",\"authors\":\"J. Reidenberg, N. C. Russell, Alexander J. Callen, S. Qasir, Thomas B. Norton\",\"doi\":\"10.2139/SSRN.2418247\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In the last fifteen years, the Federal Trade Commission and the White House have promoted notice and choice as the preferred mechanism for protecting consumers’ privacy online. But law and policy scholars doubt the efficacy of this mechanism. Research shows that consumers rarely read website privacy policies, that such policies are often too complex for users to understand, and that website policy statements do not match consumers’ privacy expectations. Efforts to ameliorate theses issues through technological tools, such as privacy filters and do-not-track codes, have been unsuccessful. Further, these tools do not address whether notice and choice theory aligns with the actual privacy harms that consumers experience. This alignment remains unexplored. This article, thus, proposes to examine the relationship between the notice and choice theory and users’ actual privacy concerns. The article takes a novel approach that examines privacy litigation and FTC enforcement actions. This focus on the wrongs litigated in the real world reveals the most important harms that consumers experience and provides a better understanding of the efficacy of the notice and choice framework.The data set compiled to support the research for the article consists of all federal class action complaints alleging online privacy violations filed during the last ten years and the Federal Trade Commission complaints and settlements addressing online privacy. The article next addresses the roles that jurisdiction and competence play in framing claims and identifies a typology of the wrongful acts experienced by consumers. The research shows that four types of claims appear in both private litigation and public enforcement with respect to personal information: (1) unauthorized disclosure, (2) surreptitious collection, (3) failure to secure, and (4) undue retention. The article then applies this typology to map “zones of effectiveness” for the notice and choice regime. The article identifies which wrongs a proper notice and choice regime can and cannot address. The research demonstrates that while some wrongful practices might be avoided by the inclusion of specific statements in a notice, others will be incurable through notice. The latter set of wrongs is, thus, outside the “zone of effectiveness” of a notice and choice regime. Lastly, the article concludes with a discussion of whether and how the harms that consumers experience match the outcomes of litigation and FTC settlement orders.This research is supported by the National Science Foundation grant 1330214 “TWC SBE: Option: Frontier: Collaborative: Towards Effective Web Privacy Notice and Choice: A Multi-Disciplinary Prospective.”\",\"PeriodicalId\":179517,\"journal\":{\"name\":\"Information Privacy Law eJournal\",\"volume\":\"875 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2014-03-29\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"70\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Information Privacy Law eJournal\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.2139/SSRN.2418247\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Information Privacy Law eJournal","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.2139/SSRN.2418247","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 70

摘要

在过去的15年里,联邦贸易委员会(Federal Trade Commission)和白宫一直把通知和选择作为保护消费者在线隐私的首选机制。但法律和政策学者对这一机制的有效性表示怀疑。研究表明,消费者很少阅读网站的隐私政策,这些政策往往过于复杂,用户无法理解,网站的政策声明也不符合消费者的隐私期望。通过技术工具改善这些问题的努力,如隐私过滤器和不跟踪代码,都没有成功。此外,这些工具并没有解决通知和选择理论是否与消费者所经历的实际隐私损害相一致。这种一致性仍未被探索。因此,本文建议研究通知与选择理论与用户实际隐私关注之间的关系。本文采用了一种新颖的方法来研究隐私诉讼和联邦贸易委员会的执法行动。这种对现实世界中错误诉讼的关注揭示了消费者所经历的最重要的伤害,并提供了对通知和选择框架的有效性的更好理解。为支持这篇文章的研究而汇编的数据集包括过去十年中所有指控侵犯在线隐私的联邦集体诉讼,以及联邦贸易委员会针对在线隐私的投诉和和解。接下来的文章讨论了管辖权和能力在构建索赔中所起的作用,并确定了消费者所经历的不法行为的类型。研究表明,在私人诉讼和公共执法中都出现了四种类型的个人信息索赔:(1)未经授权的披露,(2)秘密收集,(3)未能保护,(4)不当保留。然后,本文将这种类型应用于通知和选择制度的“有效区域”地图。本文指出了适当的通知和选择制度能够解决和不能解决的错误。研究表明,虽然在通知中加入具体声明可以避免一些不法行为,但其他不法行为通过通知将无法治愈。因此,后一组错误不在通知和选择制度的“有效范围”之内。最后,本文最后讨论了消费者所遭受的损害是否与诉讼结果和联邦贸易委员会和解令相匹配,以及如何相匹配。本研究由美国国家科学基金会1330214基金资助“TWC SBE:选项:前沿:协作:迈向有效的网络隐私声明和选择:多学科前景”。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Privacy Harms and the Effectiveness of the Notice and Choice Framework
In the last fifteen years, the Federal Trade Commission and the White House have promoted notice and choice as the preferred mechanism for protecting consumers’ privacy online. But law and policy scholars doubt the efficacy of this mechanism. Research shows that consumers rarely read website privacy policies, that such policies are often too complex for users to understand, and that website policy statements do not match consumers’ privacy expectations. Efforts to ameliorate theses issues through technological tools, such as privacy filters and do-not-track codes, have been unsuccessful. Further, these tools do not address whether notice and choice theory aligns with the actual privacy harms that consumers experience. This alignment remains unexplored. This article, thus, proposes to examine the relationship between the notice and choice theory and users’ actual privacy concerns. The article takes a novel approach that examines privacy litigation and FTC enforcement actions. This focus on the wrongs litigated in the real world reveals the most important harms that consumers experience and provides a better understanding of the efficacy of the notice and choice framework.The data set compiled to support the research for the article consists of all federal class action complaints alleging online privacy violations filed during the last ten years and the Federal Trade Commission complaints and settlements addressing online privacy. The article next addresses the roles that jurisdiction and competence play in framing claims and identifies a typology of the wrongful acts experienced by consumers. The research shows that four types of claims appear in both private litigation and public enforcement with respect to personal information: (1) unauthorized disclosure, (2) surreptitious collection, (3) failure to secure, and (4) undue retention. The article then applies this typology to map “zones of effectiveness” for the notice and choice regime. The article identifies which wrongs a proper notice and choice regime can and cannot address. The research demonstrates that while some wrongful practices might be avoided by the inclusion of specific statements in a notice, others will be incurable through notice. The latter set of wrongs is, thus, outside the “zone of effectiveness” of a notice and choice regime. Lastly, the article concludes with a discussion of whether and how the harms that consumers experience match the outcomes of litigation and FTC settlement orders.This research is supported by the National Science Foundation grant 1330214 “TWC SBE: Option: Frontier: Collaborative: Towards Effective Web Privacy Notice and Choice: A Multi-Disciplinary Prospective.”
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Policy Responses to Cross-border Central Bank Digital Currencies – Assessing the Transborder Effects of Digital Yuan Artificial Intelligence in the Internet of Health Things: Is the Solution to AI Privacy More AI? Comments on GDPR Enforcement EDPB Decision 01/020 Privacy Rights and Data Security: GDPR and Personal Data Driven Markets Big Boss is Watching You! The Right to Privacy of Employees in the Context of Workplace Surveillance
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1