Introduction
On June 27, 2016, the United Nations adopted the general statement of the internet which was proposed to protect the rights of humans through the use of the internet as a fundamental right; however, approximately 26 countries utilize computational propaganda, such as predictive analytical models, through social media platforms, as a tool to control the spread of information including ways to suppress fundamental human rights, discredit political opponents, and drown out dissenting opinions. The United Nations recognized that the international States must take initiative in addressing security concerns with regards to the use and operability of the internet, namely, States must accord human rights obligations and protect the freedom of expression, association, and privacy of individuals on the internet.
This paper analyzes the current data and privacy regulations that address the collection of user information during internet and social media usage. Generally, the scope of this paper focuses on the users right to privacy from the perspective of current use cases by well-known technology and social media companies. Specifically, use cases by Facebook, Inc. (which collectively owns Facebook, Instagram, and WhatsApp), ByteDance, Ltd. (also known as Tik Tok), Alphabet, Inc. (also known as Google); and Amazon.com, Inc. (also known as Amazon) are analyzed to demonstrate how technology companies engage in surveillance capitalism. Current data regulations are analyzed with respect to addressing the advertising centered business models of Surveillance Capitalism. Specific United States Constitutional rights that technology companies may infringe upon while engaging in the practice of Surveillance Capitalism, such as the right to freedom of speech, the right to assembly, the right to privacy, and the right to protection from warrantless searches and seizures, may be addressed in this paper, but are not specifically analyzed as such analysis would exceed the scope of this research. The purpose of this paper is to expose limitations in current data privacy regulations and highlight actions by technology companies that may need to be addressed in federal legislation in order to address security concerns and human rights obligations.
What is Surveillance Capitalism?
Through the exponential growth of social media, big technology companies are driving internet usage and data collection through advertisement centered business models. These business models have caused privacy and ethical concerns over how the companies engage in the use of its user’s behavioral characteristics and residual data. The business model that the big technology companies have adopted has driven the growth of the stock market so much that the reliance on big tech has yielded the market structure titled Surveillance Capitalism.
Surveillance Capitalism is “(1) a new economic order that claims human experience as free raw material for hidden commercial practices of extraction, prediction, and sales; (2) a parasitic economic logic in which the production of goods and services is subordinated to a new global architecture of behavioral modification; (3) a rogue mutation of capitalism marked by concentrations of wealth, knowledge, and power unprecedented in human history; (4) the foundational framework of surveillance economy; (5) as significant a threat to human nature in the natural world industrial capitalism was to the natural world in the nineteenth and twentieth century; (6) the origin of a new instrumentation power that asserts dominance over society and presents startling challenges to market democracy; (7) a movement that aims to impose a new collective order based on total certainty; and (8) an expropriation of critical human rights that is best understood as a coup from above: an overthrow of the people’s sovereignty.”
The human experience that is captured as free raw material is in the form of data. For example, technology companies such as Google and Facebook offer free services to users. In exchange for the free services the technology companies collect data from its users, specifically identifiers, personal information, and residual data. Residual data, such as internet cookies and cache, is information stored on a computer that was collected from the pages the users accessed and the activities of the user on the website. There are two types of internet cookies, single-session cookies and persistent/multi-session cookies. The single-session cookies are locally stored to help the user navigate on the website where such information is deleted after the user closes its browser. Multi-session cookies are stored on the hard drive of the user’s computer where such information may include user identifiers, personal information, and other information to improve the quality of the service.
The technology companies access the data stored on the user’s computers, compiling a database of demographics about a users’ web browsing experience. The users’ interests, visited web pages, clicked on products, shopping carts, internet protocol addresses, and other data is collected for a consumer profile. The technology companies use these consumer profiles to offer third parties advertisements directed towards a target consumer. By providing these targeted advertisements, personalized services, technology companies are able to keep users engaged with the free application by offering advertisements that correlate to the user’s interests. profound misconceptions, the only information they have is what we give them. The personal information that many users input into their profiles, such as their name, birthday, education history, is least important. The true art of surveillance capitalism relies upon data and information collection such as GPS tracking, digital traces, and residual data, which can be more invasive and personal than the average person realizes.
The technology companies argue that they collect the data to improve our services, but more of the data is analyzed to train models and used for predictive analytics to fit consumer behavior to patterns of human behavior. These models predict how people with the characteristics of the model behave over time and predict how they will act over time. Thus, these models create scenarios to determine optimal consumers, the target consumer. These models are used to improve products and services and push advertisements through predictive analytics. The advertisements are personalized and targeted towards specific groups of people that are more likely to engage in commerce. The specific consumers are more likely to engage with the content and the advertisements that are tailored to their specific interests based on their residual data.
The argument against automation and surveillance capitalism is human will power. Stating that the user has the ultimate choice where to engage with the content. However, the average screen time on a mobile device is approximately 3 hours and 48 minutes in 2020, which is approximately 1 hour and 16 minutes greater than the average daily screen time on a mobile device in 2014. These statistics suggest that the target algorithms tailored to the specific interests of the user keep the user more engaged on their mobile devices; thus, more susceptible to influence from surveillance capitalism.
Effects of Surveillance Capitalism on the Consumer
The expansion of the internet and the use algorithms to collect data on users for targeted third party advertisements and targeted content has driven internet addiction and led to mental health disorders. The applications are designed to increase feedback with the user. For example, notification symbols, such as a red exclamation point or red number on the corner of an application, entices the user to click on and interact with the application; or, notifications that tell the user a friend is online or a friend has posted for the first time in a while, enable the user to interact with the applications. The business model of the social media companies is essentially to keep people engaged on the screen through confirmation bias and short term dopamine driven feedback loops. These companies compete with one another to attract the most screen time and use time on the application. The longer a user is engaged on an application, the more data the social media company may collect, and the longer the user will be exposed to advertisements which are the key source of revenue for the social media companies. The algorithm’s collect the users data and interaction with the application, create profiles for the consumer, then sell the demographics to companies to create targeted content and targeted advertisements in order to keep the user engaged. Because the content and advertisements are targeted towards the user, they are specifically designed to the users interests keeping them more engaged with the applications. The algorithms create a model of for the characteristics of the user and use predictive analytics to keep the user scrolling through targeted content, return engagement, and exposure to advertisements.
The technology companies can essentially control what content users see and interact with. Algorithms capture the user’s residual data and information to analyze the content that the user is attracted to and likely to engage with. Therefore, the platform will target content and advertisements to increase user engagement with the platform. The longer the company can keep the user engaged with the platform, the more advertisements the user will be exposed to. This will eventually lead to increased advertisement revenue because the longer the user is exposed to advertisements, the more likely the user is to click on an advertisement or purchase a product or service. The increased interaction with the internet and social media content can lead to internet addiction.
In addition to the control of targeted content to drive interaction and revenue, these companies can target content to push political agendas and personal interests. Recently, Facebook, Inc. and Twitter, Inc. have been attempting to limit the spread of false information; however, the platforms artificial intelligence struggles with distinguishing between truthful information and false information. Essentially, truth and fact must be programmed into the system, which, given the large number of users and content shared each day, it is nearly impossible to program every truth. The problem with the targeted content is the problem of misinformation. The largest misinformation and manipulation has recently revolved around political polarization and confirmation bias. The feedback loops and predictive data models constantly push content towards users that aligns with the beliefs of the user and the users idealized demographic. A study conducted by the Massachusetts Institute of Technology found that “fake news” and misinformation and falsehoods are 70% more likely to be retweeted than the truth is to be retweeted on Twitter. The falsehoods rapidly spreading over social media create social division and can threaten American Democracy. For example, in 2013, a false tweet purported from the Associated Press stated that there had been two explosions at the White House, injuring President Barrack Obama., This single tweet plummeted the stock mart valuation by approximately 140 Billion dollars in a matter of minutes.
The algorithms of the social media companies cannot distinguish between true information and false information. The sharing of false information contributes to the undermining of democracy. In a marketplace of ideas and freedom of expression, predictive data models on social media regulate the content users see and interact with on a daily basis. The users are increasingly confronted with misinformation and subliminal messages that the user is unaware is influencing the users actual behavior. Americans are well aware of the 2016 election interference by Russia in 2016 through the use of Facebook; however, at least six other countries including China, India, Iran, Pakistan, Saudi Arabia, and Venezuela, have engaged in large scale misinformation campaigns across international borders. These international cross-border cyber-attacks may support allegations of cyber warfare as authoritarian institutions attempt to interfere with democratic policies, attack the fundamental rights of humans, and engage in the unlawful terror attacks to indue shock, fear and political polarizations.
The power of big technology companies to manipulate social media and influence users can essentially undermine a democratic system. For example, search engine manipulation research has shown that a simple Google search can shift more than 20% of undecided voters in an election and up to 80% of undecided voters in certain targeted demographics. Search suggestions may even sway an undecided voter from a 50/50 split to approximately a 90/10 split without the user knowing that they have been influenced by targeted search engine manipulation. Such manipulation may undermine democracy such that the facial appearance of the democratic system may appear intact; however, citizens may no longer have an actual voice in deciding the winners of elections. Overall, “social media, which was once heralded as a force for freedom and democracy, has come under increasing scrutiny for its role in amplifying disinformation, inciting violence, and lowering levels of trust in media and democratic institutions.”
How are Technology Companies Commercializing User Data?
Generally, many technology companies, such as Facebook, Inc., ByteDance, Ltd., Alphabet, Inc., and Amazon.com, Inc., derive revenue through the sale of advertisements to third parties. These companies offer its users free services; for example, Facebook, Inc. offers a free social media platform allowing its users to connect and share content with one another and Alphabet, Inc. allows its users to freely search for information on its world renowned search engine, Google. These technology companies share user data with third parties so third parties can target advertisements based on the third parties desired demographic. Shared data may include personal user information such as the user’s name, internet protocol address, age, and gender. These companies also collect residual data from the user’s interaction with third party websites and applications. The use of residual data can be quite invasive to a user’s privacy, for example, the use of residual data has escalated as evidence in legal disputes and criminal prosecutions.
Facebook, Inc.
Facebook, Inc. owns and operates multiple social media applications including Facebook, Instagram, and WhatsApp. These social media applications are designed for users to connect with each other and share literature, pictorial and graphic, audio-visual works, and other content. The user of Facebook, Inc.’s applications, however, generates no direct revenue for Facebook, Inc. through its use of the free social media applications. Facebook, Inc. generates substantially all of its revenue from advertisements purchased by third parties to be displayed on the social media applications. The third parties purchase the advertisements and the advertisements are displayed on a variety of Facebook, Inc.’s products. As Facebook, Inc. generates more users and gathers more data, the advertisement business model becomes more successful and produces greater revenue for Facebook, Inc. In fact, all of Facebook, Inc.’s revenue collected from Facebook, Instagram, and WhatsApp is dependent on targeting advertisements based on the collected residual data of the user. The residual data is a compilation of data signals depicting the users internet activity on third party websites and services not owned by Facebook, Inc.
Facebook, Inc.’s worldwide active monthly users has grown from approximately 618 million active daily users at years end of 2012 to approximately 2.26 billion active daily users as of Dec. 31, 2019. Over the span of approximately 8 years, Facebook’s active monthly users has grown approximately 366% and has reached roughly 30% of the worldwide population. The population reach of Facebook allows Facebook to gather massive amounts of data about its users. Using this data, Facebook uses predictive analytics to track user behaviors to target advertisements, personalize content, and stimulation longer interactions within the Facebook application.
In 2012, Facebook, Inc. admitted to conducting large scale psychological research on its users, essentially experimenting with application design and algorithms without the users informed consent outside of the initial click wrap agreement associated with Facebooks Data Use Policy which users are obligated to agree to when the users account was first created. Through these experiments, Facebook altered the users news feed to either reduce the amount of positive posts a user interacted with or reduce the amount of negative posts a user interacted with. Facebook concluded that the users who experienced reduced positive expressions produced posts that reflected more negative emotions; whereas, users who experiences reduced negative expressions produced posts with more positive outlooks and emotions. The experiment revealed the data company had the ability to inflict emotional contagion on its users. Essentially, through the stroke of the company’s keyboard and through a few lines of code, Facebook, Inc. was able to make users experience more happiness and make other users experience more depression and sadness without notifying the user.
Facebook, Inc. further conducted another social experiment on approximately 61 million of its Facebook users. The experiment focused on exposing certain users to messages promoting the importance of voting and political mobilization. Facebook stimulated the user by displaying subliminal ques on the users timeline and profile to exploit vulnerabilities in human psychology. The results from the social media election posts indicated that Facebook, Inc. was able to directly influence the political expression of the users and mobilized an increased number of users to vote in the election. The experiment revealed the effect of social transmission on real world voting. The results suggest that Facebook, Inc. was likely responsible for a voter an increase in approximately 0.60% voter turnout, or approximately 340,000 voters. After Facebook, Inc. proved that it can influence the outcome of elections, foreign governments capitalized purchasing advertisements and spreading Facebook posts for the sole purpose of influencing the outcome of the United States Presidential Election of 2016. According to the Senate Intelligence Committee, data from Facebook revealed “120 million Russian backed pages built a network of over 3.3 million people . . . [and] over 80,000 organic unpaid posts reached an estimated 126 million real people – more than a third of the [United States] population.” The Federal Election Commission was unable to bad the advertisements because the 1984 law only applies to advertisements that mention a candidate, political party, or federal election or have an election connected or election influencing purpose. The false and misleading posts by foreign nationalists specifically portrayed to ideals of a political parties to cause division among the people. This example specifically highlights the major issues of surveillance capitalism and artificial intelligence. The artificial intelligence that controls what users see and tailors the experience to the user based on the users residual internet trails cannot distinguish between false and misleading information and truth. Essentially, foreign nationals, through Facebook, were able to extort the user data and algorithms to change real world behavior and influence the election of the greatest democracy in the world.
As Facebook, Inc. headlines the mainstream media for data privacy concerns, its founder and Chief Executive Officer (“CEO”), Mark Zuckerberg, has called for governments to propose new regulations to “protect society from harmful content”. Specifically, follow allegations of interfering in the 2016 Presidential election, Facebook, Inc.’s CEO has called for governments to intervene in the regulation of political advertisements on the internet because automated data and content screening systems have difficulty determining what content is considered political and distinguishing between factual and false content. These calls for regulation are centered around censorship of content post and may pose first amendment issues outside of the scope of this paper. The world renowned CEO has not called for regulations revolving around data privacy protections for users. It is unlikely that large technology companies will call for consumer data privacy protections because the regulations would adversely affect the companies advertisement business model, increase operating costs, and decrease revenue. Facebook, Inc. has openly acknowledged that changes to the regulatory environment of its products, which are the sale of advertisements, would adversely affect its influx of revenue.
Following Facebook, Inc.’s involvement in the 2016 Presidential Election, the Federal Trade Commission compelled Facebook, Inc. to enter into a modified consent order to increase privacy compliance with consumer data privacy laws, such as the California Consumer Privacy Act and the General Data Protection Regulation. Per the agreement, Facebook, Inc. must comply with the following regulations:
- Facebook, Inc. must exercise greater oversight over third-party apps, including by terminating app developers that fail to certify that they comply with Facebook’s platform policies or fail to justify their need for specific user data;
- Facebook, Inc. is prohibited from using telephone numbers obtained to enable a security feature (e.g., two-factor authentication) for advertising;
- Facebook, Inc. must provide clear and conspicuous notice of its use of facial recognition technology, and obtain affirmative express user consent prior to any use that materially exceeds its prior disclosures to users; and,
- Facebook must establish, implement, and maintain a comprehensive data security program; Facebook must encrypt user passwords and regularly scan to detect whether any passwords are stored in plaintext; and Facebook is prohibited from asking for email passwords to other services when consumers sign up for its services.
These regulations by the Federal Trade Commission enhance the current compliance regulations established by the California Consumer Privacy Act and the General Data Protection Regulation.
Legislative policies and federal regulations are changing the landscape of how these large technology companies implement its user data. The regulations must establish standards and requirements for companies like Facebook, Inc. to protect the privacy interests of the users. These policies will change the social media environment and the way these companies pursue surveillance capitalism. Facebook, Inc. has expressly acknowledged that “compliance with the [Federal Trade Commission] consent order, the [General Data Protection Regulation], the [California Consumer Privacy Act], and other regulatory and legislative privacy requirements will require significant operational resources and modifications to [its] business practices, and any compliance failures may have a material adverse effect on [its] business, reputation, and financial results.”
ByteDance, Ltd.
Headquartered in Beijing, China, ByteDance, Ltd. is an internet technology company most commonly known for its social media application, TikTok, which has amassed worldwide popularity among its users. TikTok has been downloaded by approximately 175 million United States users and over one billion users worldwide. On May 15, 2019, United States President, Mr. Donald J. Trump (hereinafter, “President Trump”), issued Executive Order No. 13873, Securing the Information and Communications Technology and Services Supply Chain (hereinafter, the “Executive Order 13873”). The Executive Order 13873 instructed the United States Department of Commerce to “identify, assess, and address certain information and communications technology and services transactions that pose an undue risk to critical infrastructure or the digital economy in the United States, or an unacceptable risk to United States national security or the safety of United States persons.” Following inquiry by the Secretary of Commerce, President Trump issued, on August 6, 2020, Executive Order No. 13942, Addressing the Threat Posed by TikTok, and Taking Additional Steps to Address the National Emergency With Respect to the Information and Communications Technology and Services Supply Chain (hereinafter, the “TikTok Order”). The TikTok Order revealed that TikTok automatically captures and records user information such as global positioning system location data, browsing, search history, cookies, and residual third party data. The extensive and invasive data collection may allow the Chinese Communist Party to access the users personal and proprietary information, creating a national security risk for Americans. Such information could allow the foreign government to “track the locations of Federal employees and contractors, build dossiers of personal information for blackmail, and conduct corporate espionage.” Besides the invasive usage of its users data and private information, TikTok has also allegedly censored content deemed politically incentive to the Chinese Communist Party including the Hong Kong protests revealing China’s treatment of Uyghurs and other Muslim minorities.
According to TikTok, et al. v. Donald J. Trump, President of the United States, et al., the Secretary of State concluded that ByteDance, Ltd. Stored the American data on servers controlled by Alibaba, a Chinese company controlled by the laws of the People’s Republic of China, which require surveillance and intelligence operations by its technology companies. The Secretary of Commerce also detailed the information TikTok gathers on its users. Specifically TikTok gathers substantial information regarding:
- registration information, such as age, username and password, language, and email or phone number;
- profile information, such as name, social media account information, and profile image;
- user-generated content, including comments, photographs, videos, and virtual item videos that you choose to upload or broadcast on the platform;
- payment information, such as PayPal or other third-party payment information (where required for the purpose of payment);
- phone and social network contacts (names and profiles);
- opt-in choices and communication preferences;
- information in correspondence users send to TikTok; and,
- information sent by users through surveys or participation in challenges, sweepstakes, or contests such as gender, age, likeness, and preferences.
The information gathered can likely be used to extort the users, whether directly through use of the information, or indirectly through targeted advertisements and censored content. TikTok justifies the collection of its user data and its subsequent sharing with the People’s Republic of China and the Chinese Communist Party through its click wrap agreement where users provide consent when first creating an account.
Please note that the action, filed by TikTok, seeks injunctive relief from the TikTok Order and alleges that the United States actions violate the Administrative Procedure Act, the First Amendment, and the Due Process Clause of the Fifth Amendment to the United States Constitution, exceeds the President’s and Secretary of Commerce’s authority under IEEPA, and violates the takings clause of the Fifth Amendment to the United States Constitution, the merits and outcome of which exceed the scope of this paper.
Alphabet, Inc.
Alphabet, Inc. is the parent company of Google, LLC (hereinafter “Google”). Google states that it does not engage in the sale of the personal data collected on its users; however, Google operates through a process called real-time bidding. Real time bidding allows businesses to purchase advertisements in real time to be displayed to users that fit the businesses desired demographic. Google will provide the advertisers with anonymous lists of internet protocol addresses and the respective users characteristics including age, phone number, and email. This personal data is never sold to the advertising business. Google simply provides the businesses with a list containing the users information and allows the businesses to bid against one another for the purchase of an advertisement. Therefore, Google does not directly sell the information of its users; it uses the information for the sale of advertisements.
A pending class action lawsuit against Google alleges that Google tracks and collects is users information while the user is practicing safeguards to protect its data, specifically, while the user is web-browsing on Google’s private browser mode. Over 70% of online websites and publishers on the internet utilize Google Analytics, a Google business optimization software. The product allows businesses to gather data from its visitors regardless if the user believes they are opting out of tracking by using a private or protected browser. The complaint alleges that the Google product’s communicate with the web browser to record visitor information. Google servers record the user’s internet protocol address and the associated visited website to build a profile with the associated internet protocol address. Each instance when a user visits a website or enters information, the Google Analytics track the users activity to build the profile about the user. The user profile is then distributed to businesses willing to bid on advertisements targeted towards the user’s demographic. This complaint alleges violations of the California Invasion of Privacy Act. The complaint, filed on June 6, 2020, is ongoing as of this writing in the United States District Court for the Northern District of California.
In addition to gathering information from a user’s internet browsing, the growth of the smart home market has opened additional avenues for such companies to gather user information. Google, as well as companies such as Amazon.com, Inc., have developed smart home technologies to enhance the control a user has over its home. Many of the smart home technologies, including Google Home, Google Nest Thermostat, Amazon Alexa, Ring, smart plugs, and in home camera’s, incorporate sensors to detect environmental stimuli, such as humidity, movement, voice detection, etc. Both Google and Amazon record and store the biometric information obtained by the smart home devices. Google and Amazon.com, Inc. allow users to request information the respective company has stored relating to the user. For example, stored user data requested from Amazon.com, Inc. and Google revealed that the technology companies each stored and recorded approximately two thousand (2,000) biometric voice recordings each. Shifting through the thousands of voice recordings reveled conversations recorded without commanding the Google Home or Amazon Alexa using the voice command “Hey Google” or “Alexa”. These conversations were made within the privacy of the user’s home and bedroom, recording voice conversations without the user’s knowledge.
Amazon.com, Inc.
Amazon.com, Inc. (hereinafter “Amazon”) is an ecommerce marketplace and technology company. Because Amazon is a marketplace of goods, Amazon regularly shares personal user information with third party manufacturers and distributers, and third party payment processing services. In addition to the personal information that Amazon collected and shared on its users including age, gender, address, phone numbers, credit card numbers, and internet protocol addresses, Amazon collected and shared biometric information, including voice profile from an enabled feature on Amazon’s Alexa; geolocation data, such as the location of the users device or computer; audio of visual information, such as voice recordings when the user speaks to Amazon’s Alexa, or images and videos collected or stored in connection with Amazon Services including Amazon Ring; internet or other electronic network activity information, including content interaction information, such as content downloads, streams, and playback details; commercial information, such as purchase and content streaming activity. Additionally, Amazon makes clear that it has not sold any of its users personal identifying information “as it is defined in the California Consumer Privacy Act”.
Following the enactment of the California Consumer Privacy Act, which will be extensively discussed below in Section V, Amazon has attempted to become more transparent about its use and collection of user data. However, in becoming more transparent, Amazon has broadened its disclosures. For example, instead of stating that Amazon collects “voice recordings when the user speaks to Amazon’s Alexa”, Amazon states that it “automatically collect[s] and store[s] certain types of information about [the user’s] use of Amazon services, including information about [the users] interaction with content and services.” Amazon further details examples of the information collected which does include voice recordings and interactions with Alexa voice services. Like Facebook, Inc., ByteDance, Ltd., and Google, Amazon collects internet cookies and residual internet data from its users to provide advertisement companies with information that allows them to target advertisements to a certain users demographic.
After comparing the information Amazon collects and distributes for business purposes about its users before and after the California Consumer Privacy Act, little, if any differences have been changed following the enactment of the California Consumer Privacy Act. Amazon’s collection of personal information about its customers and the exploitation of its user’s data provides uncertainty about the effectiveness of the California Consumer Privacy Act. Amazon’s limited changes in the data it collects and distributes about its users highlights the limitations that the California Consumer Privacy Act poses, and it emphasizes that the California Consumer Privacy Act may not adequately protect the privacy of consumers.
Consumer Data Protection Laws
Increasing concerns over the use and exploitation of consumer data by large technology companies has prompted various legislation and discussion around the world. In effort to combat the exploitation of consumer data by technology companies various state legislative bodies have taken initiative to strengthen the data privacy laws. Led by the California Consumer Data Protection Act (hereinafter the “CCPA”) and the European Union General Data Protection Regulation (hereinafter the “GDPR”), state legislatures are beginning to model legislation and adopt consumer data protection regulations based on these novel privacy bills to protect the interests of its constituents. The State of Illinois has gone as far as to pass data privacy legislation regulating the use of biometric information in its novel bill titled the Illinois Biometric Information Privacy Act (hereinafter the “BIPA”). The State of New York has also passed the Stop Hacks and Improve Electronic Data Security Act (hereinafter the “SHIELD Act”). Below is a brief summary and discussion of each landmark data privacy legislation. The analysis briefly discusses the purpose each law seeks to achieve, the protections that each law grants to the personal information of users and consumers, and the relief options available to users and consumers who may have been harmed by the release of personal information. Furthermore, this discusses draws concern to potential limitations in the legal framework of each the data privacy laws such that each respective law may not adequately achieve the goal of protecting private consumer information.
California Consumer Privacy Act (CCPA)
The purpose of the CCPA, which was signed into law on June 28, 2018 having an effective date of January 1, 2020, is to give consumers more control over the personal information that businesses and technology companies collect about them. It is important to understand that this law is California State Law; therefore, the law only governs the State of California. However, the CCPA has a ‘long arm’ provision such that any business that conducts business in the State of California and either has a gross annual revenue of over $25 million; buys, receives, or sells personal information of 50,000 or more California residents, households, or devices; or derives 50% or more of its annual revenue from selling California resident’ personal information, must abide by the CCPA.
As a protected class under the CCPA, the consumer has a right to know the personal information that a business collects about them, how it is used, and how it is shared with third parties. Therefore, the CCPA includes a notice provision such that businesses must publicly disclose the information they collect about its consumers and users. Businesses allow users to request their complete profiles of data that have been collected by the businesses because, in addition to the right-to-know, each consumer may request the business to delete their personal information and opt-out of the sale of their personal information to third parties
For purposes of the CCPA, personal information is defined as “information that identifies, relates to, . . . , or could be reasonably linked . . . with a particular consumer or household [including] identifiers such as real name, alias, postal address, Unique personal identifier, online identifier, Internet protocol address, email address , account name, Social Security number, driver’s license number, passport number, or other similar identifiers; commercial information including records of personal property , products or services purchased , approved, or considered, or other purchasing or consuming histories or tendencies; biometric information; Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding a consumers interaction with an Internet website, application, or advertisement; geolocation data; audio, electronic, visual, thermal, olfactory, or similar information; professional or employment related information; and education information defined as information that is not publicly available.”
Generally, a business operating under the jurisdiction of the CCPA cannot engage in the sale of personal information. As previously discussed above, big technology companies have a business model that revolves around the sale of advertisements that discloses personal information to third parties. However, the CCPA provides an exception to the general rule such that a business does not engage in the sale of personal information if the “business uses or shares with a service provider personal information of a consumer that is necessary to perform a business purpose and (i) the business has provided notice of that information being used or shared in its terms and conditions, and (ii) the service provider does not further collect, sell, or use the personal information of the consumer except as necessary to perform the business purpose.” Therefore the advertisement business models that companies like Facebook, Inc, Alphabet, Inc., and Amazon.com, Inc. rely on to generate revenue are exempt from the CCPA because simply by providing notice of its data policies and uses in its terms and conditions.
Furthermore, the CCPA does not provide a private right of action for users. If a user believes that a business violated the CCPA or if the user was harmed as a result of the sale of personal information then the user generally cannot sue the business. The user may only sue the business for violations of the CCPA if the violation was a caused by a data breach that was a result of the businesses failure to maintain reasonable safeguards. Again, the standard of compliance for the business is reduced, to a reasonable standard. The users that was damaged by the sale of private information may only resort to complaints to the business and the attorney general, of which the business is further provided a 30 day opportunity to cure the breach. Overall, the CCPA facially appears as a data privacy stronghold; however, the CCPA lacks the foundations to hold businesses accountable for their actions and ensure that businesses maintain the privacy of personal information. The CCPA is merely a transparency policy by which businesses have to provide notice in its terms of service to its users about the information it captures.
European Union General Data Protection Regulation (GDPR)
The GDPR is the landmark data protection regulation of the European Union applicable to the 27 member countries of the European Union, including, Austria, Belgium, Bulgaria, Croatia, Cypress, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden. However, even countries and businesses not within the European Union may still have to comply with the GDPR because of its extraterritorial reach such the GDPR applies to any processing of personal data of subjects who are within the European Union and its processing activities are related to the offering of goods or services, irrespective of whether a payment of the data subject is required; or the monitoring of the behavior of the data subject is within the European Union. Therefore, any business or country conducting business within a member country or having users or consumers in a member country may have to abide by the GDPR. The intent of the GDPR was to be written to broadly protect personal data of its member citizens; however, there may be scenarios where the wording of the territorial reach will not apply where a third party that offers goods or services to the European Union redirects the consumer at the point of purchase to another third party site not specifically advertising to the European Union. Such a scenario may exist with e-commerce websites that redirect to the host website to actually purchase the product. The type of services that may evade the protection of the GDPR may include drop shipping, which is an order fulfilment method where the seller does not actually manufacture or keep inventory of product; rather, the seller passes on the consumers data of the order to a third party website that will ship directly to the consumer. The third party never engaged in the offering of goods or services to a member citizen of the European Union, thus that business may not subject to the GDPR. For example, drop shipping commonly occurs through ecommerce marketplaces in the United States such as Amazon.com, Inc. and eBay, Inc.; and through Chinese ecommerce marketplaces such as AliExpress, DHGate, and Alibaba. Therefore, the third-party fulfillment services may not be required to comply with the terms of the GDPR.
Effective May 25, 2018, the purpose of the GDPR is to protect the fundamental rights and freedoms of natural persons, particularly with regards to the processing of personal data and the free movement of personal data. Personal data, as defined in Article 4 of the GDPR, “means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, psychological, genetic, mental, economic, cultural or social identity of that natural person.” This definition is similar to that of the CCPA. The CCPA definition for personal information is more specific, yet the GDPR definition leave open the availability of broad interpretation. Unlike the CCPA, which focuses on the ‘sale’ or personal information, the GDPR is concerned with the processing of information by which processing is defined as “any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.” Based on the aforementioned limitation in the extraterritorial reach of the GDPR, the personal data of the users would be better protected if the GDPR required proactive supervisory roles by businesses to maintain detailed, accurate, and disclosed data trails as the data is processed between the business and any third-parties.
In addition to the difference between the GDPR and the CCPA with regards to the processing of data and the sale of data respectively, the GDPR provides remedies to users unlike the remedies available under the CCPA. Specifically, the GDPR provides users with the opportunity to lodge a complaint with supervisory authority and seek judicial remedy. Therefore, a user essentially has a private right of action against businesses for damages resulting from violations of the GDPR. In fact, persons harmed by such violations have the right to receive financial compensation for damages suffered. In addition to liability for damages, businesses in violation of the GDPR may be subject to administrative fines of up to 10 million euros or up to 2% of the total worldwide annual turnover of the previous financial year, whichever is greater. The penalties for violating the GDPR is quite substantial; therefore, businesses have an incentive in abiding by the regulations set forth and protecting private user information.
Illinois Biometric Information Privacy Act (BIPA)
Enacted in 2008, BIPA is the earliest legislation of the CCPA, GDPR and SHIELD Act. The legislature of the State of Illinois recognized the growing use of biometric information in the practice of businesses, security screening sectors, and in the financial transactions sector. The fear that resonated with the legislature was that biometrics are biologically unique to individuals and cannot be readily changed when compromised as compared to financial information and social security numbers which can be issued anew. Therefore, the legislature enacted BIPA to safeguard the collection, use, handling, storage, retention, and destruction of biometric identifiers and information.
BIPA was enacted ahead of the popularity of biometric identifiers and accurately foresaw its dominant use in technology sector. For example, Facebook, Inc. did not implement facial recognition until 2010; Apple Inc. did not implement ‘Touch ID’, its fingerprint recognition software used to unlock the iPhone, until it unveiled the launch of the iPhone 5S in 2013; Apple Inc. did not implement its ‘Face ID’, which is facial recognition software used to unlock the iPhone, until 2017 with the launch of the iPhone X. The State of Illinois took prophylactic measures against biometric implementation by social media companies by enacting BIPA.
Biometric Identifiers under BIPA means “a retina or iris scan, fingerprint, voiceprint, or can of hand or face geometry. Biometric Identifiers do not include writing samples, written signatures, photographs, human biological samples used for valid scientific testing or screening, demographic data, tattoo descriptions, or physical descriptions such as height, weight, hair color, or eye color. Biometric identifiers do not include donated organs, tissues, or parts as defined in the Illinois Anatomical Gift Act or blood or serum stored on behalf of recipients or potential recipients of living or cadaveric transplants and obtained or stored by a federally designated organ procurement agency. Biometric identifiers do not include biological materials regulated under the Genetic Information Privacy Act. Biometric identifiers do not include information captured from a patient in a health care setting or information collected, used, or stored for health care treatment, payment, or operations under the federal Health Insurance Portability and Accountability Act of 1996. Biometric identifiers do not include an X-ray, roentgen process, computed tomography, MRI, PET scan, mammography, or other image or film of the human anatomy used to diagnose, prognose, or treat an illness or other medical condition or to further validate scientific testing or screening.”
BIPA also defines biometric information and confidential and sensitive information. “Biometric information means any information, regardless of how it is captured, converted, stored, or shared, based on an individual's biometric identifier used to identify an individual. Biometric information does not include information derived from items or procedures excluded under the definition of biometric identifiers. Confidential and sensitive information means personal information that can be used to uniquely identify an individual or an individual's account or property. Examples of confidential and sensitive information include, but are not limited to, a genetic marker, genetic testing information, a unique identifier number to locate an account or property, an account number, a PIN number, a pass code, a driver's license number, or a social security number.”
To protect the users private biometric information, BIPA prohibits businesses from “collecting, capturing, purchasing, receiving through trade or otherwise obtaining a persona biometric information unless the [business] first, and in writing, informs the individual that biometric information is being collected or stored, the specific purpose and length of time for which the biometric information is being collected, stored and used, and receives the individuals written consent to the collection, use or storage of biometric information” and BIPA further prohibits businesses from selling, leasing, trading, or otherwise profiting from a person’s biometric information.”
Because the implementation of biometric processing in technology did not take off until the early decade of 2010, BIPA did not gain legal traction until the punitive class action lawsuit against Facebook, Inc. in 2015. Facebook, Inc. went on to settle the class action lawsuit for $650 million, the largest cash settlement for a data privacy related lawsuit, after the Ninth Circuit Court of Appeals affirmed the district courts class certification in 2018 and further denied Facebook, Inc.’s petition for a rehearing en banc. The lawsuit against Facebook, Inc. alleged violations of BIPA with regards to Facebook’s automatic ‘tag’ feature on photos which it would recognize facial features in photographs and suggest that a person that matches the facial recognition be tagged in the photo. A benefit of BIPA is that it provides plaintiffs with a private right of action. The Supreme Court further enhanced the benefit of the private right of action by holding that “an individual need not allege some actual injury or adverse effect, beyond violation of his or her rights under the Act, in order to qualify as an “aggrieved” person and be entitled to seek liquidated damages and injunctive relief pursuant to the Act.” The private right of action provides users with an adequate remedy for relief and provides businesses with an incentive to comply with BIPA because violations could result in liability of statutory damages up to $1,000 for each negligent action, and up to $5,000 for each intentional or reckless violation. These damages add up substantially when BIPA also permits class action lawsuits. If this policy were standardized around the world, Facebook, Inc., for example, having approximately 2.2 billion monthly users across its platforms could be substantially harmed by a class action lawsuit for damages.
Stop Hacks and Improve Electronic Data Security Act (SHIELD Act)
Recently, on March 21, 2020, the SHIELD Act became effective within the State of New York which applies to “any person or business which owns or licenses computerized data which includes private information” of a New York resident. In light of both the passing of the CCPA and BIPA, the State of New York chose to adopt similar language with respect to the definition of personal information. The SHIELD Act chose to distinguish between personal information and private information. Personal information is defined as “information concerning a natural person which, because of name, number, personal mark, or other identified, can be used to identify such natural person”; whereas, private information is defined as “either: (i) personal information consisting of any information in combination with any one or more of the following data elements, when either the data element or the combination of personal information plus the data element is not encrypted, or is encrypted with an encryption key that has also been accessed or acquired:
- social security number;
- driver’s license number or non-driver identification card number;
- account number, credit or debit card number, in combination with any required security code, access code, password or other information that would permit access to an individual’s financial account;
account number, credit or debit number, if circumstances exist wherein such number could be used to access an individual’s financial account without additional identifying information, security code, access code, or password; or
biometric information, meaning data generated by electronic measurements of an individual’s unique physical characteristics, such as a fingerprint, voice print, retina or iris image, or other unique physical representation or digital representation of biometric data which are used to authenticate or ascertain the individual’s identity; or
(ii) a user name or e-mail address in combination with a password or security question and answer that would permit access to an online account.” Similar to the CCPA, the “private information does not include publicly available information which is lawfully available to the general public from federal, state, or local government records.” As defined in the SHIELD Act, personal and private information is very specifically defined, leaving little room for broad interpretation unlike the GDPR which defines personal information broadly and the CCPA which defines personal information into broad categories of information.
To the benefit of the user and the consumer, the SHIELD ACT requires businesses to develop, implement, and maintain reasonable safeguards to protect the security, confidentiality, and integrity of the private information of its users. Each data security program must maintain reasonable safeguards to ensure the protection of its user’s private information where such reasonable safeguards should include designating an employee or employees to coordinate the data security program; training and managing employees in the security program practices and procedures; assessing internal and external risks and implementing controls to reduce those risks; vetting service providers and binding them contractually to safeguard private information; and, securely destroying private information within a reasonable amount of time after it is no longer needed for business purposes. These safeguards ensure that there is adequate notice of the use and collection of personal information as well as control over the chain of data between the user, business, and any third party services. Knowledge of the chain of data may allow businesses and users to adequately track data breaches and hold violating parties accountable for illegally exposing private user data. However, such penalties for violations of the provisions of the SHIELD Act, including the notification and disclosure requirements and the safeguard requirements, may not adequately hold an infringer accountable for its actions.
Unlike the heavy penalties imposed by the GDPR to disincentive businesses from violating the provisions of the act, the SHIELD Act only imposes penalties on businesses in the amount of five thousand dollars or up to twenty dollars per instance, whichever is greater, provided that the latter does not exceed two hundred fifty thousand dollars. The violating business may also be liable for damages for actual costs or losses incurred by the damaged persons resulting from the violation. These penalties do not impose enough liability on the business to protect the data, especially large companies generating multi-million dollars per year in revenue.
The Problems
Guided by the aforementioned use cases, current technology companies are exploiting data and privacy regulations because the data regulations fail to adequately protect consumers data. The existing regulations, led by the California Consumer Privacy Act which will be discussed below, seek to protect the sale of the consumer information to third parties. As previously stated, the technology companies are not engaging in the sale of consumer information; rather, the technology companies practice in the sale of advertisements. The advertisements are sold to a third-party company with a desired demographic. The third-party company seeking to increase its sales through targeted advertising relays it is the demographics of its target consumer to the technology company wherein the said technology company distributes the target consumer’s viewable content. This example is simply a sale of advertisements guided by consumer data that is not directly sold to third parties. Therefore, the main problem with current data regulations is that the ‘sale’ of business information is not adequately defined or provided too many exceptions to the general rule. For example, the current data regulations mandates notice disclosures and safeguards, yet provides sales use exceptions for business purposes and limitations on liability for damages.
The second problem is that a majority of the current data privacy laws do not provide a private right of action. Therefore, if a business violates data privacy laws and engages in the misappropriation of personal information, then a harmed user may not be able to sue for damages. Usually, only the Attorney General of the State may bring action against the company. Therefore, businesses may be disincentivized to fully comply with data protection laws.
Furthermore, despite the actual use, exploitation, and manipulation of user data by technology companies, an additional problem that exists is that a majority of the data and private information is collected and stored by a select few companies that dominate the market share as big technology. Current data regulation does not address this issue. The issue of market dominance in data privacy is governed by federal antitrust laws. Analysis of big technology with regards to federal antitrust laws is outside the scope of this paper. The sheer market dominance of big technology companies provides no alternatives for users to find similar services. Specifically, the market dominance combined with the business model structure creates the perfect recipe for surveillance capitalism. Where businesses offer free services to users and dominate the market there is simply no available options to users. Therefore, users are required to opt into click wrap agreements to access the services of these market dominant companies that of which will contribute to the users consent to the use of personal data by the technology companies. This issue was previously exampled by the Facebook use case above. Given the state of commerce today and the size of the large technology companies, a user would likely struggle to adapt daily life without using services offered by companies such as Google, Amazon.com, Inc, and Facebook. This proposition suggests that the only true solution to the data privacy problem may rely on backs of antitrust laws which will be briefly discussed below.
The Legal Dilemma
Overall, large technology companies have systematically implemented technology to collect, use, and exploit user data to target their interest and commercially benefit from the advertising model of their companies. The legal dilemma legislatures face is whether to increase regulation over the use and collection of user data by large technologies to benefit and protect the personal information of the user at the expense of personalized technology for a better user experience.
Current data and privacy regulations fail to address the problems with surveillance capitalism which are leading to user influence and manipulation and which can potentially lead to the downfall of democracy through the spread or misinformation and targeted content. Companies such as Facebook, Inc., ByteDance, Ltd., Alphabet, Inc., and Amazon.co, Inc. use advanced algorithms to target content to users based on the user’s interests. The companies generate the user’s interest through the collection, analyzation, and storage of the user’s data. Once the user’s interests are aligned, these technology companies sell advertisements to the target consumer based on the interests of the user and the demographic of the product being advertised.
If lawmakers choose to further advance the data privacy protections, then lawmakers should focus on regulating the use specifically with regards to targeted algorithms and the sale of targeted advertisements. Such regulation would effectively tackle the growing problems with surveillance capitalism. Provide business with use exemptions and limited liability for damages allow companies to continue to exploit the advertisement business models to their commercial gain.
Additionally, if data privacy regulation cannot regulate the business structures of the large technology companies, then antitrust actions may need to be brought against the large technology companies to protect the personal information of the users. Most recently, antitrust lawsuits have been brought against Facebook, Inc. and Alphabet, Inc. for their control of the marketplace and excluding competitors from offering services that may better protect the privacy of the user’s data and protect the freedom of expression, association, and privacy of individuals on the internet.,