Who Leads at Half-time? Three Conflicting Visions of Internet Privacy Policy

by Karl D. Belgum[*]

Cite As: Karl D. Belgum, Who Leads at Half-time?: Three Conflicting Visions of Internet Privacy Policy, 6 RICH. J.L. & TECH. 1, (Symposium 1999) <>.[**]

Table of Contents:

I. Introduction

II. Threats to Privacy Online

III. The Current State of Privacy Regulation

IV. Critiques of Privacy Policy

V. Who Leads at Halftime?: Current Privacy Initiatives in the United States

VI. Conclusion

I. Introduction

{1} Concern about privacy on the Internet runs high, but the prescriptions for treatment vary widely. Privacy advocates seek different goals when formulating policy proposals. Some seek to protect individuals and society from the effects of loss of privacy, including the loss of human dignity. Others seek to encourage the development of online markets in personal information, so that consumers can profit from their own information, rather than giving it away. Still, others seek primarily to promote the growth of e-commerce, and see privacy fears as a threat to that goal. These goals are fundamentally inconsistent, and that inconsistency is obscured by the fact that much of the current debate about online privacy focuses on the tools of regulation, rather than the goals for which regulation is sought.

{2} Part I of this article will briefly survey the current concern over online privacy, why it is considered important, and how it is threatened. Part II will identify three distinct perspectives in current thinking about Internet privacy, which will be defined as the "dossier society pessimists", the "market opportunists", and the "privacy peacemakers". Part III reviews current policy initiatives regarding online privacy to see which of the schools of thought identified above predominates in the public policy debate. That section concludes that such initiatives generally fall into the "privacy peacemaker" camp, aiming to control the worst and most visible abuses of privacy, so as to avoid impairing the growth of e-commerce. Current initiatives are not aimed at promoting the goals of the market opportunists, who hope to see markets in personal information develop online; nor are they aimed at averting or reversing the advent of dossier society so feared by the dossier society pessimists.


II. Threats to Privacy Online

A. Public concern over online privacy

{3} From the perspective of many policymakers, the perception that privacy is at risk online is as important as the reality. Public opinion polling data are frequently cited to support the need for privacy regulation.[1] One of the most frequently-cited surveys is an Equifax/Harris poll reported in the March 1998 issue of Business Week, which indicated that two-thirds (2/3) of non-Internet users said they would be more likely to begin using the Internet if their privacy were assured.[2] Non-users cited privacy as the most important reason for staying off the Internet -- more important than cost or technical complexity.[3] Of those using the Internet, seventy-eight (78) percent said they would use it more if their privacy were guaranteed.[4]

{4} Not only do the polling data indicate that individuals view privacy as a fundamental value, they also highlight the concern among Internet promoters that privacy fears may slow the public's acceptance of e-commerce, which is an important practical reason for the government to address those concerns.[5]

{5} While the majority of commentators accept the polling data at face value, a dissenting position also exists. The dissenters point out that techniques for protecting online privacy have existed for years, but are not well utilized. Anonymizer services have been available for some time that mask the identity of online users, for a nominal cost. Most users do not take advantage of them;[6] however, either because of the perceived technical complexity of using them, the price, or the mere fact that users do not care as much about privacy as advocates contend.[7] In addition, polling questions which simply ask "do you care about privacy online" are bound to generate more positive responses than surveys that ask respondents to rank privacy in importance, compared with other public and private issues.[8] Regardless of these observations, however, the perceived wisdom of policymakers continues to be that privacy is an important value to Americans which must be safeguarded if e-commerce is to achieve its full potential.[9]

B. Nature of the Threat

{6} The Internet raises new threats to privacy, and enhances old threats as a result of the increased data processing capability of computers combined with the data gathering and dissemination potential of the Internet itself. As the Federal Trade Commission staff noted in a 1998 report on one of its privacy workshops:

Globalization and new technologies are radically changing the contours of the late Twentieth Century marketplace. In the 1980's, the personal computer revolution enhanced the ability of government, industry and consumers to capture a vast array of personal information automatically. In the 1990's, the technology underlying the Internet is making it even easier and less expensive to gather, store, analyze, transmit and reuse personal information in ways that were unimaginable just a few years ago.[10]

{7} Personal data, such as address, phone number, income, property value, and marital status have always been available to those willing to dig.[11] The Internet can make it possible for a much wider class of persons -- essentially all Internet users -- to gain access to similar types of personal information at little or no cost.

{8} "Profiling" is the term used to denote the gathering, assembling, and collating of data about individuals in databases which can be used to identify, segregate, categorize and generally make decisions about individuals known to the decisionmaker only through their computerized profile.[12]

{9} There is a perception that such activities conducted online pose a greater threat to privacy than similar activities in the off-line world. Data obtained and recorded in digital form can be preserved indefinitely, and the perception that a permanent record of our movements and actions is recorded and available to posterity is oppressive to many.[13]

{10} The first step in the process of data gathering can be either overt or covert. It is this stage that receives the most attention in connection with policymaking, in part, because it is the stage of which users are most aware. In addition, data gathering may be the stage of the process most amenable to regulation, since it may be the only stage of the process in which the data subject is directly involved and can therefore assert (or meaningfully waive) his rights. Internet users voluntarily disclose a great deal of information about themselves through registration pages, user surveys, online contests, application forms, and transaction documents.[14] Information disclosures may be required as a condition of participating in an online chat room or bulletin board.[15]

{11} In its 1998 survey of online privacy practices, the Federal Trade Commission ("FTC") found that ninety-two percent (92%) of the 1,402 websites surveyed collected some personal data. The most popular items of data were name, e-mail address, postal address and phone number.[16] The FTC found that websites soliciting personal information usually did not contain any posted privacy policy. Only fourteen percent (14%) of websites had any sort of privacy disclosure, and only a single site was found to meet all the criteria of notice, access, security and third-party disclosure identified by the FTC as critical.[17]

{12} Nervousness about solicitation of personal information online may be enhanced by the fact that, unlike brick and mortar businesses that present a "face" to the real world and may have an incentive to maintain a favorable reputation in the community, webpages appear as purely electronic fronts. The user has only a limited ability to peer behind the front to determine who, if anyone, stands behind the behavior of the page sponsor. Indeed, users may not even know the identity of the entity to which they are giving their personal information.[18]

{13} On the other hand, the interactive nature of Internet communications may foster a greater level of trust in some users, particularly children or the unsophisticated. As the FTC staff noted after a workshop on childrens' privacy:

[T]he unique qualities of the Internet make it a particularly intrusive medium for children. The medium capitalizes on 'one to one marketing' and permits the site to develop a personal relationship with the user. For example, with more detailed collection of data on a child, future e-mail solicitations may come from an animated character appearing on the child's screen, addressing him by name and urging him to purchase a specific product -- perhaps a product over which the child lingered the last time he visited the site. The safeguards of traditional broadcast media, which bar 'host selling' and require separation between program, editorial and advertising, do not currently exist online.[19]

{14}Websites can also extract information that users do not voluntarily provide, such as the user's e-mail address, the type of browser, the type of computer being used, and the Internet address (URL) from which the user linked to the current site.[20] Websites can identify repeat users through the use of "cookies", which are small programs inserted onto the user's hard drive by the webpage which are accessed when the user revisits the page at a later date.[21] Websites can track the "clickstream" of the user, recording the portions of the page visited, and individual clicks made within each page.[22] This data can be recorded, stored, aggregated, and analyzed as evidence of consumer preferences by the webpage sponsor.[23]

{15} Recently, attention has focused on hardware and software systems that can assign a unique identification number to each personal computer, and the risk posed by such systems that webpages will be able to identify and track individual users. Controversy erupted in February 1999 over the disclosure that Intel's Pentium III chip contained unique numerical identifiers.[24] Similar controversy arose over the discovery that Microsoft software contains a "Registration Wizard," which assigns a unique identifier to each PC on which Microsoft software is loaded.[25]

{16} The most frequent use of data obtained from non-governmental websites online is marketing.[26] Website sponsors use data about their own visitors to learn which aspects of their page, or the goods and services offered on it, users are drawn to most. Such data may be useful even if collected only in aggregate form. In addition, data tied to the identity of individual users allow the page sponsor to program the page to display custom tailored product and service options, as well as advertising, when the user next visits the page. Individual preference data tied to individual name, address, phone or email address information may be sold to direct marketers or others for use in marketing goods and services bearing no relation to the subject matter of the page or transaction through which the information was originally obtained.

III. The Current State of Privacy Regulation

{17} The response to the above-described threats to privacy has been varied. As usual, where some see risk others see opportunity. However, most commentators appear to agree that existing law provides little protection for personal data online.

A. The tort of invasion of privacy

{18} The common law tort of invasion of privacy does not provide significant protection in the off-line world,[27] let alone the new online environment. The reasons for this are many, having to do with the intellectual history of the tort and its antagonistic posture versus the First Amendment and press defendants.[28]

1. Inadequate scope of the common law torts of invasion of privacy

{19} The tort of invasion of privacy had its origins in the seminal article by Warren and Brandeis in 1890, entitled The Right to Privacy, in which the authors argued for recognition of the tort we would today call "public disclosure of private facts."[29] Through subsequent common law development and legislation, the tort of invasion of privacy became widely established. In 1960, Dean Prosser surveyed seventy years of experience with the tort and declared that, rather than a single tort, there were really four separate and quite distinct torts masquerading as a single right to privacy: (1) the tort of appropriation of one's name or likeness for the commercial benefit of another, as where a person's picture is used in an advertisement without permission; (2) public disclosure of private facts, the tort first championed by Warren and Brandeis and directed squarely at disclosure of personal facts in the tabloid press; (3) the tort of intrusion into seclusion, which has been described as a lesser form of trespass; and (4) "false light", which protects against the public use of one's name or image in a way that imputes to the subject views the subject does not hold or otherwise inaccurate circumstances.[30] Prosser's four part reductionist analysis of the tort proved persuasive and was codified in the Restatement (Second) of Torts, for which he was the reporter.[31] Innumerable law reviews have been written about the origin and nature of the four privacy torts. The important fact for the present discussion is that the four common law torts are generally considered to be irrelevant when it comes to online privacy issues, although a few commentators have argued for expansion of common law rights as a partial solution to online privacy threats.[32]

{20} False light can be rejected immediately as a solution to online primary concerns because it requires some element of falsity.[33] The predominant concern with respect to online privacy is that too much truth will be obtained and disseminated about us; a rule that only bars publication of false information is a non-starter. The tort of intrusion into solitude would appear to be inapplicable online because it requires, as the name implies, an "unreasonable and offensive intrusion into the seclusion of another."[34] Much of the personal data obtained online is provided voluntarily by users, and, in any event, no consensus has emerged that time spent on the Internet constitutes time in "seclusion," except perhaps in seclusion from family members and others in the real world who occupy the same residence as the online user.

{21} The tort of public disclosure of private facts would appear to fail for the same reason. To be actionable, there must be a disclosure of facts that are private.[35] Plaintiffs repeatedly lose such cases upon a showing that the fact in question was already in the public domain where, for example, it was obtained from a public record or other source outside the plaintiff's control, or obtained from plaintiff directly while in a public place.[36] Facts obtained from an online user may not be considered private when voluntarily provided by the user to a "stranger" webpage, or when gleaned from observation of online behavior while visiting the webpage. Moreover, public disclosure of private facts hinges on the embarrassment that accompanies publication of private facts to a wide audience.[37] Online privacy concerns regarding profiling are unrelated to the wide distribution of the personal information. The fact that a marketing firm obtains personal information, and uses or sells it to a limited number of third parties, generally does not involve the same kind of embarrassment because the data remains invisible to the data subject as well as the public at large.[38]

{22} The tort of appropriation also has little apparent application online.[39] What is appropriated from online users is their personal information, which has value in a marketing context. Online information is not used to sell products to others by associating the subject with the product in a testimonial manner or by use of the subject's face on the product packaging. Instead, the information is used to make decisions about how to market products or services to the subject himself. While information about the subject is certainly "appropriated" online, it is not the kind of information, or the kind of appropriation, that has traditionally been the subject of the appropriation tort.

{23} On a more general level, the common law privacy torts fail to protect online privacy because they do not protect actions taken in public,[40] and the Internet is arguably a public environment. The torts protect only private facts, whereas, a great deal of online privacy concern focuses on information that is "personal," without really being "private" -- name, address, phone number, e-mail address, and information regarding our conduct in the presence of, or in transactions with, strangers. Finally, the common law privacy torts are aimed at protecting against egregious conduct which causes a socially unacceptable level of shame or humiliation, a level of protection far more limited than what most consumers seem to want online.

B. Limitations on the current "sectoral" approach to privacy regulation in the United States

{24} Legislative protection of privacy in the United States is sometimes charitably referred to as "sectoral", meaning that legislation is directed in piecemeal fashion toward specific industries or issues, rather than constituting a global privacy policy for the nation as a whole.[41] Apologists for the American system stress the flexibility of this form of regulation, its ability to tailor regulation closely to the needs of individual situations, and its tendency to avoid the sins of overregulation which might accompany a more comprehensive, "one-size-fits-all" regulatory scheme.[42] Less charitably, the current U.S. regulatory scheme could be referred to as a disorganized patchwork thrown up in response to individual, highly-publicized instances of abuse, but leaving certain important areas of privacy underprotected.[43]

{25} Regulation of personal data privacy can be found in a handful of separate federal statutes.[44] Specific statutes protect privacy interests in video rental records,[45] student loan information,[46] and drivers license information.[47] The Fair Credit Reporting Act[48] regulates the conduct of credit reporting agencies. Other statutes specifically limit the ability of the government to disclose personal information about individuals.[49] In addition, several federal statutes protect electronic communications from disclosure.[50]

{26} While no federal agency has general authority to regulate online privacy, unfair and deceptive practices with respect to privacy -- such as posting a privacy policy and then violating it -- may give rise to FTC enforcement action.[51]

IV. Critiques of Privacy Policy

{27} Commentators, legislators and regulators viewing the online privacy landscape and asking the question, "where do we go from here?" arrive at dramatically different answers. The conflicting points of view can be categorized and contrasted in various ways. For this article, I have divided them into three "camps" which I have labeled the "dossier society pessimists", the "market opportunists", and the "privacy peacemakers".[52]

A. The dossier society pessimists

1. What is the dossier society?

{28} The phrase "dossier society" conjures up the image of a society in which every detail of life is recorded and preserved in a central filing system accessible to those with power over their fellow citizens. Concerns about the dossier society certainly pre-date the advent of the computer, especially with respect to surveillance by totalitarian and repressive governments.[53] In 1971, Arthur Miller found that establishment of a dossier society was well under way in America, stating that, "the dossier society's genesis dates back several decades to the federal government's entry into the taxation and social welfare spheres."[54] Miller cited as examples, the federal census and the government's involvement in defense, housing, welfare, and jobs programs, all of which gather and use tremendous amounts of data about individuals in the course of administering various programs. But, with the increasing use of the credit card and the mainframe computer in the 1960's, the critical commentary came to focus increasingly on the abuses that were possible in the private sphere.[55] Numerous popular and academic accounts predicted a dramatic impact on individuals and society from the combination of increased information gathering, data storage capacity, computation abilities, and communicative capabilities of digital computers.[56]

{29} The concerns of dossier society critics are summed up by Professor Vern Countryman in his 1971 article:

The computer has further facilitated the quest for efficiency. With its endless capacity to store data and to regurgitate it with lightning-like speed, it is inefficient not to use the computer to combine the various dossiers compiled on each individual. If the present trend continues, the day will come when the push of a button will produce a complete 'data profile' on each citizen, from his departure from the womb (or perhaps sometime earlier) to some time after he enters his tomb.[57]

2. Concerns about Accuracy, Discrimination and Human Dignity

{30} More specifically, "dossier society" concerns can be discussed under three separate headings: accuracy, discrimination, and human dignity. Unfairness results when decisions are made based on inaccurate data. Inaccuracies can arise in personal information databases when data becomes outdated or stale, or when data is improperly entered in the first instance. In addition, errors or distortions in reading and interpreting data are likely when data is collected (accurately) for one purpose, but is then transferred to another entity for use in answering questions not directly related to the reasons the data was collected in the first instance.

{31} Statistically-generated profiles may mask old-fashioned race prejudice or other illicit biases which are explicitly ruled out of order on grounds of public policy.[58] On a more subtle level, a form of bias may be inherent in the way computers think. The use of computer matching to answer questions about an individual frequently involves an exercise in sorting, matching, and averaging that individual's traits compared with others -- what we in human terms, would call stereotyping. There is something offensive to our notion of individualism when we are judged solely based on the average characteristics of the various classes to which we may be assigned membership, even if there is nothing "suspect" about the classes themselves.[59]

{32} This concern with discrimination is also related to a general concern with the impact that constant monitoring and judging of human behavior have on "human dignity."[60] Critics view the recording of daily events, purchases, communications, and inquiries as a form of surveillance. Data gathering and maintenance through the Internet arguably more resembles surveillance than casual observation in public. Unlike a casual glance in a public space, the "view" of an online observer with respect to online behavior is crisp and clear, since one-hundred percent of online behavior can be captured, and it is unforgettable, since data recorded digitally can be preserved in perpetuity at minimal cost.[61]

{33} One effect of surveillance is to promote law-abiding behavior, and surveillance (more innocuously termed "monitoring") is useful for both education and training, as well as punishment.[62] However, the fear is that constant surveillance inevitably induces caution and self-censorship. Surveillance discourages not only illegal or immoral behavior, but originality, spontaneity, and risk taking in general.[63] Advocates of strong privacy protection maintain that room to experiment and to make mistakes is essential to human growth and a feeling of freedom. There is also a perception that being observed without consent is a form of violation, as reflected in laws regarding wiretapping, eavesdropping, and "peeping Toms."[64]

{34} From a political perspective, the concern is that online digital surveillance will tend to limit dissent and the expression of unpopular opinion.[65] This insight is reflected in cases upholding the right to participate in political activities on an anonymous basis.[66] Even without the assumption that Internet surveillance will be used directly to expose dissenters to public opprobrium, constant monitoring may be harmful to the social fabric in more subtle ways. Preservation of free, unmonitored individual space may be essential to maintenance of a society based on the value of individualism. As a result, the loss of privacy may be harmful not only to the sensitive individuals who feel aggrieved by its loss. It may also constitute a harm to society itself,[67] even if individual members of that society do not mind the loss, and willingly give up their privacy or trade it away for financial or other consideration. The logical consequence of this viewpoint is that society itself has an interest in preventing individuals from exposing themselves to too much loss of privacy.

3. Policy initiatives related to acceptance of the dossier society critique

{35} As a working hypothesis, we can consider public policy pronouncements to embody elements that the dossier society critique if they include certain identifiable features. One such feature would be outright limits on alienability of data, designed to protect individuals and society as a whole from the debilitating effects of the dossier society, despite the pressure posed by technology, commercial markets in information, or just plain citizen apathy.

{36} A second feature would be limitations on the use of personal information databases and data-matching programs to make decisions about individual rights or opportunities.[68] Such measures would reflect the concern with discrimination inherent in such programming.

{37} Third, proposals motivated by dossier society concerns might be expected to place limits on the sheer quantity of data collected or stored. Such limits would include requirements that data be destroyed after a certain period of time, or prohibitions on collecting certain types of data even at all.[69]

{38} Finally, such prophylactic measures would not limit themselves to regulation at the point of data collection, but would extend to data obtained from public records and to other third party sources.

B. The Privacy Market Opportunists

{39} By the label "privacy market opportunist", I mean to describe those who promote the development of markets in personal data.[70] Privacy market opportunists begin with the assumption that, even though privacy may be a "fundamental human right," that does not mean that individuals should not have the ability to decide for themselves how much that right is worth to them personally, and whether to sell, trade or give away their private information in their own self-interest.[71]

{40} As a result, the market opportunist analysis does not focus on the importance of privacy or the role it plays in the lives of individuals or society. Instead, it focuses on describing the theoretical benefits and limitations of free and active markets in private information, identifying obstacles to creation of such markets, and proposing policy measures designed to foster development of such markets.[72] The goal is to let consumers share in the value of their own personal information.[73]

1. Benefits of a market in personal information

{41} Market opportunists observe that the current state of the law results in personal data being too cheaply valued and therefore, overutilized.[74] However, there is also the general recognition that, absent some change in the existing law or technology, efficient markets in personal data are unlikely to emerge any time soon.[75] In short, the current "crisis" in privacy, which results in so much commentary and attention in legal and regulatory circles, is not merely a result of technological changes that make increased surveillance possible; it is also the result of market failures due to poor social choice in the allocation of property rights in information.[76]

{42} Under the existing United States privacy regime, personal data is the property of the person or entity who captures and organizes it.[77] Those favoring the development of markets in personal data reject the assumption that data appropriators necessarily own such data merely because they collected it through their webpage and compiled it into a useful format.[78] Instead, the determination of how to allocation property rights in data must be made based upon an evaluation of the relative amount of information and power in the hands of the parties to the transaction, and the social goals (efficiency usually predominant among them) to be achieved by allowing such trades.[79]

{43} Some commentators have speculated as to what markets in personal data might look like. One vision is of individual consumers entering into transactions online with individual websites, in which requests for information, either overt or surreptitious, prompt the consumer to demand a quid pro quo in the form of either money, or more likely, a credit for additional online goods and services which would otherwise not be free. Others see consumers using intermediaries as information brokers to bundle up the information provided by a "tranch" of 1,000 or more similarly-situated individuals, and to market that information to commercial buyers. Royalties on such sales would be returned to the data subjects in some form, minus a profit for the broker.[80]

{44} It is apparent that in some ways, the Internet is the ideal environment for envisioning the development of markets in personal information. Contract terms can be offered, and consent registered and documented very efficiently online. The personal data itself can be transferred from the subject to the commercial entity online (again, whether overtly or covertly), and the consideration for the trade can flow back to the data subject online as well, in the form of credits for online services.

{45} There is some indication that this world is already upon us. Companies called infomediaries are already springing up to market individual data, and others are offering goods and services online in exchange for personal information.[81] Consumers are already willing to pay for privacy in other areas of their lives, and may be more than willing to enter into privacy transactions online.[82]

2. Obstacles to the creation of markets in personal information

{46} Enthusiasm for markets in individual information is tempered by the practical difficulties accompanying any attempt to set up such markets. First, a great deal of information about individuals is already in the public domain, including information from public and semi-public sources. That information will compete with any information an individual attempts to sell about himself.[83] Second, once an individual sells his information, control of that information is lost. Even if the terms of the contract of sale or license prohibit retransmission to third parties or reuse for purposes not agreed upon, such terms would be very difficult to enforce. Punishment of cheaters and leakers will be difficult and rare. As a result, some admit that exactly how a market in privacy would actually work in practice is only dimly understood at this point.[84]

{47} Moreover, asymmetries in information and bargaining power may result in built-in advantages for commercial information appropriators, as compared with individual data subjects. The buyer will usually know more about the anticipated use of the information than the seller. A consumer may face relatively high costs in the form of money, time and inconvenience by turning down an online transaction merely because it would entail certain information disclosures; whereas, to the merchant, one individual's potential transaction may be far too insignificant to make it worth bargaining over privacy rights on an individual basis.[85] On the other hand, the attempt to establish a market in personal information, combined with recognized property rights in such data, may require creation a legal and enforcement system with an unacceptably high level of expense and complexity.[86]

{48} In light of the above concerns, one may wonder whether any markets in individual information are likely to develop. This author tends to think such markets will develop simply because the consumer is always in possession of at least one key piece of information that is unavailable from public sources, and as such, because it changes daily, is always fresh and valuable for sale. That information consists of the consumer's own subjective interest in being marketed a given product, service, or subject matter. An individual who wakes up one morning with the desire to buy a new car or a set of golf clubs has something valuable to sell in the form of his own subjective state of mind. This information has a short shelf life and may not be available to marketers through any source other than the consumer himself.

3. Policy initiatives of the market opportunists

{49} The first principle for any market opportunist, of course, must be that the law should allow transactions in personal information to occur. They would oppose inalienability rules preventing individuals from determining whether to sell information about themselves or how much to charge for that information.[87]

{50} In general, proponents of markets in personal data would encourage government action intended to equalize information among participants in data transactions by requiring websites to post privacy policies, disclose the use being made of information gathered online, and otherwise ensure that consumer consent is meaningful when obtained.[88] Proponents of markets in personal information suggest modifying the "default rule" as one way to equalize information.[89] The present default rule is that, absent explicit agreement to the contrary, the webpage sponsor is presumed to be the owner of any information obtained on the page. A contrary default rule could be imposed as a matter of law; however, under which the use of personal information for purposes beyond the transaction in which it was provided would be barred, absent affirmative consent. A modified form of the present rule would be an "opt out" rule, under which consumers would have the right to remove their name from mailing lists or otherwise retrieve their personal information by taking affirmative steps. The contrary rule would be an "opt in" rule.

{51} An "opt in" rule can be seen as transaction forcing and market promoting. By requiring the webpage sponsor to bring the issue to the data subject's attention in an explicit manner and to seek affirmative consent, it is much more likely that consent will not be granted absent a transaction involving consideration flowing to the data subject. Under the present system data subjects give their data away not realizing they are even parting with something of potential value.

{52} Not everyone who examines the issue concludes that an "opt in" rule is warranted. Such a rule may be inefficient if it discourages too many individuals from participating, and, as a result, the total data pool becomes less valuable for everyone.[90] In general, however, we would consider transaction forcing "opt in" rules to be the hallmarks of the privacy market opportunist.

{53} Consistent with the above proposals, privacy market opportunists might also support initiatives to clarify a data subject's property rights in personal data obtained from all sources, including third parties, not just from the subject himself.[91] Establishment of such rights would be onerous to data appropriators, and would pose a much higher burden on the commercial use of personal data because it would require the appropriator to affirmatively contact data subjects with which he has no other relationship in order to obtain permission for the use of their data.[92]

{54} Finally, one of the principal difficulties in maintaining a fair market in privacy is the difficulty private citizens would face in policing adherence to stated privacy policies, or the terms of any transaction allowing only limited use of specific personal data.[93] Privacy market opportunists should be expected to support measures to bring government enforcement to bear on Internet sites that abuse information by using it beyond the scope of any license agreed to in the transaction.

C. The Privacy Peacemakers

1. Concern over promoting online commerce

{55} The third orientation discussed here is referred to as the "privacy peacemaker". This perspective focuses not on protecting society from the debilitating effects of loss of privacy, nor promoting a transfer of ownership rights in personal data from appropriators to data subjects, forcing markets in such information to develop. Instead, the main concern of the "privacy peacemakers" is to ensure that privacy fears -- well founded or otherwise -- do not impede the continued growth on online commerce.

{56} The idea that privacy concerns must be dealt with in order for the Internet to achieve its full potential is stated explicitly in the pronouncements of numerous government organizations proposing online privacy guidelines.[94] Such concerns are also cited by private sector commentators interested in promoting development of the Internet.[95] Such statements are frequently accompanied by citations to public opinion polling data, as cited in Section I, evidencing a high level of public concern about the issue.[96]

{57} A related argument expresses the fear that unless privacy is dealt with through industry self-regulation, the public will demand imposition of heavy-handed government regulation,which will hamper the development of the Internet.[97] The main point, however, is that "privacy peacemakers" measure any proposed privacy protection scheme as much by what it does not accomplish (impairing the growth of the Internet), as by what it does accomplish. In seeking an accommodation of privacy concerns while making the minimum imposition on business, "privacy peacemakers" frequently use the rhetoric of "balancing." The desire of online users for privacy must be balanced against the American tradition of free transfer of information, the First Amendment, and the legitimate needs of business.[98]

{58} Not surprisingly, the ranks of the "privacy peacemakers" are made up largely of representatives of the Internet industry and politicians, whose job is to balance the demands of competing constituencies. As a result, the "privacy peacemaker" camp is far more numerous and better funded than either the dossier society pessimists (who tend to be academics or public interest privacy advocates) or the market optimists (who are almost exclusively academics).

2. "Privacy peacemaker" thinking in public policy initiatives

{59} Policy initiatives reflecting the peacemaker orientation would be expected to focus on scandalous and controversial forms of privacy abuse that might impact public trust in the Internet or prompt legislative overreaction. Regulation would focus on sensitive financial or medical information, information related to gender, children, or personal safety. Identity theft and child stalking would be at the top of the list, regardless of their actual prevalence in the society. One would expect to see little or no protection of neutral biographical data (other than that useful for committing identity theft) or information related to consumer preferences and lifestyle, regardless of whether that information might have commercial value.[99]

{60} Second, one would expect "privacy peacemaker" regulation to focus on protection where it is most visible, and therefore reassuring. The most visible portion of the personal information spectrum is the nexus where information is gathered from or provided to the individual consumers. One would expect to see few or no restrictions imposed on the use of data outside public view.

{61} Finally, one might expect to see a higher level of protection being made available to the committed, vocal and technologically savvy minority of citizens who are well informed about online privacy issues and know how to protect their rights.[100] Provisions allowing consumers to "opt out" of certain uses of their personal information may respond to the goals of "privacy peacemakers", in that they provide a safety valve for the concerned minority who might protest if no such outlet were provided. One would not expect "privacy peacemaker" proposals to contain inalienability provisions or other limitations on the use of data for its own sake, nor would one expect to see proposals to vest individuals with anything like a property right in their personal information.
V. Who Leads at Halftime?: Current Privacy Initiatives in the United States

{62} The game of defining and regulating online privacy rights is far from over. At most, it is halftime, with the final score unknown. Still, trends have emerged which lead one to conclude that the "privacy peacemaker" camp clearly holds the halftime lead, dominating the debate in most arenas and having the largest influence on policy proposals. Dossier society pessimist and market opportunist concerns are marginalized, appearing only inferentially in policy proposals. This paper concludes by reviewing current policy proposals in two areas: (1) "fair information handling practices," which form the basis for online privacy proposals by the Clinton administration, and (2) the Federal Trade Commission's legislative proposal for regulating online privacy.

A. Fair information handling practices and the Clinton Administration

{63} Various entities have compiled lists of fair information handling practices for their own internal use, in an effort to influence public policy or to encourage voluntary adherence by others. In 1972, the Department of Health Education and Welfare ("HEW") established a federal advisory committee which reviewed the handling of information at the federal agency level and promulgated a series of "fair information practices," which have been cited and built upon by numerous other entities since that time.[101] In 1980, the Organization for Economic Cooperation and Development ("OECD") issued its own guidelines for handling personal data.[102] The Council of Europe adopted a Convention for the Protection of Individuals with Regard to Automatic Processing of Personal Data in 1985.[103] A 1995 report by the Privacy Policy Working Group of the United States Government's Information Infrastructure Task Force [104] also included fair information handling principles. In 1995, the European Commission issued its Privacy Directive, setting out the rights of data subjects and the responsibilities of data processors.[105] Each of these documents was built upon the concept of defining fair information handling practices.

{64} On July 1, 1997, the Clinton White House released the Framework for Global Electronic Commerce,[106] a general policy statement setting out the administration's philosophy regarding the relationship between government and the world of electronic commerce. The portion of that document addressing online privacy endorsed general privacy principles articulated in several prior policy statements, including the 1995 report by the IITF Task Force.[107]

{65} More recently, a 1998 paper by the Department of Commerce ("DOC") entitled, "Elements of Effective Self-Regulation for the Protection of Privacy and Questions Related to Online Privacy" listed nine privacy principles[108] regarded as typical fair information handling guidelines:

1. "Awareness": Disclosure of the identity of the data collecting party and means for avoiding participating in such transactions;

2. "Choice": A mechanism to exercise options, including "affirmative choice" for certain "sensitive" categories of information relating to, for example, medical conditions, or children;

3. "Data security": Protections against improper alteration or misappropriation of data;

4. "Data integrity": Keeping data which is accurate and relevant for the purposes for which it was collected;

5. "Consumer access": The ability of consumers to review and correct data about themselves, although the document warns that the extent of access may vary by industry, due to the costs involved; and

6. "Accountability": Companies should be accountable in some manner for compliance with their own policies.

In addition, the Principles include three "enforcement principles":

1. "Consumer recourse": A way to resolve disputes that is "readily available and affordable";

2. "Verification": A third-party check on compliance; and

3. "Consequences": Sanctions for failure to comply.

{66} Several areas of dispute exist with respect to the interpretation and adequacy of these types of fair information handling practices. With respect to "awareness" (sometimes also called "notice"), it may be questioned whether posting a privacy notice on a webpage really provides notice to more than a small handful of users who actually bother to access the posted policy and read it. The fact that only a small minority of users will access such policy statements indicates that the peacemaker function of such notices provides protection only for the vocal and informed few, but not the mass of Internet users.

{67} The principle of "choice" (or "consent") implicates the selection of default rules discussed above, and whether affirmative consent ("opt in") must be obtained before a website sponsor can use information gathered in one transaction for other purposes or transfer it to third parties.[109] Statements of fair information handling practices usually assume that "opt out" rules are generally adequate.[110] The highest level of protection offered generally consists of an affirmative "opt in" requirement for some kinds of sensitive information or classes of vulnerable persons.[111] The "opt out" nature of consent in most fair information handling guidelines gives them a decidedly peacemaker bent. They do little to force, or to even encourage, transactions in personal data.

{68} Controversy also exists regarding the extent to which consumers are entitled to see the information kept about them, and on what terms access will be provided.[112] This debate highlights the fact that fair handling practices guidelines do not recognize a property right in the data subject; the data is presumed to be owned by the data collector and, as a result, the data subject's right to access must be balanced against considerations of cost and convenience to the data appropriator.

{69} Some fair information practices guidelines stress that only "relevant" information should be gathered, and that once the purpose of the information has been fulfilled, it should be destroyed.[113] These sorts of limitations, unenforceable as they may be, reflect the concerns of the dossier society pessimists in limiting the existence of information dossiers in general, separate and apart from any particular showing of abuse or harm. However, such guidelines generally shrink from imposing concrete limitations that are capable of enforcement.[114]

{70} Finally, disputes exist over the concept of enforcement and accountability,[115] which revolve around the extent to which commercial entities (or their trade organizations) should be allowed to police themselves, or whether an external audit and disciplinary function is necessary. Proposals range from the relatively toothless[116] to the full panoply of administrative sanctions and private rights of action, including provisions for attorneys' fees and punitive damages.[117]

{71} In addition, fair information handling guidelines directed specifically at the online environment generally fall into the peacemaker camp in that they tend to address rights only for information collected from the subject online. Notice, access and other similar rights apply to information gathered directly from the individual, not to all information collected by the entity from third parties, nor do such guidelines contain inalienability rules.[118]

{72} The current negotiations between the United States and the European Union ("EU") over the 1995 Privacy Directive ("Directive") concern the issues cited above. The Directive is perceived to be substantially more protective of privacy than the current American regulatory scheme for various reasons. First, the Directive contemplates the establishment of national privacy regulators in each EU member state,[119] something unknown in the United States. Moreover, the Directive establishes and requires adoption of a nationwide privacy law in each member state, governing all processing of personal data, whether by computer or manually, and applying across the board to all industry segments and transactions.[120] The Directive is not limited to the regulation of handling information obtained at the data gathering stage, nor to that obtained through a particular medium. The Directive applies to all processing of data, regardless of how that data came into the hands of the processor,[121] and it contains an expanded list of subjects deemed to be sensitive, as to which special restrictions on use and transfer apply.[122]

{73} Nevertheless, the Directive is built around a list of rights of data subjects,[123] and duties of data processors,[124] that track, in broad brush, the same fair information handling practices principles described above.[125] In that regard, while the Directive contemplates a greater government role in privacy regulation, it must still be considered fundamentally a "privacy peacemaker" regulation.

{74} The fundamental similarity between the goals of privacy regulation in the United States and the EU can be seen in the dramatic narrowing of the debate between the two sides in recent months. Because the Directive provides that data may not be exported from the EU to any country that does not provide roughly equivalent privacy protection,[126] the threat that data flows from the EU to the U.S. will be cut off has prompted extensive negotiations between Clinton administration officials and EU privacy negotiators.[127] The United States' position in those negotiations has been to urge that self-regulatory measures by industry trade associations can constitute adequate protection to qualify members of those associations to receive data flows from entities in the EU.[128] At last report, the U.S. negotiators maintained that the two sides were close to reaching an agreement.[129]

B. Legislation

{75} A review of Internet-related privacy legislation proposed by the FTC confirms the impression discussed above. The public policy debate is taking place largely within the privacy peacemaker model, and is not directed toward substantially curtailing the use of personal information dossiers in business, nor is it intended to encourage the development of markets in such information. Leaving aside statutes prohibiting interception of electronic communications, the principle statute aimed at online privacy at the federal level to date is the Children's Online Privacy Protection Act.[130] As of the date of this article, no general Internet privacy legislation has been passed.[131]

{76} In the summer of 1998, the Federal Trade Commission ("FTC") reported to Congress that the vast majority of websites collect personal data of some sort from site visitors, but that very few of them even post a privacy policy, considered the bare minimum of privacy protection to most.[132] FTC Chairman, Robert Pitofsky testified before Congress in July 1998, that the failure of the business community to implement a system of self-regulation for online privacy prompted the agency to recommend federal legislation for online privacy protection.[133] In that testimony, the FTC chairman outlined the Commission's vision of what Internet privacy regulation should look like.[134] That vision is, fundamentally, a peacemaker model.

{77} The FTC-proposed legislation setting forth four basic privacy principles, adopted from various existing fair information handling practices guidelines. Those principles would include (1) "Notice/awareness"; (2) "Choice/consent"; (3) "Access/participation" (the right to obtain access to and correct personal data); and (4) "Security/Integrity".[135] A regulatory agency (presumably, the FTC) would then be given the responsibility to issue more detailed regulations enforcing these basic principles. Self-regulation would still be encouraged, however, as a preferred solution. The agency would be authorized to approve industry self-regulatory schemes, and once approved, participation in such schemes would serve as a safe harbor from further federal regulation and enforcement.[136]

{78} Evaluation of such a scheme is difficult in the abstract because so much would depend on the specific regulations adopted by the agency. Noticeably absent from the FTC's proposed basic principles; however, is any language fundamentally limiting the current business practice of gathering extensive amounts of personal information or indicating that significant aspects of such use should be curtailed on grounds the dossier society pessimists would recognize. The statutory scheme outlined by the FTC would not appear to authorize the agency to recognize property rights in personal information on behalf of data subjects, nor impose transaction forcing measures for the sake of spurring a market in such information.

VI. Conclusion

{79} Most discussions of online privacy policy focus on the tools of privacy protection -- the choice between government regulation, industry self-regulation, or laissez faire market discipline. At the same time, however, a number of diverse commentators are raising fundamental questions about what society ultimately hopes to accomplish in regulating online privacy. Some raise questions about whether cyberspace is the place to draw a line in the sand in the battle against the emerging dossier society. Others seek to take advantage of the unique features of the Internet to promote a market in personal information which, if successful, would constitute a significant transfer of wealth to the middle class, whose personal data is highly valued by business. The viewpoints of those authors have not featured prominently in the privacy proposals debated in Washington, D.C. Many new proposals for privacy regulation are bound to be introduced in the regulatory and legislative sphere over the upcoming year. The intent of this article has been to assist observers of the ongoing privacy debate in evaluating policy proposals more critically, in terms of what goals they promote, and what assumptions they embody, as well as what regulatory tools they seek to employ.

[*] Karl D. Belgum is an attorney with Thelen, Reid & Priest, LLP of San Francisco, California where he is a partner in the Business Litigation Group and is head of the firm's Internet practice initiative.

[**]NOTE: All endnote citations in this article follow the conventions appropriate to the edition of THE BLUEBOOK: A UNIFORM SYSTEM OF CITATION that was in effect at the time of publication. When citing to this article, please use the format required by the Seventeenth Edition of THE BLUEBOOK, provided below for your convenience.

Karl D. Belgum, Who Leads at Half-time?: Three Conflicting Visions of Internet Privacy Policy, 6 RICH. J.L. & TECH. 1, (Symposium 1999), at

