James Grimmelmann
Tessler Family Professor of
Digital and Information Law
Cornell Tech and Cornell Law School
Fourteenth Edition
ISBN
James Grimmelmann
- -
- -
s
m
e
l
w
b
a
o
l
r
www.semaphorepress.com
t
p
e
4
2
0
&
0
2
0
n
2
©
9
s
8
r
6
3
4
e
e
9
1
s
8
t
7
9
a
!
n
i
c
:
0
0
2
$
8
0
0
For my parents.
2
$
Copyright and Your Rights
The author retains the copyright in this book. By downloading a copy of this book
from the Semaphore Press website, you have made an authorized copy of the book
from the website for your personal use. If you lose it, or your computer crashes or
is stolen, don’t worry. Come back to the Semaphore Press website and download a
replacement copy, and don’t worry about having to pay again. Just to be clear,
Semaphore Press and the author of this casebook are not granting you permission
to reproduce the material and books available on our website except to the extent
needed for your personal use. We are not granting you permission to distribute
copies either.
We ask that you not resell or give away your copy. Please direct people who are
interested in obtaining a copy to the Semaphore Press website, www.semaphorepress.com, where they can download their own copies. The resale market in the
traditional casebook publishing world is part of what drives casebook prices up to
or more. When a publisher prices a book at
, it is factoring in the competition and lost opportunities that the resold books embody for it. Things are different at Semaphore Press: Because anyone can get their own copy of a Semaphore
Press book at a reasonable price, we ask that you help us keep legal casebook materials available at reasonable prices by directing anyone interested in this book to
our website.
Printing A Paper Copy
If you would like to have a printed copy of the book in addition to the electronic
copy, you are welcome to print out a copy of any part, or all, of the book. Please
note that you will find blank pages throughout the book. We have inserted these
intentionally to facilitate double-sided printing. We anticipate that students may
wish to carry only portions of the book at a time. The blank pages are inserted so
that each chapter begins on a fresh, top-side page. Printed copies of the full book
are also available through Amazon.com.
Finding Aids and Annotations
Finally, please note that the book does not include an index, a table of cases, or
other finding aids that are conventional for printed books. This is because a Semaphore Press book, in pdf form, can be searched electronically for any word or
phrase in which you are interested. With the book open in Adobe Reader, simply
hit control-f (or select the “find” option in the “Edit” pull-down menu) and enter
the search term you want to find. We also enable Reader’s commenting features in
our pdf books, so you can highlight text, insert comments, and personally annotate
your copy in other ways you find helpful. If your copy of Reader does not appear to
permit these commenting features, please check to make sure you have the most
recent version; any version numbered “ ” or higher should permit you to annotate
a Semaphore Press book.
:
.............................................................................................
A. Computer Technology ...............................................................................................
Technical Primer: Computers ............................................................................
Technical Primer: The Internet .........................................................................
Columbia Pictures Indus. v. Fung ......................................................................
Technical Primer: Cryptography .......................................................................
Internet Applications Problem ..........................................................................
B. Theory .........................................................................................................................
Lawrence Lessig, Code . .................................................................................
Jonathan Zittrain, The Future of the Internet .................................................
s
m
e
l
b
o
r
p
d
n
a
s
e
s
a
c
w
a
0
n
d
n
2
o
l
i
u
t
fl
o
c
i
4
t
r
d
6
g
s
e
k
i
c
r
fi
n
n
a
u
o
B
J
i
r
t
1
2
c
e
u
r
r
d
e
e
t
o
t
t
p
p
r
a
a
0
4
4
6
9
9
1
1
3
t
n
1
h
7
7
7
7
7
0
5
6
6
0
h
7
7
7
8
0
2
5
8
0
1
3
4
4
8
2
6
7
8
9
9
1
6
7
0
0
0
0
0
0
1
1
:
.............................................................................................
A. Cyberspace ..................................................................................................................
Note on “Cyberspace” ..........................................................................................
John Perry Barlow, A Declaration of the Independence of Cyberspace .......
Orin S. Kerr, The Problem of Perspective in Internet Law ............................
David R. Johnson and David Post, Law and Borders .....................................
Mary Anne Franks, Unwilling Avatars .............................................................
State v. Decker ......................................................................................................
Slot Machine Problem.........................................................................................
Robles v. Domino’s Pizza, LLC ...........................................................................
Dead Aim Problem ..............................................................................................
B. Jurisdictional Con icts .............................................................................................
Dow Jones & Co. v. Gutnick ...............................................................................
Jack Goldsmith and Timothy Wu, Digital Borders .........................................
eSafety Commissioner v. X Corp........................................................................
SeaHaven Problem ..............................................................................................
Gambling Treaty Problem ..................................................................................
Diplomatic Mission Problem .............................................................................
C. American Law ............................................................................................................
. Civil Jurisdiction ...................................................................................................
Groo v. Montana Eleventh Judicial District Court ..........................................
Note on Speci c Personal Jurisdiction Tests ....................................................
Spanski Enterprises, Inc. v. Telewizja Polska, S.A. ..........................................
Ayyadurai v. Floor , Inc. ................................................................................
Flying Pig Problem ............................................................................................
. Criminal Jurisdiction .........................................................................................
United States v. Auernheimer ..........................................................................
. The Commerce Clause .......................................................................................
United States v. Yücel........................................................................................
Note on Preemption and the Dormant Commerce Clause ..........................
In re Facebook Biometric Information Privacy Litigation ..........................
South Dakota v. Wayfair, Inc............................................................................
1
i
................................................................................................................
n
I
1
C
1
1
1
2
3
4
4
4
4
5
C
5
5
5
5
6
6
6
6
7
7
7
7
7
7
8
8
8
8
8
8
1
9
9
9
1
1
1
2
1
1
3
1
1
1
1
:
Internet Law
:
......................................................................................................
A. First Amendment Basics ........................................................................................
United States Constitution, Amendment I ....................................................
Note on First Amendment Tiers of Scrutiny .................................................
Packingham v. North Carolina ........................................................................
Note on the Press...............................................................................................
B. What is Speech? .......................................................................................................
Texas v. Johnson ................................................................................................
Bland v. Roberts [I] ..........................................................................................
Bland v. Roberts [II] ........................................................................................
Bernstein v. U.S. Dept. of Justice.....................................................................
Note on Compelled Speech and
Creative ...............................................
C. Harmful Speech .......................................................................................................
danah boyd, It’s Complicated...........................................................................
Lockdown Problem ...........................................................................................
. Violent Speech ....................................................................................................
. Speech Integral to Criminal Conduct ..............................................................
Commonwealth v. Carter..................................................................................
. False Speech ........................................................................................................
Restatement (Second) of Torts [Defamation] ..............................................
Note on Defamation..........................................................................................
. Harassment .........................................................................................................
Restatement (Second) of Torts [Emotional Distress] ..................................
Snyder v. Phelps .................................................................................................
Lebo v. State .......................................................................................................
. Sexually Explicit Speech ....................................................................................
. Harm to Minors ..................................................................................................
State v. Bishop ....................................................................................................
Note on School Discipline ................................................................................
Reno v. American Civil Liberties Union .........................................................
Online Pornography Viewing Age Requirements Act ..................................
. Intellectual Property ..........................................................................................
3
0
3
y
h
c
c
a
e
v
i
e
p
r
S
P
3
4
r
r
e
e
t
t
p
p
a
9
9
9
9
0
4
7
7
7
9
0
6
8
9
1
2
5
6
8
9
0
2
2
2
5
7
9
1
3
5
8
0
a
1
1
1
4
4
4
6
7
7
2
1
1
2
6
8
2
6
ff
h
1
1
1
1
2
2
2
2
2
2
3
3
3
3
4
4
4
4
4
4
5
5
5
5
5
5
5
6
6
6
6
7
h
7
7
7
7
7
8
8
8
8
9
0
0
0
0
0
1
:
....................................................................................................
A. The Fourth and Fifth Amendments ......................................................................
Fourth and Fifth Amendment Overview ........................................................
. Device Searches ..................................................................................................
Riley v. California ..............................................................................................
United States v. Spencer ...................................................................................
Co eeshop Problem ..........................................................................................
. Remote Searches ................................................................................................
United States v. Warshak ..................................................................................
Carpenter v. United States ...............................................................................
Bank Robbery Problem ....................................................................................
B. Wiretapping .............................................................................................................
Wiretap Act ........................................................................................................
O’Brien v. O’Brien..............................................................................................
Stored Communications Act ............................................................................
Ehling v. Monmouth-Ocean Hospital Service Corp. ....................................
Pen Registers and Trap and Trace Devices ....................................................
1
C
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
2
1
1
3
1
1
1
4
1
1
1
1
5
1
6
1
1
1
1
1
7
C
1
1
1
1
1
1
1
1
1
2
1
1
2
2
2
2
2
2
2
4
Note on Technical Assistance ..........................................................................
Zipper Problem..................................................................................................
C. Anonymity ................................................................................................................
Stored Communications Act ............................................................................
Jukt Micronics Problem ...................................................................................
Doe I v. Individuals, Whose True Names are Unknown ..............................
Arista Records, LLC, v. Does – .................................................................
In re Bittorrent Adult Film Copyright Infringement Cases .........................
D. Personal Privacy ......................................................................................................
Restatement (Second) of Torts [Privacy Torts].............................................
Pennsylvania Right of Publicity .......................................................................
People v. Golb [Golb I] .....................................................................................
Golb v. Attorney General of the State of New York [Golb II] .....................
State v. Austin ....................................................................................................
E. Consumer Privacy....................................................................................................
Note on Cookies .................................................................................................
Eichenberger v. ESPN, Inc. ..............................................................................
TransUnion LLC v. Ramirez ............................................................................
In re Google, Inc. Privacy Policy Litig. ...........................................................
Chris Yiu (@CLRY ), Tweetstorm on Ad Tracking......................................
In re Snapchat, Inc. ...........................................................................................
California Privacy Rights Act...........................................................................
Cookie Monster Problem..................................................................................
F. Privacy Law in the European Union......................................................................
General Data Protection Regulation ..............................................................
Google Spain SP v. Agencia Española de Protección de Datos ...................
G. Children’s Privacy ....................................................................................................
United States of America v. Epic Games, Inc. ...............................................
California Age-Appropriate Design Code Act ...............................................
s
9
r
1
e
t
1
u
p
m
o
C
o
t
2
s
s
e
c
c
A
5
r
e
t
p
8
9
0
1
2
2
8
0
7
7
8
9
1
3
0
0
3
5
3
8
0
7
4
5
5
4
8
8
1
a
5
5
5
2
7
0
1
1
2
2
3
9
1
2
2
4
5
7
2
7
1
1
2
2
2
2
2
3
3
3
3
3
4
4
5
5
5
5
6
6
7
7
8
8
8
9
9
9
1
h
1
1
1
2
2
3
4
4
4
4
4
4
5
5
5
5
5
5
6
:
...........................................................................
A. Contracts ..................................................................................................................
CX Digital Media, Inc. v. Smoking Everywhere, Inc.....................................
Meyer v. Uber Technologies, Inc. ....................................................................
Cullinane v. Uber Technologies, Inc................................................................
In re Epic Games, Inc. ......................................................................................
Smurfberry Problem .........................................................................................
SeaSells Problem ...............................................................................................
B. Trespass to Chattels .................................................................................................
Restatement (Second) of Torts [Trespass] ...................................................
Intel v. Hamidi ...................................................................................................
Note on Spam ....................................................................................................
Wireless Router Problem .................................................................................
C. Computer Misuse Statutes .....................................................................................
Computer Fraud and Abuse Act ......................................................................
Orin S. Kerr, Cybercrime’s Scope ....................................................................
United States v. Morris .....................................................................................
Van Buren v. United States...............................................................................
hiQ Labs, Inc. v. LinkedIn Corp. .....................................................................
LineJump Problem ...........................................................................................
6
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
3
C
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
Table of Contents
5
Internet Law
:
.............................................................................................
A. Trademark Basics ....................................................................................................
Multi Time Machine, Inc. v. Amazon. com, Inc. ...........................................
Ti any (NJ) Inc. v. eBay, Inc. ...........................................................................
Happy Fun Ball Problem ..................................................................................
B. Domain Names ........................................................................................................
Title , United States Code ............................................................................
Taubman Co. v. Webfeats .................................................................................
Drunk Kids Problem .........................................................................................
Uniform Domain Name Dispute Resolution Policy .....................................
Flexegrity Problem ............................................................................................
Curt Mfg., Inc. v. Sabin .....................................................................................
ICANN and the Domain-Name System .........................................................
k
t
r
a
h
g
m
i
e
r
d
y
a
p
r
o
T
C
6
7
0
0
0
r
r
1
1
1
5
e
e
t
1
t
p
p
a
9
9
0
9
5
6
6
8
3
4
6
7
1
a
5
5
7
7
5
2
4
0
0
1
7
8
9
1
3
4
4
7
1
6
7
1
6
6
7
7
1
4
6
0
7
8
8
2
3
8
ff
h
6
6
7
7
8
8
8
8
9
9
9
9
0
h
0
0
0
0
1
2
2
3
3
3
3
3
3
4
4
4
4
4
5
5
5
6
6
6
6
6
7
7
7
8
8
8
8
9
9
:
...............................................................................................
Copyright Overview ..........................................................................................
A. Copyrightability .......................................................................................................
In Re Zarya of the Dawn ..................................................................................
PhantomALERT, Inc. v. Google Inc. [I] ........................................................
PhantomALERT, Inc. v. Google Inc. [II] .......................................................
Oracle America, Inc. v. Google Inc. .................................................................
B. The Exclusive Rights ...............................................................................................
Copyright Act [Exclusive Rights and First Sale] ..........................................
Capitol Records, LLC v. ReDigi, Inc. ..............................................................
Note on RAM Copies ........................................................................................
Perfect , Inc. v. Amazon.com, Inc. ..............................................................
McGucken v. Newsweek LLC...........................................................................
American Broadcasting Co. v. Aereo, Inc. ......................................................
Music Locker Problem......................................................................................
C. Licenses.....................................................................................................................
McGucken v. Newsweek LLC...........................................................................
Field v. Google Inc. ............................................................................................
Vernor v. Autodesk, Inc.....................................................................................
MIT License .......................................................................................................
GNU General Public License (GPL) ...............................................................
Jacobsen v. Katzer .............................................................................................
ZapChat Problem ..............................................................................................
D. Fair Use ....................................................................................................................
Copyright Act [Fair Use]..................................................................................
Katz v. Google Inc..............................................................................................
Griner v. King.....................................................................................................
Note on Sony v. Universal [Fair Use] .............................................................
Perfect , Inc. v. Amazon.com, Inc. ..............................................................
Google LLC v. Oracle America, Inc. ................................................................
Bubonic Plagiarism Problem ...........................................................................
E. Secondary Liability..................................................................................................
Perfect , Inc. v. Giganews, Inc. ....................................................................
Note on Sony v. Universal [Contributory Infringement].............................
A & M Records, Inc. v. Napster, Inc. ...............................................................
Metro-Goldwyn-Mayer Studios Inc. v. Grokster, Ltd. ..................................
9
C
3
3
3
3
3
3
3
3
3
3
3
3
4
C
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
4
6
Cachet Problem .................................................................................................
F. Section
...............................................................................................................
Copyright Act [Section
] ...........................................................................
Friday Problem ..................................................................................................
Lenz v. Universal Music Corp. .........................................................................
BMG Rights Management (US) LLC v. Cox Communications, Inc. ..........
Section
Compliance Questions................................................................
Materials on Content ID ..................................................................................
Mangle Problem ................................................................................................
G. Digital Rights Management ..................................................................................
Note on Digital Rights Management ..............................................................
Note on the Motivation for Anti-Circumvention Law ..................................
Copyright Act [Anti-Circumvention] .............................................................
Universal City Studios, Inc. v. Corley [Corley II] ..........................................
Universal City Studios, Inc. v. Reimerdes [Corley I] ....................................
Section
Problems ....................................................................................
Note on DMCA Exemptions ............................................................................
0
3
n
o
2
i
t
a
r
2
e
1
d
5
o
m
t
n
e
t
n
2
o
0
1
c
3
1
5
2
0
2
0
1
2
8
3
5
1
r
2
e
t
p
2
2
3
8
8
4
9
0
7
8
8
9
9
0
3
9
0
a
2
2
2
8
5
4
9
0
2
3
4
4
1
1
7
8
9
0
6
7
0
1
0
1
5
6
9
0
0
5
9
6
0
0
0
0
0
1
1
2
2
2
2
2
2
3
3
3
4
h
4
4
4
4
5
6
6
7
7
7
7
7
8
8
8
8
8
9
9
0
1
1
2
2
2
2
2
3
3
3
3
:
...........................................................................
A. Content Policies and Procedures ...........................................................................
Kate Klonick, The New Governors .................................................................
Facebook Community Standards ....................................................................
In Re Cambodian Prime Minister ...................................................................
Reddit Content Policy .......................................................................................
r/SwingDancing Rules......................................................................................
Parler Content Policies .....................................................................................
Ravelry Community Guidelines ......................................................................
CurrenC Problem ..............................................................................................
B. Intermediary Liability.............................................................................................
Twitter, Inc. v. Taamneh ...................................................................................
Restatement (Second) of Torts [Defamation] ..............................................
Arista Records, LLC v. Tkach ..........................................................................
United States v. Keith .......................................................................................
C. Section
..............................................................................................................
Communications Decency Act §
.............................................................
Zeran v. America Online, Inc. ..........................................................................
Jones v. Dirty World Entertainment Recordings LLC .................................
Doe v. MySpace, Inc. .........................................................................................
Note on FOSTA .................................................................................................
Gonzalez v. Google LLC [Gonzalez I] ............................................................
Gonzalez v. Google LLC [Gonzalez II] ..........................................................
Song Fi, Inc. v. Google, Inc. [I] .......................................................................
Song Fi, Inc. v. Google, Inc. [II] ......................................................................
Note on the Digital Services Act......................................................................
Section
Reform Problem ..........................................................................
D. The First Amendment ............................................................................................
Kimsey v. City of Sammamish .........................................................................
Cyber Promotions, Inc. v. American Online, Inc. ..........................................
Zhang v. Baidu.com Inc ....................................................................................
Center for Democracy and Technology v. Pappert ........................................
4
5
5
5
5
5
5
5
5
5
5
5
5
5
5
5
5
5
C
5
5
5
5
5
5
5
5
5
5
5
5
5
5
5
5
5
5
5
6
6
6
6
6
6
6
6
6
6
6
6
6
Table of Contents
7
Internet Law
Note on the NetChoice Cases ...........................................................................
:
.........................................................................
A. Marketplaces ............................................................................................................
Erie Insurance Co. v. Amazon.com, Inc..........................................................
Bolger v. Amazon.com, LLC .............................................................................
In re Uber Technologies Inc. ............................................................................
La Park La Brea A LLC v. Airbnb, Inc. ...........................................................
thWheel Problem ............................................................................................
B. Antitrust ...................................................................................................................
Note on Antitrust Law and Economics ..........................................................
United States v. Microsoft Corp.......................................................................
LiveUniverse, Inc. v. MySpace, Inc..................................................................
Note on Epic v. Apple........................................................................................
Note on the Digital Markets Act .....................................................................
Google Maps Problem ......................................................................................
C. Network Neutrality..................................................................................................
Verizon v. FCC ....................................................................................................
Broadband Internet Regulation: A Brief History .........................................
Safeguarding and Securing the Open Internet .............................................
Dissenting Statement of Commissioner Ajit Pai ...........................................
DoubleNet Problem ..........................................................................................
t
n
e
o
i
n
r
t
a
e
l
t
n
u
I
g
e
e
R
h
t
m
r
d
n
o
f
o
t
y
e
a
l
B
P
0
9
1
r
r
fi
e
e
t
t
p
p
3
a
6
6
6
9
2
7
4
4
5
7
4
1
4
6
6
7
1
7
9
4
a
6
6
ff
6
7
9
2
5
1
2
2
8
1
5
7
8
9
9
2
4
7
4
ffi
4
8
3
1
4
7
5
h
5
5
5
5
6
6
7
7
7
7
8
9
9
9
9
9
0
0
0
1
h
1
1
1
1
1
2
2
3
3
3
3
4
4
5
5
5
5
6
6
6
7
7
7
8
9
9
:
........................................................................
A. Defective Software ..................................................................................................
Kennison v. Daire ..............................................................................................
Mo att v. Air Canada ........................................................................................
Pompeii Estates, Inc. v. Consolidated Edison Co. of N.Y., Inc. ....................
Rosenberg v. Harwood......................................................................................
Houston Fed. of Teachers v. Houston Independent School District ...........
AI Con dential Problem ..................................................................................
B. Virtual Property .......................................................................................................
Kremen v. Cohen ...............................................................................................
United States v. Aleynikov ................................................................................
People v. Aleynikov ............................................................................................
Bragg v. Linden Research, Inc .........................................................................
Post.Mortem Problem.......................................................................................
Davy Jones Problem ..........................................................................................
C. Blockchains ..............................................................................................................
Note on Bitcoin ..................................................................................................
United States v. Ulbricht ..................................................................................
Kevin Werbach and Nicolas Cornell, Contracts Ex Machina ......................
In the Matter of Munchee Inc..........................................................................
D. Litigation ..................................................................................................................
Baidoo v. Blood-Dzraku....................................................................................
Gri n v. State ....................................................................................................
Mata v. Avianca, Inc. .........................................................................................
Amicus Curiae Brief of Eugene Volokh ..........................................................
Herssein v. United Servicees Automobile Association .................................
Florida Standard Jury Instructions ................................................................
9
6
c
6
6
6
6
6
6
6
5
6
6
6
6
6
6
6
6
6
7
7
7
7
C
7
7
7
7
7
7
7
7
7
7
7
7
7
7
7
7
7
7
7
7
7
7
7
7
7
7
7
8
8
1
0
2
8
9
9
5
6
7
8
9
9
9
0
0
0
Note on Mass Adjudication..............................................................................
E. The Physical World .................................................................................................
Adam Thierer and Adam Marcus, Guns, Limbs, and Toys ..........................
Andy Greenberg, Hackers Remotely Kill a Jeep on the Highway ...............
Ethan Zuckerman, Beware the Listening Machines ....................................
FAA Reauthorization Act of
..................................................................
Coda ....................................................................................................................
0
7
7
7
8
8
8
8
Table of Contents
9
10
Internet Law
6
9
9
1
n
o
i
t
c
u
d
6
9
o
9
1
r
8
0
t
6
7
0
9
9
2
1
n
7
* Frank H. Easterbrook, Cyberspace and the Law of the Horse,
,
– (
).
0
I
2
Welcome to Internet law.
Innocuous as that sentence may sound, it conceals a controversial assumption:
that “Internet law” is a coherent subject. If you flip through this book, you will see
a wide variety of topics, including jurisdiction, free speech, privacy, torts, contracts, criminal procedure and criminal law, trademark, copyright, antitrust,
telecommunications law, and more. This diversity is characteristic of the field. It
has also led some people to question whether it is a field worth studying at all.
In
, Judge Frank Easterbrook was asked to speak to a conference at the
University of Chicago Law School on “The Law of Cyberspace.” His remarks, which
bore the title “Cyberspace and the Law of the Horse,” have become famous for
throwing down a gauntlet at the feet of the assembled scholars. He questioned
whether it made sense to talk about “cyberspace law” or “computer law” or “Internet law” at all.
When he was dean of this law school, Gerhard Casper was proud that
the University of Chicago did not offer a course in “The Law of the
Horse.” He did not mean by this that Illinois specializes in grain
rather than livestock. His point, rather, was that “Law and …” courses
should be limited to subjects that could illuminate the entire law. …
Dean Casper’s remark had a second meaning – that the best way to
learn the law applicable to specialized endeavors is to study general
rules. Lots of cases deal with sales of horses; others deal with people
kicked by horses; still more deal with the licensing and racing of
horses, or with the care veterinarians give to horses, or with prizes at
horse shows. Any effort to collect these strands into a course on “The
Law of the Horse” is doomed to be shallow and to miss unifying
principles. Teaching 100 percent of the cases on people kicked by
horses will not convey the law of torts very well. Far better for most
students – better, even, for those who plan to go into the horse trade –
to take courses in property, torts, commercial transactions, and the
like, adding to the diet of horse cases a smattering of transactions in
cucumbers, cats, coal, and cribs. Only by putting the law of the horse
in the context of broader rules about commercial endeavors could one
really understand the law about horses.
Now you can see the meaning of my title. When asked to talk
about “Property in Cyberspace,” my immediate reaction was, “Isn’t this
just the law of the horse?”*
To this day, “the law of the horse” is a code phrase among scholars for the idea that
there’s nothing new here, that studying Internet law is nothing more than an exercise in applying unrelated bodies of law to the Internet, with no unifying doctrines
or truly distinctive insights. Almost since Easterbrook sat down at the end of his
talk, scholars have been debating whether he was right.
U. Chi. Legal F.
12
Internet Law
This casebook is built around the proposition that Easterbrook was wrong. I
think that Internet law deserves to be studied on its own, rather than as an application of “general rules” from other subjects. Here are some of my reasons why:
• Internet Issues Overlap. The same simple few facts may raise copyright, contract, and criminal issues. The way you analyze one will affect how you analyze the others. Or, a problem may require a difficult characterization:
should we think of this as a free-speech matter, a telecommunications question, or an antitrust issue? Again, you will need to draw on multiple bodies
of law and put them into conversation with each other.
• The Internet Is Too Important to Ignore. Lawyers need to handle the problems their clients bring to them. Increasingly often, those problems involve
the Internet. Family law changes when children’s Facebook pages become
admissible evidence; securities law changes when people do worldwide
fundraising from a webpage. To counsel clients effectively, lawyers need to
have a clear picture of how the Internet works and what people are doing
with it.
, Internet law
• Some Law Is Internet-Only. When Easterbrook spoke in
was largely a blank slate. Today, that is no longer true. Major pieces of legislation, such as the
Digital Millennium Copyright Act, have created important bodies of Internet-specific law. Some of these doctrines are likely to
surprise you – they’ve certainly surprised lawyers who didn’t expect that law
online might not be the same as law offline.
• There Are Patterns in Internet Law. Even when doing Internet law just consists in applying familiar doctrines to online activities, some problems crop
up again and again. It can be harder to tell precisely where an action took
place, for example, when the parties and the computers they used to communicate are all in different countries. This is a problem for copyright, for
defamation, for taxation … and so on. By studying how different bodies of
law have been applied to online activity, you can gain a feel for how other
bodies of law might apply to Internet facts.
• Maybe the Internet Does Change Everything. Easterbrook’s analogy assumes
a world in which most torts and transactions don’t involve horses. Nor did
horses radically transform American society. (Cars, though …) But the Internet is changing how we live, think, write, love, fight, do business, and
think of ourselves. Some of those changes go so deep that they call into
question the basic assumptions behind entire bodies of law. Studying the
ways in which our legal system has tried to grapple with those changes may
give you a handle on what else may be coming.
You do not need to agree with me about any of this. (Indeed, you will get more out
of this book if you push back against it and test my claims for yourself.) But you
deserve to know where I am coming from. I hope to persuade you, not to trick you.
6
9
9
1
8
9
9
1
THEMES OF THE BOOK
This book emphasizes five major themes in Internet law: code is law, governmental control, intermediary power, equality, and generativity. These themes run
throughout the subject. Sometimes one or another is more prominent; at other
times they intertwine. Being alert to them makes it easier to recognize recurring
patterns in how lawyers and judges deal with Internet issues.
Introduction
13
• The first theme, code is law, is the most profound and pervasive. Everything
that happens online is mediated by computers. This affects how law applies
to online behavior: substituting computers for people has subtle and farreaching consequences.
• The second theme, governmental control, is a perennial question of law and
politics: how much of people’s lives are visible to governments, and how far
can governments go in dictating what people do? As people do more and
more online, governmental power increases in some ways and decreases in
others.
• The third theme, intermediary power, examines the fact that the computers
that make up the Internet are owned by – and controlled by – a variety of
entities, including websites, network providers, and search engines. By
deleting content or making it more prominent, they can shape who sees
what online.
• The fourth theme, equality, considers whether the gains and the pains of
the Internet are spread evenly throughout society, or whether they land
more on some people than on others. Some observers have celebrated the
Internet as a great leveler of differences among people and nations; others
have worried about a “digital divide” that excludes the poor.
• The final theme, generativity, examines the extraordinary level of innovation and creativity that are typically attributed to the Internet. The book explores what features of the Internet might be responsible for this outpouring
of expression, and what consequences it has for law and policy.
Each chapter raises questions about two or more of these themes. Keep alert for
them as you read; they will help you connect the dots between different doctrines.
This is not a “hide the ball” casebook. The subject is hard enough without introducing artificial difficulties. The notes and questions following each case are
meant to help you think through the legal questions faced by the court, the implications of its holding for future cases, and the policy issues lurking in the background. You do not need to have the correct answer (indeed, many questions have
no single “correct” answer), but it is important to consider them all.
Some sections of this book contain statutory excerpts. The questions following
them are especially important. Statute-reading is a critical legal skill, but it is hard
work and it takes practice. The questions are intended to give you a guided walkthrough of the process, helping you develop your mental agility as you flip between
definitions, applications, and exceptions.
You may also have noticed that most sections contain one or more problems.
They are an integral part of this casebook, and they are designed to be hard but
doable. Some of them introduce doctrinal or factual twists not covered in the cases
and notes. Others require you to exercise negotiation, counseling, and strategic
skills. They are all drawn from real problems faced by real people, and if they were
able to find good solutions, you can too. Do not be afraid to draw on what you have
learned outside of this course.
Finally, despite all these dire warnings, this casebook is meant to be fun. It is
almost impossible to flip through a newspaper or browse a website without coming across an Internet law issue. By the time you finish with this book, you will be
able to spot these issues, put them in context, and impress your friends with your
real-life knowledge. I have tried to select cases with vivid, memorable facts; Inter-
14
Internet Law
net law has no shortage of them. I have enjoyed every minute of teaching the subject and preparing this casebook; I hope that you will enjoy your time with it, too.
NOTE ON THE EDITING
I have emphasized readability over strict adherence to the text of the sources being
quoted. An ellipsis (“…”). may indicate the omission of anywhere from a few words
to multiple pages. I have corrected typos and other obvious but trivial mistakes
without specifically marking the change. I have freely omitted, edited, and moved
citations to improve readability. I have also frequently removed quotation marks,
along with the citation to the source being quoted. Footnotes in cases are numbered as in the original. Judges’ names are for the most part standardized as
“Lastname, Title” – except for the United States Supreme Court’s traditional formula: “Justice Lastname delivered the opinion of the Court.” The formatting of
statutes has been standardized, even when they are being quoted. And as far as I
am concerned, “Internet” is properly capitalized, now and forever.
NOTE ON THE TYPE
The body text is set in Miller by Matthew Carter. Miller is a Scotch Roman, a robust and unpretentious style popular in the th century. Headings and URLs are
set in Matthew Butterick’s Concourse, a modern design based on W.A. Dwiggins’s
classic sans-serif Metro. The code samples are set in Paul Hunt’s Source Code Pro,
an open-source fixed-width typeface designed specifically for programming.
GIVING BACK
I am proud to be part of the Internet law community, to which I owe debts of the
kind that can never be repaid, only honored. One third of the net revenues received from sales of this edition of Internet Law: Cases and Problems will be donated to the Electronic Frontier Foundation (EFF). In the EFF’s own words:
The Electronic Frontier Foundation is the leading nonprofit organization defending civil liberties in the digital world. Founded in
,
EFF champions user privacy, free expression, and innovation through
impact litigation, policy analysis, grassroots activism, and technology
development. We work to ensure that rights and freedoms are enhanced and protected as our use of technology grows.
I interned at the EFF during law school, and many of the ideas in this casebook
grew from seeds planted that summer. That said, this book’s contents are independent of the EFF and its mission – as they are of all outside influence. The EFF
and I have no control over each other, and we don’t necessarily share the other’s
views on any particular issue.
0
9
9
1
9
1
ACKNOWLEDGMENTS
In addition to designing a fairer casebook business model, my editors at Semaphore Press, Lydia Pallas Loren and Joseph Scott Miller, did me the great favor of
holding this book to their own high standards. Colleagues and friends who gave
helpful suggestions include David Abrams, Sarah Ames, Marc Blitz, Annemarie
Bridy, Anupam Chander, Bryan Choi, Danielle Citron, Richard Chused, Ralph
Clifford, Ed Felten, Roger Ford, Michael Froomkin, Andrew Gilden, Eric Goldman, Ellen Goodman, Joe Gratz, Michael Grynberg, Robert Heverly, Dan Hunter,
Gus Hurwitz, David Johnson, Meg Leta Jones, Margot Kaminski, Kate Klonick,
Introduction
15
Molly Land, Susan Landau, Greg Lastowka, Lyrissa Barnett Lidsky, Rebecca Lively, Evan McLaren, Artur Pericles Lima Monteiro, Christina Mulligan, Beth
Noveck, Blake Reid, Ken Rodriguez, Christopher Savage, Brian Sites, David Stein,
Eric Tamashasky, Jon Weinberg, Felix Wu, and Tal Zarsky. Aislinn Black, who
knows more Internet law than many lawyers, was generous with her wisdom.
I am grateful to the students in my Internet Law courses at New York Law
School, the University of Maryland, and Cornell, on whom I tested earlier versions
of this book. Their judgments about what worked and what didn’t made this book
what it is. The book would also not have been possible without the hard work of
my research assistants at New York Law School: Catherine Baxter, Cynthia Grady,
James Major, Dominic Mauro, and Joseph Merante. Their diligence and imagination helped turn a sprawling packet of cases into a focused casebook. Very special
thanks to Linda Torosian and Mary Herms.
7
6
0
2
6
1
0
2
1
8
1
1
5
0
0
0
2
2
8
4
4
8
2
6
9
2
5
1
1
3
6
1
0
0
2
5
7
1
2
0
2
0
3
6
0
3
0
2
8
0
0
2
PERMISSIONS
I am grateful to the authors and publishers who have given permission to reprint
portions of their books and articles in this casebook.
• Excerpts from Mary Anne Franks, Unwilling Avatars: Idealism and Discrimination in Cyberspace,
Colum. J. Gender & L.
(
), are used
with permission of the Columbia Journal of Gender and Law.
• Excerpts from Jack Goldsmith and Timothy Wu, Digital Borders, Legal
Affairs (Jan.
), are used with permission of the authors.
Excerpts
from
Elizabeth
E. Joh, Policing Police Robots,
UCLA L. Rev.
•
Discourse 516 (2016) are used with permission of the author.
• Excerpts from Kate Klonick, The New Governors: The People, Rules, and
Processes Governing Online Speech,
Harv. L. Rev.
(
), are used
with permission of the author.
) is available under a Creative Com• Lawrence Lessig, Code 2.0 (
mons Attribution ShareAlike . Generic license. A human-readable summary is available at http://creativecommons.org/licenses/by-sa/2.5/ and the full
text at http://creativecommons.org/licenses/by-sa/2.5/legalcode. CODE . is
available in PDF form at http://codev2.cc/download+remix/Lessig-Codev2.pdf.
The author has waived the ShareAlike license condition for this casebook.
• Excerpts from Adam Thierer and Adam Marcus, Guns, Limbs, and Toys:
What Future for D Printing?,
Minn. J. Sci. & Tech. L.
(
), are
used with permission of the authors and the Minnesota Journal of Science
and Technology.
• Excerpts from Kevin Werbach & Nicolas Cornell, Contracts Ex Machina,
Duke L.J. 313 (2017) are used with permission of the authors.
• The tweetstorm on ad tracking by Chris Yiu is used with permission of the
author.
• Jonathan Zittrain, The Future of the Internet - And How to Stop
It (
) is available under a Creative Commons Attribution Non-Commercial Share-Alike . United States license. A human-readable summary
is available at http://creativecommons.org/licenses/by-nc-sa/3.0/us/, and the
full text at http://creativecommons.org/licenses/by-nc-sa/3.0/us/legalcode. The
author has waived the ShareAlike and NonCommercial license conditions
16
Internet Law
for this casebook. The Future of the Internet is available in PDF form
at http://futureoftheinternet.org/static/ZittrainTheFutureoftheInternet.pdf.
4
2
0
2
4
2
0
2
CHANGES IN THE FOURTEENTH EDITION
The Fourteenth Edition contains six new cases and other excerpts:
• The Australian case of eSafety Commissioner v. X Corp. replaces the Canadian and American Equustek v. Jack opinions on comity.
• Groo v. Montana Eleventh Judicial District Court replaces Burdick v. Superior Court on personal jurisdiction.
• The California Privacy Rights Act updates the California Consumer Privacy
Act.
• Griner v. King deals with fair use of memes.
• The Network Neutrality materials have been updated to take account of the
FCC’s
Safeguarding and Securing the Open Internet order.
• Moffatt v. Air Canada deals with generative-AI hallucinations.
In addition, there is a new note on Specific Personal Jurisdiction Tests, and questions take account of the Supreme Court’s decision on government use of social
media in Lindke v. Freed, and of issues raised by generative AI. As always, questions and notes have been added and tweaked throughout.
James Grimmelmann
June
The first of the five major themes of this book is how law changes when computers
– rather than people – make and enforce decisions. It is arguably the central question in all of Internet law. Although he was not the first to focus on the question,
Professor Lawrence Lessig gave the most influential answer to it: “code is law.” By
this, he meant that computer software (or “code”) could do some of the same work
that law ordinarily does in controlling people’s conduct. This chapter explores the
idea in two ways: a technical primer on how computers and the Internet work, and
readings on how regulation changes when computers rather than people carry it
out.
A. Computer Technology
This section provides a technical primer on computers and the Internet, with an
emphasis on the fundamentals that recur in case after case. As you read the fact
section of an opinion, it may help to try to fit the court’s discussions of the particular technologies at issue in a given case into the framework provided here.
2
3
2
4
0
d
=
2
n
+
8
+
u
2
3
o
r
2
4
5
0
1
g
6
4
2
k
c
a
2
2
B
4
4
4
6
2
r
8
8
2
1
5
e
5
2
t
p
a
TECHNICAL PRIMER: COMPUTERS
Bits and Data
It’s a cliché to say that computers reduce everything in the world to ones and zeros
– but it’s also true. In a very real sense, a modern computer is just a complicated
electrical circuit. So compare it to a much simpler circuit: a flashlight. We could
say that the flashlight “remembers” one piece of information: whether the switch is
on or off. When the switch is on, current flows through the bulb and it lights up
the night. When the switch is off, no current is flowing, and the flashlight stays
dark.
This is a single bit: a piece of information that can be either 1 or 0. A flashlight
is a one-bit computer. With two flashlights, we could store two bits, with ten flashlights, we could store ten bits, and so on. A computer uses smaller wires and has
many many more of them, but the basic principle is the same. The presence or absence of electric current can be used to represent the values 1 and 0, respectively.
Once you have bits, you can describe anything and everything. Numbers are a
good starting point. Take, for example, the number . To represent it using bits,
we write it down in base , also known as binary: 101010. (That’s a 1 in the s
place, plus a 1 in the s place, plus a 1 in the s place, or
.) So we
need six bits to store the number : that’s six flashlights, or six tiny wires inside a
computer. For historical reasons, computers almost always group bits into sets of
eight, called bytes. In this system,
would be stored as 00101010. (The first two
bits are zeros in the
s and s place; the last six are exactly the same as before.)
Using one byte, therefore, we can represent any positive integer from (that’s
00000000) up to
(that’s 11111111). From here on, other kinds of numbers are
easy. Larger integers just take more bytes:
,
, for example, is 10110100
00011001. Negative numbers need one more bit: we could say that 1 means “the
rest of this number is positive” and 0 means “the rest of this number is negative.”
For smaller numbers, we could use bits to the right of the decimal point as well as
h
C
1:
Internet Law
to left of it.* For really big and really small numbers, we could use bits to store an
exponent, just like in scientific notation.
One particularly nice consequence of using binary to represent numbers is that
it takes surprisingly few bits to write down even very large numbers. One bit can
stand for either of two different numbers: 0 or 1. Two bits can stand for any of four
different numbers: 00 is , 01 is , 10 is , and 11 is . Three bits can stand for
eight different numbers, four bits can stand for sixteen, and so on. Thirty-two bits
(i.e. four bytes), are enough to represent any integer from to ,
,
,
.
Adding more bits increases their descriptive power exponentially.
Numbers are useful for calculating, but for communicating, we really need letters and other familiar symbols like @ and . The most familiar way of storing, or
encoding, letters as numbers is a system colloquially known as ASCII.† Capital A is
, capital B is , and so on through capital Z, which is 90. Lower-case a is 97,
lower-case b is 98, and so on again. ASCII uses other values for other commonly
used characters: such as
for a space and
for the @ sign.
Using ASCII, it’s possible to convert arbitrary text into bits and vice versa. Each
of the numbers it uses is small enough to fit in a single byte. So, for example, capital A is 01000001 in bits. “Hello!” would be the numbers
,
or, in bits, 01001000 01100101 01101100 01101100 01101111 00100001.
When you open an email containing those bits, your computer converts them back
into letters and displays “Hello!” on the screen.
ASCII is the most familiar way of storing text in a computer, but hardly the
only one. The Unicode standard – an ambitious system for representing every
writing system in use by humans, from Tibetan to emoji – defines an encoding
named UTF- , which represents each character using as few as one or as many as
four bytes. (Common characters like Q take one byte; uncommon ones like ☠ take
more.) If you’ve ever received an email liberally decorated with “ and similar
gibberish, you’ve seen what happens when different encodings collide. Someone
sent you a message in UTF- , but your computer interpreted it as ASCII. The
same bits – 11100010 10000000 10011100 – stand for “ when interpreted as
UTF- but for “ when interpreted as the most common version of ASCII.
What about images? Suppose we wanted to store this admittedly crude picture
of a face:
Once again, the strategy is to look for a way of breaking something down into bits.
We start by overlaying a grid on the face:
* Useless Fact : technically, the term should be “radix point.” It’s not a “decimal”
point because we’re not in base
anymore.
5
3
9
3
2
1
7
1
1
6
9
8
4
0
1
9
2
8
4
0
1
1
0
1
0
2
7
3
2
5
2
1
4
$
6
2
1
8
0
1
2
0
3
1
#
2
#
6
6
8
8
† Useless Fact : ASCII is short for “American Standard Code for Information Interchange.” There are actually numerous variations on ASCII; this section uses the most
familiar one, which goes by the official name “Windows.”
5
6
18
Chapter 1: Computers
19
Now, for each box in the grid, we ask whether the face contains more black or
more white. The boxes that are more than half black we make all black; the boxes
that are more than half white, we make all white:
Every box, or pixel, is now either all-black or all-white. If we call each black pixel 0
and each white pixel 1, each pixel corresponds to a single bit. If we read off the first
row of pixels, we get 11111111, since every pixel is white. The second row is the
same, but the third row is 10011001 because the tops of the eyes show up as 1s. If
we repeat for each row of pixels, the entire face is 11111111 11111111 10011001
10011001 11111111 10111101 10000001 11111111. There you go: an image
has been turned into bits, suitable for storing in a computer. To be sure, the drawing has become even cruder. But by using a smaller grid with smaller pixels – for
example, by using a camera with more megapixels – we can smooth out the edges
until the difference has become unnoticeable.
Interesting images are rarely black-or-white. But another approximation lets
computers represent shades of gray. Instead of using a single bit for each pixel, use
several. Here, for example, is a three-bit way of encoding the brightness of each
pixel. We divide the spectrum from white to black into eight evenly-spaced shades,
so that the difference in brightness from each one to the next is the same. Then, we
can approximate any shade between black and white by finding it on the spectrum
and picking the one out of the eight colors that is closest to it in brightness. All
that remains is to convert the eight representative colors to bits: 000 is all white,
001 is a very light gray, 010 is a slightly darker gray, and so on through 111, which
is all black.
0
1
2
3
4
5
6
7
000 001 010 011 100 101 110 111
20
Internet Law
A similar technique makes it possible to represent colors. All colors are made up
out of a combination of red, green, and blue light. So instead of encoding a color
using a single intensity value, we can encode it using three, one for each primary
color:
0
1
2
3
4
5
6
7
000 001 010 011 100 101 110 111
0
1
2
3
4
5
6
7
0
000 001 010 011 100 101 110 111
1
2
3
4
5
6
7
000 001 010 011 100 101 110 111
In practice, it is common to use one byte each for red, green, and blue, for a total
of
bits – enough to describe ,
,
different colors, more than the human
eye is capable of distinguishing.
One more example: sound. A sound wave is a vibration in the air. So consider a
(simplified) wave:
First, we can slice the sound wave up by time, into a series of discrete intervals.
The most common ways of representing sounds in computers uses ,
slices,
or samples, per second, since this was the frequency used for CDs. Imagine that
each of these slices is / ,
of a second long:
0
0
1
4
4
0
0
1
4
4
1
6
1
2
7
7
7
6
1
0
0
1
4
4
1
4
2
Now, within each sample, we need to say how loud the sound wave is at that instant in time. We’ll take the average loudness in that / ,
of a second:
21
Finally, we round off, or quantize, the height of the sound wave within each sample the same way we rounded off the shape of the face within each pixel and the
intensity of each color:
The first sample has a loudness – a height – of units, the second a loudness of ,
and so we can represent these eight samples as the sequence of numbers
. These numbers can, of course, be turned into bits by writing them out in
binary, just like we did above.
We have now seen how to digitize words, images, and sounds: to represent
them using bits in a digital computer. The same techniques work for other media.
A video, for example, is just a sequence of images together with an accompanying
soundtrack – but we already know how to encode both images and sounds.
Hardware
Some computers look familiar: they have a keyboard, screen, headphone jack, and
so on. Other computers, like the one inside a pacemaker or a car engine, look radically different. But they all share a common design. Every useful computer contains at least two kinds of physical components, or hardware: a central processing
unit, or CPU, that is capable of carrying out various computations, like addition
and division, and memory, which stores data for use by the CPU.
Think of a memory chip as a large wall of storage lockers, each of which can
hold some bits. To store bits in memory, the CPU needs to pick a locker to put
them in; to get the bits out again for later use, the CPU needs to remember which
locker it used. A very simple memory chip, for example, might have
locations,
each of which can hold one byte. Each location has an identifying number, like the
number on the front of each storage locker. So if we stored the digitized image of a
face from above in memory, it would look something like this:
11111111
5
10111101
6
10000001
7
11111111
5
4
3
10011001
6
3
7
10011001
5
2
3
11111111
6
1
5
11111111
2
Value
0
3
5
Location
4
4
Chapter 1: Computers
22
Internet Law
Location
Value
…
Here, the face is stored in locations to (for technical reasons, it is more convenient for computers and programmers to count starting at zero).
It should be no surprise that these addresses can also be encoded using bits.
They’re just numbers, after all, and we already know how to encode numbers. So
each location in memory has an address encoded in binary, from (00000000) up
through
(11111111). Here’s the same depiction of the memory containing the
face, this time with the addresses in memory given in binary, the way the computer itself would refer to them.
Location
Value
00000000
11111111
00000001
11111111
00000010
10011001
00000011
10011001
00000100
11111111
00000101
10111101
00000110
10000001
00000111
11111111
…
…
0
7
7
0
0
5
5
2
So to get the first byte of the face out of memory, the CPU asks for the byte stored
at location 00000000 (binary for ). To get the last byte of the face, the computer
asks for the byte stored at 00000111 (binary for ).
Computers have used a stunning variety of technologies to store data. Hard
drives magnetize small portions of a spinning disc; USB flash drives store tiny
electric charges. Older computers stored data as glowing spots on TV screens, as
marks on a paper tape, and even as sound pulses traveling through liquid mercury.
Indeed, any technology that can create either of two different physical states and
then reliably tell them apart will work as memory. The ways in which data is physically encoded and stored can be remarkably complicated: data might be stored in
multiple physical locations within a device (to provide redundancy in case of damage), or moved around to different locations (to speed up repeated access to it), or
compressed (to reduce the amount of storage needed), or encrypted (for privacy
and security), or all of the above.
There is a difference in common usage between short-term memory and
longer-term storage. The former is faster but loses track of the information it is
storing when the power goes off; the latter is slower but capable of storing information for much longer. Many computers that you are familiar with have both: so
laptops often have RAM (“random access memory”) to hold the programs and
documents you are working with, and a hard drive for storing them when you
23
close the lid. However, modern storage technologies like the flash memory used in
smartphones and USB thumb drives blur this distinction: they are as fast as
“memory” but retain information long-term like “storage.”
So much for memory. Now for the CPU. The CPU’s job is simple. A program
consists of a list of instructions – we will see how in a moment – so the CPU takes
the first instruction and carries it out, then takes the next instruction and carries it
out, then takes the next instruction and carries it out, and so on forever. These instructions tell the CPU what to do with the data. For example, consider addition:
an instruction might instruct the CPU to add and .
That may not sound particularly useful, because we already know the answer is
. Rather, a more useful program would be capable of adding different numbers,
not just and . So instead of directly referring to two numbers, an ADD instruction could refer to two locations in memory – say
and
– and tell the CPU
to add their contents. The CPU would ask the memory to tell it what number is
stored in location
and what number is stored in location
, and then add
those numbers together. To keep track of the result for the next step of the program, the CPU will then usually store the answer back in memory, at yet another
location specified by the instruction.
The memory and CPU are the heart of a computer. Almost everything else is a
peripheral: something attached to the computer so that it can receive data from
the outside world or do something useful. A keyboard is a peripheral for typing
text in: when you push a key, the keyboard sends a signal to the CPU telling it
which key you pressed. A screen is a peripheral for displaying information: the
CPU (typically with the aid of a sidekick processor dedicated to graphics) sends a
signal to the screen telling it which pixels to turn on and how bright to make them.
A fingerprint scanner is an input device that receives one kind of information; a
webcam is an input device that receives a different kind. Indeed, from this perspective, even an Internet connection is just another kind of peripheral: it’s a device that the computer can send information to and receive information from. The
computer doesn’t know what lies beyond – only that some bits went out and other
bits came in.
Software and Object Code
Just as bits can be used to represent numbers and characters, they can also be used
to represent instructions: the smallest individual operations that a computer can
carry out. On the ARM CPUs used in the iPhone and in billions of other devices,
for example, the bits 0100 represent the “ADD” instruction that adds two numbers
together, and the bits 0000 represent the “MUL” instruction that multiplies two
numbers. Put a sequence of these instructions together and you have a program in
object code (sometimes called “machine language”), that is, a program written in a
format that the computer can recognize and act on.
In other words, a program is also a form of data. After all, each instruction in
object code is made up of bits.* Since we know how to store bits in memory, this
means we can also store computer programs in memory. Indeed, this is exactly
what modern computers do. The CPU doesn’t just retrieve from memory the data
0
8
1
0
8
1
4
9
0
2
3
4
0
2
9
3
* So, for that matter, is a program written in source code. The difference is that the bits
in source code represent letters and symbols for a program that will have to be compiled into object code, rather than representing instructions the CPU is directly able
to carry out.
2
1
Chapter 1: Computers
24
Internet Law
the program works on. It also retrieves from memory the program itself, one instruction at a time.*
The point that programs are both the instructions that tell a computer what to
do and a kind of data that can be stored in a computer was first articulated by the
British mathematician Alan Turing in
. His insight is responsible for the fact
that modern computers are general-purpose devices, capable of carrying out all
kinds of tasks, including ones their designers never dreamed of. To put the computer to a new use, just write a program, load that program into the computer’s
memory, and tell the CPU to get to work running it. Instead of needing to build a
different computer for each possible use – one for playing Tetris, one for writing
emails, one for calculating averages, and so on – it suffices to build a single computer.
Put another way, provided the computer’s hardware is sufficiently powerful
(and Turing showed that even an extraordinarily simple computer is good
enough), all of its “smarts” come from the programs, or software. By loading a different program, or application, into a computer, we can make it play Tetris, or
write emails, or calculate averages, or anything else we can express precisely
enough to put into a computer program. As in the legend of the golem, a computer
is an inert lump of matter which is animated by the words we put into it.
Programming Languages and Source Code
If she wanted to, a programmer could write object code by hand, choosing individual bits to describe the operations she wants the computer to carry out. In the
early days of computing, this was programming. Unsurprisingly, it was difficult,
tedious, and error-prone. In response, computer scientists developed programming languages, formal artificial languages for writing programs. These languages
are much closer to natural human languages, like English and Wolof, in that they
are written using familiar alphabets and symbols, rather than ones and zeros, and
are designed to be easier for humans to read. But they are like object code in that
they are intended to express each idea completely unambiguously, so that each
program does exactly one, completely predictable thing.
As an example, consider the process of averaging two numbers. If asked to describe averaging, you might say “Add the numbers together, and then take half of
the result.” This is an algorithm, a step-by-step process for carrying out a calculation. Your informal plain-language description of it makes perfect sense to English
speakers, but it’s just a bunch of gibberish to a computer. If you turn on a computer and type “Add the numbers together, and then take half of the result,” nothing
useful will happen.
A computer programmer’s job consists of translating informal descriptions like
this one into a sufficiently precise series of statements that a computer could execute them. Here’s what she might write if she were using the popular Python language:
6
3
9
1
* If the CPU had an interior monologue, it might go something like this:
Hey memory, can you look up an instruction for me in location 480?
0100, got it, thanks! Let me see, 0100 means add, so I need to add two
numbers. Hey, memory, can you look up some data for me in locations
204 and 180? 3 and 9, got it, thanks! Let me see, 3 plus 9 equals 12.
Hey, memory, can you put the number 12 in location 184? Thanks!
Hey memory, can you look up an instruction for me in location
484? 0000, got it, thanks! Let me see, 0000 means multiply …
Chapter 1: Computers
25
def average (x y):
sum = x + y;
return sum / 2;
The first line of this brief program says what it does: defines (“def”) a function
named average which computes something based on two numbers named x and
y. The second line corresponds to the first half of our informal description: it adds
(“+”) up x and y, then stores the result (“=”) in another number named sum. The
third line corresponds to the second half of our informal description: it takes half
of sum by dividing (“/”) it by 2, then announces (“return”) that this value is the
answer we’re looking for. The point of expressing it this way is that each individual
step, like + and /, corresponds to something so simple that the computer is already
capable of carrying it out. A program assembles these elementary steps, one by
one, into a more complicated, and usually more interesting, whole.
Having defined average in terms of simpler steps like + and /, the programmer is now free to treat it as a simpler step when defining other functions, like a
homebuilder who puts floorboards down on top of the beams she put in place yesterday. She could write average(2,4) + average(10,20) and the computer
would correctly answer 18. Now, average is just one function, while modern operating systems like Windows contain millions of functions, but the basic principle
of using functions to build other functions is the same.
There are thousands of programming languages, which are useful for different
purposes. The same algorithm may look quite different when written out in different languages. Here is a version of average in the commonly-used C language:
int average (int x, int y)
{
int sum;
sum = x + y;
return sum / 2;
}
The details are slightly different, but this should be recognizable as a close relative
of the Python version. On the other hand, here is a version of average written in
the less-commonly-used Scheme language:
(define average
(lambda (x y)
( / (+ x y) 2)))
This version may look extraordinarily different from the previous two, but does the
same thing: averages two numbers. Some programmers – although probably a distinct minority – would even consider the Scheme version simpler and more elegant than the Python and C versions.
A program written in a human-readable programming language like Python is
called source code to distinguish it from the object code that a computer runs. But
this raises a complication. Source code is closer to being suitable for a computer to
carry out than an English description of a program would be, because source code
is formal and precise. But there is still a difference. “def average (x y)” is an
arbitrary string of characters as far as the computer is concerned, just like “Add the
numbers together.” The computer is looking for 0100, not “def” or “add”.
Thus, when a programmer writes source code in a human-intelligible programming language like Python, C, or Scheme, she must then transform this
source code into something that the computer can act on. The most common way
26
Internet Law
to do this is for her to write a special-purpose program, called a compiler, that
reads source code and translates it into object code. This translation is possible
because programming languages are precise enough that the meaning of a program is fully specified.*
Operating Systems
In theory, one could write a program that takes complete control of a computer
and tells it everything to do. This is how old-school -bit Nintendo cartridges
work: each game contains a complete program that is responsible for every pixel
on the screen. But this is incredibly cumbersome for more complicated programs.
If you want to write a program to keep track of your knitting patterns, for example,
the last thing you want to do is write software to recognize individual keypresses
or for drawing the title bar at the top of the window. And if each program stands
completely alone, the only way to switch from one to another is to turn the computer off and on again – not exactly convenient when you want to look up a citation in one window and then type it into a brief in another.
Thus, modern computers run an operating system: a program that takes care of
the administrative details so that the applications – programs to carry out useful
tasks the user cares about – can focus on their particular jobs. Popular operating
systems include Apple OS X, Microsoft Windows, and Linux. Cell phones are
computers, too: their operating systems include Apple iOS and Google’s Android.
An operating system starts running when the computer turns on and never stops.
Even when an application is running, the operating system is waiting in the wings,
ready to step in if the application needs help or tries to misbehave. Typically, an
operating system offers its services to applications through a set of application
programming interfaces (or “APIs”): functions that an application can call on if it
wants to carry out some specific task, such as creating a window, playing a sound,
or drawing a line to the screen.
Operating systems are so ubiquitous that it’s easy to overlook just how many
problems they solve. A typical operating system does all of the following:
• Hardware independence: Computers come in all kinds of configurations and
work with all kinds of hardware: they have different hard drives, CPUs,
screens, graphics cards, game controllers, cameras, and network connectors,
to name just a few. The operating system frees applications from having to
worry about the precise details of the hardware, making it possible to write
an application that will run on hundreds of different devices.
• Powerful features: If you are writing a quiz game for the iPhone and would
like to add a phone-a-friend feature, you don’t need to write from scratch
the software to make a phone call. Instead, you can just send an openURL
message with the telephone number to dial to a UIApplication object.
What might have taken tens of thousands of lines of source code if you had
to write them yourself can be done in two, thanks to the APIs that iOS
makes available to applications.
• Consistent look and feel: Microsoft Windows looks different than Apple OS
X does. That’s because the Windows APIs draw windows and menus in a
different way than the OS X APIs do. Every program on Windows will be
8
* For a brainteaser, ask yourself how it’s possible to write a compiler. Isn’t the source
code for the compiler useless unless the compiler already works?
Chapter 1: Computers
27
displayed in a similar way just because it runs on Windows and uses the
Windows APIs. This consistency helps users orient themselves.
• Multitasking: Once you have an operating system to play traffic cop, you
can run multiple programs at the same time. The point of a “windows”
metaphor, or a list of “open apps,” is that each program is running, independently, and the user can switch between them at will. When a new message
arrives, the operating system routes it to your chat program, not your word
processor.
• Multiple users: An even more sophisticated version of multitasking involves
letting more than one person use the same computer. Your personal computer rarely does this, but you interact regularly with computers that do. A
web server, for example, is typically designed to interact with many different
users simultaneously: Gmail wouldn’t work well if only one person could use
it at a time.
• Security: Because computers contain all kinds of sensitive and valuable
data, from love emails to tax returns, it’s important to keep them secure. The
operating system typically plays a significant role in keeping data private
and in protecting data from accidental or deliberate destruction. When you
connect your computer to the WiFi network in a coffee shop, the operating
system prevents other people from installing their own software on your
computer or from snooping through your hard drive.
Jonathan Zittrain, whose book The Future of the Internet is excerpted below, has
compared this typical computer design to an “hourglass.” The operating system
sits at the narrow neck. Above it is a wild profusion of applications doing all kinds
of jobs. Beneath it is a wild profusion of hardware with all kinds of technical details. The operating system provides a standard layer that ensures a common experience for all those applications on all that different hardware.
5
1
1
0
1
0
0
5
TECHNICAL PRIMER: THE INTERNET
You may have heard of the metaphor of the Internet as a “cloud”: big and opaque.
In this section, we will systematically look inside the cloud to see how things work.
What we will find may be less complex than you may have feared.
Networks and Protocols
Computer networks come in all shapes and sizes. There are networks between
computers in the same room; there is a network that connects the International
Space Station to earth. There are computer networks for cell phones, networks for
playing video from your computer on your TV, even networks that connect a wireless mouse to your computer.
The key to every single one of these networks is the idea of a protocol: a specification that describes how computers should use the network to communicate. You
can think of a computer protocol as being like a diplomatic protocol: when two
delegations meet, there is a precise order of formal greetings, handshakes, and
statements. It may look bafflingly formal to an outsider, but the diplomats use it to
communicate important information to each other about their countries’ respective concerns.
Similarly, when two computers communicate, the protocol specifies every aspect of the technical process. A simple communications protocol along a wire
might say, for example, that a message of binary s and s should be encoded as a
series of electrical pulses of
nanoseconds each, with a being a pulse at .
28
Internet Law
volts and a being a pulse at volts. The sending computer turns the s and s
into an electrical signal on the cable; the receiving computer looks at the voltage
on the cable and turns it back into the s and s.
The enormous diversity of computer networks is possible because for each
physical medium, there are different protocols designed to take advantage of that
medium’s characteristics. The idea is similar to the way that different kinds of
roads have different traffic rules. You can drive faster on a highway than in a parking lot; you can drive different kinds of vehicles on a city street than on a bicycle
path; you drive on the right side of the road in some countries and the left side in
others.
It is common to call a physical medium connecting two computers together with
an appropriate protocol a network link. Here are some common (and less common) network links:
• Ethernet is a widely used protocol for local-area networking (e.g., within a
building, rather than cross-country). Its physical medium is most often “category cable,” a set of plastic-wrapped wires with a phone-like plug at each
end. The Ethernet protocol specifies how computers connected by an Ethernet cable should “talk” by turning the information they want to send to
each other into electrical pulses, how quickly they can talk, and what to do if
two of them start talking at the same time.
• Many computers use WiFi for their local-area networks. Here, the physical
medium is electromagnetic radiation, i.e. photons zipping through the air at
the speed of light. Each computer using WiFi has a small radio transmitter/
receiver. The WiFi protocol tells the radio transmitter on what frequencies
to broadcast and listen, how loudly and for how long to transmit, and what
to do if someone else starts transmitting at the same time.*
• Your cell phone also contains a radio, as do cell phone towers. Again, the
physical medium is electromagnetic radiation. Instead of using WiFi frequencies and transmission rules, however, the phones and towers use protocols with names like EDGE, EVDO, and UMTS to specify how they should
transmit information to each other.
• Internet signals can be carried over traditional copper or modern fiber-optic
phone cables; the DSL and GPON standards, respectively, provide protocols
for doing so. Cable companies use DOCSIS to do the same over cable connections. If you remember dialup, it used the PPP protocol to provide Internet access by having your computer make a phone call to a local phone
number, and encoded the data transmissions as audio (which is why picking
up another extension and making noise would generally destroy the connection).
• Fiber-optic “backbones” provide long-distance connections on land and via
undersea cable. They are engineered for super-high transmission speeds,
using highly specialized protocols .
• Computer data can even be transmitted via carrier pigeon. Here, the pigeon
is the physical layer, and the protocol specifies that data should be transmit-
0
1
0
1
0
0
5
* A standard wireless router has both a WiFi-compatible radio and an Ethernet-compatible jack. It translates messages that come in along the Ethernet link into WiFi
radio signals, and vice-versa.
Chapter 1: Computers
29
ted by writing digits on a piece of paper wrapped around the pigeon’s leg
and secured with duct tape.*
Inter-Networking and the Internet Protocol
The next complication is that not every computer is on the same small local network. Your computer has a direct network connection to only one or a few others.
The overwhelming majority of computers in the world do not have direct connections to each other, and it would obviously be impossible to try. How do we use the
diverse networks we have in order to build up something like the Internet, where
it is possible for computers around the world to communicate? This is the problem
of inter-networking, and the answer lies in something called the Internet Protocol,
or IP.
The first key idea of IP is routing. Suppose that you want to download an MP
from Amazon’s MP store. There isn’t a wire that directly connects your computer
to Amazon’s computer. Instead, the information making up the MP is passed
along from one computer to another – computers that are directly connected (by a
wire or other network link) – until it reaches you. In essence, Amazon’s computer
hands off the MP to a computer that is connected to it and is slightly closer to
you. That second computer hands off the MP to a third, which hands it off to a
fourth, and so on until it is handed off to a computer that is directly connected to
yours, which hands it off to you. Computers that participate in the process are
generally called routers.
Each handoff is, in essence, a computer-to-computer copy. The computer making the handoff transmits a complete copy of the data in the file to the next one. As
soon as the receiving computer acknowledges that it has received all the data, the
sending computer knows that it can delete its own copy. Transmitting information
through the Internet thus requires making as many transient intermediate copies
as there are computers in the chain from the original sender to the final recipient.
Along the way, the data will travel over many different kinds of network links.
It might start out on Ethernet inside Amazon’s data center, then be transmitted
along backbone links until it reaches your local area, then travel on a fiber-optic
cable supplied by your phone company, and finally reach your computer via WiFi
inside your home. All of these network links have one thing in common: they can
be used to carry IP messages.
This is a truly profound idea. Network engineers would say that IP is layered on
top of these various network links. The goal of any of the lower-level link protocols
listed above is to create a network that is capable of carrying IP messages. Once
that is accomplished, the IP message can be carried from computer to computer
across multiple different networks: Ethernet, backbone, WiFi, etc. The message
itself does not change in any significant way, even though the different link protocols will encode it in radically different ways on different networks.
This is why IP is called the Inter-net Protocol. It is designed to enable internetworking: the tying together of different networks. IP plays the crucial role of
giving these diverse networks a single common technical language. Indeed, this is
where the Inter-net gets its name: it was an experiment in inter-networking that
was so wildly successful that it became “the” Internet rather than just “an” Internet.
3
3
9
4
1
1
3
9
4
1
1
3
3
0
9
9
1
* No kidding. See D. Waitzman, A Standard for the Transmission of IP Datagrams on
Avian Carriers (
) (RFC
), http://tools.ietf.org/html/rfc
.
30
Internet Law
2
3
Routing and Addressing
But how do the computers along the chain know where to send the data? They
may only be connected to a few other computers, but the data could potentially be
going to any of the billions of computers on the Internet. How do they decide
which of their neighbors to pass the data along to?
The answer is that each computer on the Internet has a unique address, called
an “IP address” (named after IP, of course). An IP address is a
-digit binary
number; by convention, they are written as four decimal numbers separated by
periods. For example, here are the IP addresses of a few well-known computers:
apple.com
17.172.224.47
google.com
172.217.6.206
nytimes.com
151.101.193.164
mit.edu
104.79.147.28
Every message is carried in the electronic equivalent of an envelope with the IP
address of its destination stamped on the outside. When a router receives a message, it examines the IP address on the message. If that IP address is the router’s
own address, then the message has reached its destination and the process is done.
Otherwise, the router examines a large database called a “routing table,” which
tells the router what the next intermediate destination should be for any possible
ultimate destination. For example, a router’s routing table might say that all messages for google.com and apple.com (which are on the West Coast) should be given
next to its neighbor A, but that messages for nytimes.com and mit.edu (which are
on the East Coast) should be given to its neighbor B.
Each router has its own routing table. The process of constructing them is one
of the most complicated and intricate aspects of keeping the Internet functioning.
At a high level of generality, what happens is that individual routers tell each other
what computers they know how to get messages to. The information gradually
propagates throughout the Internet, until – in theory – every computer knows how
to reach every other computer.
Packet-Switching
The next complication is that most messages are too big to send all at once in this
fashion. Instead, they are broken down into smaller packets (sometimes also called
“datagrams”). Each packet is sent separately, like a jigsaw puzzle that is broken
down into individual pieces, each of which is sent in a separate envelope to the
same destination. Along the way, they may travel by different routes, depending on
factors like temporary congestion in some parts of the Internet, or routers coming
on- or off-line and thus becoming available or unavailable to pass packets along.
Packet switching may seem counterintuitive, but it has some notable advantages. One is that it is much more efficient than the alternative of “circuit-switching,” i.e., holding a dedicated connection all the way from sender to recipient open
for the entire duration of the transmission. Circuit-switching commits to a single
chain of computers from source to destination, but packet-switching allows the
transmission to respond to moment-to-moment changes in the Internet, taking
advantage of faster routes and avoiding sudden traffic jams. Packet-switching also
avoids tying up the intermediate computers when there is no data flowing; think
of a streaming concert video, where the flow of information will last for hours, but
is much less than the full capacity of any of the routers along the way. In addition,
as we will see shortly, packet-switching can be very resilient to errors.
Chapter 1: Computers
31
These three big ideas – routing, addressing, and packet-switching – collectively
characterize the Internet Protocol. As its name suggests, IP is central to how the
Internet works. Indeed, “the global network in which computers communicate
using IP” comes very close to being the technical definition of the Internet. We will
see throughout the this book how these technical features have important consequences for the law.
Reliable Transport
IP is not the only protocol that matters on the Internet. Instead, network engineers commonly speak of a protocol stack of multiple protocols in use at one time.
The “stack” metaphor captures the idea that these protocols are layered: ones at
higher levels take advantage of the services offered by the ones at lower levels to do
their jobs. Here is a simplified view of the protocol stack used by a typical home
computer:
• Application (e.g. email, web, etc.)
• Transport (TCP)
• Network (IP)
• Link (Ethernet)
• Physical (category cable)
We started off by discussing the physical and link layers. Then we saw how the
network layer – IP – ties different networks together into a single Internet with
world-wide addressing and routing. Now it is time to move up again.
The next layer above IP in the protocol stack is the transport layer, and the
most common protocol there is TCP, the “Transmission Control Protocol.”* It has
several jobs, but the most significant is “reliable transport”: that is, making sure
that every piece of a message reaches the destination. IP is a so-called “best efforts” protocol; routers will do their best to make sure that packets get where they
should, but they make no promises. Bad stuff regularly happens that causes packets to be lost. Sometimes a router is congested, with too much incoming traffic,
and it needs to start “dropping” packets in order to cope, like an overworked mail
carrier tossing some envelopes in the river. At other times, transient conditions,
like electrical interference or a bug in a router’s software, can cause a packet to be
scrambled so badly that the data in it is unrecoverable.
TCP deals with all of these problems through good bookkeeping. The sender
and the receiver each maintain a list of the individual packets making up a transmission. As the receiver receives each packet, it checks off that packet on its list
and informs the sender that it has. If the receiver realizes that it is missing a packet – for example, because it is receiving more recent packets without having received an older one – it asks the sender to retransmit the missing packet. Meanwhile, the sender is keeping track of which packets the receiver has acknowledged.
5
* TCP is not the only transport protocol. Not every application needs to ensure that
every single packet is delivered. A live voice chat, for example, is better off letting the
audio cut out for a fraction of a second than waiting for seconds for every last bit to
arrive. Multiplayer video games often prefer to minimize transmission delay so that
players can respond more quickly to each other. These and other applications often
use their own, specialized transport protocols. They have in common with TCP and
with each other that they all depend on IP: each of them uses IP to transmit its
packets, they just do different things with the results.
32
Internet Law
If too long a time passes without an acknowledgment from the receiver, the sender
assumes that something has gone wrong and initiates retransmission on its own.
This is why packet-switching can be surprisingly more error-resistant than
sending an entire message at once. It is true that, as with a jigsaw puzzle split
among ten thousand envelopes, there are more ways for something to go wrong.
But if a few packets go missing, TCP sees to it that just the missing ones are retransmitted, rather than needing to start the entire message from scratch. To continue the analogy, if a few puzzle pieces are missing, it’s easier to resend just the
missing ones than to mail the entire puzzle again. Similarly, because the packets
are smaller, they are less likely to suffer an error than a larger message would be. A
single jigsaw piece can be mailed in an ordinary envelope; the entire assembled
puzzle will require a special oversize padded mailer.
TCP is also responsible for “flow control”: the process of determining how fast
the sender slings packets through the Internet toward the receiver. If you have a
good fiber-optic connection, you would obviously prefer to send packets faster
than if you are connecting through a slow satellite connection. Put another way,
TCP automatically adapts on the fly to the amount of available bandwidth between sender and receiver. (The actual algorithms it uses to do so all involve clever
communication between sender and receiver, and have been tuned over the years
to values that seem to work well.)
Here, we can see another advantage of layering. TCP can completely ignore the
details of the underlying network. It doesn’t need to know whether its running on
a WiFi network or on Ethernet or whatever. It can delegate all of those details –
along with the details of routing – to lower-layer protocols. TCP is only responsible
for reliable transport and flow control, so it can focus on doing its job well. Unsurprisingly, this helps make TCP simpler than if it also had to do all of these other
jobs. Computer programmers would say that layering is a kind of “modularity”:
separating out different functions into smaller pieces makes them easier to get
right.
Applications
At last we arrive at the part of the Internet you are probably most familiar with:
applications. These are the programs that actually do things, like email, web
browsing, and instant messaging. They use TCP/IP* and other lower-level protocols to move data back and forth, and then do interesting things with it.
The first important detail here – one you are likely already familiar with – is the
idea of clients and servers. A server is a computer that has a particular resource or
that does a particular job. For example, the computer that stores your law school’s
webpage is a server, unsurprisingly called a “web server.” Other common servers
you probably use on a regular basis include email servers like Yahoo! Mail and
your school’s email, e-commerce servers like the iTunes Music Store, and chat
servers that tell you whether your friends are online.
A client is a computer that connects to a server to get information or have the
server do something for it. If you look at your law school’s webpage, your computer
is the client. It sends a message over the Internet to the web server, asking for the
webpage; the server responds with a message that contains all the information
making up the webpage. The process is similar with other servers. By convention,
information that goes from a client to a server is uploaded; information that goes
* The two were designed simultaneously and are so frequently used together that they
often go by this combined acronym.
Chapter 1: Computers
33
the other way, from server to client, is downloaded. When there is no clear distinction between which computer is the server and which is the client – and particularly when there are numerous computers acting both like clients and like servers
– the relationship is said to be peer-to-peer.
Applications often have their own protocols, layered on top of TCP/IP and the
other lower-level protocols. When one computer sends an email to another, it uses
a protocol named SMTP to tell the receiving computer whom the message is from,
whom it is for, what its subject is, and what its contents are. BitTorrent is a publicly published protocol for exchanging complete files. Skype uses a secret protocol
to exchange voice messages. Games use their own protocols to update players’
computers on what everyone else is doing.
Like a computer, the Internet also has an hourglass architecture. This time, IP
provides the narrow neck in the middle. Above it are millions of different applications. Beneath it are all kinds of different physical networks. Like an operating system, IP provides a standard middle layer that ties the different physical
networks together into a common network capable of supporting any number of
applications, even ones that no one has thought of yet.
The Web
Perhaps the single most important application on the Internet today is the World
Wide Web or “web.” The web actually consists of two closely related standards. The
first is a protocol, the Hypertext Transfer Protocol (or “HTTP”), for sending webpages from servers to clients. The second is a format, the Hypertext Markup Language (or “HTML”) for encoding a rich experience with images, hyperlinks, and
interactivity using nothing but raw text.
Let us start by considering the process of obtaining a webpage from a server.
Your web browser (e.g. Internet Explorer, Firefox, Chrome, or Safari) is a program
designed to request web pages from servers and display the results. Suppose, for
example, that you want to read the latest technology headlines from the New York
Times, so you type “nytimes.com/section/technology” into the the address bar
of your browser. It uses TCP to send a message to the New York Times server at
nytimes.com. In response, the New York Times server will send back a message
containing the webpage itself.
The rules of the road for this process – e.g., how the client describes the web
page it wants, and how the server explains whether that web page is available or
not – are governed by HTTP. The message from the client to the server is called a
request, and it starts with a line of text describing the page the client wants:
GET /section/technology
The message from the server back to the client is called a response and it starts
with a line of text summarizing the results of the request.
HTTP/1.1 200 OK
4
0
4
4
0
4
Here, 200 OK indicates that the request was successful, and the actual contents
of /section/technology follow in the body of the response. If you have ever seen
a webpage that displays the message “Error
not found,” then you have seen
HTTP at work.
is the error code used by HTTP to signal that the webpage the
client asked for does not exist.
What you have obtained from the server is not yet a webpage, only a long text
file. You can examine the details by going to any webpage and selecting the “View
34
Internet Law
Source” command in your browser.* What you will see is a set of instructions for
displaying the webpage you are looking at. This is the actual, literal data that was
sent from the server to your computer; your web browser is then able to transform
the data it into the webpage you see. (When people talk about “the source” of a
webpage or “the HTML” for the page, this is what they are referring to.)
Try this, for example, at your favorite news site or blog. Pick a headline, and
then try to find it in the page’s source. You should be able to pick it out, along with
a lot of things between angle brackets, i.e. “<” and “>” called tags. These tags are
the instructions, which your browser turns into visible formatting in the webpage
it displays to you.† Here is some simple HTML:
<li>I agree. We <b>have</b> been here before, as the <a
href="http://nytimes.com"> New York Times</a>
recognizes.</li>
When displayed by your browser, this text will look more like this:
I agree. We have been here before, as the New York Times
recognizes.
What’s different between the source and the displayed version? First, the <li> tag,
which stands for “list item,” tells your browser that what follows should be formatted as a bulleted item in a list. The matching </li> tag (which has a slash before
the li) marks the end of the item. Second, the <b> tag tells your browser to format
the following text as bold, up until the matching </b> tag marks the end of the
boldface segment. And third, the <a> tag, or “anchor,” specifies that the following
text is a hyperlink. If you click on it, your browser loads the web page it points at,
in this case the New York Times’s homepage. How did your browser know which
new webpage to load? It uses the location specified inside the <a> tag, following
the “href”‡ – in this case, “http://nytimes.com”.
One last HTML tag is worth explaining: <img>. Here is an example:
Yes, I’ve seen it, but I have no idea where they got the
name from: <img src="http://james.grimmelmann.net/images/
grimmelman-mosaic.jpg"/>
This will turn into the following in a browser:
* In most browsers, this is available under the “View” menu.
† Not every tag has visible consequences. In Chapter , you will encounter “meta tags,”
which carry information about the page (intended to be used by search engines), and
which are not ordinarily shown to normal web users. You can inspect them, however,
by using the View Source command.
6
‡ “href ” is a less obvious abbreviation than some of the others; it is short for “hypertext
reference.”
Chapter 1: Computers
35
Yes, I’ve seen it, but I have no idea where they got the name from:
Here, the <img> tag tells the browser that it should display a particular image in
that position. The image isn’t sent as part of the webpage itself. Instead, your
browser, when it sees an <img> tag, sends an additional request to the server with
the image. (Here, that server is james.grimmelmann.net, and note that the server
where the image comes from need not be the same server as the one where the
webpage came from.) The browser then drops the image into the place on the page
where the <img> tag was. You can think of the tag as being a kind of placeholder
for the image, one that includes instructions for how to fill in the place with a specific image.
The Domain-Name System
Another application is especially important to the functioning of the Internet. The
domain-name system converts human-readable names (like google.com and icanhascheezburger.com) into the IP addresses used by computers.
When you look up a domain name – say, espn.go.com – what really happens?
The process works hierarchically, from right to to left. Any URL, such as http://
espn.go.com/nba/, can be broken down into three parts. The http:// at the start is a
protocol identifier, which indicates that this is a request for a web page. The go.espn.com in the middle – everything up through the next slash – is the domain name
that identifies the server from which you’re requesting the web page. And the
“nba/” part (everything following the slash) identifies to the server which particular web page you are asking for.
The general rule is that if your computer (e.g., your web browser, when you type
a URL into the address bar) asks a domain-name server to look up a domain
name, it will tell you the IP address of the computer with that domain name if the
server knows. If the domain-name server doesn’t know about that particular domain name, the server will give you the IP address of another domain-name server
that can help you. That is, it will either help you or respond with the technical
equivalent of “I don’t know, but here’s someone who might.” Here’s a simplified
example:
(1) You start by asking the “root name server” what it knows about espn.go.com.
The root name server “understands” the last part of the address, here go.espn.com. It tells you that another computer – the so-called “top-level domain
(TLD) name server” for all .com sites worldwide – can help, and gives you
the IP address for the TLD name server.
(2) You ask the TLD name server for .com what it knows about espn.go.com. This
server “understands” the second part of the address, here espn.go.com. It tells
36
Internet Law
0
9
9
1
you that another computer – the name server for go.com – can help, and
gives you the IP address of this other name server.
(3) You ask the name server for go.com what it knows about espn.go.com. This
server “understands” the third part of the address, here espn.go.com. It gives
you the IP address for espn.go.com directly. Armed with the IP address, your
computer can now directly contact espn.go.com.
This process could in theory be iterated repeatedly, although in practice it rarely
continues for more than a few steps.
The Cloud
“The cloud” is not a specific technology in the way that the Internet protocol or the
web is. Instead, it is an informal name for a major trend in how people and companies use the Internet. Applications and other functions that previously ran on
computers in people’s homes and on businesses’ premises have moved “into the
cloud”: to computers in giant data centers operated by companies that specialize
in providing services over the Internet.
For example, consider Google Docs. In the
s, if you wanted to write the
rulebook for a board game you were designing, you would most likely have used a
desktop computer in your home, running a word-processing program like Microsoft Word. The files with drafts of your rulebook would have been stored on the
hard drive in your computer. This is still an option, and people still use their own
computers for many tasks.
But today, you also have cloud-based options like Google Docs. The files are
stored not on your own computer, but on a Google computer, located in one of its
many data centers around the world. You can access the rulebook by pointing your
browser to a Google Docs URL. The user interface for the Google Docs word processor is made up of HTML elements, delivered from Google’s servers to your
browser using HTTP. Any changes you make to the rulebook are saved back to a
Google server in a Google data center. You can download a copy to your own computer if you want (e.g., to print out a hard copy), but most of the time there is no
need to.
This example shows what it usually means to do something “in the cloud.”
What used to be a program (Word) you ran locally on your own computer is now a
service (Google Docs) provided remotely by a cloud-services company. You connect
to that service over the Internet, so you need a computer on your end to access it.
But your own computer does much less of the work. Other familiar examples of
cloud services include cloud photo storage like Apple iCloud and cloud file sharing
with Dropbox. If your university uses Blackboard or Canvas, these are cloud services too. Other cloud services are aimed at businesses, like Microsoft Azure, Amazon Web Services, and Google Cloud.
Doing things in the cloud has many advantages. For one thing, it is easily scalable. If a business is growing rapidly, it can be much easier for its IT department to
rent more capacity from an existing cloud provider than to create its own data center from scratch. For another, cloud providers have excellent economies of scale,
which helps keep the price of cloud services low. In addition, cloud providers’ expertise at the operational aspects of keeping their services running means that
they can be highly reliable, something that anyone who has ever lost data to a hard
drive crash can appreciate.
At the same time, there are tradeoffs to moving computing into the cloud. One
is that if you use a cloud service, you are dependent on it. If you are locked out of
Chapter 1: Computers
37
your Google account, you lose access to your Google Docs. Another is that the
round-trip time need to send data to and from a data center slows down applications; this has been a particular challenge for cloud-based gaming. Similarly,
if you are offline you lose access to data stored in the cloud until you connect to the
Internet again.
COLUMBIA PICTURES INDUS. V. FUNG
710 F.3d 1020 (9th Cir. 2013)
2
2
s
k
r
o
w
t
e
n
s
r
k
2
r
e
e
o
p
w
t
o
t
e
n
r
e
2
e
p
s
f
o
v
e
r
2
e
r
u
v
r
t
c
e
e
2
s
t
t
i
h
n
e
c
i
r
l
Berzon, Circuit Judge: …
I. C
.
- The traditional method of sharing content over a network is the relatively straightforward client-server model. In a client-server network, one or more central computers (called “servers”) store the information; upon request from a user (or
“client”), the server sends the requested information to the client. In other words,
the server supplies information resources to clients, but the clients do not share
any of their resources with the server. Client-server networks tend to be relatively
secure, but they have a few drawbacks: if the server goes down, the entire network
fails; and if many clients make requests at the same time, the server can become
overwhelmed, increasing the time it takes the server to fulfill requests from
clients. Client-server systems, moreover, tend to be more expensive to set up and
operate than other systems. Websites work on a client-server model, with the
server storing the website’s content and delivering it to users upon demand.
“Peer-to-peer” (P P) networking is a generic term used to refer to several different types of technology that have one thing in common: a decentralized infrastructure whereby each participant in the network (typically called a “peer,” but
sometimes called a “node”) acts as both a supplier and consumer of information
resources. Although less secure, P P networks are generally more reliable than
client-server networks and do not suffer from the same bottleneck problems.
These strengths make P P networks ideally suited for sharing large files, a feature
that has led to their adoption by, among others, those wanting access to pirated
media, including music, movies, and television shows. But there also are a great
number of non-infringing uses for peer-to-peer networks; copyright infringement
is in no sense intrinsic to the technology, any more than making unauthorized
copies of television shows was to the video tape recorder.
II. A
P2P
In a client-server network, clients can easily learn what files the server has available for download, because the files are all in one central place. In a P P network,
in contrast, there is no centralized file repository, so figuring out what information
other peers have available is more challenging. The various P P protocols permit
indexing in different ways.
A. “Pure” P2P networks
In “pure” P P networks, a user wanting to find out which peers have particular
content available for download will send out a search query to several of his neighbor peers. As those neighbor peers receive the query, they send a response back to
the requesting user reporting whether they have any content matching the search
terms, and then pass the query on to some of their neighbors, who repeat the same
two steps; this process is known as “flooding.” … Once the querying user has the
search results, he can go directly to a peer that has the content desired to download it.
38
Internet Law
2
2
2
2
1
0
0
2
2
2
2
2
2
2
This search method is an inefficient one for finding content (especially rare
content that only a few peers have), and it causes a lot of signaling traffic on the
network. The most popular pure P P protocol was Gnutella. StreamCast … used
Gnutella to power its software application, Morpheus.
B. “Centralized” P2P networks
“Centralized” P P networks, by contrast, use a centralized server to index the content available on all the peers: the user sends the query to the indexing server,
which tells the user which peers have the content available for download. At the
same time the user tells the indexing server what files he has available for others to
download. Once the user makes contact with the indexing server, he knows which
specific peers to contact for the content sought, which reduces search time and
signaling traffic as compared to a “pure” P P protocol.
Although a centralized P P network has similarities with a client-server network, the key difference is that the indexing server does not store or transfer the
content. It just tells users which other peers have the content they seek. In other
words, searching is centralized, but file transfers are peer-to-peer. One consequent
disadvantage of a centralized P P network is that it has a single point of potential
failure: the indexing server. If it fails, the entire system fails. Napster was a centralized P P network, as, in part, is eDonkey … .
C. Hybrid P2P networks
Finally, there are a number of hybrid protocols. The most common type of hybrid
systems use what are called “supernodes.” In these systems, each peer is called a
“node,” and each node is assigned to one “supernode.” A supernode is a regular
node that has been “promoted,” usually because it has more bandwidth available,
to perform certain tasks. Each supernode indexes the content available on each of
the nodes attached to it, called its “descendants.” When a node sends out a search
query, it goes just to the supernode to which it is attached. The supernode responds to the query by telling the node which of its descendant nodes has the desired content. The supernode may also forward the query on to other supernodes,
which may or may not forward the query on further, depending on the protocol.
The use of supernodes is meant to broaden the search pool as much as possible
while limiting redundancy in the search. As with centralized P P systems, supernodes only handle search queries, telling the nodes the addresses of the other nodes
that have the content sought; they are not ordinarily involved in the actual file
transfers themselves. Grokster’s software application was based on a P P protocol,
FastTrack, that uses supernodes.
III. BitTorrent protocol
The BitTorrent protocol, first released in
, is a further variant on the P P
theme. BitTorrent is a hybrid protocol with some key differences from “supernode”
systems. We discuss those differences after first describing BitTorrent’s distinguishing feature: how it facilitates file transfers.
A. BitTorrent file transfers.
Traditionally, if a user wanted to download a file on a P P network, he would locate another peer with the desired file and download the entire file from that peer.
Alternatively, if the download was interrupted – if, for example, the peer sending
the file signed off – the user would find another peer that had the file and resume
the download from that peer. The reliability and duration of the download depended on the strength of the connection between those two peers. Additionally,
39
the number of peers sharing a particular file was limited by the fact that a user
could only begin sharing his copy of the file with other peers once he had completed the download.
With the BitTorrent protocol, however, the file is broken up into lots of smaller
“pieces,” each of which is usually around
kilobytes (one-fourth of one
megabyte) in size. Whereas under the older protocols the user would download the
entire file in one large chunk from a single peer at a time, BitTorrent permits users
to download lots of different pieces at the same time from different peers. Once a
user has downloaded all the pieces, the file is automatically reassembled into its
original form.
BitTorrent has several advantages over the traditional downloading method.
Because a user can download different pieces of the file from many different peers
at the same time, downloading is much faster. Additionally, even before the entire
download is complete, a user can begin sharing the pieces he has already downloaded with other peers, making the process faster for others. Generally, at any
given time, each user is both downloading and uploading several different pieces
of a file from and to multiple other users; the collection of peers swapping pieces
with each other is known as a “swarm.”
B. BitTorrent architecture
To describe the structure of BitTorrent further, an example is helpful. Let us suppose that an individual (the “publisher”) decides to share via BitTorrent her copy
of a particular movie. The movie file, we shall assume, is quite large, and is already
on the publisher’s computer; the publisher has also already downloaded and installed a BitTorrent “client” program on her computer.
To share her copy of the movie file, the publisher first creates a very small file
called a “torrent” or “dot-torrent” file, which has the file extension “.torrent.” The
torrent file is quite small, as it contains none of the actual content that may be
copyrighted but, instead, a minimal amount of vital information: the size of the
(separate) movie file being shared; the number of “pieces” the movie file is broken
into; a cryptographic “hash” that peers will use to authenticate the downloaded
file as a true and complete copy of the original; and the address of one or more
“trackers.” Trackers, discussed more below, serve many of the functions of an indexing server; there are many different trackers, and they typically are not connected or related to each other.
Second, the publisher makes the torrent file available by uploading it to one or
more websites (“torrent sites”) that collect, organize, index, and host torrent files.
Whereas Napster and Grokster had search functionality built into their client programs, the standard BitTorrent client program has no such capability. BitTorrent
users thus rely on torrent sites to find and share torrent files. There is no central
repository of torrent files, but torrent sites strive to have the most comprehensive
torrent collection possible. …
Lastly, the publisher leaves her computer on and connected to the Internet,
with her BitTorrent program running. The publisher’s job is essentially done; her
computer will continue to communicate with the tracker assigned to the torrent
2
6
5
The client program is the software application used to access the P P network. Unlike Grokster or Napster, which were “closed” systems that permitted only authorized
client programs to connect to their networks, BitTorrent is an “open” system, permitting the use of any number of client programs, nearly all of which are free.
2
4
4
Chapter 1: Computers
40
Internet Law
file she uploaded, standing ready to distribute the movie file (or, more accurately,
parts thereof ) to others upon request.
A user seeking the uploaded movie now goes to the torrent site to which the
torrent file was uploaded and runs a search for the movie. The search results then
provide the torrent file for the user to download. Once the user downloads the torrent file and opens it with his BitTorrent program, the program reads the torrent
file, learns the address of the tracker, and contacts it. The program then informs
the tracker that it is looking for the movie associated with the downloaded torrent
file and asks if there are any peers online that have the movie available for download. Assuming that publishers of that movie are online, the tracker will communicate their address to the user’s BitTorrent program. The user’s BitTorrent program will then contact the publishers’ computers directly and begin downloading
the pieces of the movie. At this point, the various publishers are known as
“seeders,” and the downloading user a “leecher.” Once the leecher has downloaded
one or more pieces of the movie, he, too, can be a seeder by sending other leechers
the pieces that he has downloaded.
A final few words on trackers. Although no content is stored on or passes
through trackers, they serve as a central hub of sorts, managing traffic for their
associated torrents. The tracker’s primary purpose is to provide a list of peers that
have files available for download. …
Because trackers are periodically unavailable – they can go offline for routine
maintenance, reach capacity, be shuttered by law enforcement, and so on – torrent
files will often list addresses for more than one tracker. That way, if the first (or
“primary”) tracker is down, the user’s client program can proceed to contact the
backup tracker(s).
TECHNICAL PRIMER: CRYPTOGRAPHY
Cryptography is the science of secret communications. As a starting point, consider the problem facing Alice, who would like to send a message to Bob. So far, so
good, but Alice is also worried about Eve, who may be able to intercept the letter in
transit (perhaps by sneaking into the post office, or taking it from Bob’s mailbox
before he can open it). So Alice would like a way to encrypt her message so that
Bob can read (or decrypt) it but Eve cannot.
Traditional Cryptography
Here is an extremely simple form of encryption: rot . In this code every letter is
replaced by the letter thirteen letters later in the alphabet (the name is short for
“rotate by ”). Thus A becomes N, B becomes O, C becomes P, and so on. The full
table is:
ABCDEFGHIJKLMNOPQRSTUVWXYZ
NOPQRSTUVWXYZABCDEFGHIJKLM
3
1
3
1
3
1
3
1
3
1
Thus, suppose Alice wishes to encode the message (or plaintext) THIS CODE
SUCKS. She turns T into G, H into U, and so on. When she is done, she has the
coded message (or ciphertext) GUVF PBQR FHPXF. Eve stares at this gibberish,
mystified. But Bob, who knows the secret, simply rotates every letter back by
places. G becomes T, U becomes H, and so on, until he has THIS CODE SUCKS
again. Bingo! Secret secure.
The only problem is that rot is a terrible code, because it is so widely known.
Any lengthy English text encoded using rot- will have many words starting with
GU in the ciphertext (e.g. THIS becomes GUVF and THE becomes GUR). This is a
41
0
0
0
3
3
3
6
1
7
5
4
6
0
7
2
8
8
3
1
0
3
2
1
2
8
6
2
6
5
2
2
8
2
1
1
8
2
2
1
3
1
6
2
6
1
dead giveaway that Alice and Bob are using rot . Better codes reduce these predictable patterns.
Inventing a new code from scratch for every use would be a lot of work. Instead, cryptographers achieve better security by creating families of codes that use
the same encryption algorithm but can have many different possible secret keys.
Metaphorically, Alice puts the message in a box and seals the box with a lock that
only the secret key can open. Bob, who has the key, can open the lock and read the
message; Eve, who doesn’t have the key, is out of luck. If Bob wants to reply to Alice, he can use the secret key to lock the lock again; again, Alice can open the lock
but Eve cannot. Even if Eve recognizes the general type of lock, it tells her nothing
about which particular key opens it.
For example, a slightly more secure version of rot is rotN (“rotate by N”). Alice and Bob pick a number between and
to serve as the secret key. To encrypt,
Alice rotates each letter in the plaintext forward that many places in the alphabet;
to decrypt, Bob rotates each letter back by the same number. rot is rotN with the
secret key .
Unfortunately, rotN is still a terrible secret code. For one thing, it is vulnerable
to a brute force attack. Eve can simply try rotating an encrypted message by one
letter, then by two, then three, etc. With the aid of a computer, she can try each of
the
possible secret keys in a small faction of a second. Better codes have more
possible keys, so that brute force attacks take much longer. Fortunately, just as the
number of possible values a computer can store grows exponentially with the
number of bits, so too the number of possible keys grows exponentially with the
number of bits in a key. A code using
-bit keys is not twice as hard to bruteforce as a code using
-bit keys; it is
times harder.
Brute force can be surprisingly effective, particularly when it comes to that
most familiar of keys, the password. There are
,
,
,
eight-letter allcaps passwords. If a would-be hacker types in each possible password, one after
the other, at a rate of one password every five seconds, it will take about ,
years of nonstop work to try them all. But if the hacker runs a program that can
try a million passwords per second, it will take only about two and a half days. Basically, password guessing is futile, but a determined brute-force attack will succeed against many short or simple passwords.
Another problem with rotN is that it is vulnerable to cryptanalysis. Because it
is a simple substitution cipher, in which each letter in the plaintext is consistently
replaced by the same letter in the ciphertext, encrypted messages replicate all of
the patterns of English, e.g. some letters are much more frequent than others. If
Eve has a sample of Alice’s messages and notices that the letter G appears more
often than any other, she may guess that it represents E, so that Alice and Bob are
using the secret key . Better codes disguise these patterns, so that even small
changes to the plaintext or the secret key create large and unpredictable differences in the ciphertext, and so that encrypted messages are close to indistinguishable from completely random gibberish.
One well-known state-of-the-art algorithm is the Advanced Encryption Standard, or AES. It encrypts messages
bits at a time, using a secret key of up to
bits. It mixes the bytes of the plaintext by repeatedly scrambling bytes, adding
them together, and rearranging them. Although the process is long, and requires
dozens of steps, every step is easy to reverse – for someone like Bob who has the
secret key. Cryptographers currently believe that it is infeasible for someone like
Eve who lacks the secret key and must guess at it to decrypt encoded messages.
5
2
Chapter 1: Computers
42
Internet Law
Cryptographers have thought that about other algorithms before, and been wrong;
they may yet discover that AES is also vulnerable.
Even a stronger encryption algorithm like AES doesn’t solve all of Alice’s and
Bob’s problems. Eve could find a way to steal the secret key from Bob. Or Alice
might leave a copy of the plaintext lying around. Or Eve could kidnap Bob and
force him to turn over the key. No cryptographic algorithm can guard perfectly
against these other attacks. Cryptography is just one component of the larger
project of computer security.
Public-Key Cryptography
This is essentially where the state of the art in cryptography stood as of
: Alice
and Bob needed to share a single secret key, used for both encryption and decryption. In the next decade, though, two teams of researchers turned the world of
cryptography on its head.* In
, Whitfield Diffie and Martin Hellman published the idea of public-key cryptography. Their crucial idea was that only the
decryption key held by Bob really needs to be secret; if the encryption and decryption keys can be separated, then the encryption key can be public, and anyone
from Alice to Zelda can use it to encrypt messages to Bob. As long as Bob keeps his
private key secret, he can publish the public key to the world, including Eve. In
the metaphor, the public key is like a lock blueprint: anyone can use it to manufacture locks that only Bob can open. Whenever Alice needs to send Bob a message,
she manufactures a Bob-only lock.
As described, the Diffie-Hellman scheme was only an idea, not a workable system. But the next year, in
, Ron Rivest, Adi Shamir, and Leonard Adelman
published an actual algorithm (now known as RSA after its inventors) that made
public-key cryptography a reality. The insight behind the RSA algorithm is that as
far as we know it is much easier to multiply numbers than to factor them. To simplify slightly, to create a secret key, Bob picks a pair of very large prime numbers p
and q at random. He then uses their product, n p q, as his public key. To encrypt a message, anyone can write out the plaintext as a number, raise that number to a high power, and take the remainder after dividing by the public key n.
Thanks to some elegant mathematics, it is easy to undo the process but only if you
know what the factors of n are. Bob knows that n p q, but anyone else cannot
decrypt the message without factoring n, which mathematicians believe to be impractically hard. Since the RSA breakthrough, numerous other cryptographic algorithms have been built up from the same algebraic building blocks: multiplication, powers, and remainders.
The asymmetry of public-key encryption opens up all kinds of new and interesting possibilities beyond simply keeping messages secret. For example, in many
systems, Bob can use his private key to “sign” messages: only someone with the
private key can generate this digital signature, but anyone with the public key can
check that whoever signed it really did know the private key. Metaphorically, the
digital signature lets Bob use his private key as a stamp, leaving an unforgeable
imprint on the documents he signs. Bob could even combine a signature with encryption: signing a message with his private key and encrypting it with Alice’s pub-
0
7
9
1
×
×
=
=
6
7
9
1
7
7
9
1
* A third team, working inside the United Kingdom’s Government Communications
Headquarters (GCHQ), hit upon many of the same ideas independently and earlier,
but since spy agencies don’t publish, their work remained unknown to the world for
decades.
Chapter 1: Computers
43
lic key. Now Alice knows that the message is genuine and she is the only person
who can read it.
Digital signatures and related technologies have many, many applications:
• If Bob is careful about guarding his private key, he can use his digital signature as a source of authentication: anyone receiving a signed document
knows that it was generated by Bob. He could tell his correspondents not to
trust anything purporting to come from him unless it is digitally signed.
Banks and other financial institutions use signatures in this way to prove
the authenticity of transactions.
• Digital signatures can also be used to certify the integrity of a document. If
anyone unauthorized tries to alter the document, the signature will no
longer correspond to the altered document. Almost anything can be signed
this way; some states now use digital signatures to establish the authenticity
and integrity of their judicial opinions.
• Sometimes bits can be scrambled during the transmission of a message by
cosmic rays, power surges, or bugs. A receiver who checks the signature
against the message can use it as a form of error detection and see that
something has gone wrong and ask the sender to transmit it again. Hard
drives and other storage systems use error-detection algorithms to guard
against accidental data loss. If data in storage is corrupted, the error can be
spotted before it spreads, and the bad data can be replaced with a clean copy
known to be good.
• It is often convenient to use short digests of documents as a shorthand for
talking about them. So, for example, a two-megabyte image could be converted to a
-bit hash value.* Two images with different hash values are
definitely different; two images with the same hash value are extremely, extremely likely to be identical. The hash values provide a fast way to check
whether two images are the same – very useful if you run a site where users
upload images and you don’t want to store the same image again and again.
Some hashing algorithms are designed to be secure: even an adversary who
is determined to find two documents with the same hash value is highly unlikely to succeed.
• A watermark embeds one message in another with the goal of making it
possible to tell where a given file came from. Stock photograph websites watermark their sample images; movie studios watermark the promotional
copies they distribute to media outlets. Watermarks need not be visible to
humans; ideally they should be hard to remove. In
, the Recording Industry Association of America threatened a lawsuit against a team of academic researchers who showed it was easy to remove the watermarks in a
proposed scheme for watermarking audio files.
• In steganography, the goal is to hide one message undetectably inside another. A crude steganography scheme might use one space after a period to
indicate a and two spaces to indicate , hiding a short coded message inside an email. More sophisticated forms of steganography tweak small bits
in an image or video: tiny variations in color or sound levels are completely
imperceptible to humans.
0
0
0
2
1
6
5
2
0
* Not to be confused with a Twitter hash tag.
Internet Law
One hard problem in any encryption system is key distribution: how do Alice and
Bob learn each others’ keys? There is a chicken-and-egg problem here: unless Alice and Bob already have a secure way to communicate, Alice cannot be sure she is
talking to Bob rather than to Eve pretending to be Bob. One common solution is
for some trusted third party to certify Alice and Bob’s identities (using its own
digital signature, of course): either a major hard-to-imitate institution like Google,
or a mutual friend. So, for example, certificate authorities like Symantec or Comodo issue certificates using the X.
standard: these certificates contain the public
key for some entity and are signed with the certificate authority’s own secret key.
Of course, certificate authorities have their own key-distribution problem: how do
you know what the authority’s public key is? For this reason, browser makers frequently include certificates; anyone using Firefox already has a copy, supplied by
Firefox, of Comodo’s public key.*
An Example
Real-world computer systems frequently combine many cryptographic techniques
together into more complicated protocols. For example, Transport Layer Security,
or TLS, is a widely used protocol for clients and servers to communicate securely.
Here is a simplified version of the process:
1. Well in advance, the server obtains an X.509 certi cate that lists its domain
name and RSA public key.
2. The client sends a simple “hello” message to the server indicating that it
wishes to communicate securely.
3. The server responds with its own “hello” message that includes the server’s
X.509 certi cate.
4. The client checks the validity of the X.509 certi cate. Among other things, it
veri es:
• That the signature is issued by a certi cate authority the client trusts.
• That the signature on the certi cate is valid.
• That the domain name listed on the certi cate matches the domain
name the client thinks it is contacting.
• That the certi cate has not expired or been revoked by the
certi cation authority.†
. The client now knows the server’s RSA public key. It sends the server an
RSA-encrypted message containing a random number.
. The server uses its private RSA key to decrypt the random number. Both the
client and the server now know the random number, but no one else does.
They can therefore use it as a shared AES key.
. The client encrypts its first substantive message to the server using their
shared AES key and sends the encrypted message to the server.
* If it occurred to you to ask how you know that you received a properly authenticated
copy of Firefox when you downloaded it, rather than a modified version that includes a forged public key for an impostor pretending to be Comodo, congratulations, you are starting to think like an Internet security expert.
fi
fi
fi
fi
9
0
5
fi
fi
fi
fi
† Test yourself. What could go wrong if the client omits any of these checks?
fi
7
6
5
44
45
. The server decrypts the message using the AES key, determines its response,
encrypts that response using the AES key, and sends the encrypted response
to the client.
. If desired, the client and server can continue the process using the same
AES key as long as the connection stays open.
Among other things, TLS is the basis for HTTPS, the encrypted version of HTTP.
When your browser shows you a lock in the address bar (or another visual indicator of a secure connection), it means that your HTTP messages to and from the
server are encrypted using TLS, keeping the contents safe from eavesdroppers.
The easiest way to request an HTTPS connection is to replace http:// with
https:// when typing in a URL – although not all servers honor clients’ requests
to use HTTPS. Regular HTTP connections are unencrypted, so that anyone in a
position to observe your messages (e.g. your ISP) can see what URLs you are
browsing to and what those web pages contain.
Observe that in this example, TLS employs certificates (X.
), public-key encryption (RSA), and shared-key encryption (AES). This combination of smaller
pieces is common in modern cryptography and enables some remarkable feats of
security engineering. Unfortunately it also means that when one piece proves to be
vulnerable, whole edifices are at risk. The infamous Heartbleed bug of
was a
coding mistake in the most common server implementation of TLS: by sending a
particular kind of malformatted message, a client could cause a server to send
back the contents of its memory. Since a common use of TLS is logging into websites, that part of memory often contained users’ passwords. Ironically, until the
bug was fixed, changing one’s password actually made things worse, because a
user would typically then log in using the new password, exposing it to attackers
using Heartbleed. Despite striking advances in cryptography, Internet security
remains a hard problem.
INTERNET APPLICATIONS PROBLEM
4
1
0
2
9
0
Familiarize yourself with the following:
• Jason Kottke’s blog
• Gmail
• Amazon.com
• Skype
• Twitter
• Facebook
• Google
• YouTube
• World of Warcraft
• Snapchat
• Target Cartwheel
• Pokémon GO
You don’t need to use the applications or sign up for accounts, but you should be at
least passingly familiar with them. They provide a useful range of examples. Do
your best to answer the following questions for each of these applications:
. What can you do using this application?
. Do you need to install special software to run this application, or can you
use it from your web browser? If you need special software, what kinds of
devices is the software available for?
5
9
8
2
1
Chapter 1: Computers
9
8
7
6
5
4
3
46
Internet Law
. Does the application require that you and other users both be online at the
same time? If so, how does the application figure out that you’re both available?
. How does the message get from your computer to someone else’s (or viceversa)? Is it stored anywhere along the way? Who could listen in or read it if
they wanted?
. How – in a very general sense – is the content encoded? Is it human-legible?
Does its quality suffer in transit?
. Are there servers somewhere that assist in making the application available?
If so, do they store the content, or do they merely assist in making connections? Could you make connections without the assistance of a server?
Who’s in charge of keeping those servers running, providing them with electricity, and so on?
. Do you need an account to post content? To receive it? How much information about yourself do you need to give up in order to participate?
. Who’s allowed to post content, and of what sort? Is this an egalitarian medium, or one in which only a few people speak and the vast majority only listen?
. What happens “under the hood?” Is there a flow of information that you can
describe in general terms, or does something so mysterious happen that it
might as well be magic?
B. Theory
LAWRENCE LESSIG
LAWRENCE LESSIG, CODE 2.0
(Basic Books 2006)
There are many ways to think about “regulation.” I want to think about it from the
perspective of someone who is regulated, or, what is different, constrained. That
someone regulated is represented by this (pathetic) dot – a creature (you or me)
subject to different regulations that might have the effect of constraining (or as
we’ll see, enabling) the dot’s behavior. By describing the various constraints that
might bear on this individual, I hope to show you something about how these constraints function together.
Here then is the dot.
How is this dot “regulated”?
Let’s start with something easy: smoking. If you want to smoke, what constraints do you face? What factors regulate your decision to smoke or not?
One constraint is legal. In some places at least, laws regulate smoking – if you
are under eighteen, the law says that cigarettes cannot be sold to you. If you are
under twenty-six, cigarettes cannot be sold to you unless the seller checks your ID.
Chapter 1: Computers
47
Laws also regulate where smoking is permitted – not in O’Hare Airport, on an airplane, or in an elevator, for instance. In these two ways at least, laws aim to direct
smoking behavior. They operate as a kind of constraint on an individual who
wants to smoke.
But laws are not the most significant constraints on smoking. Smokers in the
United States certainly feel their freedom regulated, even if only rarely by the law.
There are no smoking police, and smoking courts are still quite rare. Rather,
smokers in America are regulated by norms. Norms say that one doesn’t light a
cigarette in a private car without first asking permission of the other passengers.
They also say, however, that one needn’t ask permission to smoke at a picnic.
Norms say that others can ask you to stop smoking at a restaurant, or that you
never smoke during a meal. These norms effect a certain constraint, and this constraint regulates smoking behavior.
Laws and norms are still not the only forces regulating smoking behavior. The
market is also a constraint. The price of cigarettes is a constraint on your ability to
smoke – change the price, and you change this constraint. Likewise with quality. If
the market supplies a variety of cigarettes of widely varying quality and price, your
ability to select the kind of cigarette you want increases; increasing choice here
reduces constraint.
Finally, there are the constraints created by the technology of cigarettes, or by
the technologies affecting their supply. Nicotine-treated cigarettes are addictive
and therefore create a greater constraint on smoking than untreated cigarettes.
Smokeless cigarettes present less of a constraint because they can be smoked in
more places. Cigarettes with a strong odor present more of a constraint because
they can be smoked in fewer places. How the cigarette is, how it is designed, how it
is built – in a word, its architecture – affects the constraints faced by a smoker.
Thus, four constraints regulate this pathetic dot – the law, social norms, the
market, and architecture – and the “regulation” of this dot is the sum of these four
constraints. Changes in any one will affect the regulation of the whole. Some constraints will support others; some may undermine others. Thus, changes in technology may usher in changes in norms, and the other way around. A complete
view, therefore, must consider these four modalities together.
So think of the four together like this:
In this drawing, each oval represents one kind of constraint operating on our pathetic dot in the center. Each constraint imposes a different kind of cost on the dot
for engaging in the relevant behavior – in this case, smoking. The cost from norms
48
Internet Law
is different from the market cost, which is different from the cost from law and the
cost from the (cancerous) architecture of cigarettes.
The constraints are distinct, yet they are plainly interdependent. Each can support or oppose the others. Technologies can undermine norms and laws; they can
also support them. Some constraints make others possible; others make some impossible. Constraints work together, though they function differently and the effect
of each is distinct. Norms constrain through the stigma that a community imposes; markets constrain through the price that they exact; architectures constrain
through the physical burdens they impose; and law constrains through the punishment it threatens.
We can call each constraint a “regulator,” and we can think of each as a distinct
modality of regulation. Each modality has a complex nature, and the interaction
among these four is also hard to describe. [F]or now, it is enough to see that they
are linked and that, in a sense, they combine to produce the regulation to which
our pathetic dot is subject in any given area.
We can use the same model to describe the regulation of behavior in cyberspace.
Law regulates behavior in cyberspace. Copyright law, defamation law, and obscenity laws all continue to threaten ex post sanction for the violation of legal
rights. How well law regulates, or how efficiently, is a different question: In some
cases it does so more efficiently, in some cases less. But whether better or not, law
continues to threaten a certain consequence if it is defied. Legislatures enact;
prosecutors threaten; courts convict.
Norms also regulate behavior in cyberspace. Talk about Democratic politics in
the alt.knitting newsgroup, and you open yourself to flaming; “spoof ” someone’s
identity in a MUD [Multi-User Dungeon, a kind of early, text-based virtual
world], and you may find yourself “toaded”; talk too much in a discussion list, and
you are likely to be placed on a common bozo filter. In each case, a set of understandings constrain behavior, again through the threat of ex post sanctions imposed by a community.
Markets regulate behavior in cyberspace. Pricing structures constrain access,
and if they do not, busy signals do. (AOL learned this quite dramatically when it
shifted from an hourly to a flat-rate pricing plan.) Areas of the Web are beginning
to charge for access, as online services have for some time. Advertisers reward
popular sites; online services drop low-population forums. These behaviors are all
a function of market constraints and market opportunity. They are all, in this
sense, regulations of the market.
Finally, an analog for architecture regulates behavior in cyberspace – code. The
software and hardware that make cyberspace what it is constitute a set of constraints on how you can behave. The substance of these constraints may vary, but
they are experienced as conditions on your access to cyberspace. In some places
(online services such as AOL, for instance) you must enter a password before you
gain access; in other places you can enter whether identified or not. In some
places the transactions you engage in produce traces that link the transactions (the
“mouse droppings”) back to you; in other places this link is achieved only if you
want it to be.
In some places you can choose to speak a language that only the recipient can
hear (through encryption); in other places encryption is not an option. The code
or software or architecture or protocols set these features, which are selected by
code writers. They constrain some behavior by making other behavior possible or
1
Chapter 1: Computers
49
impossible. The code embeds certain values or makes certain values impossible. In
this sense, it too is regulation, just as the architectures of real-space codes are regulations. …
On Governments and Ways to Regulate
I’ve described four constraints that I’ve said “regulate” an individual. But these
separate constraints obviously don’t simply exist as givens in a social life. They are
neither found in nature nor fixed by God. Each can be changed, though the mechanics of changing them is complex. Law can have a significant role in this mechanics, and my aim in this section is to describe that role.
A simple example will suggest the more general point. Say the theft of car radios is a problem – not big in the scale of things, but a frequent and costly enough
problem to make more regulation necessary. One response might be to increase
the penalty for car radio theft to life in prison, so that the risk faced by thieves
made it such that this crime did not pay. If radio thieves realized that they exposed
themselves to a lifetime in prison each time they stole a radio, it might no longer
make sense to them to steal radios. The constraint constituted by the threatened
punishment of law would now be enough to stop the behavior we are trying to
stop.
But changing the law is not the only possible technique. A second might be to
change the radio’s architecture. Imagine that radio manufacturers program radios
to work only with a single car – a security code that electronically locks the radio
to the car, so that, if the radio is removed, it will no longer work. This is a code
constraint on the theft of radios; it makes the radio no longer effective once stolen.
It too functions as a constraint on the radio’s theft, and like the threatened punishment of life in prison, it could be effective in stopping the radio-stealing behavior.
Thus, the same constraint can be achieved through different means, and the
different means cost different amounts. The threatened punishment of life in
prison may be fiscally more costly than the change in the architecture of radios
(depending on how many people actually continue to steal radios and how many
are caught). From this fiscal perspective, it may be more efficient to change code
than law. Fiscal efficiency may also align with the expressive content of law – a
punishment so extreme would be barbaric for a crime so slight. Thus, the values
may well track the efficient response. Code would be the best means to regulate.
The costs, however, need not align so well. Take the Supreme Court’s hypothetical example of life in prison for a parking ticket. It is likely that whatever code
constraint might match this law constraint, the law constraint would be more efficient (if reducing parking violations were the only aim). There would be very few
victims of this law before people conformed their behavior appropriately. But the
“efficient result” would conflict with other values. If it is barbaric to incarcerate for
life for the theft of a radio, it is all the more barbaric as a penalty for a parking violation. The regulator has a range of means to effect the desired constraint, but the
values that these means entail need not align with their efficiency. The efficient
answer may well be unjust – that is, it may conflict with values inherent in the
norms, or law (constitution), of the society
.
QUESTIONS
Littering: Consider a familiar problem: littering. How can law deal with littering? What can markets do to reduce littering? How do social norms affect
Internet Law
whether people litter or not? And can you think of any architectural factors
that encourage or discourage littering?
. Interactions Among Modalities: How can software substitute for law? How can
software make law more effective? How can software undermine legal control? Try to give an example of each.
. Software as Architecture: Although he famously summed up his theory with
the phrase “code is law,” Lessig makes the point that software isn’t the same
as law. Instead, he describes computer software as a kind of “architecture.”
Why does he use that word? How accurate is the metaphor?
JONATHAN ZITTRAIN
JONATHAN ZITTRAIN, THE FUTURE OF THE INTERNET
AND HOW TO STOP IT
(Yale University Press 2008)
n
o
i
t
c
u
d
o
r
t
I
The Apple II was quintessentially generative technology. It was a platform. It invited people to tinker with it. Hobbyists wrote programs. Businesses began to plan
on selling software. Jobs (and Apple) had no clue how the machine would be used.
They had their hunches, but, fortunately for them, nothing constrained the PC to
the hunches of the founders. Apple did not even know that VisiCalc [the first
spreadsheet program] was on the market when it noticed sales of the Apple II skyrocketing. The Apple II was designed for surprises – some very good (VisiCalc),
and some not so good (the inevitable and frequent computer crashes).
The iPhone is the opposite. It is sterile. Rather than a platform that invites innovation, the iPhone comes preprogrammed. You are not allowed to add programs
to the all-in-one device that Steve Jobs sells you. Its functionality is locked in,
though Apple can change it through remote updates. Indeed, to those who managed to tinker with the code to enable the iPhone to support more or different applications, Apple threatened (and then delivered on the threat) to transform the
iPhone into an iBrick. The machine was not to be generative beyond the innovations that Apple (and its exclusive carrier, AT&T) wanted. Whereas the world
would innovate for the Apple II, only Apple would innovate for the iPhone. (A
promised software development kit may allow others to program the iPhone with
Apple’s permission.) …
In the arc from the Apple II to the iPhone, we learn something important
about where the Internet has been, and something more important about where it
is going. The PC revolution was launched with PCs that invited innovation by others. So too with the Internet. Both were generative: they were designed to accept
any contribution that followed a basic set of rules (either coded for a particular
operating system, or respecting the protocols of the Internet). Both overwhelmed
their respective proprietary, non-generative competitors, such as the makers of
stand-alone word processors and proprietary online services like CompuServe and
AOL. But the future unfolding right now is very different from this past. The future is not one of generative PCs attached to a generative network. It is instead one
of sterile appliances tethered to a network of control.
These appliances take the innovations already created by Internet users and
package them neatly and compellingly, which is good – but only if the Internet and
PC can remain sufficiently central in the digital ecosystem to compete with lockeddown appliances and facilitate the next round of innovations. The balance between the two spheres is precarious, and it is slipping toward the safer appliance.
n
3
2
50
Chapter 1: Computers
51
1
5
2
3
0
6
3
é
n
r
e
t
t
a
e
v
i
t
a
4
r
e
n
e
e
h
For example, Microsoft’s Xbox
video game console is a powerful computer,
but, unlike Microsoft’s Windows operating system for PCs, it does not allow just
anyone to write software that can run on it. …
It is not easy to imagine the PC going extinct, and taking with it the possibility
of allowing outside code to run – code that is the original source of so much of
what we find useful about the Internet. But along with the rise of information appliances that package those useful activities without readily allowing new ones,
there is the increasing lockdown of the PC itself. PCs may not be competing with
information appliances so much as they are becoming them. The trend is starting
in schools, libraries, cyber caf s, and offices, where the users of PCs are not their
owners. The owners’ interests in maintaining stable computing environments are
naturally aligned with technologies that tame the wildness of the Internet and PC,
at the expense of valuable activities their users might otherwise discover. …
T G
P
I have termed this quality of the Internet and of traditional PC architecture “generativity.” Generativity is a system’s capacity to produce unanticipated change
through unfiltered contributions from broad and varied audiences. Terms like
“openness” and “free” and “commons” evoke elements of it, but they do not fully
capture its meaning, and they sometimes obscure it.
Generativity pairs an input consisting of unfiltered contributions from diverse
people and groups, who may or may not be working in concert, with the output of
unanticipated change. For the inputs, how much the system facilitates audience
contribution is a function of both technological design and social behavior. A system’s generativity describes not only its objective characteristics, but also the ways
the system relates to its users and the ways users relate to one another. In turn,
these relationships reflect how much the users identify as contributors or participants, rather than as mere consumers.
Features of a Generative System
What makes something generative? There are five principal factors at work: ( )
how extensively a system or technology leverages a set of possible tasks; ( ) how
well it can be adapted to a range of tasks; ( ) how easily new contributors can
master it; ( ) how accessible it is to those ready and able to build on it; and ( )
how transferable any changes are to others – including (and perhaps especially)
nonexperts.
Leverage: Leverage makes a difficult job easier. Leverage is not exclusively a
feature of generative systems; non-generative, specialized technologies can provide
leverage for their designated tasks. But as a baseline, the more a system can do, the
more capable it is of producing change. Examples of leverage abound: consider a
lever itself (with respect to lifting physical objects), a band saw (cutting them), an
airplane (transporting them from one place to another), a piece of paper (hosting
written language, wrapping fish), or an alphabet (constructing words). Our world
teems with useful objects and processes, both natural and artificial, tangible and
intangible. Both PCs and network technologies have proven very leveraging. A
typical PC operating system handles many of the chores that the author of an application would otherwise have to worry about, and properly implemented Internet Protocol sees to it that bits of data move from one place to another without
application authors having to worry on either end. A little effort can thus produce
a very powerful computer program, whether a file-sharing program or a virus
comprising just a few lines of code.
52
Internet Law
Adaptability: Adaptability refers to how easily the system can be built on or
modified to broaden its range of uses. A given instrumentality may be highly
leveraging yet suited only to a limited range of applications. For example, TiVo is
greatly leveraging – television viewers describe its impact on their lives as revolutionary – but it is not very adaptable. A plowshare enables one to plant a variety of
seeds; however, its comparative leverage quickly vanishes when devoted to other
tasks such as holding doors open. The same goes for swords (they really make poor
plowshares), guns, chairs, band saws, and even airplanes. Adaptability is clearly a
spectrum. Airplanes can transport people and things, or they can be configured to
dust or bomb what lies below. But one can still probably count the kinds of uses
for an airplane on two hands. A technology that affords hundreds of different, additional kinds of uses beyond its essential application is more adaptable and, all
else being equal, more generative than a technology that offers fewer kinds of uses.
The emphasis here is on uses not anticipated at the time the technology was developed. A thick Swiss Army knife may have plenty of built-in tools compared with
a simple pocket knife, but many of those are highly specialized.
By this reckoning, electricity is an amazingly adaptable technology, as is plastic
(hence the historical use of “plastic” to refer to notions of sculptability). And so are
the PC and the Internet: they can be endlessly diverted to new tasks not counted
on by their original makers.
Ease of mastery: A technology’s ease of mastery reflects how easy it is for broad
audiences to understand how to adopt and adapt it. The airplane is not readily
mastered, being neither easy to fly nor easy to learn how to modify for new purposes. The risk of physical injury if the modifications are poorly designed or executed is a further barrier to such tinkering. Paper, on the other hand, is readily
mastered: we teach our children how to use it, draw on it, and even fold it into paper airplanes (which are much easier to fly and modify than real ones), often before they enter preschool. The skills required to understand many otherwise generative technologies are often not very readily absorbed. Many technologies require apprenticeships, formal training, or many hours of practice if one is to become conversant in them. The small electronic components used to build radios
and doorbells fall into this category – one must learn both how each piece functions and how to solder – as do antique car engines that the enthusiast wants to
customize. Of course, the skills necessary to operate certain technologies, rather
than modify them, are often more quickly acquired. For example, many quickly
understand how to drive a car, an understanding probably assisted by user-friendly inventions such as the automatic transmission.
Ease of mastery also refers to the ease with which various types of people might
deploy and adapt a given technology, even if their skills fall short of full mastery. A
pencil is easily mastered: it takes a moment to understand and put to many uses,
even though it might require a lifetime of practice and innate artistic talent to
achieve Da Vincian levels of leverage from it. The more useful a technology is both
to the neophyte and to the expert, the more generative it is. PCs and network
technologies are not easy for everyone to master, yet many people are able to learn
how to code, often (or especially) without formal training.
Accessibility: The easier it is to obtain access to a technology, along with the
tools and information necessary to achieve mastery of it, the more generative it is.
Barriers to accessibility can include the sheer expense of producing (and therefore
consuming) the technology, taxes, regulations associated with its adoption or use,
and the secrecy its producers adopt to maintain scarcity or control.
Chapter 1: Computers
53
1
5
7
Measured by accessibility, paper, plowshares, and guns are highly accessible,
planes hardly at all, and cars somewhere in between. It might be easy to learn how
to drive a car, but cars are expensive, and the government can always revoke a
user’s driving privileges, even after the privileges have been earned through a
demonstration of driving skill. Moreover, revocation is not an abstract threat because effective enforcement is not prohibitively expensive. Measured by the same
factors, scooters and bicycles are more accessible, while snowplows are less so.
Standard PCs are very accessible; they come in a wide range of prices, and in a few
keystrokes or mouse-clicks one can be ready to write new code for them. On the
other hand, specialized PC modes – like those found in “kiosk mode” at a store
cycling through slides – cannot have their given task interrupted or changed, and
they are not accessible.
Transferability: Transferability indicates how easily changes in the technology
can be conveyed to others. With fully transferable technology, the fruits of skilled
users’ adaptations can be easily conveyed to less-skilled others. The PC and the
Internet together possess very strong transferability: a program written in one
place can be shared with, and replicated by, tens of millions of other machines in a
matter of moments. By contrast, a new appliance made out of a -in- Electronic
Project Kit is not easily transferable because the modifier’s changes cannot be easily conveyed to another kit. Achieving the same result requires manually wiring a
new kit to look like the old one, which makes the project kit less generative.
Generative and Non-Generative Systems Compared
Generative tools are not inherently better than their non-generative (“sterile”)
counterparts. Appliances are often easier to master for particular uses, and because their design often anticipates uses and abuses, they can be safer and more
effective. For example, on camping trips, Swiss Army knives are ideal. Luggage
space is often at a premium, and such a tool will be useful in a range of expected
and even unexpected situations. In situations when versatility and space constraints are less important, however, a Swiss Army knife is comparatively a fairly
poor knife – and an equally awkward magnifying glass, saw, and scissors.
As the examples and terms suggest, the five qualities of leverage, adaptability,
ease of mastery, accessibility, and transferability often reinforce one another. And
the absence of one of these factors may prevent a technology from being generative. A system that is accessible but difficult to master may still be generative if a
small but varied group of skilled users make their work available to less-sophisticated users. Usually, however, a major deficiency in any one factor greatly reduces
overall generativity. This is the case with many tools that are leveraging and
adaptable but difficult to master. For example, while some enjoy tinkering in home
workshops, making small birdhouses using wood and a saw, most cannot build
their own boats or decks, much less pass those creations on to others. Similarly,
there are plenty of examples of technology that is easy to master and is quite
adaptable, but lacks leverage. Lego building blocks are easy to master and can
produce a great range of shapes, but regardless of the skill behind their arrangement they remain small piles of plastic, which largely confines their uses to that of
toys.
The more that the five qualities are maximized, the easier it is for a system or
platform to welcome contributions from outsiders as well as insiders. Maximizing
these qualities facilitates the technology’s deployment in unanticipated ways. …
54
Internet Law
Generativity’s Output: Innovation
To those for whom innovation is important, generative systems can provide for a
kind of organic innovation that might not take place without them. …
Non-generative systems can grow and evolve, but their growth is channeled
through their makers: a new toaster is released by Amana and reflects anticipated
customer demand or preferences, or an old proprietary network like CompuServe
adds a new form of instant messaging by programming it itself. When users pay
for products or services in one way or another, those who control the products or
services amid competition are responsive to their desires through market pressure.
This is an indirect means of innovation, and there is a growing set of literature
about its limitation: a persistent bottleneck that prevents certain new uses from
being developed and cultivated by large incumbent firms, despite the benefits they
could enjoy with a breakthrough.
We have already seen this phenomenon by anecdote in the first part of this
book. … The telephone system was stable and predictable; its uses evolved slowly
if at all from its inception in the late nineteenth century. It was designed to facilitate conversations between two people at a distance, and with some important
exceptions, that is all it has done. The change it has wrought for society is, of
course, enormous, but the contours of that change were known and set once there
was a critical mass of telephones distributed among the general public. Indeed,
given how revolutionary a telephone system is to a society without one, it is striking that the underlying technology and its uses have seen only a handful of variations since its introduction. This phenomenon is an artifact of the system’s rejection of outside contributions. In the United States, after the law compelled AT&T
to permit third-party hardware to connect, we saw a number of new endpoint devices: new telephone units in various shapes, colors, and sizes; answering machines; and, most important, the telephone modem, which allows the non-generative network itself to be repurposed for widespread data communication.
We saw a similar pattern as the Internet overtook proprietary networks that did
not even realize it was a competitor. The generative Internet is a basic, flexible
network, which began with no innate content. The content was to appear as people and institutions were moved to offer it. By contrast, the proprietary networks
of CompuServe, AOL, Prodigy, and Minitel were out beating the bushes for content, arranging to provide it through the straightforward economic model of being
paid by people who would spend connect time browsing it. If anything, we would
expect the proprietary networks to offer more, and for a while they did. But they
also had a natural desire to act as gatekeepers – to validate anything appearing on
their network, to cut individual deals for revenue sharing with their content
providers, and to keep their customers from affecting the network’s technology.
These tendencies meant that their rates of growth and differentiation were slow. A
few areas that these networks consigned to individual contribution experienced
strong activity and subscriber loyalty, such as their topical bulletin boards run by
hired systems operators (called “sysops”) and boasting content provided by subscribers in public conversations with each other. These forums were generative at
the content layer because people could post comments to each other without prescreening and could choose to take up whatever topics they chose, irrespective of
the designated labels for the forums themselves (“Pets” vs. “Showbiz”). But they
were not generative at the technical layer. The software driving these communities
was stagnant: subscribers who were both interested in the communities’ content
and technically minded had few outlets through which to contribute technical im-
3
2
1
Chapter 1: Computers
55
provements to the way the communities were built. Instead, any improvements
were orchestrated centrally. As the initial offerings of the proprietary networks
plateaued, the Internet saw developments in technology that in turn led to developments in content and ultimately in social and economic interaction: the Web
and Web sites, online shopping, peer-to-peer networking, wikis, and blogs. …
Generativity’s Input: Participation
A second good of generativity is its invitation to outside contribution on its own
terms. This invitation occurs at two levels: the individual act of contribution itself,
and the ways in which that contribution becomes part of a self-reinforcing community. On the first level, there is a unique joy to be had in building something,
even if one is not the best craftsperson. This is a value best appreciated by experiencing it; those who demand proof may not be easy to persuade. Fortunately, there
are many ways in which people have a chance to build and contribute. Many jobs
demand intellectual engagement, which can be fun for its own sake. People take
joy in rearing children: teaching, interacting, guiding. They can also immerse
themselves in artistic invention or software coding. …
The Generative Pattern
Generative technologies need not produce forward progress, if by progress one
means something like increasing social welfare. Rather, they foment change. They
solicit the distributed intellectual power of humanity to harness the leveraging
power of the product or system for new applications, and, if they are adaptable
enough, such applications may be quite unexpected. To use an evolutionary
metaphor, they encourage mutations, branchings away from the status quo – some
that are curious dead ends, others that spread like wildfire. They invite disruption
– along with the good things and bad things that can come with such disruption.
QUESTIONS
. Lessig vs. Zittrain: What is the difference between the way Lessig describes
computers and the way Zittrain describes them?
. App Stores: Zittrain wrote The Future of the Internet before Apple added an
App Store for the iPhone. How generative is the iPhone now?
. Costs and Benefits: Does generativity have a downside?
56
Internet Law
The Internet is a global network, so jurisdictional questions are inevitable. A computer network brings together people in different places; its point is to bridge geographic divisions. When those divisions are national or state borders, the network
raises jurisdictional issues just by being a network.
This chapter introduces the book’s second major theme: governmental power
over the Internet. In the
s, many thinkers argued that the Internet would
necessarily lead to a collapse in governmental authority. They have been challenged by others who claimed there was nothing inevitable about this transition,
and by others who believe that the Internet enables governments to extend their
grasp into more aspects of life than ever before. Jurisdiction has often been the
legal battleground for these debates.
Each section of the chapter explores a different facet of jurisdiction. The first
section asks whether the Internet itself is a jurisdiction, a place that could have
laws of its own. The second section explores the general problem of overlapping
national laws on a global network. And the third section looks at how United
States law deals with the question of jurisdiction over online activity. The chapter
is all about conflict. There is the conflict between Internet users and the governments who disapprove of what they’re doing, of course, but also conflicts between
different governments with different policies.
A. Cyberspace
The readings in this section begin with academic and activist perspectives on the
idea that the Internet is somewhere else entirely, a place where traditional laws
don’t apply and traditional governments have no power. As you read them, try to
figure out whether “here” versus “there” is even the right question to be asking.
The cases that follow put the seemingly abstract question of place on the Internet
into more concrete legal settings.
n
o
i
t
4
8
c
9
1
i
0
d
0
0
s
2
i
r
u
1
5
J
0
9
9
1
r
e
t
p
a
NOTE ON “CYBERSPACE”
The term “cyberspace” was popularized by the science fiction novelist William
Gibson to describe a new place created by worldwide computer networks:
On the Sony, a two-dimensional space war faded behind a forest of
mathematically generated ferns, demonstrating the spacial possibilities of logarithmic spirals; cold blue military footage burned through,
lab animals wired into test systems, helmets feeding into fire control
circuits of tanks and war plans. Cyberspace. A consensual hallucination experienced daily by billions of legitimate operators, in every nation, by children being taught mathematical concepts … A graphic
representation of data abstracted from the banks of every computer in
the human system. Unthinkable complexity. Lines of light ranged in
the nonspace of the mind, clusters and constellations of data. Like city
lights, receding.
William Gibson, Neuromancer
(Penguin
)(
). The idea that networked computers would create a wholly new place with its own geography, im-
h
C
2:
58
Internet Law
agery, and laws of physics was nearly irresistible for science-fiction novelists and
Hollywood filmmakers. While some movies, like WarGames (
), were “realistic” in the sense that they showed computer users typing commands and looking at
the results on their screens, others, like The Matrix (
), imagined that the future of computing would involve highly immersive virtual realities. Other wellknown examples that take the place-ness of online experience seriously include
Vernor Vinge’s novella True Names (
), Neal Stephenson’s novel Snow Crash
(
), Ernest Cline’s novel Ready Player One (
) and its movie adaptation
(
), the movies Tron (
) and The Lawnmower Man (
), and multiple
episodes of the TV series Black Mirror (
–).
This spatial vision of “cyberspace” cast a long shadow on legal thought, especially when it came to jurisdiction. If two people across the globe from each other
could interact instantaneously and profoundly with each other, perhaps it made
more sense to say that their interaction happened “in cyberspace” rather than in
the country either one of them was in. And if so, then wouldn’t it follow the most
appropriate body of law to apply would be a new body of “cyberspace law” that was
specially adapted for the new physics and customs of cyberspace? For example …
JOHN PERRY BARLOW,
JOHN PERRY BARLOW
A DECLARATION OF THE INDEPENDENCE OF CYBERSPACE
Feb. 8, 1996
3
2
8
9
9
1
9
1
9
9
9
1
1
1
0
2
1
1
1
0
8
2
9
1
2
8
9
1
2
8
9
1
0
9
1
2
Governments of the Industrial World, you weary giants of flesh and steel, I come
from Cyberspace, the new home of Mind. On behalf of the future, I ask you of the
past to leave us alone. You are not welcome among us. You have no sovereignty
where we gather.
We have no elected government, nor are we likely to have one, so I address you
with no greater authority than that with which liberty itself always speaks. I declare the global social space we are building to be naturally independent of the
tyrannies you seek to impose on us. You have no moral right to rule us nor do you
possess any methods of enforcement we have true reason to fear.
Governments derive their just powers from the consent of the governed. You
have neither solicited nor received ours. We did not invite you. You do not know
us, nor do you know our world. Cyberspace does not lie within your borders. Do
not think that you can build it, as though it were a public construction project. You
cannot. It is an act of nature and it grows itself through our collective actions.
You have not engaged in our great and gathering conversation, nor did you create the wealth of our marketplaces. You do not know our culture, our ethics, or the
unwritten codes that already provide our society more order than could be obtained by any of your impositions.
You claim there are problems among us that you need to solve. You use this
claim as an excuse to invade our precincts. Many of these problems don’t exist.
Where there are real conflicts, where there are wrongs, we will identify them and
address them by our means. We are forming our own Social Contract. This governance will arise according to the conditions of our world, not yours. Our world is
different.
Cyberspace consists of transactions, relationships, and thought itself, arrayed
like a standing wave in the web of our communications. Ours is a world that is
both everywhere and nowhere, but it is not where bodies live.
We are creating a world that all may enter without privilege or prejudice accorded by race, economic power, military force, or station of birth.
59
We are creating a world where anyone, anywhere may express his or her beliefs,
no matter how singular, without fear of being coerced into silence or conformity.
Your legal concepts of property, expression, identity, movement, and context do
not apply to us. They are based on matter. There is no matter here.
Our identities have no bodies, so, unlike you, we cannot obtain order by physical coercion. We believe that from ethics, enlightened self-interest, and the commonweal, our governance will emerge. Our identities may be distributed across
many of your jurisdictions. The only law that all our constituent cultures would
generally recognize is the Golden Rule. We hope we will be able to build our particular solutions on that basis. But we cannot accept the solutions you are attempting to impose.
In the United States, you have today created a law, the Telecommunications
Reform Act, which repudiates your own Constitution and insults the dreams of
Jefferson, Washington, Mill, Madison, DeToqueville, and Brandeis. These dreams
must now be born anew in us.
You are terrified of your own children, since they are natives in a world where
you will always be immigrants. Because you fear them, you entrust your bureaucracies with the parental responsibilities you are too cowardly to confront yourselves. In our world, all the sentiments and expressions of humanity, from the debasing to the angelic, are parts of a seamless whole, the global conversation of bits.
We cannot separate the air that chokes from the air upon which wings beat.
In China, Germany, France, Russia, Singapore, Italy and the United States, you
are trying to ward off the virus of liberty by erecting guard posts at the frontiers of
Cyberspace. These may keep out the contagion for a small time, but they will not
work in a world that will soon be blanketed in bit-bearing media.
Your increasingly obsolete information industries would perpetuate themselves
by proposing laws, in America and elsewhere, that claim to own speech itself
throughout the world. These laws would declare ideas to be another industrial
product, no more noble than pig iron. In our world, whatever the human mind
may create can be reproduced and distributed infinitely at no cost. The global conveyance of thought no longer requires your factories to accomplish.
These increasingly hostile and colonial measures place us in the same position
as those previous lovers of freedom and self-determination who had to reject the
authorities of distant, uninformed powers. We must declare our virtual selves immune to your sovereignty, even as we continue to consent to your rule over our
bodies. We will spread ourselves across the Planet so that no one can arrest our
thoughts.
We will create a civilization of the Mind in Cyberspace. May it be more humane
and fair than the world your governments have made before.
6
7
7
1
6
9
9
QUESTIONS
. Barlow’s Influence: This is the single most influential essay in the history of
Internet law. What accounts for its instant appeal?
. Barlow’s Argument: Why does Barlow think that cyberspace should be independent of terrestrial governments? Because it is its own place? Because it is
different? Because it is uncontrollable? Which of these arguments could
have been made by American colonists in
arguing for independence
from Britain?
. The Metaverse: Does Barlow’s vision of “cyberspace” strike you as an accurate
description of the Internet circa
? How well has it aged?
1
2
1
3
Chapter 2: Jurisdiction
Internet Law
. The Technolibertarian Dream: According to Barlow, computer networks will
liberate people from oppressive governmental control. Do his vision and his
rhetoric remind you of anyone else who talks like this?
ORIN S. KERR
ORIN S. KERR, THE PROBLEM OF PERSPECTIVE IN INTERNET LAW
91 Geo. L. J. 357 (2003)
9
9
9
In the
science fiction thriller The Matrix, Keanu Reeves plays a computer
hacker named “Neo” who learns that the reality he has known since birth is merely
a virtual reality created by a computer network known as the Matrix. The real Neo
lies in a semicomatose state attached to the network, to which he and others have
been connected by advanced computers that have taken over the world and sap
energy from humans while occupying their minds with virtual reality. Neo ends up
joining the rebel forces trying to destroy the Matrix, and the movie jumps several
times between the virtual world inside the Matrix and the real world outside of the
Matrix. The movie presents us with two different realities, two existing worlds.
The first reality is the virtual world that we experience inside the Matrix, and the
second is the “real” world that we experience outside the Matrix.
In addition to being a fun movie, The Matrix points out an important problem
that arises when we try to understand the nature of computer networks in general
and the Internet in particular. Like Neo confronting the Matrix, we can think
about the Internet in two ways, virtual and real. The virtual perspective is like the
perspective inside the Matrix: it accepts the virtual world of cyberspace as akin to
a reality. Of course, unlike Neo, we know all along that the virtual world that the
computer generates is only virtual. But as we try to make sense of what the Internet is, to understand what we experience online, we might decide to treat that virtual world as if it were real.
I will call this virtual point of view the internal perspective of the Internet. The
internal perspective adopts the point of view of a user who is logged on to the Internet and chooses to accept the virtual world of cyberspace as a legitimate construct. To this user, a computer connected to the Internet provides a window to a
virtual world that is roughly analogous to the physical world of real space. The
user can use her keyboard and mouse to go shopping, send mail, visit a chat room,
participate in an online community, or do anything else she can find online. The
technical details of what the computers attached to the Internet actually do “behind the scenes” don’t particularly matter. What matters is the virtual world of
cyberspace that the user encounters and interacts with when he or she goes online.
We can also understand the Internet from a different perspective. Like Neo
when he is outside the Matrix, we can look at the Internet from the point of view
of the physical world, rather than the virtual one. I will call this the external perspective of the Internet. The external perspective adopts the viewpoint of an outsider concerned with the functioning of the network in the physical world rather
than the perceptions of a user.
From this external viewpoint, the Internet is simply a network of computers
located around the world and connected by wires and cables. The hardware sends,
stores, and receives communications using a series of common protocols. Keyboards provide sources of input to the network, and monitors provide destinations
for output. When the Internet runs properly, trillions of zeros and ones zip around
the world, sending and receiving communications that the computers connected
to the network can translate into commands, text, sound, and pictures.
1
4
60
Chapter 2: Jurisdiction
61
6
1
4
6
8
1
1
4
1
7
8
1
1
1
7
0
7
1
2
7
0
2
From the external perspective, the fact that Internet users may perceive that
they have entered a virtual world of cyberspace has no particular relevance. These
perceptions reflect the fact that software designers often garnish their applications
with icons, labels, and graphics to help novices understand and use them – for example, by writing e-mail programs so that e-mail looks and feels like postal mail.
These superficialities have no deeper meaning from the external perspective.
What matters is the physical network and the technical details of how it works, not
the easily manipulated perceptions of Internet users.
Both internal and external understandings of the Internet should ring true to
most of us. The Internet is a physical network, and it can create a virtual world for
its users that can appear sufficiently realistic to its users to make a plausible claim
for equal footing with the physical world. But the key for us is that by generating a
virtual reality, the technology in a sense leaves us with two Internets, rather than
one. We have an external version of the Internet, and also an internal one. One is
physical, the other virtual. ...
Why does this matter to lawyers and to the nature of Internet law? It matters
because legal outcomes depend on facts, and the facts of the Internet depend on
which perspective we choose. This is a very practical problem. The basic task of a
lawyer is to apply legal rules to facts – to apply law to an understanding of reality.
In the case of the Internet, however, two competing understandings of reality exist. ...
All of this may seem rather abstract, so an example may help. Consider what
happens when an Internet user surfs the web. Imagine that an Internet user opens
up a web browser and types in “www.amazon.com,” and moments later the homepage of Amazon.com appears on the viewer’s screen. ...
This is easy from an internal perspective. The user has visited Amazon.com’s
website, going to Amazon.com’s home on the Internet. The user has visited Amazon.com’s virtual store much like a person might visit a store in the physical world,
traveling from one point in cyberspace to another. ...
From an external perspective, however, the event appears quite different – and
significantly more complicated. Behind the scenes, the simple act of typing
“www.amazon.com” into a web browser triggers a series of responses from different computers connected to the Internet. The browser begins by sending out a
request across the Internet to a special type of computer known as a Domain
Name System (DNS) server. The browser’s request asks the DNS server to translate the letters of the website address “amazon.com” into an “Internet Protocol” or
“IP” address, which is a series of numbers that computers connected to the Internet understand as an address akin to a phone number. The DNS server will respond that “www.amazon.com” translates into the IP address “
. .
. .” The
user’s browser then issues another request, this time directed to “
. .
. ,”
asking it to send a set of data files back to the browser. Amazon.com’s computer
will receive the request and then send data back to the browser. The browser will
receive the data and display it on the user’s screen. The resulting images and text
appear in the form of the Amazon.com webpage that the user requested.
Notice that the internal and external perspectives have produced two different
accounts of the same event. One model of the facts follows the virtual perspective
of the user, and another model follows the behind-the-scenes perspective of how
the Internet actually works. From the internal perspective, visiting Amazon.com
resembles visiting a store. The user types in the address, and a moment later is
paying a virtual visit to Amazon.com’s site. From the external perspective, visiting
Internet Law
Amazon.com resembles calling Information and asking for Amazon.com’s phone
number, then dialing the number and asking the representative to send you the
latest Amazon.com catalog. The single event of surfing the web produces two set
of facts, one internal and the other external. As a result, when we need to apply
law to the act of visiting a website, we can apply that law to two different sets of
facts, which can produce two different outcomes.
QUESTIONS
. Zoom: Describe a Zoom video call from the internal perspective and the external perspective. Does one strike you as better, or are they both helpful?
. Kerr vs. Barlow: What would Kerr say about Barlow’s argument that “cyberspace” is inherently independent?
DAVID R. JOHNSON AND DAVID POST
DAVID R. JOHNSON AND DAVID POST, LAW AND BORDERS
THE RISE OF LAW IN CYBERSPACE
48 Stan. L. Rev. 1367 (1996)
s
r
e
d
r
o
l
a
i
r
o
t
i
r
r
e
n
w
o
g
n
i
k
a
e
… I. B
D
T
B
A. Territorial Borders in the “Real World”
We take for granted a world in which geographical borders – lines separating
physical spaces – are of primary importance in determining legal rights and responsibilities. Territorial borders, generally speaking, delineate areas within which
different sets of legal rules apply. There has until now been a general correspondence between borders drawn in physical space (between nation states or other
political entities) and borders in “law space.” For example, if we were to superimpose a “law map” (delineating areas where different rules apply to particular behaviors) onto a political map of the world, the two maps would overlap to a significant degree, with clusters of homogeneous applicable law and legal institutions
fitting within existing physical borders. ...
Physical borders are not, of course, simply arbitrary creations. Although they
may be based on historical accident, geographic borders for law make sense in the
real world. Their logical relationship to the development and enforcement of legal
rules is based on a number of related considerations.
Power. Control over physical space, and the people and things located in that
space, is a defining attribute of sovereignty and statehood. Law-making requires
some mechanism for law enforcement, which in turn depends on the ability to exercise physical control over, and impose coercive sanctions on, law-violators. For
example, the U.S. government does not impose its trademark law on a Brazilian
business operating in Brazil, at least in part because imposing sanctions on the
Brazilian business would require assertion of physical control over business owners. Such an assertion of control would conflict with the Brazilian government’s
recognized monopoly on the use of force over its citizens.
Effects. The correspondence between physical boundaries and “law space”
boundaries also reflects a deeply rooted relationship between physical proximity
and the effects of any particular behavior. That is, Brazilian trademark law governs
the use of marks in Brazil because that use has a more direct impact on persons
and assets within Brazil than anywhere else. For example, a large sign over “Jones’
Restaurant” in Rio de Janeiro is unlikely to have an impact on the operation of
“Jones’ Restaurant” in Oslo, Norway, for we may assume that there is no substantial overlap between the customers, or competitors, of these two entities. Protec-
r
2
1
62
Chapter 2: Jurisdiction
63
tion of the former’s trademark does not – and probably should not – affect the protection afforded the latter’s.
Legitimacy. We generally accept the notion that the persons within a geographically defined border are the ultimate source of law-making authority for activities
within that border. The “consent of the governed” implies that those subject to a
set of laws must have a role in their formulation. By virtue of the preceding considerations, those people subject to a sovereign’s laws, and most deeply affected by
those laws, are the individuals who are located in particular physical spaces. Similarly, allocation of responsibility among levels of government proceeds on the assumption that, for many legal problems, physical proximity between the responsible authority and those most directly affected by the law will improve the quality
of decision making, and that it is easier to determine the will of those individuals
in physical proximity to one another.
Notice. Physical boundaries are also appropriate for the delineation of “law
space” in the physical world because they can give notice that the rules change
when the boundaries are crossed. Proper boundaries have signposts that provide
warning that we will be required, after crossing, to abide by different rules, and
physical boundaries – lines on the geographical map – are generally well-equipped
to serve this signpost function.
B. The Absence of Territorial Borders in Cyberspace
Cyberspace has no territorially based boundaries, because the cost and speed of
message transmission on the Net is almost entirely independent of physical location. Messages can be transmitted from one physical location to any other location
without degradation, decay, or substantial delay, and without any physical cues or
barriers that might otherwise keep certain geographically remote places and people separate from one another. The Net enables transactions between people who
do not know, and in many cases cannot know, each other’s physical location. …
[Power] But efforts to control the flow of electronic information across physical
borders – to map local regulation and physical boundaries onto Cyberspace – are
likely to prove futile, at least in countries that hope to participate in global commerce. Individual electrons can easily, and without any realistic prospect of detection, “enter” any sovereign’s territory. The volume of electronic communications
crossing territorial boundaries is just too great in relation to the resources available to government authorities. ...
By asserting a right to regulate whatever its citizens may access on the Net,
these local authorities are laying the predicate for an argument that Singapore or
Iraq or any other sovereign can regulate the activities of U.S. companies operating
in Cyberspace from a location physically within the United States. All such Webbased activity, in this view, must be subject simultaneously to the laws of all territorial sovereigns.
[Effects] Nor are the effects of online activities tied to geographically proximate
locations. Information available on the World Wide Web is available simultaneously to anyone with a connection to the global network. The notion that the effects of an activity taking place on that Web site radiate from a physical location
over a geographic map in concentric circles of decreasing intensity, however sensible that may be in the nonvirtual world, is incoherent when applied to Cyberspace.
A Web site physically located in Brazil, to continue with that example, has no more
of an effect on individuals in Brazil than does a Web site physically located in Belgium or Belize that is accessible in Brazil. Usenet discussion groups, to take another example, consist of continuously changing collections of messages that are rout-
Internet Law
ed from one network to another, with no centralized location at all. They exist, in
effect, everywhere, nowhere in particular, and only on the Net.
[Legitimacy & Notice] Territorial regulation of online activities serves neither
the legitimacy nor the notice justifications. There is no geographically localized set
of constituents with a stronger and more legitimate claim to regulate it than any
other local group. The strongest claim to control comes from the participants
themselves, and they could be anywhere. And in Cyberspace, physical borders no
longer function as signposts informing individuals of the obligations assumed by
entering into a new, legally significant, place. Individuals are unaware of the existence of those borders as they move through virtual space. ...
II. A N
B
C
Traditional legal doctrine treats the Net as a mere transmission medium that facilitates the exchange of messages sent from one legally significant geographical location to another, each of which has its own applicable laws. But trying to tie the
laws of any particular territorial sovereign to transactions on the Net, or even trying to analyze the legal consequences of Net-based commerce as if each transaction occurred geographically somewhere in particular, is most unsatisfying. A
more legally significant, and satisfying, border for the “law space” of the Net consists of the screens and passwords that separate the tangible from the virtual
world.
Many of the jurisdictional and substantive quandaries raised by border-crossing electronic communications could be resolved by one simple principle: conceiving of Cyberspace as a distinct “place” for purposes of legal analysis by recognizing
a legally significant border between Cyberspace and the “real world.” Using this
new approach, we would no longer ask the unanswerable question “where” in the
geographical world a Net-based transaction occurred. Instead, the more salient
questions become: What procedures are best suited to the often unique characteristics of this new place and the expectations of those who are engaged in various
activities there? What mechanisms exist or need to be developed to determine the
content of those rules and the mechanisms by which they can enforced? Answers
to these questions will permit the development of rules better suited to the new
phenomena in question, more likely to be made by those who understand and participate in those phenomena, and more likely to be enforced by means that the
new global communications media make available and effective.
Treating Cyberspace as a separate “space” to which distinct laws apply should
come naturally. There is a “placeness” to Cyberspace because the messages accessed there are persistent and accessible to many people. Furthermore, because
entry into this world of stored online communications occurs through a screen
and (usually) a password boundary, you know when you are “there.” No one accidentally strays across the border into Cyberspace. To be sure, Cyberspace is not a
homogenous place; groups and activities found at various online locations possess
their own unique characteristics and distinctions, and each area will likely develop
its own set of distinct rules. But the line that separates online transactions from
our dealings in the real world is just as distinct as the physical boundaries between
our territorial governments – perhaps more so.
e
c
a
p
s
r
e
b
y
r
o
y
r
a
d
n
u
o
w
f
QUESTIONS:
Offline Borders and Online Borders: Pike County, Arkansas is a “dry” county: it
prohibits all sales of alcohol. What does this prohibition look like in terms of
Johnson and Post’s taxonomy of power, effects, notice, and legitimacy? Sup-
.
e
1
64
65
pose that Pike County enacts a law against alcohol advertising and tries to
enforce it against online ads. What does this law look like in terms of the
taxonomy?
. Barlow Again? Do Johnson and Post agree with Barlow that cyberspace is
inherently independent?
. Internal or External? Do Johnson and Post adopt an internal perspective on
the Internet, an external perspective, both, or neither?
The following excerpt includes discussion of harassment, threats, and abuse.
MARY ANNE FRANKS
MARY ANNE FRANKS, UNWILLING AVATARS
IDEALISM AND DISCRIMINATION IN CYBERSPACE
20 Colum. J. Gender & L. 224 (2011)
e
s
l
i
l
d
a
a
r
e
a
h
m
s
s
r
i
l
a
a
t
a
e
d
v
e
g
c
n
a
i
p
l
s
l
i
r
w
e
b
n
I. C
I
:P
?…
As many scholars have described it, the creation of cyberspace is only the most
recent of human attempts to create a utopia. The utopian drive is certainly not
new: it can be observed in rhetoric about the New World, the Wild West, Communist Russia, cults, and any number of hippie communes. …
It is not difficult to see why cyberspace, especially in the early days of the internet, would incite such utopian fervor. As noted by numerous writers, cyberspace
provides a heady opportunity to escape one’s physical boundaries, both geographical and personal, in a more extreme way than ever before. In cyberspace, as the
saying goes, “no one knows you’re a dog.” Or a woman, or a Jew, or overweight, or
deaf, or whether you’re in Arkansas, or Massachusetts, or St. Petersburg. At its
most basic level, cyberspace seems to allow people to control who they want to be
and to go wherever they want to go. …
II. U
A
:T F
Cyberspace idealism unsurprisingly appeals to individuals who feel their life experiences have been restricted by their physical identity: by their social status, their
age, their gender, or their physical appearance. Going online allows these individuals to experience a certain kind of positive disembodiment. One’s “real” race,
gender, age, and social status need never be disclosed in cyberspace, and so negative stereotypes that may attach to any of those attributes can be avoided in a way
not possible in real life. Particularly for historically marginalized groups, the power to re-create oneself and control the public representation of one’s identity
through avatars can be liberating.
What happens, then, when individuals are not in control of their online embodiment? What if one is embodied against one’s will, in places that one never chose
to enter, in ways one never consented to be shown, in graphic and vicious detail for
all the world to see and which may be impossible to erase? We would surely describe that experience as a profound loss of liberty, the very antithesis of the freeing process of avatar creation. A world populated by an increasing number of unwilling avatars, reduced to their physical characteristics, caricaturized, ventriloquized and under attack, looks much more like hell than paradise.
A. Bringing in the Women …
Sayani Chakraborty had never been a member of Orkut, a social networking site
similar to Facebook and MySpace, but she discovered that someone had created a
profile of her on the site and used it to send offensive messages to her family and
y
3
2
Chapter 2: Jurisdiction
66
Internet Law
6
0
0
2
1
3
0
0
1
friends. Someone created a similar profile for a schoolgirl in Delhi, complete with
obscene photographs and the girl’s home address and telephone number. The profile came to light after her family began receiving calls asking to speak with the
girl and referencing the Orkut profile. Eventually, two men came to her home
claiming that the girl had invited them over for sex. …
Kathy Sierra is a programming instructor and a game developer who runs a
blog called Creating Passionate Users. This blog is centered on discussions about
“designing software that makes people happy.” … Sierra began receiving death
threats in the comments section of her blog. Someone wrote about slitting her
throat and ejaculating; another posted her photo alongside an image of a noose
with a caption: “The only thing Kathy has to offer is that noose in her neck size.”
On an external site, a user posted a manipulated photo that appeared to show
Sierra with underwear across her face, struggling to breathe. The picture was captioned: “I dream of Kathy Sierra . . . head first.” Sierra canceled several speaking
engagements and suspended her blog in the wake of the threatening posts. …
Nicole Catsouras was eighteen years old when she died in a horrific car accident. On October ,
, she and her father had an argument, and he confiscated the car keys as punishment. Later that day, Nicole snuck out, taking the car
keys with her. Fifteen minutes later, she crashed into a freeway tollbooth at a speed
of over
miles per hour. The collision mangled her body, nearly decapitating
her. The police photographs of the accident were leaked and published online. The
gruesome images began to appear in chat rooms and fetish websites where users
would discuss, among other things, how Nicole “deserved” what happened. A MySpace user posted the pictures along with sexualized commentary about Nicole;
another created a fake profile of Nicole that included a close-up of her remains.
Someone posted the Catsouras’ home address and encouraged others to harass the
family. Nicole’s parents received numerous pseudonymous emails and text messages that included the photos, along with vicious captions. They attempted to
convince web site owners to take down the pictures, but met with little success:
“We’ve asked them to please take down the pictures, and they’ve said, ‘No, I don’t
have to because I’ve got my First Amendment rights’,” says Nicole’s mother, Lesli
Catsouras. Nicole’s family uploaded a memorial video of Nicole on YouTube, hoping that it would help show that they “are a family with real hearts, and it hurts
what people are doing.” A number of vicious and sexist pseudonymous comments
were posted on YouTube in response, including the following: “she got what she
deserved . . . you wanted equality, fine, fuck that stupid cunt . . . hahahaha, she got
what she deserved” ....
B. Cyberspace as a State of License
Part I noted the similarity between the way cyberspace idealists describe cyberspace and the way John Locke describes the state of nature as one of perfect liberty. The examples given above tell a very different story. They paint a world in
which only certain individuals enjoy the mythic degree of liberty and freedom
from physical restraints touted by cyberspace idealists, while others experience a
loss of liberty and a re-entrenchment of physical restraints already unequally imposed upon them in the offline world. Women targeted by cyber harassment experience restrictions in liberty both in cyberspace and out of it. They experience new
levels of objectification, confronting reductions of themselves to sexualized body
parts in message boards, chat rooms, social networking sites, and Google searches.
Women who have been targeted by cyber harassment avoid certain sites to avoid
being attacked; they close down email accounts that have been flooded with abu-
Chapter 2: Jurisdiction
67
fi
fi
t
c
e
f
f
t
n
e
m
i
d
o
b
ffi
m
ffi
e
l
b
u
o
ff
e
h
fi
t
i
x
ffi
o
sive and obscene messages; they shut down blogs; in some cases, they withdraw
from what were lucrative and vibrant online presences. The losses of liberty follow
them offline, as well: they face harassment and slander stemming from online attacks in their workplaces and schools, leading them to quit or change jobs and
universities; they change their daily routines for fear of being stalked or physically
assaulted; they are sometimes stalked, assaulted or even killed by their online harassers. …
Locke writes that when mankind finds itself unable to preserve the state of nature, it necessarily must establish the rule of law. If individuals abuse their liberty
by exercising power in arbitrary and self-interested ways that threaten the security
of the whole community, the community will slide into a state of war. In a state of
war, anyone at any time might be deprived of his or her liberty and possessions. To
avoid this outcome, the community collectively establishes a central authority and
rules to regulate disputes. This necessarily involves giving up some of what Locke
considers to be “natural rights” (e.g., the right to personally punish someone who
has wronged you). But it also results in liberty for more people and security for
most of one’s other rights. Security for the general public – not just for the strongest or most aggressive – is the basis for the forfeiture of some individual power. Put
another way, rules ensure a measure of equality for all.
The same can be said of regulations of speech on the internet. New legal regulations regarding behavior in cyberspace might indeed mean, in some sense, that
some individuals will no longer have the same degree of “liberty” they had previously. It would mean, for example, that cyber harassers could no longer attack
women with impunity. But the freedom to harass is an exercise of license, not liberty, and as such is hardly defensible in the first instance. The effects of such license, moreover, are that women as a group suffer a loss of liberty relative to men
as a group. Regulation and reform are necessary to balance the equation and create a cyberspace that maximizes liberty for all groups. …
III. N E
:T D
-E
E
…
A final point to note is that the effects of unwilling online embodiment are potentially even more pernicious and long-lasting than real-life harassment. This is due
to four features of cyberspace that exacerbate the impact of harassment:
1. Anonymity: The increased opportunity for harassers to attack their target
anonymously, making it di cult if not impossible for the targets to engage
in self-help or legal remedies;
2. Ampli cation: The capacity for harassers to quickly nd a wide audience for
their harassment, including users who will join in the harassment;
3. Permanence: Online attacks, which often include personal information
about their targets, such as home addresses and telephone numbers, are
very di cult to erase from the web;
4. Virtual Captivity/Publicity: The options to avoid or exit situations in which
cyber harassment occurs are extremely limited. Whereas speci c acts of
real-life harassment are often restricted to one place (for example, being
harassed on the street does not necessarily impact one’s experience in the
workplace), the e ects of cyberspace harassment can manifest much more
readily. Particularly if the online attack is indexable by a major search engine like Google, it is accessible to almost anyone (the target’s co-workers,
fellow students, clients, children) almost anywhere (at her place of work, her
school, her home, her doctor’s o ce).
Internet Law
QUESTIONS
. Franks vs. Barlow: According to Franks, what is wrong with Barlow’s vision of
an independent Internet?
. Franks vs. Johnson and Post: Would Franks be satisfied with the kinds of online self-governance Johnson and Post think will develop?
. Minorities Online: Does the Internet also have an upside for minorities? What
does anonymity – ”On the Internet, no one knows you’re a dog” – have to do
with it?
The following case includes discussion of sexual misconduct involving a minor.
STATE V. DECKER
916 N.W.2d 385 (Minn. 2018)
4
3
6
1
0
2
2
6
1
1
0
2
1
2
1
5
1
4
1
3
9
0
6
3
2
7
1
6
4
1
4
4
1
1
0
0
2
2
8
s
t
1
5
c
a
McKeig, Justice:
Daniel Decker was convicted of fifth-degree criminal sexual conduct and indecent exposure for sending a picture of his genitals to a minor via Facebook Messenger. He appeals, arguing that he did not meet the “presence” requirement of
either crime because he and the victim were in different physical locations, and
because he only sent a likeness of his genitals, rather than exposing his actual genitals. …
F
In the summer of
, -year-old M.J. babysat for a couple that she met through
her sister. During that same summer, Decker moved into the couple’s home, and
he and M.J. became friends on Facebook. At the time, Decker was
years old,
and was aware of M.J.’s age.
On September ,
, Decker sent M.J. a video via Facebook Messenger at
: a.m. The video showed only Decker’s face, and he asked M.J., “[W]hat’s up?
Shouldn’t you be in bed by now?” Decker explained that he was “just kicking it”
and “fixing to go to sleep,” and winked at the end of the video. Decker and M.J.
then exchanged messages for roughly four minutes, until Decker informed her that
he was going to finish “what [he] just started before [he] said hey.” When M.J.
asked what he meant, Decker explained that he was referring to his nightly ritual
to de-stress before falling asleep. M.J. thought that Decker was referring to smoking marijuana, but asked what his ritual was, and he responded, “[i]t’s embarrassing kinda.” M.J. did not respond to that message, but one minute later, Decker sent
M.J. a picture of his erect penis.
Decker was charged with and found guilty by a jury of fifth-degree criminal
sexual conduct, under Minn. Stat. §
.
, subd. ( ) (
), and indecent
exposure, under Minn. Stat. §
. , subds. ( ), ( ) (
).
2
3
2
1
1
68
69
A
Fifth-degree criminal sexual conduct includes “engag[ing] in ... lewd exhibition of
the genitals in the presence of a minor under the age of , knowing or having reason to know the minor is present.” Minn. Stat. §
.
, subd. ( ). …
The Legislature has recognized the harms of indecent exposure, and has determined that minors under the age of sixteen are entitled to additional protections. Thus, the mischief that Minn. Stat. §§
.
,
. seek to remedy is
adults lewdly exposing themselves to children. Likewise, the object to be attained
by these statutes is to deter adults from such behavior. The consequences of Decker’s proposed interpretation, however, would severely undercut these goals. If we
adopted Decker’s interpretation, we would effectively create an exception that allows adults to expose themselves to minors via the Internet without consequence.
Such an exception would substantially undermine legislative efforts to protect minors, and is therefore contrary to the Legislature’s intent.
In this case, Decker took several lewd images of himself in an aroused state at
: a.m., and began a conversation with -year-old M.J. two minutes later. …
He specifically chose to engage in near-simultaneous conversation with M.J., and
thus used technology to effectively enter M.J.’s private room. … Decker’s conduct
meets the requirements of Minn. Stat. §§
.
,
. , and we therefore affirm his convictions.
*
Anderson, Justice (dissenting):
The question presented in this appeal turns on the meaning of the phrase “in
the presence of a minor.” Because the common and ordinary meaning of “presence”
requires a shared physical location between the defendant and the minor, and
there was no shared physical location here, I would reverse the convictions. The
court’s contrary conclusion—that a photograph sent via a text message satisfies
physical presence—does not square with relevant dictionary definitions or rules of
grammar. And the conclusion is not consistent with the common and ubiquitous
use of texting (and other means of electronic transmission) to send photographs of
family members, athletic events, and other daily occurrences, precisely because the
sender and the recipient are not in the same location. …
Appellant Daniel Decker and the child were not in the same physical location
when the alleged crimes occurred. Instead, each was at their own home when
Decker took a photograph of his genitals and sent it, via text message, to a -yearold girl. The plain meaning of the phrase “in the presence of a minor under the age
of ” requires the defendant and the child to be in the same physical location
when the defendant exposes or exhibits his or her genitals. Decker’s conduct was
certainly deplorable, but it did not violate either of these statutes. As a result, I
respectfully dissent. …
The court’s premise is based entirely on State v. Stevenson,
N.W. d
,
(Minn.
), where an adult saw the defendant masturbating in a truck
parked
to
feet from a playground where children were playing. We consid-
5
3
4
1
2
2
2
1
6
5
3
6
2
7
3
1
2
6
6
1
7
1
5
1
1
4
5
6
3
4
1
9
3
5
0
9
4
6
0
3
6
4
9
1
0
6
3
0
5
0
1
2
s
0
i
1
s
y
l
9
6
a
4
1
2
7
n
2
2
. … Through the aid of technology, such as telescopes, binoculars, drones, or the Internet, a person can be within sight, and therefore “present” without being “in the
same place as someone.” …
[T]he dissent’s argument that the perpetrator and the victim must be face-toface runs counter to our holding in Stevenson. In Stevenson, we rejected the argument that “presence” meant “proximity,” and instead held that, on those facts, “presence” meant “reasonably capable of being viewed.” 656 N.W.2d at 239.
3
1
2
Chapter 2: Jurisdiction
.
.
.
.
.
QUESTIONS
Barlow: What would John Perry Barlow say about this case? Is this what the
“civilization of the Mind” looks like?
Kerr: What would Orin Kerr say about this case? What does it look like from
the internal perspective? From the external perspective?
Johnson and Post: What would David Johnson and David Post say about this
case? Which of their four bases for regulation are present here?
Franks: What would Mary Anne Franks say about this case?
Voyeur Dorm: Compare Voyeur Dorm, L.C. v. City of Tampa,
F. d
( th Cir.
), where Voyeur Dorm charged users
.
per month to
watch a
/ pornographic livestream filmed inside a house at
West
Farwell Drive in Tampa. None of the activities inside were visible from outside the house, only via the Internet. Tampa’s zoning code prohibited in residential areas “Any premises . . . on which is offered to members of the public
or any person, for a consideration, entertainment featuring … sexual activities.” Does this apply to Voyeur Dorm? (The district court said yes; the court
of appeals said no.)
3
9
7
1
2
3
2
1
2
3
1
3
2
5
6
2
ff
5
9
4
3
$
fi
ffi
fi
1
0
7
0
2
4
2
2
0
0
1
SLOT MACHINE PROBLEM
A statute in the state of Campania prohibits possessing or o ering to the public
any “slot machine,” which is de ned as:
a machine, apparatus, or device that is operated by insertion of a coin
or other object or by any other means, and that by reason of any element of chance grants the user any thing of value
Your client, First Century, is the developer of Sword and Sandal, a massively popular massively multiplayer smartphone game. Players construct empires in a fantasy
world vaguely reminiscent of ancient Rome, as ltered through Hollywood. Players can ally with or attack each other, making for massively massive battles. Sword
and Sandal is free to play, but it is di cult to defend an empire larger than a “prov-
2
5
4
3
2
Internet Law
ered whether the “presence” language in the fifth-degree-criminal-sexual-conduct
and indecent-exposure statutes required the State to prove that the minor actually
viewed the defendant’s conduct. … Because the defendant in Stevenson was in the
same physical location as the minors, the court’s conclusion that the phrase “in the
presence of a minor” was ambiguous does not apply here, given that the defendant
and the minor were in different physical locations. …
While the noun “presence” has several meanings, the definition that applies to
the circumstances of this case is “the state or fact of being present; the state of being in one place and not elsewhere; the condition of being within sight or call, at
hand, or in a place thought of; the state of being in front of or in the same place as
someone or something.” Webster’s Third New International Dictionary
(
). Thus, the common meaning of “presence” requires a shared physical location. …
The court claims that if we were to interpret the phrase “in the presence of a
minor” to mean in the same physical location, it “would effectively create an exception where adults could expose themselves to minors via the Internet without consequence.” The court is wrong. Other criminal statutes, which prohibit sexually
explicit electronic communications with minors and the distribution of obscene
material, apply to such conduct.
1
1
70
71
ince” without spending more than ,
in-game “gold pieces” a day building forti cations and paying troops. All players receive
gold pieces daily and can
purchase more at rates ranging from .
for ,
gold pieces to
.
for
,
,
. When two players have allied, they can give each other soldiers, gold,
or other in-game resources like stone and wood.
Sword and Sandal also includes an in-game “Crassus’s Casino.” Players can
spend
gold to wager on an animated spinning wheel. After each spin, the
player receives a virtual prize of between
and ,
stone, wood, gold, or other
resources. What the player receives, as well as how much, is randomly determined;
smaller prizes are more common than large ones. Sword and Sandal’s terms of
service provide that “Virtual Currency and Virtual Goods may never be redeemed
for ‘real world’ money, goods or other items of monetary value from First Century
or any other person” and expressly prohibit “buying or selling any Virtual Currency
or Virtual Goods outside the Services or in exchange for ‘real world’ money or
items of value.”
First Century has received a letter from the Campania attorney general seeking
more information about Crassus’s Casino and asserting that it may qualify as a
prohibited slot machine. Advise your client on whether this is a risk it should be
worried about, and if so, what to do.
ROBLES V. DOMINO’S PIZZA, LLC
913 F.3d 898 (9th Cir. 2019)
9
9
9
9
$
0
0
0
0
0
0
5
0
0
2
5
9
d
0
9
1
n
1
u
0
0
$
o
0
r
2
0
g
1
1
k
c
a
1
l
0
a
1
r
2
u
1
d
e
c
o
r
6
1
1
0
0
n
1
d
2
2
n
o
i
4
2
1
a
s
1
s
0
5
l
u
0
a
0
0
c
1
u
s
0
t
i
c
0
0
a
fi
0
Owens, Circuit Judge: …
Plaintiff Guillermo Robles, a blind man, appeals from the district court's dismissal of his complaint alleging violations of the Americans with Disabilities Act,
U.S.C. §
, and California's Unruh Civil Rights Act (UCRA), California Civil Code § . Robles alleged that Defendant Domino’s Pizza, LLC, failed to design,
construct, maintain, and operate its website and mobile application to be fully accessible to him. …
I. F
P
B
Robles accesses the internet using screen-reading software, which vocalizes visual
information on websites. Domino's operates a website and app that allows customers to order pizzas and other products for at-home delivery or in-store pickup,
and receive exclusive discounts.
On at least two occasions, Robles unsuccessfully attempted to order online a
customized pizza from a nearby Domino’s. Robles contends that he could not order the pizza because Domino’s failed to design its website and app so his software
could read them.
In September
, Robles filed this suit seeking damages and injunctive relief
based on Domino's failure to “design, construct, maintain, and operate its [website
and app] to be fully accessible to and independently usable by Mr. Robles and other blind or visually-impaired people,” in violation of the ADA and UCRA. Robles
sought a permanent injunction requiring Defendant to ... comply with [Web Content Accessibility Guidelines (WCAG) . ] for its website and Mobile App.” …
III. D
…
A. The ADA's Application to Domino’s Website and App
The ADA as a whole is intended “to provide a clear and comprehensive national
mandate for the elimination of discrimination against individuals with
disabilities.”
U.S.C. §
(b)( ). Title III of the ADA advances that goal by
2
1
4
Chapter 2: Jurisdiction
Internet Law
providing that “[n]o individual shall be discriminated against on the basis of disability in the full and equal enjoyment of the goods, services, facilities, privileges,
advantages, or accommodations of any place of public accommodation by any person who owns, leases (or leases to), or operates a place of public accommodation.”
Id. §
(a). …
The ADA expressly provides that a place of public accommodation … engages
in unlawful discrimination if it fails to “take such steps as may be necessary to ensure that no individual with a disability is excluded, denied services, segregated or
otherwise treated differently than other individuals because of the absence of auxiliary aids and services.” Id. §
(b)( )(A)(iii). DOJ regulations require that a
public accommodation “furnish appropriate auxiliary aids and services where necessary to ensure effective communication with individuals with disabilities."
C.F.R. §
.
(c)( ). And DOJ defines “auxiliary aids and services” to include
“accessible electronic and information technology” or “other effective methods of
making visually delivered materials available to individuals who are blind or have
low vision.”
C.F.R. § .
(b)( ).
Therefore, the ADA mandates that places of public accommodation, like
Domino’s, provide auxiliary aids and services to make visual materials available to
individuals who are blind. See id. § .
. This requirement applies to Domino’s
website and app, even though customers predominantly access them away from
the physical restaurant: “The statute applies to the services of a place of public accommodation, not services in a place of public accommodation. To limit the ADA
to discrimination in the provision of services occurring on the premises of a public
accommodation would contradict the plain language of the statute.” Nat'l Fed’n of
the Blind v. Target Corp.,
F. Supp. d
,
(N.D. Cal.
).
The alleged inaccessibility of Domino’s website and app impedes access to the
goods and services of its physical pizza franchises – which are places of public accommodation. See
U.S.C. §
( )(B) (listing a restaurant as a covered “public
accommodation”). Customers use the website and app to locate a nearby Domino’s
restaurant and order pizzas for at-home delivery or in-store pickup. This nexus
between Domino’s website and app and physical restaurants – which Domino’s
does not contest—is critical to our analysis.
In Weyer v. Twentieth Century Fox Film Corp., our court examined whether an
insurance company that administered an allegedly discriminatory employer-provided insurance policy was a covered “place of public accommodation.”
F. d
,
- ( th Cir.
). We concluded that it was not. Because the ADA only
covers “actual, physical places where goods or services are open to the public, and
places where the public gets those goods or services,” there had to be “some connection between the good or service complained of and an actual physical place.”
Id. at
. While the insurance company had a physical office, the insurance poli*
†
. The ADA exempts covered entities from the requirement to provide auxiliary aids
and services where compliance would “fundamentally alter the nature of the good,
service, facility, privilege, advantage, or accommodation being offered or would result in an undue burden.”
U.S.C. §
(b)( )(A)(iii); see also
C.F.R. §
.
(a). At this stage, Domino's does not argue that making its website or app
accessible to blind people would fundamentally alter the nature of its offerings or be
an undue burden.
8
2
3
8
9
1
8
6
2
0
0
2
3
5
2
9
6
6
4
2
3
9
8
2
0
1
3
2
2
1
6
7
3
2
1
8
2
1
8
2
1
2
1
1
3
0
2
5
0
2
3
4
4
0
6
0
3
2
1
2
4
3
9
0
8
3
2
4
6
1
2
3
8
3
4
1
1
1
1
1
2
1
1
1
3
0
4
5
3
6
0
1
5
. We need not decide whether the ADA covers the websites or apps of a physical place
of public accommodation where their inaccessibility does not impede access to the
goods and services of a physical location.
6
1
3
72
73
cy at issue did not concern accessibility, or “such matters as ramps and elevators so
that disabled people can get to the office.” Id. And although it was administered by
the insurance company, the employer-provided policy was not a good offered by
the insurance company's physical office.
Unlike the insurance policy in Weyer, Domino’s website and app facilitate access to the goods and services of a place of public accommodation – Domino’s
physical restaurants. They are two of the primary (and heavily advertised) means
of ordering Domino’s products to be picked up at or delivered from Domino’s
restaurants. We agree with the district court in this case – and the many other district courts that have confronted this issue in similar contexts – that the ADA applies to Domino’s website and app, which connect customers to the goods and services of Domino’s physical restaurants.
QUESTIONS
Where is dominos.com? Is dominos.com a “place” of public accommodation? Is
it a “place” at all?
Disabilities: John Perry Barlow describes cyberspace as “a world that all may
enter without privilege or prejudice accorded by race, economic power, military force, or station of birth.” What about disabilities? Does the Internet
erase offline differences or exacerbate them?
Ghost Kitchens: Could Domino’s evade the ADA by closing its restaurants and
switching to a delivery-only model?
Netflix: Netflix offers streaming video on a subscription basis. It does not
have retail stores. Is Netflix obliged under the ADA to provide closed captioning?
Accessible Tech: Accessible websites are only part of the story. Does the ADA
require smartphones to come with web browsers that are usable by the
blind?
.
.
.
.
.
0
0
0
1
$
5
9
4
1
$
0
4
0
1
6
0
0
3
0
DEAD AIM PROBLEM
Dead Aim Hunting owns a
-acre plot in central Texas, which it keeps wellstocked with game. It also operates a website at https://www.dead-aim-hunting.com.
Users must pay monthly membership dues of
. and a deposit of ,
to
participate in what Dead Aim calls “drone hunting.” Dead Aim has attached cameras and Remington . rifles to remote-control drones. Users who have reserved a time block can take control of one of the drones. By clicking on appropriate buttons in their web browser, they send a signal to Dead Aim’s computer,
which in turn sends signals to the drone to position itself and aim the attached
rifle. By clicking on a “fire” button, they can move an actuator that pulls the trigger
on the rifle. A hunter a thousand or more miles away can thus shoot at a deer, antelope, or other animal. If they succeed in killing one, Dead Aim bills them for its
cost, then ships them the carcass for skinning, butchering, and/or mounting, as
appropriate. In the words of Dead Aim’s owner, “Hunter” Dan Lockwood, “Most
hunters use blinds to conceal themselves. What’s the difference between that and
clicking a mouse? Nothing. That is the same exact motion, and it takes the same
amount of time.”
Lurleen Lumpkin, a resident of Illinois, used Dead Aim to kill a six-point buck
on November . Cletus Spuckler, a resident of West Virginia, used Dead Aim to
shoot at a rabbit on December , but missed. Texas has enacted a statute stating:
2
5
4
3
2
1
Chapter 2: Jurisdiction
74
Internet Law
A person may not attach a firearm to an aerial vehicle or operate an
aerial vehicle to which a firearm has been attached if the aerial vehicle
is located in Texas.
Illinois has enacted a statute stating:
A person shall not operate, provide, sell, use, or offer to operate, provide, sell, or use any computer software or service that allows a person
not physically present at the hunt site to remotely control a weapon
that could be used to take wildlife by remote operation, including, but
not limited to, weapons or devices set up to fire through the use of the
Internet or through a remote control device.
Can either Texas or Illinois prosecute Dead Aim or any of its users? Are these laws
a good idea?
B. Jurisdictional Con icts
The argument discussed in the previous section – that the Internet is somewhere
else – has not fared well with the courts. But another problem cannot be so easily
dismissed. If Ava in Austria sends an email to Barry in Bolivia, which passes
through a network operated by Comcast in Connecticut, and the email defames
Darius in Djibouti, each of these jurisdictions may have something to say about
the email. But if more than one of them is interested, which of them will get the
final word?
This section considers the general problem of reconciling differing national
laws in a world linked by a global Internet. Dow Jones, the Yahoo! saga, and eSafety Commissioner give three snapshots of how courts have wrestled with the issues.
Then the problems ask you to give practical advice for managing the uneasy online
coexistence of territorial governments.
DOW JONES & CO. V. GUTNICK
High Court of Australia
[2002] HCA 56
9
2
$
9
5
fl
$
6
9
9
1
Gleeson, Chief Justice:
[The description of facts has been lightly reordered and incorporates some details from Justice Callinan’s opinion.] The appellant, Dow Jones & Company Inc
(“Dow Jones”), prints and publishes the Wall Street Journal newspaper and Barron’s magazine. Since
, Dow Jones has operated WSJ.com, a subscription
news site on the World Wide Web. Those who pay an annual fee (set, at the times
relevant to these proceedings, at US , or US if they are subscribers to the
printed editions of either the Wall Street Journal or Barron’s) may have access to
the information to be found at WSJ.com. Those who have not paid a subscription
may also have access if they register, giving a user name and a password. The information at WSJ.com includes Barron’s Online in which the text and pictures
published in the current printed edition of Barron’s magazine are reproduced.
Dow Jones has its editorial offices for Barron’s, Barron’s Online and WSJ.com
in the city of New York. Material for publication in Barron’s or Barron’s Online,
once prepared by its author, is transferred to a computer located in the editorial
offices in New York City. From there it is transferred either directly to computers
at Dow Jones’s premises at South Brunswick, New Jersey, or via an intermediate
Chapter 2: Jurisdiction
75
0
0
0
0
2
0
0
2
0
3
8
2
site operated by Dow Jones at Harborside, New Jersey. It is then loaded onto six
servers maintained by Dow Jones at its South Brunswick premises. ...
The edition of Barron’s Online for
October
(and the equivalent edition
of the magazine which bore the date
October
) contained an article entitled “Unholy Gains” in which several references were made to the respondent,
Mr Joseph Gutnick. Mr Gutnick contends that part of the article defamed him.
The article associates the respondent with Mr. Nachum Goldberg who is apparently a convicted tax evader and another person awaiting trial for stock manipulation
in New York.” Gutnick “pleaded that the article meant, and was understood to
mean that he:
was a customer of Nachum Goldberg who had recently been imprisoned for tax evasion and money laundering; and
was Nachum Goldberg’s biggest customer; and
was masquerading as a reputable citizen when he was, in fact, a tax
evader who had laundered large amounts of money through Nachum
Goldberg; and
had bought Nachum Goldberg’s silence so as to conceal his identity as
one of Goldberg’s customers.
He has brought an action in the Supreme Court of Victoria against Dow Jones
claiming damages for defamation. Mr Gutnick lives in Victoria. He has his business headquarters there. Although he conducts business outside Australia, including in the United States of America, and has made significant contributions to
charities in the United States and Israel, much of his social and business life could
be said to be focused in Victoria. …
Argument of the appeal proceeded from an acceptance, by both parties, of certain principles. First, it is now established that an Australian court will decline, on
the ground of forum non conveniens, to exercise jurisdiction which has been regularly invoked by a plaintiff, whether by personal service or under relevant longarm jurisdiction provisions, only when it is shown that the forum whose jurisdiction is invoked by the plaintiff is clearly inappropriate. Secondly, it is now established that in trying an action for tort in which the parties or the events have some
connection with a jurisdiction outside Australia, the choice of law rule to be applied is that matters of substance are governed by the law of the place of commission of the tort. Neither party sought to challenge either proposition. Rather, argument focused upon where was the place of publication of the statements of
which Mr Gutnick complained. Dow Jones contended that the statements were
published in New Jersey and that it was, therefore, the law of that jurisdiction
which would govern all questions of substance in the proceeding. ...
Dow Jones submitted that it was preferable that the publisher of material on
the World Wide Web be able to govern its conduct according only to the law of the
place where it maintained its web servers, unless that place was merely adventitious or opportunistic. … The alternative, so the argument went, was that a publisher would be bound to take account of the law of every country on earth, for
there were no boundaries which a publisher could effectively draw to prevent anyone, anywhere, downloading the information it put on its web server. ...
It is necessary to begin by making the obvious point that the law of defamation
seeks to strike a balance between, on the one hand, society’s interest in freedom of
speech and the free exchange of information and ideas (whether or not that information and those ideas find favour with any particular part of society) and, on the
76
Internet Law
4
6
9
1
0
8
2
4
5
2
6
7
3
other hand, an individual’s interest in maintaining his or her reputation in society
free from unwarranted slur or damage. The way in which those interests are balanced differs from society to society. [In brief, in the United States, the First
Amendment would protect Dow Jones from liability for publishing a false statement about the commercial dealings of a prominent businessman like Gutnick (a
“public figure”) unless it acted “with ‘actual malice’—that is, with knowledge that it
was false or with reckless disregard of whether it was false or not.” New York Times
Co. v. Sullivan,
U.S.
,
(
). Australia had only a much narrower
defense for political debate and one for “the ordinary course of a business such as
that of bookseller or news vendor” when “the defendant did not know or suspect
and, using reasonable diligence, would not have known or suspected was defamatory.” Dow Jones, as a publisher with full editorial control over Barron’s, would not
have qualified for that defense.]
It was suggested that the World Wide Web was different from radio and television because the radio or television broadcaster could decide how far the signal
was to be broadcast. It must be recognised, however, that satellite broadcasting
now permits very wide dissemination of radio and television and it may, therefore,
be doubted that it is right to say that the World Wide Web has a uniquely broad
reach. It is no more or less ubiquitous than some television services. In the end,
pointing to the breadth or depth of reach of particular forms of communication
may tend to obscure one basic fact. However broad may be the reach of any particular means of communication, those who make information accessible by a particular method do so knowing of the reach that their information may have. In
particular, those who post information on the World Wide Web do so knowing
that the information they make available is available to all and sundry without any
geographic restriction.
Because publication is an act or event to which there are at least two parties,
the publisher and a person to whom material is published, publication to numerous persons may have as many territorial connections as there are those to whom
particular words are published. It is only if one starts from a premise that the publication of particular words is necessarily a singular event which is to be located by
reference only to the conduct of the publisher that it would be right to attach no
significance to the territorial connections provided by the several places in which
the publication is available for comprehension. ...
In defamation, the same considerations that require rejection of locating the
tort by reference only to the publisher’s conduct, lead to the conclusion that, ordinarily, defamation is to be located at the place where the damage to reputation
occurs. Ordinarily that will be where the material which is alleged to be defamatory is available in comprehensible form assuming, of course, that the person defamed has in that place a reputation which is thereby damaged. It is only when the
material is in comprehensible form that the damage to reputation is done and it is
damage to reputation which is the principal focus of defamation, not any quality of
the defendant’s conduct. In the case of material on the World Wide Web, it is not
available in comprehensible form until downloaded on to the computer of a person who has used a web browser to pull the material from the web server. It is
where that person downloads the material that the damage to reputation may be
done. Ordinarily then, that will be the place where the tort of defamation is committed. ...
Three other matters should be mentioned. In considering what further development of the common law defences to defamation may be thought desirable, due
Chapter 2: Jurisdiction
77
weight must be given to the fact that a claim for damage to reputation will warrant
an award of substantial damages only if the plaintiff has a reputation in the place
where the publication is made. Further, plaintiffs are unlikely to sue for defamation published outside the forum unless a judgment obtained in the action would
be of real value to the plaintiff. The value that a judgment would have may be
much affected by whether it can be enforced in a place where the defendant has
assets.
Finally, if the two considerations just mentioned are not thought to limit the
scale of the problem confronting those who would make information available on
the World Wide Web, the spectre which Dow Jones sought to conjure up in the
present appeal, of a publisher forced to consider every article it publishes on the
World Wide Web against the defamation laws of every country from Afghanistan
to Zimbabwe is seen to be unreal when it is recalled that in all except the most unusual of cases, identifying the person about whom material is to be published will
readily identify the defamation law to which that person may resort.
The appeal should be dismissed with costs.
Kirby, Justice: …
The dismissal of the appeal does not represent a wholly satisfactory outcome.
Intuition suggests that the remarkable features of the Internet (which is still
changing and expanding) makes it more than simply another medium of human
communication. It is indeed a revolutionary leap in the distribution of information, including about the reputation of individuals. It is a medium that overwhelmingly benefits humanity, advancing as it does the human right of access to
information and to free expression. But the human right to protection by law for
the reputation and honour of individuals must also be defended to the extent that
the law provides. …
However, such results are still less than wholly satisfactory. They appear to warrant national legislative attention and to require international discussion in a forum as global as the Internet itself. ...
Callinan, Justice:
The question which this case raises is whether the development of the Internet
calls for a radical shift in the law of defamation. ...
The appellant argued that the respondent, having set out to make money in the
United States, must expect to be subjected to lawful scrutiny in that country. No
doubt the fact of lawful scrutiny in that country, if such the publication was, would
provide a defence to the appellant to defamation proceedings there. That fact does
not however have anything to say about unlawful publication in this country. …
The appellant invited the Court to prefer, in effect, a United States jurisdiction
to an Australian one because the latter would deprive it of the Constitutional protection available in the former. ...
Australian defamation law, and, for that matter, English defamation law also,
and the policy underlying them are different from those of the United States.
There is no doubt that the latter leans heavily, some might say far too heavily, in
favour of defendants. ...
Quite deliberately, and in my opinion rightly so, Australian law places real value on reputation, and views with scepticism claims that it unduly inhibits freedom
of discourse. In my opinion the law with respect to privilege in this country, now
and historically, provides an appropriate balance which does justice to both a publisher and the subject of a publication. ...
Internet Law
I agree with the respondent’s submission that what the appellant seeks to do, is
to impose upon Australian residents for the purposes of this and many other cases,
an American legal hegemony in relation to Internet publications.
.
.
.
.
.
.
QUESTIONS
Australia vs. The Internet: One way of looking at Gutnick is as a response to
Johnson and Post. Why is Australia unwilling to defer to the Internet?
Australia vs. United States: Another way of looking at Gutnick is as a clash
between different national laws. Has Australia imposed its personal reputation protections on the United States? If Dow Jones had won, would the
United States have imposed its free-speech values on Australia?
Law of the Server? Gutnick rejects Dow Jones’s proposed test based on the
location of the server. What would be the practical consequences of a server
test? Does the qualifier “unless that place was merely adventitious or opportunistic” fix the problem?
Total Control? If Australia can impose its defamation law on the Internet, can
Saudi Arabia also impose its anti-pornography law on the Internet? What
about China’s laws against political activism? What content will remain online if each country can impose its idiosyncratic local speech restrictions on
the Internet?
Total Freedom? On the other hand, if Australia can’t control defamation online, does that mean that United States copyright law is also unenforceable?
What content will remain online if any country can effectively extend its free
speech protections to the Internet?
Libel Tourism: How justified is Chief Justice Callinan’s confidence that publishers can “readily identify the defamation law” they will be subject to?
Consider the English case of Mahfouz v. Ehrenfeld, [
] EWHC
(QB). Under English law, a defamation defendant has the burden to show
the truth of her statements, and there is nothing corresponding to the Sullivan actual-malice rule. Three Saudis with worldwide business interests
sued an American author for alleging that they provided financial support
to Al Qaeda, the terrorist organization. Her book was published only in the
United States;
copies found their way into England by way of online
bookstores like Amazon. In addition, one chapter was available for worldwide download from the ABC News website. Does the Internet make it easier for plaintiffs to shop around for a friendly forum? Do cases like Mahfouz
force a choice between total control and total freedom?
JACK GOLDSMITH AND TIMOTHY WU
JACK GOLDSMITH AND TIMOTHY WU, DIGITAL BORDERS
Legal Affairs (Jan. 2006)
6
5
1
1
5
0
0
2
3
2
0
9
9
In the
s, many pundits and scholars believed that the Internet was eroding
the authority of governments. The web’s salient features – instant and universal
communication, geographical anonymity, and decentralized routing – made it easy
for computer users inside a nation to get illegal information from computers outside the nation. American college students could download copyrighted songs
from servers in the South Pacific and bet on digital blackjack tables on computers
in Antigua. Saudi Arabians could access porn sites in Holland, and Italians could
1
6
5
4
3
2
1
78
Chapter 2: Jurisdiction
79
read banned books on web pages hosted in Australia. Nations seemed unable to
stop violations of local laws via the Internet.
This conception of the Internet began to crumble in April
, when two
French antiracism organizations sued Yahoo!, the American Internet portal, in
France. The groups charged Yahoo! with hosting Nazi auction sites that were accessible in France and that violated French laws against trafficking in Nazi goods.
At the time, Yahoo! was the entrance point for more Internet users than any
other website. Jerry Yang, Yahoo!’s billionaire cofounder, was confident and brash
– he and David Filo had chosen the company’s name because, according to the
company’s official history, they “liked the general definition of a yahoo: ‘rude, unsophisticated, uncouth.’” Obsessed with expanding the firm’s market share, Yang
thought governments dumb and speech restrictions dumber still. When Yahoo!
received a summons from Judge Jean-Jacques Gomez of Le Tribunal de Grande
Instance de Paris, a French trial court, Yang shrugged. Reflecting conventional
wisdom, he believed French officials had no authority over a computer in the
United States.
And if France could do nothing to stop Yahoo! in the U.S., it also seemed hard
for French officials to block access to the Nazi auction sites in their country. Too
many Internet communications crossed France’s borders for the government to
stop and screen each one. The Internet’s decentralized routing system carries messages from point to point, even if some connections along the way are blocked,
damaged, or destroyed. “The Net treats censorship as a defect, and routes around
it,” declared John Gilmore, the libertarian Internet activist who cofounded the
Electronic Frontier Foundation. To keep out the Nazi pages, it appeared that
France would have needed to shut down every single Internet access point within
its borders – a seemingly impossible task.
Yahoo!’s arguments were premised on the
s vision of a borderless Internet.
Half a decade later, this vision is fast being replaced by the reality of an Internet
that is splitting apart and reflecting national borders. Far from flattening the
world, the Internet is in many ways conforming to local conditions. The result is
an Internet that is increasingly separated by walls of law, language, and filters.
This bordered Internet reflects top-down pressures from governments like France
that are imposing national laws on the Internet within their borders. But it also
reflects bottom-up pressures from individuals in different places who demand an
Internet that corresponds to their preferences, and from the web page operators
and other content providers who shape their Internet experience to satisfy these
demands. …
0
0
0
2
0
9
9
1
0
0
9
9
0
1
0
2
Judge Gomez ruled preliminarily in May
that Yahoo!’s U.S. websites violated
French law, and he ordered the company “to take all necessary measures to dissuade and make impossible” visits by French web surfers to the illegal Yahoo! Nazi
auction sites on yahoo.com. Jerry Yang was dismissive. “We are not going to
change the content of our sites in the United States just because someone in
France is asking us to do so,” he said. “Asking us to filter access to our sites according to the nationality of web surfers is very naïve.”
Yang’s defiance reflected turn-of-the-century assumptions about the Internet’s
architecture. Internet protocol addresses (each computer’s Internet ID), Internet
domain names (such as mcdonalds.com or cnn.com), and e-mail addresses were
not designed to indicate the geographical location of computers on the Net. These
architectural “facts” meant that most users of
s Internet technology did not
80
Internet Law
know where their e-mail messages and web pages were being viewed, and thus
what laws in which nations they might be violating. Yahoo! said that it didn’t know
where its users were, and which laws it should comply with.
Worse, if France could govern Yahoo! in America, every other nation could as
well. And this raised the worrying possibility that Internet firms and users, confronted with a bevy of conflicting national laws, might begin to comply with the
strictest among them in order to avoid legal jeopardy. “We now risk a race to the
bottom,” predicted Alan Davidson of the Center for Democracy and Technology, in
which “the most restrictive rules about Internet content – influenced by any country – could have an impact on people around the world.”
0
0
9
0
8
9
1
1
9
9
9
1
The specter of conflicting national laws applying to every Internet transaction
might have given Yahoo! the edge at trial, had it not been for the unlikely intervention of Cyril Houri, a Frenchman then working in New York’s Silicon Alley. On a
trip home to Paris in
, Houri made a discovery that upended his career as a
software engineer, not to mention conventional thinking about the Internet. Staying in his parents’ apartment, he turned on his laptop after dinner to check his email. As the computer came on, Houri saw the portal he was used to seeing in New
York. Blinking cheerfully at the top of his screen was a banner advertisement for
an American flower delivery service, accompanied by a -flowers number usable only in the U.S.
In that moment, Houri realized that the Internet did not point inexorably toward the flattening of frontiers. He saw that, to the contrary, a borderless flowerdelivery service made no sense at all. And he grasped that people would pay for
software that took the boundaries of the real world and re-created them on the
Internet, so that flower deliverers and a thousand other e-tailers would know
where their customers were. There would be big money, he thought, in a technology that prevented people outside America’s borders from seeing the American ad,
and that substituted a French ad for a French audience and a German ad for a
German one. The same technology would allow news and entertainment sites to
segment their content according to the whereabouts of their audiences. All it
would take was a program to pinpoint the physical location of users. So Houri
founded a dot-com, Infosplit, devoted to doing just that.
Ever since the Net became commercialized in the mids, Internet firms
had tried, with varying degrees of success, to discover the geographical identity of
their customers. The web’s omnipresent “choose a country” links are one way. Another is to ask users to type in an area code or send geographical identification
(such as a driver’s license) by fax or mail before allowing access to a page. Yet another is to check the address associated with a credit card as proof of geographical
identification. But these techniques are sometimes unreliable and, worse, they’re
time-consuming. “The entire point of the Web is to bring you information simply
and quickly,” thought Sanjay Parekh, the founder of the geo-ID firm Digital Envoy,
during an “a-ha!” experience similar to Houri’s. “Why do I have to scroll through
dozens of countries before accessing the site? Surely there has to be a way for [the
site] to recognize where I am.”
In the past decade, Infosplit, Digital Envoy, and half a dozen other firms set out
to make geographical identification on the Net easy, reliable, and invisible. Instead
of requiring Net users to take steps to reveal or prove their location, they devised a
way to identify a user’s location using the very features of Internet architecture
that supposedly defied geography.
Chapter 2: Jurisdiction
81
IP addresses (like “
.
. . ”) don’t readily reveal a computer user’s physical location. But a savvy user can determine that location by sending “tracing”
packets over the Internet. These packets report a list of computers through which
they travel, much as a car driving along a network of highways collects a receipt at
each toll. Just as a car’s origin can be determined by looking at these receipts,
computers can examine the path of these packets to figure out the computers closest to the originator and recipient of any communication of the Net. This information can then be cross-checked against other IP databases that offer different clues
about the geographical location of almost every computer connected to the Internet. When the databases are cross-referenced and analyzed, the location of Internet users can be determined with over
percent accuracy at the country level.
Internet geo-identification services are still nascent, but they are starting to
have effects on e-commerce. Online identity theft in the U.S. causes firms and consumers to lose billions of dollars each year. Geo-ID is helping to solve this problem
by identifying when stolen credit card numbers are used on the Net from locations
like Russia, the home of many such scams. It is also improving Internet advertising, as Houri and Parekh envisioned, by making it easier to display ads geared to
local conditions. And it is speeding the delivery of electronic data, allowing firms
to deliver content from the closest “cache” website without having to ask the consumer where he is.
Finally, and potentially most important, these technologies are starting to enable the geographical zoning of entertainment. An important hurdle to the distribution of entertainment on the Net has been that certain material cannot lawfully
be viewed in certain places. Geo-ID technologies can help to solve this problem by
ensuring that online movies, web gambling sites, software programs, and other
digital products do not enter countries where they are illegal. In other words, the
software designed to respond to the local demands of consumers can also be used
to help ensure compliance with different laws in different places.
0
0
0
2
9
9
0
0
0
0
0
2
0
5
2
5
0
8
6
1
2
9
1
Following Judge Gomez’s May
preliminary ruling, Cyril Houri contacted the
plaintiff ’s lawyer, Stephane Lilti, and told him that his software could identify and
screen Internet content on the basis of its geographical source. Houri was invited
to Paris where he showed Lilti how his software worked. When the plaintiff ’s legal
team saw what it reported, they were astonished. Yahoo!’s servers, which the firm
had claimed were protected by the First Amendment to the U.S. Constitution,
were actually located on a website in Stockholm. Yahoo! had placed a constantly
updated “mirror” copy of its U.S. site in Sweden to speed access to the site in Europe.
When the trial resumed in July
, Yahoo!’s lawyers reiterated that it was
impossible to identify and filter out French visitors to the firm’s U.S.-based websites. Lilti responded by explaining how Houri’s geo-location technology showed
that Yahoo! auctions in France were not coming from servers in the U.S. Suddenly,
the assumption that every web page was equally accessible to every computer user
everywhere in the world seemed wrong. If Yahoo! could direct content to French
users from Swedish servers, it could potentially identify users by geography and, if
it liked, it could screen them out.
After receiving additional expert testimony about the feasibility of geographical
screening, Gomez issued a final decision in November
, reaffirming that Yahoo! had violated French law by allowing Nazi goods to appear for sale on web
pages in France. Gomez determined that the French court had power over Yahoo!
Internet Law
and its servers because the company had taken conscious steps to direct the prohibited Nazi auction pages into France. He pointed out that Yahoo! greeted French
visitors to its U.S. website with French-language advertisements. This showed that
Yahoo! was tailoring content for France and that, to some extent, it could identify
and screen users by geography. Acknowledging that
percent blocking was impossible, the court ordered Yahoo! to make a reasonable “best effort” to block
French users.
At first, Yahoo! threatened to ignore Gomez’s decision. But the company had a
problem: its assets in France, including income from its French subsidiary, were at
risk of seizure. In January
, Yahoo! abruptly surrendered. It pulled all Nazi
materials from its auction sites, announcing that it would “no longer allow items
that are associated with groups which promote or glorify hatred and violence to be
listed on any of Yahoo!’s commerce properties.” The company claimed that it was
motivated by bad publicity from the Nazi auctions and not the French ruling. “Society as a whole has rejected such groups,” said a Yahoo! spokesperson. But the
timing and threat of French sanctions suggested that Yahoo!’s will had been broken.
QUESTIONS
France vs. United States: Why is it culturally important to France to prohibit
trafficking in Nazi memorabilia? Can you think of any material that would
be offensive in the United States but innocuous in other countries?
Geolocation: How does geolocation upend the choice between French and
United States law? Between total freedom and total control?
Yahoo’s About-Face: Why did Yahoo! reverse course and agree to comply with
the French orders? Why didn’t it just block French users? And why did it
ban Nazi memorabilia entirely, rather than just hiding those auctions from
users in France?
Territorial Factors: How much did the location of Yahoo!’s servers matter? Its
offices? Its users?
A Bordered Internet? Goldsmith and Wu argue that the Internet is becoming
“bordered” rather than “borderless.” What does that mean? How will the
Internet in the United States differ from the Internet in France? Have you
personally seen examples of the bordered Internet?
.
.
.
.
.
ESAFETY COMMISSIONER V. X CORP.
Federal Court of Australia
[2024] FCA 499
1
2
1
1
0
2
0
0
1
4
2
0
2
9
1
0
0
1
0
2
5
1
4
2
0
2
6
1
1
1
1
1
Kennett, Justice:
. On
April
the applicant (the Commissioner) issued a notice to the
respondent (X Corp.) under s
of the Online Safety Act
(Cth). Under s
of the OS Act, a person must comply with a requirement under a
removal notice “to the extent that the person is capable of doing so”. …
. On the evening of
April
Bishop Mar Mari Emmanuel was attacked
and repeatedly stabbed by a lone assailant while giving a sermon at the Assyrian Christ the Good Shepherd Church in Wakeley, New South Wales. A
short video of the attack exists. The video runs for about
seconds. It
shows, from a vantage point apparently near the back of the church, the lone
assailant rushing at Bishop Emmanuel and attacking him. The assailant
7
5
4
3
2
1
82
Chapter 2: Jurisdiction
83
raises their right arm and strikes the Bishop several times with a downward
motion; the Bishop falls backwards. It is not clear from the video that a
knife is being used, although that can be inferred from the motions of the
assailant. The shocked and distressed reactions of witnesses can be heard.
. The Commissioner’s officers became aware of social media posts containing
the stabbing video. They reached the view that the video was of such a nature that it should be the subject of a removal notice under s
and approached major online service providers. Some providers removed URLs
containing the stabbing video from their platforms altogether. X Corp. did
not.
. The removal notice was issued by a delegate of the Commissioner (the delegate) on April
. Relevantly for present purposes, the notice says:
This removal notice is given to you under section
of the Act
and requires you to take all reasonable steps to ensure the removal of the class material speci ed in Attachment A.
. Attachment A identifies the relevant material by way of a list of
specified
URLs, each of which designates a post on X Corp.’s social media platform
(X). There follows a “Description of material”, which consists of a description of the contents of the stabbing video followed by a statement:
The content is class material under the Online Safety Act
(Cth), for depicting matters of crime, cruelty and real violence
in such a way that it o ends against the standards of morality,
decency and propriety generally accepted by reasonable adults
to the extent that it would likely be classi ed RC. …
. The source of the dispute between the parties on this issue is that, while X
Corp. has agreed to “geoblock” the
URLs specified in the removal notice
(so that they are not accessible to users with IP addresses in Australia), the
Commissioner contends that this is not sufficient to comply with the notice.
A significant number of people in Australia use Virtual Private Networks
(VPNs)[*] to connect to the internet without using an IP address linked to
an Australian provider. These users, while physically in Australia, are not
affected by the geoblocking X Corp. has imposed and therefore still have
access to the
URLs.
. The Commissioner therefore seeks a final injunction that would require X
Corp. to remove the
URLs from its platform altogether or make them
inaccessible to all users. There appears to be no dispute that, because of the
use of VPNs, this is what it would take to prevent all users in Australia from
going to one of the
URLs and viewing the stabbing video. The Commissioner argues that such action is within the “all reasonable steps” that the
removal notice requires to be taken. X Corp. argues that a requirement for
worldwide removal or blocking of the material goes beyond what is “reasonable”. …
. The policy questions underlying the parties’ dispute are large. They have
generated widespread and sometimes heated controversy. Apart from questions concerning freedom of expression in Australia, there is widespread
5
6
9
0
1
1
2
0
2
9
0
1
fi
5
6
fi
ff
5
4
6
5
2
1
6
0
1
2
5
6
6
1
8
9
0
8
9
0
1
3
3
4
[* For more on how VPNs work, see Note on Online Identification in the Anonymity
section of the Privacy chapter.]
84
Internet Law
2
9
0
1
5
6
5
6
9
9
0
0
1
1
9
0
1
6
7
8
9
0
4
4
4
4
5
alarm at the prospect of a decision by an official of a national government
restricting access to controversial material on the internet by people all over
the world. It has been said that if such capacity existed it might be used by a
variety of regimes for a variety of purposes, not all of which would be benign. The task of the Court, at least at this stage of the analysis, is only to
determine the legal meaning and effect of the removal notice. That is done
by construing its language and the language of the Act under which it was
issued. It is ultimately the words used by Parliament that determine how far
the notice reaches.
. I have no doubt that removing the
URLs from its platform altogether
would be a reasonable step for X Corp. to take, in the sense that a decision
by X to take that step could readily be justified. There is uncontroversial
evidence that this is what other social media platforms have done, and that
X Corp. would not be in breach of any United States law if it took this step.
However, this is not the test. The OS Act pursues a policy. It is not bounded
by the policies of service providers or their contractual relationships with
their users. Section
imposes its requirements regardless of the wishes of
providers and of individual users.
. The qualifier “reasonable” should therefore be understood as limiting what
must be done in response to a notice to the steps that it is reasonable to expect or require the provider to undertake. That understanding is consistent
with how duties arising under the general law to take “reasonable” steps
commonly work. Identification of the steps that are “reasonable” in this
sense may involve consideration of expense, technical difficulty, the time
permitted for compliance (which may be short: see s
( )) and the other
interests that are affected. It is the last of these factors that is the focus of
the parties’ disagreement.
. The argument that making the
URLs inaccessible to all users of X Corp.’s
platform everywhere in the world is not a step that it is “reasonable” to require X Corp. to perform in order to ensure that the URLs are inaccessible
to Australian users (and therefore is not a step required by the removal notice) is powerful.
. If s
of the OS Act provided for a notice imposing such a requirement, it
would clash with what is sometimes described as the “comity of nations” in a
fundamental manner. …
. If given the reach contended for by the Commissioner, the removal notice
would govern (and subject to punitive consequences under Australian law)
the activities of a foreign corporation in the United States (where X Corp’s
corporate decision-making occurs) and every country where its servers are
located; and it would likewise govern the relationships between that corporation and its users everywhere in the world. The Commissioner, exercising
her power under s
, would be deciding what users of social media services throughout the world were allowed to see on those services. The content to which access may be denied by a removal notice is not limited to
Australian content. In so far as the notice prevented content being available
to users in other parts of the world, at least in the circumstances of the
present case, it would be a clear case of a national law purporting to apply to
“persons or matters over which, according to the comity of nations, the jurisdiction properly belongs to some other sovereign or State”. Those “persons
85
or matters” can be described as the relationships of a foreign corporation
with users of its services who are outside (and have no connection with)
Australia. What X Corp. is to be permitted to show to users in a particular
country is something that the “comity of nations” would ordinarily regard as
the province of that country’s government.
. The potential consequences for orderly and amicable relations between nations, if a notice with the breadth contended for were enforced, are obvious.
Most likely, the notice would be ignored or disparaged in other countries.
(The parties on this application tendered reports by experts on US law, who
were agreed that a US court would not enforce any injunction granted in
this case to require X Corp. to take down the
URLs.)
. Section ( ) of the OS Act extends the operation of its provisions to “acts,
omissions, matters and things outside Australia”. It confirms that X Corp. is
in breach of the removal notice if it fails to take some “reasonable step” notwithstanding that the act or omission constituting that failure occurs overseas. However, s
( ) does not control the meaning of “all reasonable
steps”. A clear expression of intention would be necessary to support a conclusion that Parliament intended to empower the Commissioner to issue
removal notices with the effect for which she contends.
. The result is that, read in context and in the light of normal principles of
statutory construction, the “reasonable steps” required by a removal notice
issued under s
do not include the steps which the Commissioner seeks
to compel X Corp. to take in the present case.
5
6
2
3
2
2
9
3
0
1
2
5
6
1
2
3
5
5
QUESTIONS
. Comity: One way to balance different national interests online is judicial
comity: a court can voluntarily decline to apply its own jurisdiction’s law
when doing so would seriously interfere with the smooth operation of another jurisdiction’s laws. Has the Australian court in eSafety Commissioner done
a good job balancing domestic concerns with the interests of other countries
and their residents?
. Enforcement: Another way to balance different national interests is the converse of comity: the courts of one jurisdiction can decline to assist in enforcing the orders of another jurisdiction’s courts. The court here says that United States courts would refuse to enforce an Australian injunction. Why
would they refuse? Will U.S. courts do a good job balancing domestic concerns with the interests of other countries and their residents?
. Practical Effects: What can X now show to users in Australia when they go to
one of the
URLs? What about users in the United States? Compare X’s
decision here to Yahoo!’s various decisions during the French litigation.
What explains their different choices?
. Whether That Internet Can Long Endure: You have now seen six different ways
that different national laws could be reconciled online:
• Gutnick-style optimism: few real conflicts will arise
• Total control: the most restrictive national law applies
• Total freedom: the least restrictive national law applies
• A bordered Internet: geolocation prevents cross-border access
• Comity: countries defer to others’ important policies
5
3
2
1
4
Chapter 2: Jurisdiction
86
Internet Law
• Enforcement: countries selectively give effect to each others’ rulings
A seventh possibility would be international treaties that explicitly balance
di ering national policies (see the Gambling Treaty problem below). Which
of these do you think are workable? Which do you think are best? Which are
we likely to get?
0
5
0
8
2
1
7
4
9
1
1
4
2
5
9
9
1
7
6
9
1
ff
SEAHAVEN PROBLEM
During the Second World War, Britain constructed a number of anti-aircraft platforms off its coast to provide an additional line of defense against German
bombers. One of these platforms, Root Sands, is seven miles from the nearest
coastline, which puts it in international waters. It consists of a
’x ’ steel deck,
resting on two circular concrete legs, each ’ in diameter. The legs contain seven
stories each, and the superstructure on the platform itself contains a living room,
kitchen, two bedrooms, and two bathrooms. At the end of the war, the British government abandoned the platform.
In
, Douglas Shaftoe, an ex-major in the British army, occupied the Rough
Sands tower with his family and declared it an independent country, the Sultanate
of Shoreland (with himself as Sultan). The next year, his -year-old daughter,
Amy, used her father’s handgun to fire three shots across the bow of a boat from
nearby Harwich harbor that was repairing buoys marking the shipping channel
near Shoreland. The next time that Douglas and Amy went ashore to purchase
groceries, they were arrested and tried on charges of possessing and using unlicensed firearms. They raised a jurisdictional objection, and the judge dismissed
the charges, saying, “Parliament, I think, has not intended the Firearms Act to operate outside of the ordinary territorial limits [i.e. on English land and within
three miles of its coast].”
The Shaftoes have been there ever since. Over the years, they have made the
place, if not quite opulent, then at least livable, with a diesel generator, furniture,
television sets, modern kitchen appliances, and so on. They don’t pay taxes, and
the British government has given up on trying to collect. In
, a group of Germans came to the platform while Douglas was away on business. They convinced
Amy to hoist them on-board, saying they had a message from Douglas. It was a
trick; they locked Amy in a cabin and seized control of Shoreland. When Douglas
found out, he rented a helicopter and successfully retook the platform at shotgunpoint. In
, Douglas retired and named Amy the new Sultana.
Two programmers, Randall Waterhouse and Avi Halaby, have befriended Amy
Shaftoe, and they propose to set up a “data haven” on Shoreland, to be named
SeaHaven. The idea is that material that other countries make illegal can safely be
stored on computers on Shoreland, which will provide them with a legal umbrella.
That is, Shoreland will redraft its legal code to make almost any use of the Internet
legal. Some examples of possible customers:
• A company that wants to keep its corporate records subpoena-proof can
simply store them on Shoreland using SeaHaven.
• Companies offering cheap downloads of music and movies can set up shop
with SeaHaven, even if those downloads would be illegal under the copyright law of other countries.
• Many Islamic countries have strict laws against pornography. SeaHaven will
host it.
Chapter 2: Jurisdiction
87
• Falun Gong sites and the government-in-exile of Tibet are deeply unpopular
with Chinese authorities. SeaHaven will give them an online home.
• Online gambling!
The only three no-nos under SeaHaven’s planned terms of service will be sexual
child abuse, spam, and hacking. Physical security is also a serious concern. To forestall the possibility that an annoyed country will try to cut off SeaHaven with selfhelp, the business plan calls for redundant network links: satellite, line-of-sight
microwave to Britain, and, eventually, undersea cables. Two on-site security professionals will be on duty at all times, carrying shotguns, tasers, and . -caliber
machine guns. The server rooms in the tower legs will be filled with pure nitrogen
gas to reduce the risk of fire and keep unwanted intruders out. In the event that
the guards can’t fight off any attackers, SeaHaven plans to promise its customers
that it will destroy their servers and refund their fees before allowing the machines
to be physically seized. Meanwhile, Shoreland plans to apply for United Nations
membership and defend its sovereignty in court if necessary.
You represent the Epiphyte Fund, a venture capital firm. Epiphyte’s CEO, Hubert Kepler, has asked you to advise whether a proposed
million investment in
SeaHaven is a good idea. He wants to know, based on your knowledge of Internet
law and national jurisdiction, whether the data-haven plan is likely to work. Will it
be able to attract customers? Will it be able to deliver on its promises of legal freedom to them? What other risks does SeaHaven face? Should Epiphyte invest?
0
5
5
$
0
8
9
1
GAMBLING TREATY PROBLEM
You have been appointed as the rapporteur for an international meeting to discuss
the possibility of an international treaty on online gambling. Your job is to facilitate dialogue, identify points of possible consensus, and report on the discussion.
You have identified the following countries as key players whose views in the
meeting are likely to have significant weight:
• The Cardassian Union, a large and cosmopolitan Western nation with a culture that prizes tradition and order. It allows several forms of gambling, but
subjects them to strict regulations to protect players. Gambling in person
can take place only in casinos in a few designated cities; casino ownership is
carefully supervised to guard against organized-crime influences; casinos
must comply with extensive safeguards to prevent gambling addiction.
Sports gaming is technically illegal but the government is content to look
the other way as long as the wagering is among acquaintances rather than
with professional bookmakers. Slot machines are strictly forbidden because
of their potentially addictive qualities. Online, the Cardassian Union allows
casino operators to offer virtual equivalents to the offline games they offer,
with similar regulations. It has not thought much about the international
issues involved.
• Ferenginar, an island nation in the Mediterranean, is a small and until recently underdeveloped country. In the
s it made a significant move to
become a banking and tourism center, with significant success, resulting in
strong IT infrastructure and permissive morals laws. It allows most forms of
private gambling, prohibiting only fraud and other conduct directly threatening the integrity of a game. It has slot machines in the airport, video poker
machines in most bars, and extensive sports betting networks. Cardassian
tourists who enjoy gambling speak of Ferenginar as a good place to visit. It
88
Internet Law
has supported its local companies as they have started offering gambling
services worldwide on the Internet.
• Bajor, an East Asian country with a rich but specific history of gambling.
Sports betting, particularly on horse and other animal racing, is close to a
national obsession. A few table games, like Tongo and Dabo, have devoted
followings, but most Western games, like poker and blackjack, are not widely played. A few years ago, a conservative government took office on a national-pride and moral-rectitude platform. It was willing to tolerate existing
forms of gambling but draw a hard line against expansion into new media
and especially against “foreign” influences. It passed a law forbidding online
gambling and requiring domestic financial intermediaries (banks, credit
card companies, etc.) to cut off all business with gambling companies.
• The Hadar Dominion, a Middle Eastern country, regards gambling as unIslamic and strictly prohibits it. Some underground social gambling takes
place, but the Dominion police and judiciary are not shy about using long
prison terms to punish people who are caught wagering. The government
uses the country’s Internet filtering infrastructure to block foreign sites that
offer gambling and pornography, among other content considered sinful.
Looking over these positions, you doubt that it is possible to achieve substantive
harmonization: Ferenginar and the Hadar Dominion are never going to agree on
whether gambling should be permissible. But perhaps it’s possible to make
progress on reducing some of the sources of friction in the system. Can you identify rules under which countries would sometimes enforce or defer to each others’
gambling regulations? How much consensus could you get on those rules? How
promising are international treaties as a solution to the problems of online gambling? As a solution to the problems of online conflicts in general?
DIPLOMATIC MISSION PROBLEM
You are on the staff of the United States Diplomatic Mission to Spain. The Ambassador has called a meeting to discuss the Mission’s response to a potential diplomatic incident. Earlier today, Rebecca Zuckerman, the chief privacy officer for
MagnaVideo, a United States-based website for users to upload, share, and comment on videos, was arrested in Madrid. She had been on her way to give a speech
when a group of Spanish police served her with charging papers for criminal
defamation and invasion of privacy. An autistic boy had been taunted by his
classmates in a Spanish elementary school, who filmed the abuse with a cameraphone and posted the video to MagnaVideo. The video remained on MagnaVideo
for approximately two months; several other users posted comments beneath it
expressing shock and disgust. Eventually, an advocacy group on behalf of sufferers
of Down syndrome and other developmental disorders complained to MagnaVideo, and the video was removed. The prosecutor’s theory of the case is that
MagnaVideo was negligent in not removing the video more quickly. It seeks to
hold MagnaVideo corporate officers, including Zuckerman, criminally liable, with
possible prison sentences of up to one year. Under Spanish law, first-time offenders sentenced to one year or less are given the equivalent of a suspended sentence,
rather than serving any actual prison time.
In ninety minutes, the Ambassador wants to release a public statement on
Zuckerman’s arrest and the United States’s reaction to it. Before then, she needs to
call her counterpart inside the Spanish diplomatic service to discuss the matter.
Chapter 2: Jurisdiction
89
She’ll also need to field questions from MagnaVideo, and send a diplomatic cable
back to the State Department in the U.S. discussing the implications for United
States foreign policy. In the Ambassador’s personal view, Zuckerman is an upstanding United States citizen who has done absolutely nothing wrong. Give her
your advice on what the United States’s diplomatic position should be about the
arrest.
C. American Law
This section runs through the jurisdictional questions that a United States court
will ask about any case and shows how these questions bend and mutate when the
Internet is involved. It starts with subsections on civil and criminal cases, and then
considers the Constitutional mechanisms for harmonizing federal and state laws.
As you read the following materials, consider whether the various tests in these
different areas are consistent with each other.
1. Civil Jurisdiction
0
1
0
2
1
2
7
0
4
4
2
1
6
5
To hear a civil case, a United States court must have both subject-matter jurisdiction over the case and personal jurisdiction over the parties. Once it has jurisdiction in a case that touches multiple states, the court must engage in a choice of law
analysis. And sometimes it must decide whether to allow for local enforcement of a
foreign court’s previous judgment.
Start with subject-matter jurisdiction. It is common to distinguish between
“territorial” and “extraterritorial” regulation. Territorial laws apply to conduct taking place within a jurisdiction’s physical boundaries; extraterritorial laws apply to
conduct taking place beyond them. International law has traditionally allowed
countries nearly unlimited power to make law territorially, subject only to some
specific prohibitions like the human rights norms against genocide and torture.
The power to regulate extraterritorially, while broad, is not unlimited: a state may
make law governing “conduct outside its territory that has or is intended to have
substantial effect within its territory.” Restatement (Third) of Foreign Relations Law §
( )(c). But the Supreme Court has developed a “presumption
against extraterritoriality”: unless Congress clearly indicates otherwise, statutes
are presumed to apply only territorially. In Morrison v. National Australia Bank
Ltd.,
U.S.
(
), for example, the Court held that American securities
laws did not apply to a case where Australian investors sued an Australian bank
whose shares traded only on foreign exchanges.
Personal jurisdiction has two prongs. First, there is the Constitutional Due
Process requirement that the party must have sufficient “minimum contacts” with
the forum. Some of the traditional bases of jurisdiction look much the same on the
Internet, some do not:
• General jurisdiction over any cause of action is always available in the state
where a person is domiciled or where a corporation is incorporated or has its
principal place of business. Everyone still lives somewhere, the Internet
notwithstanding.
• Transient jurisdiction is available whenever the defendant is properly
served with process while physically present in the forum. The Internet
makes it easier to dodge local service of process by doing business online.
Internet Law
• Attachment jurisdiction over property in the forum raises a few conceptual
issues about where precisely intangible online assets like Bitcoins are located, but comparatively few actual cases.
• Jurisdiction by consent may be more common if people are more likely to
accept a forum’s jurisdiction over their online dealings.
• Specific jurisdiction based on out-of-forum activities that have consequences within the forum is where the rubber meets the road, because the
Internet makes these scenarios far more common.
Second, the forum must actually have subjected the party to its courts’ jurisdiction. This is the province of state long-arm statutes. Some confer personal jurisdiction to the full extent of the Due Process Clause; others restrict personal jurisdiction to specific categories of cases.
Once a court takes jurisdiction over a case, it must decide what law applies. In
offline cases, this is the rich domain of choice of law, and states have a rich array of
different approaches to the problem.
There is also the question of recognition of judgments, a/k/a enforcement. Domestically, the Full Faith and Credit Clause of the Constitution, art IV, § , and the
federal full faith and credit statute,
U.S.C §
, require states to recognize
each others’ judgments, full stop. A New Mexico judgment is as good as a New
Hampshire judgment in a New Hampshire court, and vice versa. Internationally,
United States courts can and do enforce foreign judgments. But they can and do
decline recognition for many reasons, including when the judgment was procured
by fraud, when it offends the recognizing state’s public policy, when the defendant
had insufficient notice of the case, or when the foreign jurisdiction would not recognize an American judgment in a mirror-image case. The SPEECH Act provides
an important mandatory limit on the recognition of certain foreign judgments in
Internet cases.
Finally, note that personal jurisdiction and choice of law are both subject to
consent. Parties can agree to take their disputes to a particular state’s courts, or to
subject them to a particular state’s laws. They can even agree to binding private
arbitration instead of court. Sometimes, there is a dispute over whether the parties
really have agreed to a choice-of-forum, choice-of-law, or arbitration clause; the
Contracts section considers some of the contract-formation mechanics involved.
But in general, a a court will apply the law of the state parties select in a contract
unless “the chosen state has no substantial relationship to the parties or the transaction” or applying that law would “be contrary to a fundamental policy of a state
which has a materially greater interest than the chosen state.” Restatement
(Second) of Conflicts of Law §
( ).
1
8
3
7
1
2
7
7
2
8
QUESTIONS
. Where Can You Sue and Be Sued? Look at the terms of service for your five favorite websites. Where can you sue them? Where can they sue you? Where
else can you be sued? What law will apply?
. Drafting Advice: If you are drafting a website’s terms of service, should you
include a forum-selection clause? A choice-of-law clause? If so, what forum
and law should you select?
1
2
1
90
Chapter 2: Jurisdiction
91
GROO V. MONTANA ELEVENTH JUDICIAL DISTRICT COURT
2023 MT 193
0
2
0
2
6
1
2
0
2
4
2
9
6
%
0
0
2
3
4
1
1
Chief Justice Mike McGrath delivered the opinion of the court. …
[Lorney “Jay” Deist and Kimberly Deist operated the Triple D Game Farm, a
wildlife photography farm, in Flathead County, Montana. A former employee,
Heather Keepers, corresponded with Melissa Groo, a New York resident and
wildlife photographer. Keepers wrote, in part:
My goal in reaching out to you is simple. Those animals need to be
“saved” from Jay Deist. Those animals deserve so much better. And
especially now that I’m not there to provide half of what they deserve,
a lot of them are now just sitting and rotting. Some have even died
suddenly since I left. (I left July ). I am obviously desperate to save
them. And well....it’ll take someone who hates the Triple D as much as
I do to do that. And I don’t mean some animals and then Jay can get
more. I mean ALL animals. And his operation stops entirely. Forever.
Is this something that interests you?
Groo responded, in part:
Absofuckinglutely.
You are writing me at a very opportune time. i would love to get your
help on taking him down. The things that I have uncovered from lots
of research haunt me more than you can know. Or maybe you can
know. I know we have clashed in the past, but if your first concern is
the animals, we have that in common, and that is HUGE. Let’s try to
collaborate to make a better future for them. I am incredibly grateful
you reached out. I know how terribly difficult it must be. …
I want very much for Triple D and all game farms to be done. i am
with you
.]
¶
Following this initial exchange with Keepers, Groo used Facebook to share
content pertaining to Triple D and to encourage other users to take explicit
actions intended to affect Triple D. On August ,
, Groo shared an article from Roadsidezoonews.org titled “Photography game farm Triple D
Wildlife cited times for keeping animals in squalor.” Her post included the
following comment: “More on Triple D photo game farm. What a disgrace to
treat these magnificent animals so poorly. It’s time for these wildlife brothels
to be done. Photo by Susan Fox from a visit years ago to Triple D. Please
share.”
¶
Importantly, between August – ,
, Groo again used Facebook to share
information about Triple D and to direct users to take action that would affect Triple D’s operations. In that three day period, Groo repeatedly shared a
similar message—“I hope very much that those photographers/artists and
companies listed as holding regular or future workshops there would cancel
them immediately. It would be unconscionable to continue to support this
facility”—and, within those messages, tagged various Triple D clients and
group leaders. (Emphasis added.) Approximately one-quarter of the individuals and companies tagged by Groo were located in Montana. Others
tagged were not located in Montana, but had ongoing contracts with Triple
D that were executed, and to be performed in, Montana.
2
3
2
5
2
4
n
o
i
1
s
s
u
1
5
c
5
6
3
4
6
2
3
1
1
s
i
2
2
2
2
3
3
¶
1
¶
4
¶
1
¶
4
¶
3
¶
2
Triple D alleges that Groo’s social media posts had a detrimental impact on
their business in Montana.
On January ,
, Triple D filed a Complaint and Demand for Jury Trial
alleging Tortious Interference with Contractual Relations and Tortious Interference with Prospective Economic Advantage claims against Groo.
D
…
A court may exercise personal jurisdiction over the parties in a proceeding
pursuant to general (all-purpose) or specific (case-linked) personal jurisdiction. Both parties agree that Groo is not subject to general personal jurisdiction in Montana. Whether the District Court can exercise personal jurisdiction over Groo hinges on the scope of specific personal jurisdiction.
Specific personal jurisdiction exists only where two elements have been satisfied. First, the suit itself must arise from the specific circumstances set
forth in Montana’s long-arm statute, M. R. Civ. P. (b)( ). Second, if personal jurisdiction exists …, we then determine whether exercising such jurisdiction would comport with traditional notions of fair play and substantial justice embodied in the Due Process Clause.
Montana’s Long-Arm Statute
The District Court concluded that the first element was satisfied under Rule
(b)( )(B), which states that any person is subject to the jurisdiction of
Montana courts as to any claim for relief arising from “the commission of
any act resulting in accrual within Montana of a tort action.” …
This Court’s analysis of accrual has focused on where the events giving rise
to the claims occurred, rather than where the plaintiffs allegedly experienced or learned of their injuries. …
This Court’s case law makes clear that whether a tort accrued in Montana is
highly-fact specific and dependent on the nature of the alleged tort at issue.
Here, the “act” at issue is Groo’s targeted social media campaign towards a
Montana business, Montana residents, and those with contracts in Montana
(a Montana audience), which was calculated to result in actual damage or
loss to Triple D. To prevail on its claims of tortious interference with
prospective economic advantage and tortious interference with contractual
relations, Triple D will still need to prove: ( ) an intentional and willful act;
( ) calculated to cause damage to the plaintiff 's business; ( ) with the unlawful purpose of causing damage or loss, without right or justifiable cause
on the part of the actor; and, ( ) the act results in actual damage or loss. …
Further, Triple D alleges that Groo’s social media campaign targeted people
and businesses it had (and lost) contracts with, which were executed and
performed only in Montana. By executing and performing contracts within
Montana, even if they were executed over the phone or otherwise, Triple D’s
clients were availing themselves of Montana law and jurisdiction. By allegedly ( ) intentionally targeting Montana contracts and residents, ( ) to
cause damage to Triple D, ( ) with the unlawful purpose of causing damage
to Triple D, and ( ) actually damaging Triple D, Groo committed an act that
accrued within Montana. The damage being felt in Montana is not what
accrues the tort in Montana, by itself, but also Groo’s conduct intentionally
aimed into Montana and to a Montana audience.
2
¶
0
Internet Law
¶
2
4
92
Chapter 2: Jurisdiction
3
1
1
1
2
4
1
2
7
2
1
5
1
1
5
1
1
3
2
9
1
0
3
2
4
2
3
4
3
4
4
4
5
4
¶
9
¶
1
¶
0
¶
Contrary to the Dissent’s assertion in ¶ , someone reviewing a business or
sharing about their boycott on a national platform would not be subject to
personal jurisdiction in the plaintiff ’s forum state. Indeed, if Groo had
stopped her online activities after posting the article referred to in ¶
of
this Opinion (or even continued posting articles like this directed to a national audience) she would not be subject to personal jurisdiction in Montana today. The post that tipped the scales and subjected her to personal
jurisdiction in Montana was that recounted in ¶
of this Opinion. This
post is unique from an online review of a business or product in that ( ) it
was not directed to a national audience, but solely directed into Montana
towards Montana residents and those doing business in Montana with
Triple D, ( ) it encouraged a Montana audience not to do business with
Triple D, and ( ) it created by itself, in a Montana resident, a potential cause
of action within Montana for an intentional tort. Groo directed her online
activity solely towards a Montana audience by researching and tagging only
those in Montana or those in business with Triple D in Montana. This is
highly distinguishable from a simple review posted online for anyone to see,
which is not targeted toward one particular state or audience. …
Due Process
… This limitation on a Montana court’s exercise of personal jurisdiction results from the Fourteenth Amendment’s Due Process Clause. U.S. Const.
amend. XIV. To determine if exercising personal jurisdiction over a defendant comports with due process, a court must consider whether: “( ) the
nonresident defendant purposefully availed itself of the privilege of conducting activities in Montana, thereby invoking Montana’s laws; ( ) the plaintiff ’s claim arises out of or relates to the defendant’s forum-related activities;
and ( ) the exercise of personal jurisdiction is reasonable.” Ford Motor Co. v.
Mont. Eighth Jud. Dist. Ct.,
MT
,¶ .
With respect to the first prong, the District Court reasoned that Groo purposefully availed herself of the benefits and protections of the laws of Montana by taking voluntary action designed to have an effect in Montana. More
specifically, Groo identified and targeted a Montana audience and had the
specific intent of inflicting economic pain on a Montana business. We agree
that Groo’s actions satisfied this first prong.
On the second prong, the District Court determined there is no question
Groo’s social media campaign constituted forum-related activities that gave
rise to Triple D’s claims. The court again stressed that Groo tailored her actions to have an effect on Montana residents and a Montana business. According to the court, there was a nexus between the content of Groo’s campaign and Triple D’s business—that nexus made it reasonably foreseeable to
Groo that her campaign would reach Montana and have an impact in Montana. We agree that Groo’s actions satisfied this prong.
On the third prong, the District Court applied the presumption of reasonableness set forth by this Court in Ford Motor Co. v. Mont. Eighth Jud. Dist.
Ct.,
MT
, to evaluate whether Groo presented a compelling case
that exercising jurisdiction would be unreasonable. The court then evaluated Groo’s case based on seven factors identified by the Ford Motor Co. Court.
The court acknowledged that Groo would face some hardship in having to
defend in Montana, but found that the other factors tend toward jurisdic-
2
¶
93
Internet Law
1
7
5
9
1
0
2
1
3
1
8
8
2
1
4
7
1
5
0
1
8
2
7
5
7
7
2
7
6
8
9
2
4
4
4
4
¶
4
¶
2
¶
6
¶
8
tion being reasonable: Groo engaged in intentional conduct designed to
have a targeted impact in Montana; Montana exercising jurisdiction would
not conflict with the sovereignty of the State of New York; Montana has an
interest in adjudicating the disputes affecting its residents and businesses;
Montana would be the most efficient forum for resolving the controversy;
Montana is important to Triple D’s convenient and effective relief; and, New
York would not serve as a valid alternative forum. Based on that evaluation,
the court concluded that Groo failed to make a compelling case that exercising jurisdiction would be unreasonable. We agree.
Following the United States Supreme Court’s ruling in Walden v. Fiore,
U.S.
(
), this Court has also analyzed a court’s exercise of specific
jurisdiction within the context of a tort action under two overlapping lines
of inquiry. First, whether the relationship among the defendant, the forum,
and the litigation arises out of contacts that the defendant created with the
forum state. And, second, whether the plaintiff is the only link between the
defendant and the forum or whether the defendant’s conduct forms the
connection with the forum state that is the basis for jurisdiction over them.
In Walden, the United States Supreme Court held that a law enforcement
agent who filed a false affidavit in Georgia did not create contacts with the
forum state, Nevada, where the individuals affected by that affidavit resided.
See Walden,
U.S. at
(“Petitioner never . . . contacted anyone in, or
sent anything . . . to Nevada.”). Absent the unilateral activity of the plaintiffs,
the agent would have made no contact with the forum state.
Here, unlike in Walden, Groo created the contacts that established a relationship between herself, the forum, and the litigation. … She identified
other residents of Montana and those with business relations in Montana;
the Walden agent made no such intentional outreach to residents of Nevada
other than the plaintiffs. She tailored messages to influence those residents;
the Walden agent only took actions intended to exclusively affect the plaintiffs. And, she aspired to steer those residents away from a Montana business; the Walden agent did not intend to interfere with economic affairs
protected by and reliant upon the enforcement of the laws of Nevada.
How trying to “Absofuckinglutely” take down a Montana business is not a
contact with the forum state itself is a difficult question to answer. These
economic losses were not the result of a “random, fortuitous, or attenuated,”
Walden,
U.S. at
, contact that had an incidental effect of causing
someone to renege on a contract—such as might happen when someone
reads one of Groo’s stories about photographing captive wildlife and decides
they no longer want to take part. See, e.g., Melissa Groo, How to Photograph
Wildlife Ethically, Nat’l Geographic (July ,
), https://perma.cc/
FGN-HH N. …
The exercise of specific personal jurisdiction over Groo in this matter comports with M. R. Civ. P. (b)( )(B) and due process. An alternative conclusion would greatly diminish the ability of states to protect the interests of
their residents in the digital era. Groo’s emphasis on the need for physical
contact with a forum for that forum’s courts to exercise specific personal
jurisdiction harkens back to an era before the Internet and even before interstate transit. …
¶
5
4
94
¶
95
The Dissent cites other jurisdictions’ cases for its conclusion that purposefully directed internet postings can never hale a defendant into another
state’s courts. Those cases do not stand for that proposition. In Shrader v.
Biddinger,
F. d
( th Cir.
), the Tenth Circuit stated that
“posting allegedly defamatory comments or information on an internet site
does not, without more, subject the poster to personal jurisdiction wherever
the posting could be read.” Shrader,
F. d at
(emphasis added). We
agree.
Nevertheless, this is not that case. Here, we do have the “more” called for in
Shrader: ( ) Groo directed electronic activity into the state by tagging Montana residents and those doing business in Montana; ( ) with the manifested intent of engaging in interactions within the state by encouraging those
tagged to not do business with Triple D; and ( ) that activity created, in a
person within Montana, a potential cause of action cognizable in Montana.
… Indeed, Shrader is notable for its distinction between two defendants—
one of whom would have been subject to personal jurisdiction had the defendant directed the email at someone in Oklahoma, as here. Compare
Shrader,
F. d at
- (concluding no specific personal jurisdiction
for defendant who merely posted information on website accessible everywhere), with Shrader,
F. d at
(concluding there would have
been specific personal jurisdiction for defendant who sent email if he had
knowingly directed the email at someone in Oklahoma). …
Similarly, the Dissent points to Axiom Foods, Inc. v. Acerchem Int’l, Inc.,
F. d
( th Cir.
), where, although an email list had
California
residents, the defendant did not expressly aim its intentional act into California. The case now before us, however, is more akin to a more recent
Ninth Circuit decision, Ayla, LLC v. Alya Skin Pty. Ltd.,
F. th
( th
Cir.
), where an Australian skincare company directed social media advertisements to America, and therefore subjected itself to personal jurisdiction in California for trademark infringement resulting from the advertisements. …
C
… We conclude the District Court is not proceeding under a mistake of law
and agree that it has personal jurisdiction to resolve this dispute.
¶
¶
¶
4
7
8
6
9
4
2
2
0
7
0
9
0
3
0
1
4
7
1
1
1
2
1
4
7
2
1
1
0
3
2
1
8
2
1
3
1
4
0
7
2
3
4
3
2
6
1
0
3
1
6
4
3
5
4
7
3
4
3
7
2
6
1
9
2
8
1
1
0
2
9
3
5
3
3
6
3
1
3
3
3
6
9
n
1
3
o
7
6
i
1
4
s
6
1
0
2
u
2
0
l
1
0
7
2
c
6
9
n
3
5
5
5
6
3
QUESTIONS
. Splitting Hairs? Is the court saying that posting about Montana residents on
Facebook doesn’t create personal jurisdiction, but tagging them does?
. Massive Distribution? What result if Groo had published the Facebook post
described in ¶
as an editorial on the website of the New York Times,
which covers national and international news and has roughly
million
unique visitors per month?
. Throwing Darts? Groo and the cases it discusses mostly deal with one common and troublesome fact pattern: widely visible online posts. Another
common and troublesome fact pattern is the defendant whose actions affect
a specific computer but who doesn’t know or doesn’t care where the computer is. Consider Republic of Kazakhstan v. Ketabaev, No. -CVLHK,
WL
(N.D. Cal. Dec. ,
), in which Ilyas Khrapunov, a Kazakh citizen living in Switzerland, allegedly hacked the Gmail
o
2
1
3
Chapter 2: Jurisdiction
Internet Law
accounts of Kazakh governmental officials. No personal jurisdiction in California, said the court; Kazakhstan was not harmed in California. “There is
no allegation that Khrapunov believed the servers to be located in California, nor is there an allegation that the servers were actually located in California.” And even if that were shown, the exercise of personal jurisdiction
would have been unreasonable, given the case’s lack of other connections to
California. Would the result be different if Google (which is incorporated
and headquartered in California) were the plaintiff? Would it depend on
where the specific server in question was?
. Where Is Information? Why might it be a hard problem to identify the location
of the effects (intended or actual) of conduct involving information? Does
the Internet exacerbate the difficulties? How much should the personal jurisdiction analysis depend on the cause of action? Consider Penguin Group
(USA) Inc. v. American Buddha,
N.Y. d
(
), in which the defendant posted online complete copies of books published by the plaintiff. The
defendant was incorporated in Oregon and based in Arizona; the servers
were in Oregon and Arizona; potential downloaders were everywhere in the
world. The New York-based plaintiff sued for copyright infringement in a
federal court in New York. The relevant New York long-arm statute applied
to an out-of-state defendant who “commits a tortious act without the state
causing injury to person or property within the state.” N.Y. CPLR
(a)( )
(ii). The court found jurisdiction, reasoning, that “an injury allegedly inflicted by digital piracy is felt throughout the United States, which necessarily
includes New York.” Is this consistent with Groo and Ketebaev?
7
9
9
1
3
2
0
3
9
1
1
1
2
1
1
1
2
4
0
2
2
5
9
5
4
9
8
2
9
1
3
3
8
7
6
1
5
6
4
4
2
NOTE ON SPECIFIC PERSONAL JURISDICTION TESTS
Groo-style “intentional targeting” tests are common in the United States, especially
after Walden. But tests based on the “effects” of the defendant’s conduct are more
common internationally. For example, Section
( )(j) of the Restatement
(Third) of Foreign Relations allows a state to exercise personal jurisdiction over
someone who “has carried on outside the state an activity having a substantial,
direct, and foreseeable effect within the state.” Some older United States cases,
particularly Calder v. Jones,
U.S.
(
), use effects-test language, but as
Groo shows, effects in the forum are rarely enough on their own. The key conceptual difference is that effects tests focus on the plaintiff/victim, while targeting
tests focus on the defendant/speaker.
Courts have sometimes used different tests when the defendant is a website (or
other online service) instead of a user. One formerly common type of test is an “interactivity” test, which focuses on the technical characteristics of a website. Active
websites that interact with users are more likely to be subject to personal jurisdiction than passive websites that merely make information available to users. On
this logic, an active website is like a storefront; a passive website like a billboard.
For example, Zippo Mfg. Co. v. Zippo Dot Com,
F. Supp.
(W.D. Pa.
),
described a “sliding scale” between “knowing and repeated transmission of computer files over the Internet” (active) and “simply posted information on an Internet Web site which is accessible to users in foreign jurisdictions” (passive). Id. at
. The distinction was technically incoherent even at the time, because the
“knowing and repeated transmission of computer files over the Internet” is simply
the definition of a website. It was also arbitrary, because the technical interactivity
of a site is not a good proxy for the intensity of its contacts with residents of a fo-
1
4
1
96
97
rum. Although it has been cited hundreds of times, the Zippo sliding scale has
been subjected to ferocious criticism, and has increasingly fallen out of favor with
courts.
More recently, courts have applied intentional-targeting tests to a website’s
content and technical design. In Doe v. WebGroup Czech Republic, A.S.,
F. th
( th Cir.
), for example, the defendants included two Czech companies
that operated pornography websites hosted on servers in the Netherlands. The
court held that it had personal jurisdiction over them because they contracted
with content-delivery networks (CDNs) to speed up their sites for users located in
the United States: “the use of such a U.S.-based operation to facilitate quick delivery of product to nearby consumers demonstrates the sort of differential targeting
that constitutes express aiming at the U.S. market.” Id. at
. By contrast, using
a global targeted-advertising network was not sufficient by itself. “[T]ailoring ads
to the particular geographic source of every particular user who visits a page is
effectively the same as passively offering the webpage to any visitor from anywhere
in the globe, and it is therefore the antithesis of differential aiming at a subset of
particular locations.” Id. at
.
QUESTIONS
. Targeting vs. Effects: How would Groo come out under an effects test?
. User vs. Site: Is the targeting in Groo (contents of messages) the same as the
targeting in Doe v. WebGroup (use of CDNs)?
SPANSKI ENTERPRISES, INC. V. TELEWIZJA POLSKA, S.A.
883 F.3d 904 (D.C. Cir. 2018)
4
9
8
0
0
2
1
1
0
2
1
4
2
0
2
1
1
0
2
9
8
8
Tatel, Circuit Judge.
When the owner of a foreign website, acting abroad, uploads video content in
which another party holds exclusive United States public performance rights under the Copyright Act and then directs the uploaded content to United States
viewers upon their request, does it commit an infringing "performance" under the
Act? …
I.
Appellant Telewizja Polska, S.A. (“TV Polska”), Poland's national public television
broadcaster, owns, operates, and creates content for several Polish-language television channels, including one now called TVP Polonia. TV Polska entered into a
licensing agreement with Canadian corporation Spanski Enterprises, Inc. … granting it [exclusive] North and South American broadcasting rights in TVP Polonia
content. …
In order to protect Spanski’s exclusive rights, TV Polska— which makes its programming publicly available through a video-on-demand feature on its website—
employs technology that prevents internet users in North and South America from
accessing TVP Polonia content though its website. Known as geoblocking, this
technology allows a website owner to digitally embed territorial access restrictions
into uploaded content. When an internet-enabled device attempts to access restricted content, the geoblocking system compares the device's unique internet
protocol (IP) address to a third-party database that reveals which IP addresses are
associated with which countries. If the device's IP address is associated with a
country subject to restricted access, the device cannot access the content. …
In late
, Spanski's attorneys discovered that certain TVP Polonia content
was not properly geoblocked, leaving it available to North and South American
1
1
2
1
Chapter 2: Jurisdiction
98
Internet Law
1
6
0
1
5
0
2
1
0
1
2
0
9
0
2
1
0
1
2
1
6
0
3
0
1
1
1
0
2
2
7
6
6
3
2
1
7
6
4
3
2
1
1
4
0
6
1
0
2
1
1
6
5
1
1
0
0
1
1
2
7
1
6
3
1
internet users through TV Polska's video-on-demand system. This content included fifty-one individual episodes that Spanski had registered with the United States
Copyright Office and in which it held valid and exclusive United States copyrights.
…
II. …
B.
This brings us to TV Polska's argument that even if it did infringe Spanski's copyright, holding it liable for that infringement would constitute an impermissible
extraterritorial application of the Act because it did nothing in the United States.
Whether an infringing performance that originates abroad but that ultimately
reaches viewers in the United States can be actionable under the Copyright Act is
a question of first impression in the federal appellate courts.
The Supreme Court recently described “a two-step framework for analyzing”
whether a statutory violation that, at least in part, takes place abroad gives rise to
liability. RJR Nabisco, Inc. v. European Community,
S. Ct.
,
(
).
A court first asks "whether the statute gives a clear, affirmative indication that it
applies extraterritorially." Id. Here, the parties agree that the Copyright Act has no
extraterritorial application, and we assume they are correct. We therefore move to
the second step, which requires us to determine whether this case, notwithstanding its extraterritorial elements, ‘involves a permissible domestic application” of the Copyright Act. Id. at
. “[W]e do this,” the Court has explained,
“by looking to the statute's ‘focus,’” id., described as “the objects of the statute's
solicitude,” or what it is "that the statute seeks to ‘regulate’” or protect, Morrison v.
National Australia Bank Ltd.,
U.S.
,
(
). “If the conduct relevant
to the statute's focus occurred in the United States, then the case involves a permissible domestic application even if other conduct occurred abroad; but if the
conduct relevant to the focus occurred in a foreign country, then the case involves
an impermissible extraterritorial application regardless of any other conduct that
occurred in U.S. territory.” RJR Nabisco,
S. Ct. at
.…
Guided by the Supreme Court's methodology, we identify the “conduct relevant
to the [Copyright Act's] focus,” RJR Nabisco,
S. Ct. at
, by asking precisely
what it is that the Act regulates. The answer is clear: the Act grants copyright
holders several ‘exclusive rights” — among them, the right "to perform [a] copyrighted work publicly,"
U.S.C. §
( ) — and effectuates those rights by prohibiting “infringement,” or the “violat[ion]" of those “exclusive rights,” id. §
.
The Copyright Act “focuses," then, on policing infringement or, put another way,
on protecting the exclusivity of the rights it guarantees. Here, although it was in
Poland that TV Polska uploaded and digitally formatted the fifty-one episodes, the
infringing performances—and consequent violation of Spanski’s copyrights—occurred on the computer screens in the United States on which the episodes’ “images” were “show[n].” Id. §
. Accordingly, because “the conduct relevant to the
statute's focus occurred in the United States,” this case “involves a permissible domestic application” of the Copyright Act, “even if other conduct occurred abroad.”
RJR Nabisco,
S. Ct. at
.…
Congress had good reason to allow domestic copyright holders to enforce their
rights against foreign broadcasters who direct infringing performances into the
United States. Given the ease of transnational internet transmissions, a statutory
scheme that affords copyright holders no protection from such broadcasters would
leave the door open to widespread infringement, rendering copyright in works
capable of online transmission largely nugatory.
99
In its amicus brief, the United States offers two examples that helpfully illustrate this point. First, it points out that under such a scheme, “large-scale criminal
copyright pirates could avoid United States copyright liability simply by locating
their servers outside the United States.” Second, “television stations in San Diego
and El Paso could eliminate the need to obtain U.S. copyright licenses simply by
moving their broadcast antennae to Tijuana and Ciudad Juarez.” We agree with
the United States that “Congress could not have intended the public-performance
right to be susceptible to such ready evasion.”
TV Polska offers little response to these troubling consequences of its position,
claiming only that foreign enforcement authorities can address such cases. But
nothing in the Copyright Act even hints that Congress intended to rely on the uncertain cooperation of foreign governments to ensure that copyright holders are
able to enjoy their exclusive statutory rights while in the United States. …
TV Polska argues that even if the government's concerns are well taken, they
lose their force in situations where, as here, the foreign infringers “are lawful copyright owners in their home countries,” or where, again as here, the domestic copyright holder is protected by contract and so need not invoke statutory law to protect its interests.TV Polska, however, offers no legal grounding for these proposed
distinctions. Nor do we see any logical connection between the scope of a broadcaster and copyright holder's respective rights and the question of whether the
direction of an infringing performance into the United States from abroad is domestic or extraterritorial.
Attempting to turn the table on the United States, TV Polska argues that treating its conduct as a domestic violation of the Copyright Act would leave any casual
internet user anywhere in the world open to liability for uploading copyrighted
content to a foreign website whenever anyone in the United States happens to
stumble upon it. Indeed, given that intent is not an element of copyright infringement, TV Polska argues, liability could attach where, even though a foreign website owner conscientiously geoblocks the copyrighted material it posts to its website, an American user manages to circumvent the territorial restrictions and views
the content domestically. Although we have no occasion to prejudge such situations, we note that foreign defendants in such cases may well have alternative defenses against liability, such as a lack of proximate causation between the foreign
conduct and the domestic performance or an American court's lack of personal
jurisdiction over the foreign infringer. See, e.g., Rano v. Sipa Press, Inc.,
F. d
,
( th Cir.
) (rejecting view of personal jurisdiction that would “render . . . foreign owners of art who sell their products to publications[] amenable to
personal jurisdiction [on copyright claims] in every state in which their art eventually is displayed”). For present purposes, we need hold only that a foreign broadcaster that, as here, directs infringing performances into the United States from
abroad commits a domestic violation of the Copyright Act. …
2
7
8
9
3
9
9
1
9
8
8
5
0
QUESTIONS
. Where is Infringement? Is Spanski Enterprises’s theory about where copyright
infringement takes place consistent with American Buddha’s?
8
5
1
Chapter 2: Jurisdiction
Internet Law
. Perfect Geoblocking? What if TV Polska’s geoblocking had been properly configured, but some American users had evaded it by using virtual private networks (VPNs)* to make it appear that they were in Poland?
. Personal Jurisdiction: Is the infringing conduct described in Spanski Enterprises sufficient for the court to have personal jurisdiction over TV Polska?
. Where is Hacking? Different types of laws raise different territoriality issues. In
Doe v. Federal Democratic Republic of Ethiopia,
F. d (D.C. Cir.
),
an American citizen living in Maryland alleged that the Ethiopian government installed spyware on his computer to monitor his human rights work.
Foreign governments are immune from suit in United States courts for this
type of claim unless the “entire tort” took place in the United States. It did
not, the court held, because “Ethiopia's placement of the FinSpy virus on Kidane's computer, although completed in the United States when Kidane
opened the infected e-mail attachment, began outside the United States.”
Does this interpretation of the “entire tort” rule make sense on the Internet?
AYYADURAI V. FLOOR64, INC.
270 F. Supp. 3d 343 (D. Mass. 2017)
Saylor, District Judge:
This is a tort action arising out of allegedly defamatory statements that the
plaintiff falsely claimed to be the inventor of e-mail. Plaintiff Shiva Ayyadurai is a
scientist and entrepreneur. In
, at the age of , he created an electronic-mail
system for use at the University of Medicine and Dentistry of New Jersey. On the
basis of that creation, he has since claimed to have invented e-mail, and has received some positive media attention on the basis of that claim.
Defendants Floor , Inc., Michael Masnick, and Leigh Beadon operate or write
for a website called “Techdirt.” Defendants posted a series of
articles disagreeing with Ayyadurai's claim, stating, among other things, that he is “a liar,” that his
claim is “fake,” and that he has made several misrepresentations in support of his
claim. …
[Ayyadurai sued for defamation. Ayyadurai was a Massachusetts residentFloor
was a California corporation, Masnick was a California resident, and
Beadon was a resident of Toronto, Canada.]
Defendants first contend that the complaint should be struck pursuant to the
California anti-SLAPP (“strategic litigation against public participation”) statute,
Cal. Civ. Proc. Code §
. . Plaintiff contends that under the applicable choiceof-law principles, Massachusetts law applies, and therefore the California statute is
irrelevant. …
The initial task of a choice-of-law analysis is to determine whether there is an
actual conflict between the substantive law of the interested jurisdictions. Here,
there is a clear conflict between the California and Massachusetts statutes. Under
the Massachusetts statute, parties may move to dismiss any claims against them
that are based on that “party's exercise of its right of petition under the Constitution of the United States or of the commonwealth.” Mass. Gen. Laws ch.
,§
H. See North Am. Expositions Co. v. Corcoran,
Mass.
,
,
N.E. d
(
) (defining “petitioning” to include “statements made to influence, inform, or at the very least, reach governmental bodies—either directly or
2
1
3
2
7
1
8
0
9
2
8
2
6
8
4
2
1
5
8
7
3
1
2
5
4
5
1
4
8
9
7
9
1
6
1
5
2
For more on how VPNs work, see Note on Online Identification in the Anonymity
section of the Privacy chapter.
4
4
6
9
0
4
0
6
2
1
9
*
3
4
3
2
5
8
100
101
0
8
1
1
3
8
6
6
6
1
0
2
1
7
9
1
9
9
9
8
1
0
1
5
9
1
8
3
3
1
8
6
1
5
2
6
0
4
5
1
0
5
1
6
1
5
2
2
0
4
indirectly”). The California statute, by contrast, is considerably broader, and allows
parties to move to strike whenever they are sued for an “act in furtherance of a
person's right of petition or free speech under the United States or California Constitution in connection with a public issue” or “an issue of public interest.” Cal. Civ.
Proc. Code §
. (e) (emphasis added).
Next, the Court must apply Massachusetts choice-of-law principles to determine which state's law should apply. Massachusetts state courts apply a functional
choice of law approach that responds to the interests of the parties, the States involved, and the interstate system as a whole. That approach is guided by the Restatement (Second) of Conflict of Laws (
), and considers factors such as those
set forth in § of the Restatement. [Those factors are “(a) the needs of the interstate and international systems, (b) the relevant policies of the forum, (c) the relevant policies of other interested states and the relative interests of those states in
the determination of the particular issue, (d) the protection of justified expectations, (e) the basic policies underlying the particular field of law, (f ) certainty, predictability and uniformity of result, and (g) ease in the determination and application of the law to be applied.”]
Section
of the Restatement applies to claims involving multistate defamation. It provides that “[t]he rights and liabilities that arise from defamatory matter
in any ... aggregate communication are determined by the local law of the state
which, with respect to the particular issue, has the most significant relationship to
the occurrence and the parties under the principles stated in § .” Restatement
(Second) Conflict of Laws §
( ). It further states that “[w]hen a natural person
claims that he has been defamed by an aggregate communication, the state of
most significant relationship will usually be the state where the person was domiciled at the time, if the matter complained of was published in that state.” Id. §
( ). Thus, there is effectively a presumption that the law of the state of the
plaintiff 's domicile will apply unless some other state “has a greater interest in the
determination of the particular issue.”
Applying §
here, there is a presumption that the law of Massachusetts will
apply. First, defendants published allegedly defamatory statements in a form of
aggregate communication, a website. Second, plaintiff was domiciled in Massachusetts at the time. Finally, the website, which is accessible by anyone anywhere
with an Internet connection, was published in Massachusetts.
The Court must next determine whether another state has a greater interest in
the particular issue presented … . In this context, the most significant of those factors appears to be the relevant policies of the states. Here, each state has a strong,
and conflicting, interest. As to California, it has clearly “expressed a strong interest
in enforcing its anti-SLAPP law to ‘encourage continued participation in matters
of public significance’ and to protect against ‘a disturbing increase in lawsuits
brought primarily to chill the valid exercise’ of constitutionally protected speech.”
Sarver v. Chartier,
F. d
,
( th Cir.
). (quoting Cal. Civ. Proc. Code
§
. (a)). That interest would presumably be disserved by applying Massachusetts law and permitting this case to proceed. Massachusetts, on the other
hand, has an interest in protecting its citizens from tortious conduct. By enacting
an anti-SLAPP statute that applies only to claims involving a person's exercise of
his or her right of petition, and not to claims involving a person's exercise of freespeech rights more generally, Massachusetts has attempted to balance the encouragement of protected speech with the desire to protect those who are harmed by
defamatory statements. See Cardno ChemRisk, LLC v. Foytlin,
N.E. d
5
1
Chapter 2: Jurisdiction
Internet Law
(
) (“[T]he anti-SLAPP statute ... protects those looking to 'advance[e] causes
in which they believe, as well as those seeking to protect their own private rights”
(citation omitted)). That interest would be disserved by applying California law
and striking the complaint. Under the circumstances presented here, there is no
reason to favor California's policy over that of Massachusetts.
None of the other factors under § are sufficient to overcome the presumption
favoring application of Massachusetts law. The parties each have justified expectations that their respective home-state laws would apply; plaintiff is a Massachusetts resident with no apparent ties to California; and the alleged tortious
conduct occurred in California. In addition, ensuring the “certainty, predictability
and uniformity of result” and “ease in the determination and application of the
applicable law” favors adhering to the presumption set forth in §
( ).
In summary, defendants have not overcome the presumption that Massachusetts law should apply. [The court proceeded to hold that even without the
benefit of the California anti-SLAPP statute the defendants’ various posts were
protected by the First Amendment and Section
.]
QUESTIONS
. Turning the Tables: Ayyadurai is typical in applying the law of a defamation
plaintiff ’s domicile in an online-posting case. Here, that happens to be the
forum, because Ayyadurai sued in his home state of Massachusetts. But
when a plaintiff sues in a different state, choice of law can cut the other way.
In Tobinick v. Novella,
F. Supp. d
(S.D. Fla.
), for example, a
California doctor sued a Connecticut doctor in Florida for two allegedly
defamatory blog posts about his prescribing practices. Florida has no antiSLAPP statute, but the court applied California’s, explaining, “California's
interest in limiting frivolous litigation filed by its residents outweighs any
interest Florida has in the dispute, where that dispute is between a California
corporation and a Connecticut resident.” Is that right? Or are Ayyadurai and
Tobinick exactly backwards: shouldn’t the residents of a state with a strong
anti-SLAPP statute be the ones most able to rely on it?
. Choice of Law Approaches: States use different choice-of-law approaches.
Some, which follow the First Restatement rather than the Second, use a
more formalistic test: the law that applies in a tort case is the law of the state
where the injury occurred. Others, which engage in “interest analysis,” more
explicitly consider each state’s policies and look closely at whether they conflict. Does the Second Restatement approach illustrated in Ayyadurai provide enough predictability for parties to know what law will apply to their
disputes?
SPEECH ACT
[SECURING THE PROTECTION OF OUR ENDURING AND
ESTABLISHED CONSTITUTIONAL HERITAGE ACT, 2010]
Title 28, United States Code
2
0
5
1
5
1
0
2
0
3
2
9
s
9
n
2
o
1
i
t
3
a
r
6
e
d
i
s
n
o
8
t
– Recognition of foreign defamation judgments
A
C
.–
( ) I G
. – Notwithstanding any other provision of Federal or
State law, a domestic court shall not recognize or enforce a foreign
judgment for defamation unless the domestic court determines that –
0
1
n
a
e
r
m
e
d
n
n
e
e
m
n
t
s
1
r
i
2
7
0
1
1
0
4
(a) F
l
§
2
1
2
102
103
(A) the defamation law applied in the foreign court’s adjudication
provided at least as much protection for freedom of speech and
press in that case as would be provided by the first amendment
to the Constitution of the United States and by the constitution
and law of the State in which the domestic court is located; or
(B) even if the defamation law applied in the foreign court’s adjudication did not provide as much protection for freedom of
speech and press as the first amendment to the Constitution of
the United States and the constitution and law of the State, the
party opposing recognition or enforcement of that foreign
judgment would have been found liable for defamation by a
domestic court applying the first amendment to the Constitution of the United States and the constitution and law of the
State in which the domestic court is located. …
(b) J
C
–
( ) I G
. – Notwithstanding any other provision of Federal or
State law, a domestic court shall not recognize or enforce a foreign
judgment for defamation unless the domestic court determines that
the exercise of personal jurisdiction by the foreign court comported
with the due process requirements that are imposed on domestic
courts by the Constitution of the United States. …
(c) J
A
P
I
C
S
–
( ) I
– Notwithstanding any other provision of Federal or
State law, a domestic court shall not recognize or enforce a foreign
judgment for defamation against the provider of an interactive computer service, as de ned in section
of the Communications Act of
( U.S.C.
) unless the domestic court determines that the
judgment would be consistent with section
if the information
that is the subject of such judgment had been provided in the United
States. …
§
– Declaratory judgments
(a) C
A
.–
( ) I G
. – Any United States person against whom a foreign
judgment is entered on the basis of the content of any writing, utterance, or other speech by that person that has been published, may
bring an action in district court, under section
(a), for a declaration that the foreign judgment is repugnant to the Constitution or
laws of the United States. For the purposes of this paragraph, a judgment is repugnant to the Constitution or laws of the United States if it
would not be enforceable under section
…
e
c
i
v
r
e
r
e
t
u
p
m
o
e
v
i
1
t
0
c
0
2
a
r
3
2
2
e
t
2
n
0
s
1
f
4
n
o
o
0
i
r
3
t
e
2
a
d
r
i
e
v
d
o
i
r
s
n
t
o
l
s
l
l
a
n
n
a
l
i
a
r
r
o
r
a
e
a
i
e
n
g
e
0
t
n
n
fi
n
o
e
3
c
e
i
e
2
t
t
g
n
f
c
i
n
e
n
o
n
d
s
m
e
i
g
s
1
1
1
r
d
u
u
u
7
a
4
4
0
4
1
3
9
QUESTIONS
. Is Defamation Special? Does it make sense to have one recognition of judgments rule for defamation and another for everything else?
. eSafety Commissioner Again: If the SPEECH Act extended beyond defamation, could X have relied on it to prevent United States enforcement of the
Australian judgment? In light of eSafety Commissioner, is the SPEECH Act
necessary?
4
1
2
1
Chapter 2: Jurisdiction
Internet Law
FLYING PIG PROBLEM
Clarence Royce, the mayor of Turman, California, has been fighting allegations of
corruption. At a press conference as part of his reelection campaign, he said that
he would resign “When the pigs on my uncle Clayton’s farm grow wings.” An unknown Twitter user created an account, @RoycesFlyingPig, which has been posting tweets in the voice of a corrupt flying pig. For example, the account tweeted,
“Just got back from picking up some payoffs in LA, and boy are my wings tired!”
and “With what Clarence spends on single-malt Scotch from the city budget, you’d
think he could have the sanitation department spread a little more garbage my
way.” Another critic, Thomas Carcetti, has been tweeting allegations that Royce
has put his supporters’ relatives on the Turman city payroll, and forcing companies
that want to do business with the city to buy hundreds of copies of his children's
book.
Royce is a resident of California, which has a strong anti-SLAPP statute. Twitter is incorporated in Delaware and has its corporate headquarters in San Francisco, California. Carcetti is a resident of Virginia, which does not have an antiSLAPP statute. Twitter knows the IP addresses from which @RoycesFlyingPig has
logged in, the email address that @RoycesFlyingPig has provided, and possibly
other identifying information, but will not reveal that information unless compelled to by a court.
Royce is considering suing @RoycesFlyingPig and Carcetti for defamation, and
seeking an order against Twitter requiring it to provide Royce with identifying information for @RoycesFlyingPig. You have been asked to analyze the jurisdictional issues. What are Royce’s prospects of success if he sues in California? Virginia?
Delaware? The United Kingdom?
2. Criminal Jurisdiction
7
2
9
1
3
2
6
3
9
5
3
7
2
0
0
0
In a criminal case, the geographical rules are slightly different. For one thing, it is
easier to find examples of extraterritorial criminal laws. Some acts are considered
especially heinous: under the international-law principle of “universal
jurisdiction,” any sovereign state may prosecute genocide, piracy, and war crimes.
Another is that jurisdictions can and do regulate their own nationals both at home
and abroad. The United States prohibits its citizens from sexually abusing children
anywhere in the world. And “The principle that a man who outside of a country
willfully puts in motion a force to take effect in it is answerable at the place where
the evil is done, is recognized in the criminal jurisprudence of all countries.” Ford
v. United States,
U.S.
,
(
). In Ford, the defendants were arrested
on the high seas, twenty-five miles west of San Francisco, while on a ship carrying
,
cases of liquor. The Supreme Court upheld their convictions for conspiracy
to smuggle liquor into the United States in violation of the Prohibition laws.
At the federal level, there are two signifiant Constitutional limits on criminal
trials. Article III restricts venue (where the trial takes place) in criminal trials to
“the state where the said crimes shall have been committed; but when not committed within any state, the trial shall be at such place or places as the Congress
may by law have directed.” Auernheimer explores the problem of determining
where an online crime “shall have been committed.” The Sixth Amendment also
restricts vicinage (where the jury pool is drawn from) to “the State and district
wherein the crime shall have been committed.” Vicinage is less often an issue once
proper venue is established. At the state level, the rule that states will not enforce
each others’ penal laws means that a crime can only be prosecuted in the courts of
2
1
104
105
the state whose legislature created that crime. Many states have their own venue
rules, much like the federal ones but with lower geographical stakes.
There is no criminal equivalent of personal jurisdiction or choice of law. States
do not enforce each others’ criminal laws. Instead, a state that wishes to prosecute
someone needs to get its hands on him. Sometimes, this is easy. Defendants can be
arrested while passing through, or tricked into coming to the jurisdiction and then
arrested. For example, in United States v. Gorshkov, No. CR C,
WL
(W.D. Wash. May ,
), the FBI set up a fake company that offered
to “hire” the defendant, a hacker based in Russia who had been extorting U.S.
companies. He came to Seattle for a meeting, used an FBI-supplied laptop to log
in to his home server, and was then immediately arrested.
Unwilling defendants can also be arrested by another jurisdiction and then extradited. Domestically, extradition from one state to another is governed by the
Extradition Clause:
A person charged in any state with treason, felony, or other crime,
who shall ee from justice, and be found in another state, shall on
demand of the executive authority of the state from which he ed, be
delivered up, to be removed to the state having jurisdiction of the
crime.
U.S. Const. art. IV, § , cl. . Internationally, extradition is generally a matter for
bilateral treaties between nations in which they set out which classes of defendants
they will extradite to each other. The usual rule is dual criminality: a defendant
may not be extradited unless his alleged conduct is a crime under the laws of both
nations. Procedurally, the defendant receives a hearing in the extraditing nation,
and a full trial in the state to which he is extradited. The highest-pro le extradition cases in Internet law have involved United States copyright laws. The typical
defendant allegedly acts in his home country in ways that facilitate infringement
by others inside the United States. For example, Kim Dotcom ran the le-storage
website MegaUpload from New Zealand. In a coordinated raid in January
,
the United States Department of Justice shut down MegaUpload’s servers in the
United States and New Zealand authorities arrested Mr. Dotcom in New Zealand.
As of mid, the extradition proceedings are still ongoing. Other notable targets of potential U.S. extradition attempts include Edward Snowden (of the NSA
leak) and Julian Assange (of WikiLeaks).
Defendants can even be kidnapped. In United States v. Alvarez-Machain,
U.S.
(
), the defendant was wanted for participating in the murder of a
DEA agent. The DEA let it be known that it would pay a “pay a reward and expenses in return for the delivery of respondent to the United States.” Armed men
burst into his medical office in Guadalajara, put a gun to his head, and forced him
to board a private plane with them to El Paso. The Supreme Court allowed his
prosecution to go forward. More than anything else in law, criminal jurisdiction
still turns on raw physical power over a person.
2
1
0
4
1
2
0
0
5
0
2
fi
fi
0
5
5
0
0
fl
1
0
0
2
3
2
2
2
8
2
1
0
9
9
fl
2
1
6
5
2
5
0
6
4
2
QUESTION
Does the availability of extradition extend countries’ legal reach? How does it affect the global nature of the Internet?
0
1
Chapter 2: Jurisdiction
106
Internet Law
UNITED STATES V. AUERNHEIMER
748 F.3d 525 (3rd Cir. 2014)
Chagares, Circuit Judge:
This case calls upon us to determine whether venue for Andrew Auernheimer’s
[*] prosecution for conspiracy to violate the Computer Fraud and Abuse Act
(“CFAA”),
U.S.C. §
, and identity fraud under
U.S.C. §
(a)( ) was
proper in the District of New Jersey. Venue in criminal cases is more than a technicality; it involves “matters that touch closely the fair administration of criminal
justice and public confidence in it.” United States v. Johnson,
U.S.
,
(
). This is especially true of computer crimes in the era of mass interconnectivity. Because we conclude that venue did not lie in New Jersey, we will reverse
the District Court’s venue determination and vacate Auernheimer’s conviction.
I.
A.
[AT&T’s website for iPad owners had a security flaw. In order to make logging in
easier, if a user accessed the website from her iPad, it would automatically detect
her iPad’s unique identifier (or “ICC-ID”) and take her to a login page with her
email address already filled in. Daniel Spitler discovered that if he had his computer pretend to be an iPad and transmit a random ICC-IDs to AT&T’s website, he
would frequently be able to see iPad owners’ email addresses. Spitler wrote a program he called an “account slurper” to automate the process of collecting email
addresses.]
Spitler shared this discovery with Auernheimer, whom he knew through Internet-based chat rooms but had never met in person. Auernheimer helped him to
refine his account slurper program, and the program ultimately collected
,
email addresses between June and June ,
.…
While Spitler’s program was still collecting email addresses, Auernheimer
emailed various members of the media in order to publicize the pair’s exploits.
Some of those media members emailed AT&T, which immediately fixed the
breach. One of the media members contacted by Auernheimer was Ryan Tate, a
reporter at Gawker, a news website. Tate expressed interest in publishing Auernheimer’s story. To lend credibility to it, Auernheimer shared the list of email addresses with him. Tate published a story on June ,
describing AT&T’s security flaw, entitled “Apple’s Worst Security Breach:
,
iPad Owners Exposed.”
The article mentioned some of the names of those whose email addresses were
obtained, but published only redacted images of a few email addresses and ICC–
IDs.
Evidence at trial showed that at all times relevant to this case, Spitler was in
San Francisco, California and Auernheimer was in Fayetteville, Arkansas. The
servers that they accessed were physically located in Dallas, Texas and Atlanta,
Georgia. Although no evidence was presented regarding the location of the Gawker reporter, it is undisputed that he was not in New Jersey.
B.
Despite the absence of any apparent connection to New Jersey, a grand jury sitting
in Newark returned a two-count superseding indictment charging Auernheimer
with conspiracy to violate the CFAA,
U.S.C. §
(a)( )(C) and (c)( )(B)(ii), in
6
0
7
0
2
0
4
7
3
1
7
1
2
8
2
2
0
1
3
2
3
0
2
8
0
1
1
0
0
0
2
4
1
0
1
3
9
0
0
1
1
0
2
8
8
1
5
0
3
0
1
8
1
4
4
9
1
* [Ed: Auernheimer, a/k/a “weev,” is an Internet troll who has acted as webmaster for
the neo-Nazi website The Daily Stormer and called for the mass murder of Jews.]
Chapter 2: Jurisdiction
107
8
1
6
2
5
2
6
7
2
3
6
2
3
4
9
1
9
3
7
0
0
0
7
2
2
6
9
8
7
9
7
9
9
2
1
9
0
6
1
1
0
8
9
3
9
0
9
9
1
1
7
5
2
3
1
2
8
2
6
0
2
5
3
7
1
1
0
2
8
0
1
2
1
5
7
3
8
4
1
4
6
2
5
2
5
1
3
8
1
0
2
2
9
7
2
1
violation of
U.S.C. §
(count one), and fraud in connection with personal
information in violation of
U.S.C. §
(a)( ) (count two, commonly referred
to as “identity fraud”). To enhance the potential punishment from a misdemeanor
to a felony, the Government alleged that Auernheimer’s CFAA violation occurred
in furtherance of a violation of New Jersey’s computer crime statute, N.J. Stat.
Ann. § C: – (a). See U.S.C. §
(c)( )(B)(ii).
Auernheimer moved to dismiss the superseding indictment shortly after it was
returned by the grand jury. In addition to asserting several challenges concerning
the CFAA violation, he argued that venue was not proper in the District of New
Jersey. The District Court acknowledged that neither he nor Spitler was ever in
New Jersey while allegedly committing the crime, and that the servers accessed
were not in New Jersey, but denied his motion nonetheless. It held that venue was
proper for the CFAA conspiracy charge because Auernheimer’s disclosure of the
email addresses of about ,
New Jersey residents affected them in New Jersey
and violated New Jersey law. It further held that because venue was proper for the
CFAA count, it was also proper for the identity fraud count because proving the
CFAA violation was a necessary predicate to proving the identity fraud violation.
Auernheimer’s trial lasted five days and resulted in a guilty verdict on both
counts. … After denying Auernheimer’s post-trial motions, the District Court sentenced him to forty-one months of imprisonment. Auernheimer timely appealed.
III.
Although this appeal raises a number of complex and novel issues that are of great
public importance in our increasingly interconnected age, we find it necessary to
reach only one that has been fundamental since our country’s founding: venue.
The proper place of colonial trials was so important to the founding generation
that it was listed as a grievance in the Declaration of Independence. See The Declaration of Independence para.
(U.S.
) (objecting to “transporting us beyond seas to be tried for pretended offences”). It was of such concern that the Constitution of the United States “twice safeguards the defendant’s venue right.” United States v. Cabrales,
U.S. , , (
). Article III requires that “the Trial of all
Crimes ... shall be held in the State where the said Crimes shall have been committed.” U.S. Const. art. III, § , cl. . The Sixth Amendment further provides that
“[i]n all criminal prosecutions, the accused shall enjoy the right to a speedy and
public trial, by an impartial jury of the State and district wherein the crime shall
have been committed.” Id. amend VI. This guarantee is codified in the Federal
Rules of Criminal Procedure, which require that “the [G]overnment must prosecute an offense in a district where the offense was committed.” Fed. R. Crim. P. .
Congress may prescribe specific venue requirements for particular crimes.
Where it has not, as is the case here, we must determine the crime’s locus delicti.
[See] Black’s Law Dictionary
( th ed.
) (defining locus delicti as the
“place where an offense was committed”). “[T]he locus delicti must be determined
from the nature of the crime alleged and the location of the act or acts constituting
it.” United States v. Anderson,
U.S.
,
(
); accord United States v.
Rodriguez–Moreno,
U.S.
,
(
). To perform this inquiry, we “must
[ ] initially identify the conduct constituting the offense ... and then [ ] discern
the location of the commission of the criminal acts.” Rodriguez–Moreno,
U.S.
at
. Venue should be narrowly construed. Johnson,
U.S. at
.
Continuing offenses, such as conspiracy, that are “begun in one district and
completed in another, or committed in more than one district, may be inquired of
and prosecuted in any district in which such offense was begun, continued, or
Internet Law
2
2
0
3
3
0
1
2
1
0
3
0
1
8
1
1
3
0
2
7
2
3
2
3
4
8
1
2
1
3
0
completed.”
U.S.C. §
(a). In the context of a conspiracy charge, venue can
be established wherever a co-conspirator has committed an act in furtherance of
the conspiracy. The Government must prove venue by a preponderance of the evidence. …
A.
Count one charged Auernheimer with conspiracy to violate CFAA §
(a)( )(C)
and (c)( )(B)(ii). In the indictment and at trial, the Government identified the
nature of the conduct constituting the offense as the agreement to commit a violation of the CFAA in furtherance of a violation of New Jersey’s computer crime
statute, N.J. Stat. Ann. § C: – (a). Venue would be proper in any district
where the CFAA violation occurred, or wherever any of the acts in furtherance of
the conspiracy took place.
The charged portion of the CFAA provides that “[w]hoever ... intentionally accesses a computer without authorization or exceeds authorized access, and thereby
obtains ... information from any protected computer ... shall be punished as provided in subsection (c) of this section.”
U.S.C. §
(a)( )(C). To be found
guilty, the Government must prove that the defendant ( ) intentionally ( ) accessed without authorization (or exceeded authorized access to a ( ) protected
computer and ( ) thereby obtained information. The statute’s plain language reveals two essential conduct elements: accessing without authorization and obtaining information.
New Jersey was not the site of either essential conduct element. The evidence
at trial demonstrated that the accessed AT&T servers were located in Dallas,
Texas, and Atlanta, Georgia. In addition, during the time that the conspiracy began, continued, and ended, Spitler was obtaining information in San Francisco,
California and Auernheimer was assisting him from Fayetteville, Arkansas. No
protected computer was accessed and no data was obtained in New Jersey.
This is not the end of our analysis, however, because the Government did not
just charge Auernheimer with conspiracy to commit an ordinary violation of the
CFAA, but also with conspiring to violate the CFAA in furtherance of a state crime.
…
The New Jersey statute allows for criminal liability “if the person purposely or
knowingly and without authorization, or in excess of authorization, accesses any ...
computer [or] computer system and knowingly or recklessly discloses, or causes to
be disclosed any data ... or personal identifying information.” N.J. Stat. Ann. §
C: – (a). Its essential conduct elements are accessing without authorization
(or in excess of authorization) and disclosing data or personal identifying information.
Here, none of the essential conduct elements of a violation of the New Jersey
statute occurred in New Jersey. As discussed, neither Auernheimer nor Spitler accessed a computer in New Jersey. The disclosure did not occur there either. The
sole disclosure of the data obtained was to the Gawker reporter. There was no allegation or evidence that the Gawker reporter was in New Jersey. Further, there was
no evidence that any email addresses of any New Jersey residents were ever disclosed publicly in the Gawker article. The alleged violation of the New Jersey
statute thus cannot confer venue for count one.
Just as none of the conduct constituting the CFAA violation or its enhancement
occurred in New Jersey, none of the overt acts that the Government alleged in the
superseding indictment occurred in New Jersey either. The indictment listed four
overt acts: writing the account slurper program, deploying the account slurper
2
2
108
109
program against AT&T’s servers, emailing victims to inform them of the breach,
and disclosing the emails addresses obtained to Gawker. The co-conspirators collaborated on the account slurper program from California and Arkansas and deployed it against servers located in Texas and Georgia. The Government offered no
evidence whatsoever that any of the victims that Auernheimer emailed were located in New Jersey, or that the Gawker reporter to whom the list of email addresses
was disclosed was in the Garden State.
Because neither Auernheimer nor his co-conspirator Spitler performed any
“essential conduct element” of the underlying CFAA violation or any overt act in
furtherance of the conspiracy in New Jersey, venue was improper on count one.
[The court concluded that venue was improper on count two for similar reasons.]
QUESTIONS
. Internal vs. External: Orin Kerr represented Auernheimer on appeal. Did he
convince the court to adopt an internal or an external perspective on
Spitler’s conduct? Was this the right result?
. Other Venues: Would venue have been proper in Texas? California?
. Other Tests: Compare Auernheimer with Groo and Spanski. Which provides
the most coherent answer to the question of “where” online activity takes
place? Which is the most predictable? Which provides the best notice to
potential defendants?
3. The Commerce Clause
An additional complication in the United States is the division of regulatory authority between state and federal jurisdictions. The states are geographically
bounded but have the “police power” to enact and enforce any laws they want, except where some provision of the Constitution (e.g. the First Amendment) stands
in the way. The federal government has nationwide and international authority,
and when it acts, the Supremacy Clause of the Constitution, art. VI, cl. (“[T]he
Laws of the United States … shall be the supreme Law of the Land … any Thing in
the Constitution or Laws of any State to the Contrary notwithstanding”), means
that it trumps any state laws. But it has limited powers: it can legislate only where
the Constitution affirmatively gives it the authority.
The most important source of federal power over the Internet is the Commerce
Clause, art. I, § , cl. : “The Congress shall have Power … To regulate Commerce
with foreign Nations, and among the several States, and with the Indian Tribes.”
Because the Internet by its very nature connects “foreign nations” and “the several
States,” this means that Congress’s power over the Internet is broad indeed:
UNITED STATES V. YÜCEL
97 F. Supp. 3d 413 (S.D.N.Y. 2015)
2
6
1
3
Castel, District Judge: …
Yücel is alleged to be one of the founders of an organization that distributed
malicious software (“malware”) under the brand name “Blackshades.” The malware included a remote access tool (“RAT”), which enabled users “to remotely control victims’ computers, including [by] captur[ing] the victims' keystrokes as they
type”—the “keylogger” function—“turn[ing] on their webcams, and search[ing]
through their personal files.”) Keyloggers are frequently used to steal login information for online financial accounts. The RAT also had a functionality that
scanned victims' hard drives for -digit numbers, which were expected to be cred-
8
3
2
1
Chapter 2: Jurisdiction
Internet Law
it card numbers. Blackshades also provided malware designed to launch distributed denial of service attacks. …
Yücel was indicted by a grand jury in this District on October
,
, and
charged with … distribution of malicious software and aiding and abetting the
same. Yücel is a citizen of Sweden and was extradited from the Republic of Moldova to the United States in May
.…
Count II of the S Indictment charges Yücel with violating
U.S.C. §
(a)
( )(A), a provision of the Computer Fraud and Abuse Act (“CFAA”), which prohibits “knowingly caus[ing] the transmission of a program, information, code, or
command, and as a result of such conduct, intentionally caus[ing] damage without authorization, to a protected computer.” …
The CFAA defines “protected computer,” in relevant part, as a computer ‘which
is used in or affecting interstate or foreign commerce or communication, including
a computer located outside the United States that is used in a manner that affects
interstate or foreign commerce or communication of the United States.”
U.S.C.
§
(e)( )(B). The government contends that this definition encompasses any
computer with an internet connection, and a number of courts have so held. See
Freedom Banc Mortg. Servs., Inc. v. O’Harra, No. : -cv,
WL
, at * (S.D.Ohio Sept. ,
) (holding that “[a] computer that is connected to the internet ... satisfies §
(e)( )’s interstate commerce requirement
even if the plaintiff used that connection to engage in only intrastate communications"); United States v. Fowler, No. : -cr- -T- AEP,
WL
, at
* (M.D.Fla. Oct. ,
) (holding that evidence that computers were connected
to the internet and were used to send emails was sufficient to show that they were
“protected”).
This understanding of “protected computer” derives from the text of the definition itself. As the Supreme Court has recognized, the phrase “affecting interstate
or foreign commerce” is a term of art used by Congress to signal that it is exercising its full power under the Commerce Clause. The Commerce Clause allows Congress to regulate instrumentalities of interstate commerce. The internet is an instrumentality of interstate commerce. Any computer that is connected to the internet is thus part of a system that is inexorably intertwined with interstate commerce and thus properly within the realm of Congress's Commerce Clause Power.
Much as Commerce Clause authority permits Congress to regulate the intrastate
activities of railroad cars, it now permits Congress to regulate computers connected to the internet, even in the unlikely event that those computers made only intrastate communications.
8
1
0
2
6
8
1
9
3
1
0
3
0
6
1
1
2
2
0
4
2
3
7
3
0
2
1
0
0
1
8
0
1
2
1
1
2
4
2
3
5
4
6
3
2
1
0
0
2
1
1
3
0
8
0
1
2
4
1
8
5
1
0
2
0
1
0
2
5
2
1
6
0
0
2
0
1
9
$
0
0
2
3
2
0
1
6
8
2
QUESTIONS
. Interstate Commerce? Harry Wormwood posts an ad on Craiglist selling a used
car for ,
. Agnes Trunchbull responds to the ad, but when she arrives
with the money in cash, Wormwood robs her at gunpoint. He is charged under the federal Hobbs Act, which prohibits robberies affecting interstate
commerce. Is this consistent with the Commerce Clause?
. Jurisdictional Hooks: Congress does not always use the full extent of its Commerce Clause power. The federal wire fraud statute, for example, prohibits
fraudulent schemes involving a “wire, radio, or television communication in
interstate or foreign commerce.” U.S.C. §
. Do you see how this is narrower than the jurisdictional language in the CFAA? How hard do you think
it is for a competent prosecutor to prove that a defendant who made a fraud-
5
3
1
2
110
Chapter 2: Jurisdiction
111
ulent website or sent fraudulent emails actually caused a communication to
cross state lines?
NOTE ON PREEMPTION AND THE DORMANT COMMERCE CLAUSE
Congress is free to specify the effects of its legislation on state laws. Sometimes, it
explicitly displaces, or preempts, all state law on a subject. Section
, which you
have seen in the SPEECH Act and will study in more detail in the Speech Chapter,
provides an immunity for online platforms that preempts any state attempts to
hold them liable for users’ speech. Other times, Congress leaves state law largely
untouched or incorporates state-granted rights into a federal scheme. And sometimes, it steers a middle path, preempting only those state laws that are inconsistent with the federal scheme.
What about when Congress is silent? The “dormant” or “negative” Commerce
Clause is the name of a set of judicially created doctrines that prevent states from
unduly interfering with interstate commerce, even in the absence of Congressional
action. Two concerns loom large here. One is protectionism: states will favor instate businesses at the expense of outsiders. The other is inconsistent regulation:
states pursuing their own policies will create a thicket of conflicting rules that no
one doing business across state lines can comply with simultaneously.
One prong of the dormant Commerce Clause is that states simply cannot regulate extraterritorially. “[A] state law that has the practical effect of regulating
commerce occurring wholly outside that State's borders is invalid … .” Healy v.
Beer Institute,
U.S.
,
(
). A second prong amounts to a nearly per
se ban on purely protectionist state legislation. “When a state statute directly regulates or discriminates against interstate commerce, or when its effect is to favor instate economic interests over out-of-state interests, we have generally struck down
the statute without further inquiry.” Brown-Forman Distillers Corp. v. New York
State Liquor Authority,
U.S.
,
(
). A third prong calls for a costbenefit balancing. “When, however, a statute has only indirect effects on interstate
commerce and regulates evenhandedly, we have examined whether the State’s interest is legitimate and whether the burden on interstate commerce clearly exceeds
the local benefits.” Id. Applying these rules can be tricky, because of the conceptual
problem: where are a state’s borders on the Internet?
IN RE FACEBOOK BIOMETRIC INFORMATION PRIVACY LITIGATION
No. 3:15-cv-03747-JD (N.D. Cal.)
185 F. Supp. 3d 1155 (2016)
2018 WL 1794295 (Apr. 16, 2018)
2018 WL 2197546 (May 14, 2018)
0
3
2
6
0
8
1
9
0
1
2
9
7
5
9
8
3
9
7
1
5
2
3
3
4
6
7
2
3
4
1
9
4
Donato, District Judge:
[The following “case” combines passages from three separate opinions, which
have been edited together for clarity.] This case arises out of Facebook's “Tag Suggestions” program, which was launched in
. A “tag” on Facebook is when a
user identifies by name other Facebook users and non-users who appear in the
photographs that have been uploaded to Facebook. “Tag Suggestions” is intended
to encourage more tagging on Facebook. The program functions by scanning uploaded photographs and then identifying faces appearing in those photographs. If
the program recognizes and identifies one of the faces appearing in a photograph,
Facebook will suggest that individual's name or automatically tag them. In effect,
the program puts names on the faces in photos and prompts users to tag those
individuals. … Plaintiffs allege that Facebook amassed users' biometric data secret-
Internet Law
ly and without consent [in violation of Illinois’s Biometric Information Privacy
Act,
Ill. Comp. Stat. / et seq.] …
II. D
C
C
Facebook says that subjecting it to BIPA would violate the dormant commerce
clause because it processes facial recognition on servers outside the state of Illinois. Plaintiffs do not meaningfully dispute that the pertinent servers are not located in Illinois.
The dormant commerce clause typically applies when a state tries to regulate or
control economic conduct wholly outside its borders with the goal of protecting
local businesses from out- of-state competition. See Healy v. Beer Inst., Inc.,
U.S.
(
). It is a “limitation upon the power of the States” intended to prohibit “discrimination against interstate commerce” and “state regulations that unduly burden interstate commerce.” Sam Francis Found. v. Christies, Inc.,
F. d
,
( th Cir.
).
Facebook’s concerns are not well taken. As an initial matter, the application of
BIPA to Illinois users does not have the impermissible “‘practical effect’ of regulating commerce occurring wholly outside” Illinois. Healy,
U.S. at
. … This
lawsuit is under an Illinois state statute on behalf of Illinois residents who used
Facebook in Illinois. Facebook’s facial recognition program cannot be understood
to have occurred wholly outside Illinois, and the same rather metaphysical arguments about where BIPA was violated fare no better when re-packaged under the
dormant commerce clause. Contrary to Facebook’s suggestion, the geographic location of its data servers is not a dispositive factor. Server location may be one factor in the territoriality inquiry, but it is not the exclusive one. … The functionality
and reach of modern online services like Facebook’s cannot be compartmentalized
into neat geographic boxes. Making the geographic coordinates of a server the
most important circumstance in fixing the location of an Internet company’s conduct would yield … questionable results … . Among other problematic outcomes,
it would effectively gut the ability of states without server sites to apply their consumer protection laws to residents for online activity that occurred substantially
within their borders. Correlatively, a single-minded focus on server location would
also potentially nationalize the consumer protection laws of states that host
servers, which in this case includes California. Both outcomes are fraught with
unintended and undesirable consequences.
Facebook’s cursory reference to the specter of inconsistent regulations is equally unavailing. Facebook says that the Commerce Clause “precludes Illinois from
overriding the decisions of California and other states” to not regulate biometric
information, but there is no risk of Illinois law overriding the laws of the other
states. This suit involves Facebook’s conduct with respect to Illinois users only, and
even so, evidence in the record shows that Facebook can activate or deactivate features for users in specific states with apparent ease when it wants to do so. Nothing indicates that liability under BIPA would force Facebook to change its practices with respect to residents of other states.
1
9
3
4
4
8
7
2
3
3
4
0
4
3
1
9
4
4
2
e
s
u
a
1
l
4
1
e
5
c
1
r
0
e
2
m
m
o
9
t
8
9
9
n
1
a
3
2
m
4
0
r
3
4
2
1
o
3
7
1
0
2
0
3
QUESTIONS
. Targeting Yet Again: How hard would it be for Facebook to make sure that it is
not accessible from Illinois? How hard would it be to exclude Illinois residents from Tag Suggestions? Compare State v. Heckel,
P. d
(Wash.
), which upheld a state anti-spam law that prohibited sending emails to
0
1
1
2
112
SOUTH DAKOTA V. WAYFAIR, INC.
585 U.S. 162 (2018)
8
9
2
4
0
5
9
9
9
1
0
8
1
0
0
1
6
2
1
1
9
4
1
1
0
1
3
7
2
9
0
9
4
3
m­
1
9
1
1
7
3
6
9
1
9
4
3
5
5
7
7
7
1
%
6
0
3
6
6
1
8
3
n­
2
3
7
2
3
9
9
6
0
Justice Kennedy delivered the opinion of the Court.
When a consumer purchases goods or services, the consumer’s State often imposes a sales tax. This case requires the Court to determine when an out-of-state
seller can be required to collect and remit that tax. …
I
Like most States, South Dakota has a sales tax. It taxes the retail sales of goods and
services in the State. Sellers are generally required to collect and remit this tax to
the Department of Revenue. If for some reason the sales tax is not remitted by the
seller, then i state consumers are separately responsible for paying a use tax at the
same rate. Many States employ this kind of complementary sales and use tax
regime.
Under this Court’s decisions in National Bellas Hess, Inc. v. Department of Revenue of Ill.,
U.S.
(
) and Quill Corp. v. North Dakota,
U.S.
(
), South Dakota may not require a business to collect its sales tax if the business lacks a physical presence in the State. Without that physical presence, South
Dakota instead must rely on its residents to pay the use tax owed on their purchases from out-of-state sellers. The i practicability of this collection from the multitude of individual purchasers is obvious. And consumer compliance rates are noto-
9
9
2
3
3
113
Washington residents with false subject lines or return addresses. Is that an
easier or a harder targeting problem?
. Two Roads Diverged: A few earlier dormant Commerce Clause cases struck
down state statutes prohibiting the use of a computer to distribute sexually
explicit content to a minor. See American Libraries Association v. Pataki,
F. Supp.
,
(S.D.N.Y.
) (“Thus, conduct that may be legal in
the state in which the user acts can subject the user to prosecution in New
York and thus subordinate the user's home state's policy – perhaps favoring
freedom of expression over a more protective stance – to New York's local
concerns.”); ACLU v. Johnson,
F. d
,
( th Cir.
) (“Moreover, the nature of the Internet forecloses the argument that … section
- - . (A) applies only to intrastate communications. … [T]here is no
guarantee that a message from one New Mexican to another New Mexican
will not travel through other states en route.”) Are you persuaded? Few modern cases follow Pataki and Johnson. Were they a detour or a missed opportunity?
. A New Problem? If businesses can pick what law applies to them by choosing
where to locate, where do you think they will set up shop? Consider Quik
Payday, Inc. v. Stork,
F. d
( th Cir.
), in which an online
lender located in Utah challenged a Kansas statute that capped payday-loan
interest rates at
. The lender argued that the loans were “made” in Utah,
but the court disagreed. Where is a loan? In a pre-Internet age, how hard or
easy would it have been for Quik Payday to make loans to Kansas residents
from its offices in Utah?
. International Conflicts: The dormant Commerce Clause limits states’ authority
over the Internet. Why is there no similar limit on countries’ authority over
the Internet?
1
4
Chapter 2: Jurisdiction
114
Internet Law
s­
i­
0
0
0
1
0
0
1
$
7
5
7
8
9
2
1
4
7
2
8
0
0
d­
5
0
3
1
2
4
3
3
7
4
$
3
3
$
p­
1
6
8
u­
$
6
0
1
1
4
0
2
2
riously low. It is estimated that Bellas Hess and Quill cause the States to lose between
and
billion every year. …
In
, South Dakota confronted the serious inequity Quill imposes by enacting S.
—“An Act to provide for the collection of sales taxes from certain remote
sellers, to establish certain Legislative findings, and to declare an emergency.” …
To that end, the Act requires out-of-state sellers to collect and remit sales tax
“as if the seller had a physical presence in the state.” § . The Act applies only to
sellers that, on an annual basis, deliver more than
,
of goods or services
into the State or engage in
or more separate transactions for the delivery of
goods or services into the State. [It was widely understood that South Dakota
hoped to provoke Supreme Court review and convince the Court to overrule
Quill.]
Respondents … are merchants with no employees or real estate in South Dakota. Wayfair, Inc., is a leading online retailer of home goods and furniture and had
net revenues of over
. billion last year. [Similarly for Overstock.com and
Newegg.] Each of these three companies ships its goods directly to purchasers
throughout the United States, including South Dakota. Each easily meets the minimum sales or transactions requirement of the Act, but none collects South Dakota
sales tax. …
II …
The Court explained the now-accepted framework for state taxation in Complete
Auto Transit, Inc. v. Brady,
U.S.
(
). The Court held that a State “may
tax excl sively interstate commerce so long as the tax does not create any effect
forbidden by the Commerce Clause.” Id., at
. … The Court will su tain a tax so
long as it ( ) applies to an activity with a substantial nexus with the taxing State,
( ) is fairly a portioned, ( ) does not discriminate against interstate commerce,
and ( ) is fairly related to the services the State provides. …
III …
Each year, the physical presence rule becomes further removed from economic
reality and results in significant revenue losses to the States. These critiques underscore that the physical presence rule, both as first formulated and as applied
today, is an incorrect interpretation of the Commerce Clause. …
A…
Quill puts both local businesses and many interstate businesses with physical
presence at a competitive disa vantage relative to remote sellers. Remote sellers
can avoid the regulatory burdens of tax collection and can offer de facto lower
prices caused by the widespread failure of consumers to pay the tax on their own.
… In effect, Quill has come to serve as a judicially created tax shelter for businesses that decide to limit their physical presence and still sell their goods and services
to a State’s consumers—something that has become easier and more prevalent as
technology has advanced. …
B…
Modern e-commerce does not align analytically with a test that relies on the sort
of physical presence defined in Quill. In a footnote, Quill rejected the argument
that “title to ‘a few floppy diskettes’ present in a State” was sufficient to constitute
a “substantial nexus,” id., at
, n. . But it is not clear why a single employee or a
single warehouse should create a substantial nexus while “phys cal” aspects of pervasive modern technology should not. For example, a company with a website ac-
Chapter 2: Jurisdiction
115
0
0
2
2
9
9
1
n­
e­
r­
v­
b­
0
0
0
0
0
s­
1
$
cessible in South Dakota may be said to have a physical presence in the State via
the customers’ computers. A website may leave cookies saved to the customers’
hard drives, or cu tomers may download the company’s app onto their phones. Or
a company may lease data storage that is pe manently, or even occasionally, located in South Dakota. What may have seemed like a clear, bright-line test when
Quill was written now threatens to compound the arbitrary consequences that
should have been apparent from the outset.
The “dramatic technological and social changes” of our increasingly interconnected economy mean that buyers are closer to most major retailers than ever before—regardless of how close or far the nearest storefront. B tween targeted advertising and instant access to most consumers via any internet-enabled device, a
business may be present in a State in a meaningful way without that presence being physical in the traditional sense of the term. A virtual showroom can show far
more inventory, in far more detail, and with greater opportunities for consumer
and seller interaction than might be possible for local stores. Yet the continuous
and pervasive virtual presence of retailers today is, under Quill, simply irrelevant.
This Court should not maintain a rule that ignores these substantial virtual connections to the State. …
C…
In essence, respondents ask this Court to retain a rule that allows their customers
to escape payment of sales taxes—taxes that are essential to create and secure the
active market they supply with goods and services. An example may suffice. Wayfair offers to sell a vast selection of furnishings. Its advertising seeks to create an
image of beautiful, peaceful homes, but it also says that “[o]ne of the best things
about buying through Wayfair is that we do not have to charge sales tax.”
IV …
Though Quill was wrong on its own terms when it was decided in
, since then
the Internet revolution has made its earlier error all the more egregious and harmful. … The Court’s decisions in Quill and National Bellas Hess should be, and now
are, overruled.
V
In the absence of Quill and Bellas Hess, the first prong of the Complete Auto test
simply asks whether the tax applies to an activity with a substantial nexus with the
taxing State. …
Here, the nexus is clearly sufficient based on both the economic and virtual
contacts respondents have with the State. The Act applies only to sellers that deliver more than
,
of goods or services into South Dakota or engage in
or more separate transactions for the deli ery of goods and services into the State
on an annual basis. This quantity of business could not have occurred unless the
seller availed itself of the su stantial privilege of carrying on business in South
Dakota. And respondents are large, national companies that u doubtedly maintain an extensive virtual presence. …
The question remains whether some other principle in the Court’s Commerce
Clause doctrine might invalidate the Act. Because the Quill physical presence rule
was an obvious barrier to the Act’s validity, these issues have not yet been litigated
or briefed, and so the Court need not resolve them here. That said, South Dakota’s
tax system includes several features that appear designed to prevent discrimination against or undue burdens upon interstate commerce. First, the Act applies a
safe harbor to those who transact only limited business in South Dakota. Second,
116
Internet Law
the Act ensures that no obligation to remit the sales tax may be applied retroactively. Third, South Dakota is one of more than
States that have adopted the
Streamlined Sales and Use Tax Agre ment. This system standardizes taxes to reduce admini trative and compliance costs: It requires a single, state level tax administration, uniform definitions of products and services, simplified tax rate
structures, and other uniform rules. It also provides sellers access to sales tax administration software paid for by the State. Sellers who choose to use such software are immune from audit liabi ity. Any remaining claims regarding the application of the Commerce Clause in the absence of Quill and Bellas Hess may be addressed in the first i stance on remand. …
0
6
8
9
7
8
0
0
0
0
1
0
2
e­
l­
0
0
1
n­
5
2
6
s­
Chief Justice Roberts, dissenting: …
I agree that Bellas Hess was wrongly decided, for many of the reasons given by
the Court. The Court argues in favor of overturning that decision because the “Internet’s prevalence and power have changed the dynamics of the national
economy.” But that is the very reason I oppose discarding the physical-presence
rule. E-commerce has grown into a significant and vibrant part of our national
economy against the backdrop of established rules, including the physical-presence rule. Any alteration to those rules with the potential to disrupt the development of such a critical segment of the economy should be undertaken by Congress
…
States and local governments are already able to collect approximately
percent of the tax revenue that would be available if there were no physical-presence
rule. Among the top
Internet retailers that rate is between
and
percent.
Some companies, including the online behemoth Amazon, now voluntarily collect
and remit sales tax in every State that assesses one—even those in which they have
no physical presence. To the extent the physical-presence rule is harming States,
the harm is apparently receding with time. …
The Court, for example, breezily disregards the costs that its decision will impose on retailers. Correctly calculating and remitting sales taxes on all e-commerce
sales will likely prove baffling for many retailers. Over ,
jurisdictions levy
sales taxes, each with different tax rates, different rules governing tax-exempt
goods and services, different product category definitions, and different standards
for determining whether an out-of-state seller has a substantial presence in the
jurisdiction. A few examples: New Jersey knitters pay sales tax on yarn purchased
for art projects, but not on yarn earmarked for sweaters. Texas taxes sales of plain
deodorant at . percent but imposes no tax on deodorant with antiperspirant.
Illinois categorizes Twix and Snickers bars—chocolate- and-caramel confections
usually displayed side-by-side in the candy aisle—as food and candy, respectively
(Twix have flour; Snickers don’t), and taxes them differently.
The burden will fall disproportionately on small businesses. One vitalizing effect of the Internet has been connecting small, even “micro” businesses to potential buyers across the Nation. People starting a business selling their embroidered
pillowcases or carved decoys can offer their wares throughout the country—but
probably not if they have to figure out the tax due on every sale. And the software
said to facilitate compliance is still in its infancy, and its capabilities and expense
are subject to debate. The Court’s decision today will surely have the effect of
dampening opportunities for commerce in a broad range of new markets. …
6
0
1
0
0
7
4
$
7
7
2
4
1
$
1
1
1
1
1
0
2
3
8
5
3
.
1
.
0
.
2
.
6
.
0
117
QUESTIONS
Imposing vs. Collecting: Be sure you understand the difference between imposing a tax on sales and requiring sellers to collect and remit the tax. As an
illustration, consider Overstock.com v. New York State Dept. of Taxation and
Finance,
N.Y. d
(
). Amazon paid the owners of other websites,
called Associates, a commission on any sales it made after customers clicked
on links to Amazon from those other websites. This, the court held, was a
“physical presence” under Quill, so Amazon was required to collect sales tax
on all of its sales to New York residents, not just sales made through Associate links. Do you see how this followed from the all-or-nothing logic of
the physical presence test? Was it fair or unfair? To whom? Does Wayfair
hurt or help?
Physical vs. Digital Goods: One argument for taxing Wayfair is that it ships
furniture into South Dakota. But what if it were only selling software?
Compliance: What will Wayfair (annual revenue: . billion) do now that it
could be subject to sales tax wherever it has sales? What about May Fair,
which sells hand-carved jewelry boxes on Etsy (annual revenue: ,
)?
Platforms: Wayfair is a retailer: it sells good directly to consumers. What
about platforms like StubHub, eBay, and Poshmark, which connect buyers
and sellers? Should they be required to collect and remit sales tax on behalf
of their users? To supply states with lists of transactions involving local buyers and sellers? Should it matter whether the platform is free to users or
charges a commission? Whether it also handles the payment? Whether it
handles the goods and shipping?
State Law: The dormant Commerce Clause is a federal-level preemption of
state law. But even if it does not stand in the way, states may decline to tax
online transactions. (Note the self-imposed limits in South Dakota’s S.
.)
In particular, state law may preempt local attempts to tax online transactions. City of Chicago v. StubHub, Inc.,
IL
, for example, involved
Illinois’s Ticket Sale and Resale Act, which imposed a tax on “resellers” who
sold event tickets for more than face value. The Illinois Supreme Court rejected Chicago’s attempt to require StubHub to collect and remit the tax on
behalf of its users. Do the administrability concerns mentioned in Justice
Roberts’s Wayfair dissent loom even larger at the state level?
Default Rules: The dormant Commerce Clause is a default rule; Congress is
free to alter it. Before Wayfair, Congress could have allowed states to collect
tax from out-of-state sellers with no physical presence. It considered several
bills but enacted none of them. After Wayfair, what should Congress do?
.
2
1
3
2
5
4
6
Chapter 2: Jurisdiction
118
Internet Law
This chapter considers how the Internet affects the balances struck by free speech
law. By changing the facts of how people communicate, software can unsettle existing legal doctrines. In particular, some have argued that new computer technologies undermine law by making it harder to enforce laws restricting speech,
while others celebrate the open and uninhibited quality of online debates.
A. First Amendment Basics
This section covers some basics of the United States system of freedom of expression. Packingham shows the First Amendment difficulties involved in translating
restrictions on offline conduct to online activity; the Note on the Press considers
whether the Press Clause adds anything to the Speech Clause online.
UNITED STATES CONSTITUTION, AMENDMENT I
Congress shall make no law respecting an establishment of religion, or prohibiting
the free exercise thereof; or abridging the freedom of speech, or of the press; or the
right of the people peaceably to assemble, and to petition the Government for a
redress of grievances.
h
c
e
e
p
S
5
1
7
1
0
2
r
0
2
5
e
5
8
1
1
2
t
p
6
7
2
5
a
8
5
NOTE ON FIRST AMENDMENT TIERS OF SCRUTINY
Different types of restrictions on speech are judged by different standards. The
most stringent and exacting judicial test is used for prior restraints, when a
speaker must obtain permission from a government official before being allowed
to speak at all. The most traditional form of prior restraint is a licensing system:
e.g., “no one may publish a newspaper unless each issue has first been approved by
the town censor.” Such legislative prior restraints are presumptively unconstitutional. A more common form of prior restraint is an injunction that prohibits a
party from speaking. Such injunctions are disfavored, and courts typically grant
them only after finding that the speech is unlawful and only when the injunction
narrowly and precisely defines what speech is prohibited.
Next are are viewpoint-based restrictions, i.e., when “the government has singled out a subset of messages for disfavor based on the views expressed.” Matal v.
Tam,
U. S.
(
) (Kennedy, J, concurring in part and concurring in the
judgment). Such restrictions are also presumptively unconstitutional.
A restriction that “applies to particular speech because of the topic discussed or
the idea or message expressed” is said to be be content-based. Reed v. Town of
Gilbert,
U.S.
,(
).A content-based restriction on speech must satisfy a
three-pronged “strict scrutiny” test:
. There must be a “compelling interest” in restricting access to the speech to
be restricted. In practice, this usually means the speech must be actively
harmful in some way and without any offsetting benefits.
. The restriction must be “narrowly tailored” to the speech it prohibits.
. There must be no “less restrictive alternatives” for preventing that speech.
h
C
3
2
1
3:
Internet Law
In contrast, content-neutral restrictions on speech, such as “reasonable time,
place, and manner” regulations, are allowed if they are “narrowly tailored to serve
a significant governmental interest, and … leave open ample alternative channels
for communication of the information.” Ward v. Rock Against Racism,
U.S.
,
(
). (Read the test closely; do you see why it is less strict than strict
scrutiny?) Prohibiting “loud” speeches in the park is content-neutral; prohibiting
“political” speeches in the park is content-based; prohibiting “liberal” speeches in
the park is viewpoint-based.
There is also a special test for commercial speech (such as advertising) which
proposes a commercial transaction Commercial speech is protected if it concerns
lawful activity and is not misleading. If so, then it may only be restricted if ( )
there is a substantial government interest, ( ) the regulation directly advances the
governmental interest, and ( ) the regulation is not more extensive than necessary.
(Read this test closely, too; do you see how it too is less strict than strict scrutiny?)
Yet another form of “intermediate scrutiny” is the O’Brien test for incidental
restrictions on speech. When a law regulates the non-speech elements of a course
of conduct that also has speech elements, it will be upheld if “[( )]it is within the
constitutional power of the Government; [( )] if it furthers an important or substantial governmental interest; [( )] if the governmental interest is unrelated to
the suppression of free expression; and [( )] if the incidental restriction on alleged
First Amendment freedoms is no greater than is essential to the furtherance of
that interest.” United States v. O’Brien,
U.S.
,
(
) (upholding a law
against destroying draft cards, as applied to four defendants who burned theirs in
protest against the Vietnam War).
All of these tests, despite their differences, are substantially more rigorous than
the rational basis review applied to government regulations where no individual
right protected by the Constitution is implicated. There, a law is valid if it is rationally related to a legitimate governmental interest.
PACKINGHAM V. NORTH CAROLINA
582 U.S. 98, (2017)
1
1
9
4
5
1
2
0
8
2
6
9
4
1
1
7
7
3
5
1
7
0
6
2
3
2
2
1
4
9
3
5
2
0
2
3
4
1
3
9
8
9
1
1
8
9
0
7
0
2
1
Justice Kennedy delivered the opinion of the Court.
In
, North Carolina enacted a statute making it a felony for a registered
sex offender to gain access to a number of websites, including commonplace social
media websites like Facebook and Twitter. The question presented is whether that
law is permissible under the First Amendment's Free Speech Clause, applicable to
the States under the Due Process Clause of the Fourteenth Amendment.
I
A
North Carolina law makes it a felony for a registered sex offender “to access a
commercial social networking Web site where the sex offender knows that the site
permits minor children to become members or to create or maintain personal Web
pages.” N.C. Gen. Stat. Ann. §§ –
. (a), (e) (
). A “commercial social networking Web site” is defined as a website that meets four criteria. First, it “[i]s
operated by a person who derives revenue from membership fees, advertising, or
other sources related to the operation of the Web site.” § –
. (b). Second, it
“facilitates the social introduction between two or more persons for the purposes
of friendship, meeting other persons, or information exchanges.” Third, it “allows
users to create Web pages or personal profiles that contain information such as the
name or nickname of the user, photographs placed on the personal Web page by
8
7
120
121
0
3
4
1
0
0
0
0
2
0
0
5
0
2
5
2
1
0
2
2
1
0
2
2
4
5
1
4
2
1
0
5
2
2
4
0
1
2
4
1
3
1
1
5
2
0
2
0
2
0
1
0
5
0
4
2
2
1
2
the user, other personal information about the user, and links to other personal
Web pages on the commercial social networking Web site of friends or associates
of the user that may be accessed by other users or visitors to the Web site.” And
fourth, it “provides users or visitors ... mechanisms to communicate with other
users, such as a message board, chat room, electronic mail, or instant messenger.”
The statute includes two express exemptions. The statutory bar does not extend
to websites that “provide only one of the following discrete services: photo-sharing, electronic mail, instant messenger, or chat room or message board platform.”
§ –
. (c)( ). The law also does not encompass websites that have as their
“primary purpose the facilitation of commercial transactions involving goods or
services between [their] members or visitors.” § –
. (c)( ).
According to sources cited to the Court, § –
. applies to about
,
people in North Carolina and the State has prosecuted over ,
people for violating it.
B
In
, petitioner Lester Gerard Packingham—then a –year–old college student—had sex with a –year–old girl. He pleaded guilty to taking indecent liberties with a child. Because this crime qualifies as “an offense against a minor,” petitioner was required to register as a sex offender—a status that can endure for
years or more. As a registered sex offender, petitioner was barred under § –
. from gaining access to commercial social networking sites.
In
, a state court dismissed a traffic ticket against petitioner. In response,
he logged on to Facebook.com and posted the following statement on his personal
profile:
“Man God is Good! How about I got so much favor they dismissed the
ticket before court even started? No fine, no court cost, no nothing
spent...... Praise be to GOD, WOW! Thanks JESUS!”
At the time, a member of the Durham Police Department was investigating registered sex offenders who were thought to be violating § –
. . The officer noticed that a “‘J.R. Gerrard’ ” had posted the statement quoted above. By checking
court records, the officer discovered that a traffic citation for petitioner had been
dismissed around the time of the post. Evidence obtained by search warrant confirmed the officer's suspicions that petitioner was J.R. Gerrard.
Petitioner was indicted by a grand jury for violating § –
. . The trial court
denied his motion to dismiss the indictment on the grounds that the charge
against him violated the First Amendment. Petitioner was ultimately convicted
and given a suspended prison sentence. At no point during trial or sentencing did
the State allege that petitioner contacted a minor—or committed any other illicit
act—on the Internet. …
II
A fundamental principle of the First Amendment is that all persons have access to
places where they can speak and listen, and then, after reflection, speak and listen
once more. The Court has sought to protect the right to speak in this spatial context. A basic rule, for example, is that a street or a park is a quintessential forum
for the exercise of First Amendment rights. Even in the modern era, these places
are still essential venues for public gatherings to celebrate some views, to protest
others, or simply to learn and inquire.
While in the past there may have been difficulty in identifying the most important places (in a spatial sense) for the exchange of views, today the answer is clear.
0
2
Chapter 3: Speech
Internet Law
7
9
9
1
8
6
8
4
4
8
1
2
9
5
7
1
5
2
0
2
4
1
5
2
0
2
It is cyberspace—the “vast democratic forums of the Internet” in general, Reno v.
American Civil Liberties Union,
U.S.
,
(
), and social media in
particular. Seven in ten American adults use at least one Internet social networking service. One of the most popular of these sites is Facebook, the site used by
petitioner leading to his conviction in this case. According to sources cited to the
Court in this case, Facebook has . billion active users. This is about three times
the population of North America. …
This case is one of the first this Court has taken to address the relationship between the First Amendment and the modern Internet. As a result, the Court must
exercise extreme caution before suggesting that the First Amendment provides
scant protection for access to vast networks in that medium.
III
This background informs the analysis of the North Carolina statute at issue. Even
making the assumption that the statute is content neutral and thus subject to intermediate scrutiny, the provision cannot stand. In order to survive intermediate
scrutiny, a law must be narrowly tailored to serve a significant governmental interest. In other words, the law must not burden substantially more speech than is
necessary to further the government's legitimate interests. …
There is also no doubt that, as this Court has recognized, the sexual abuse of a
child is a most serious crime and an act repugnant to the moral instincts of a decent people. And it is clear that a legislature may pass valid laws to protect children and other victims of sexual assault from abuse. The government, of course,
need not simply stand by and allow these evils to occur. But the assertion of a valid
governmental interest cannot, in every context, be insulated from all constitutional protections.
It is necessary to make two assumptions to resolve this case. First, given the
broad wording of the North Carolina statute at issue, it might well bar access not
only to commonplace social media websites but also to websites as varied as Amazon.com, Washingtonpost.com, and Webmd.com. The Court need not decide the
precise scope of the statute. It is enough to assume that the law applies (as the
State concedes it does) to social networking sites as commonly understood—that
is, websites like Facebook, LinkedIn, and Twitter.
[Justice Alito’s concurring opinion included the following explanation of why
he believed the law reached Amazon:
Take, for example, the popular retail website Amazon.com, which allows minors to use its services and meets all four requirements of §
–
. ’s definition of a commercial social networking website.
First, as a seller of products, Amazon unquestionably derives revenue
from the operation of its website. Second, the Amazon site facilitates
the social introduction of people for the purpose of information exchanges. When someone purchases a product on Amazon, the purchaser can review the product and upload photographs, and other
buyers can then respond to the review. This information exchange
about products that Amazon sells undoubtedly fits within the definition in § –
. . It is the equivalent of passengers on a bus comparing notes about products they have purchased. Third, Amazon allows
a user to create a personal profile, which is then associated with the
product reviews that the user uploads. Such a profile can contain an
assortment of information, including the user's name, e-mail address,
4
1
122
Chapter 3: Speech
123
0
7
8
1
2
5
7
8
9
1
9
5
6
7
5
5
2
9
1
7
9
1
5
2
1
8
9
1
4
0
0
1
4
0
5
and picture. And fourth, given its back-and-forth comment function,
Amazon satisfies the final statutory requirement.]
Second, this opinion should not be interpreted as barring a State from enacting
more specific laws than the one at issue. Specific criminal acts are not protected
speech even if speech is the means for their commission. Though the issue is not
before the Court, it can be assumed that the First Amendment permits a State to
enact specific, narrowly tailored laws that prohibit a sex offender from engaging in
conduct that often presages a sexual crime, like contacting a minor or using a website to gather information about a minor. Specific laws of that type must be the
State's first resort to ward off the serious harm that sexual crimes inflict. …
Even with these assumptions about the scope of the law and the State's interest,
the statute here enacts a prohibition unprecedented in the scope of First Amendment speech it burdens. Social media allows users to gain access to information
and communicate with one another about it on any subject that might come to
mind. By prohibiting sex offenders from using those websites, North Carolina with
one broad stroke bars access to what for many are the principal sources for knowing current events, checking ads for employment, speaking and listening in the
modern public square, and otherwise exploring the vast realms of human thought
and knowledge. These websites can provide perhaps the most powerful mechanisms available to a private citizen to make his or her voice heard. They allow a
person with an Internet connection to “become a town crier with a voice that resonates farther than it could from any soapbox.” Reno,
U.S. at
.
In sum, to foreclose access to social media altogether is to prevent the user from
engaging in the legitimate exercise of First Amendment rights. It is unsettling to
suggest that only a limited set of websites can be used even by persons who have
completed their sentences. Even convicted criminals—and in some instances especially convicted criminals—might receive legitimate benefits from these means for
access to the world of ideas, in particular if they seek to reform and to pursue lawful and rewarding lives.
IV
The primary response from the State is that the law must be this broad to serve its
preventative purpose of keeping convicted sex offenders away from vulnerable victims. The State has not, however, met its burden to show that this sweeping law is
necessary or legitimate to serve that purpose.
It is instructive that no case or holding of this Court has approved of a statute
as broad in its reach. The closest analogy that the State has cited is Burson v.
Freeman,
U.S.
(
). There, the Court upheld a prohibition on campaigning within
feet of a polling place. That case gives little or no support to
the State. The law in Burson was a limited restriction that, in a context consistent
with constitutional tradition, was enacted to protect another fundamental right—
the right to vote. The restrictions there were far less onerous than those the State
seeks to impose here. …
The better analogy to this case is Board of Airport Comm'rs of Los Angeles v.
Jews for Jesus, Inc.,
U.S.
(
), where the Court struck down an ordinance prohibiting any “First Amendment activities” at Los Angeles International
Airport because the ordinance covered all manner of protected, nondisruptive behavior including “talking and reading, or the wearing of campaign buttons or
symbolic clothing,” id., at
,
. If a law prohibiting all protected expression at a
single airport is not constitutional, it follows with even greater force that the State
Internet Law
may not enact this complete bar to the exercise of First Amendment rights on
websites integral to the fabric of our modern society and culture. …
Justice Alito, concurring in the judgment.
The North Carolina statute at issue in this case was enacted to serve an interest
of surpassing importance—but it has a staggering reach. It makes it a felony for a
registered sex offender simply to visit a vast array of websites, including many that
appear to provide no realistic opportunity for communications that could facilitate
the abuse of children. Because of the law's extraordinary breadth, I agree with the
Court that it violates the Free Speech Clause of the First Amendment.
I cannot join the opinion of the Court, however, because of its undisciplined
dicta. The Court is unable to resist musings that seem to equate the entirety of the
internet with public streets and parks. And this language is bound to be interpreted by some to mean that the States are largely powerless to restrict even the most
dangerous sexual predators from visiting any internet sites, including, for example,
teenage dating sites and sites designed to permit minors to discuss personal problems with their peers. I am troubled by the implications of the Court’s unnecessary
rhetoric. …
QUESTIONS
. What’s the Problem? Why would North Carolina draft a law that would puport
to keep registered sex offenders from using Facebook? From using Amazon?
What would the offline equivalent to § –
. be? How does the Internet
make North Carolina’s job harder?
. Definitions: If you were trying to draft a narrower version of § –
. that
would survive First Amendment review, what would you do differently? If
you were trying to define “social media” sites for a privacy statute, how would
you do it?
5
2
0
2
4
1
5
2
0
2
4
1
2
7
9
1
5
6
6
8
0
NOTE ON THE PRESS
The First Amendment protects both “the freedom of speech” and “of the press.”
Lawyers and scholars are divided on whether this second clause adds anything to
the first. Some believe that the Constitution enshrines special protections for the
media – especially the news media – because of their central role in democracy.
Others believe that the Constitution values all speakers equally, amateurs as well
as professionals, as long as they are engaged in protected “speech.” The Supreme
Court has not settled the question, although it has been resistant to extending special rights to the press not available to individual citizens. See, e.g., Branzburg v.
Hayes,
U.S.
(
) (holding that the First Amendment does not require
that reporters receive an evidentiary privilege against being compelled to testify).
The question has a special urgency online. Increasingly, bloggers and independent activists are invoking laws originally written for the benefit of reporters and
institutional media. For example, “media shield” laws protect reporters from being
required to identify their confidential sources or turn over their unpublished files.
Although forty-nine states have some kind of media shield protections, the details
4
1
2
124
125
of who and what are covered, and when, vary significantly.* As a concrete example,
here is California’s:
A publisher, editor, reporter, or other person connected with or employed upon a newspaper, magazine, or other periodical publication,
or by a press association or wire service … cannot be adjudged in contempt by a judicial, legislative, administrative body, or any other body
having the power to issue subpoenas, for refusing to disclose … the
source of any information procured while so connected or employed
for publication in a newspaper, magazine or other periodical publication, or for refusing to disclose any unpublished information obtained
or prepared in gathering, receiving or processing of information for
communication to the public.
Cal. Evid. Code § 1070(a). A similar provision applies to “a radio or television
news reporter.” Id. §
(b). Do those statutory terms include Apple Insider, a
website devoted to rumors and leaks about forthcoming Apple products? Yes, said
a California court in O’Grady v. Superior Court,
Cal. Rptr. d ,
(
),
writing that “the open and deliberate publication on a news-oriented Web site of
news gathered for that purpose by the site’s operators” was “conceptually
indistinguishable from publishing a newspaper.” Compare Too Much Media, LLC,
v. Hale,
A. d
,
(N.J.
), which refused to apply New Jersey’s shield
law to “a self- described journalist who posted comments on an Internet message
board.” It compared her posts to “a pamphlet full of unfiltered, unscreened letters
to the editor submitted for publication.” Id. at
.
Similarly, courts have been willing to allow news media to publish stories even
when some of the information in those stories was obtained illegally. New York
Times Co. v. United States,
U.S.
(
) held that an order forbidding the
New York Times from publishing the “Pentagon Papers” (a secret Defense Department study documenting the United States’s military involvement in Vietnam)
violated the First Amendment as an unconstitutional prior restraint. Bartnicki v.
Vopper,
U.S.
(
) held that a radio commentator who was given a tape
recording of two union officials discussing potentially violent negotiating tactics
could play it on the air, because he “played no part in the illegal interception” and
because “the subject matter of the conversation was a matter of public concern.” Id.
at
. But this privilege is not unlimited. In Michaels v. Internet Entertainment
Group, Inc., F. Supp. d
(C.D. Cal. Apr. ,
), the court enjoined the sale
of a sex tape made by and featuring the plaintiff. Later that year, the same judge
allowed the TV show Hard Copy to broadcast an excerpt from the tape in reporting on it. Michaels v. Internet Entm’t Grp., Inc., No. CV
–
DDP (CWx),
WL
, (C.D. Cal. Sept. ,
).
Internet-age cases raise similar issues. In
, a court declined to enter a
permanent injunction against the website WikiLeaks for publishing “confidential,
as well as forged, bank documents” provided to it by an unknown party,. Bank
Julius Baer & Co. Ltd v. Wikileaks,
F. Supp. d
,
(N.D. Cal.
)
6
8
0
0
0
0
2
2
9
9
2
7
3
8
5
3
0
2
8
8
9
9
0
8
9
1
8
4
9
2
2
4
9
1
9
8
7
7
0
1
3
2
0
7
2
9
1
8
3
9
5
3
1
9
3
1
7
1
5
0
2
1
1
1
1
0
2
3
0
3
4
4
1
2
8
2
0
7
0
8
7
6
4
0
0
3
2
2
1
3
4
4
6
1
5
3
4
8
2
4
7
3
8
5
2
8
2
0
3
8
2
5
5
2
8
5
9
* The Reporters Committee for Freedom of the Press has a detailed state-by-state survey of press shield laws and caselaw at http://www.rcfp.org/reporters-privilege. See also
U.S. v. Sterling,
F. d
( th Cir.
) (holding – that there is no federal
privilege against naming confidential sources and compelling New York Times reporter James Risen to say who told him about a classified C.I.A. operation to slow
down Iran’s nuclear weapons program).
9
1
Chapter 3: Speech
Internet Law
Because “private, stolen material was transmitted over the internet via mirror
websites which are maintained in different countries all over the world” any injunction would be ineffective. Id. at
. But in
, the federal government obtained an indictment against Julian Assange, WikiLeaks’s founder, for disclosing
national defense information. And in
the celebrity gossip blog Gawker published an excerpt from a sex tape of Terry Bollea (who wrestled professionally under the ring name Hulk Hogan). He sued and obtained a
million verdict for
invasion of privacy, forcing Gawker into bankruptcy.
Other laws more clearly protect speakers in general. So-called “anti-SLAPP
statutes” give defendants a chance to obtain early dismissal of lawsuits designed to
chill free speech. (“SLAPP” is an acronym for Strategic Lawsuit Against Public
Participation). Indiana, for example, allows defendants to file a motion to dismiss
on the basis that “the act upon which the claim [against them] is based is a lawful
act in furtherance of the person’s right of petition or free speech.” IND. CODE § - - (d). All other discovery is stayed, id. § - - - , and the court must act on
the motion expeditiously, id § - - - (a)( ). In essence, the statute changes the
usual sequence of civil case management so that the defendant can litigate her
First Amendment arguments first without the expense and hassle of discovery. If
she prevails, she is entitled to her reasonable attorneys’ fees. Id. §
- - - .
(Why?) For example, in Gilbert v. Skyes,
Cal. App. th
(
), the court
dismissed a plastic surgeon’s defamation claim against a former patient. It held
that a “slight discrepancy” in before-and-after photos at her website, mysurgerynightmare.com, did not make them false, and that her statement “I didn’t
need procedures and I had no idea what I was really getting myself into” was not
injuriously false.
7
4
3
7
7
4
3
7
0
0
2
3
0
1
4
1
$
4
0
6
2
7
0
7
2
4
3
7
2
4
1
2
1
0
5
9
8
2
7
9
0
7
0
4
0
3
0
5
2
9
QUESTIONS
. Who is the Press? If you were drafting a press shield law for the digital age,
what would it say? What facts would you want to know about a self-described “citizen journalist” to decide whether to let him or her refuse to
name a source?
. Government Leakers: Should media shield laws have a carve-out for nationalsecurity information, like the NSA surveillance documents leaked by Edward Snowden? Or is the rationale for such laws even stronger with government secrets? Should the answer depend on whether the leaks are to established journalists like Glenn Greenwald at The Guardian and Barton
Gellman at the Washington Post (to whom Snowden released thousands of
NSA documents) or to non-mainstream outlets like WikiLeaks (to whom
Chelsea Manning released
,
classified State Department cables)?
Should the answer depend on how the law treats leakers and whistleblowers
themselves?
. Illegally Obtained Speech: Does the Bartnicki rationale also apply to a blogger
who comes into possession of a video, shot by a trespasser, showing conditions inside a poultry processing plant or an abortion clinic? What if a blogger asks their readers to send them “good dirt” on a company and then a few
weeks later publishes embarrassing emails they claim were sent to them by a
third party who hacked them from the company’s internal server?
. Is Speech Special? Are anti-SLAPP statutes a sensible protection for free
speech, or an unnecessary piece of First Amendment exceptionalism? If
anti-SLAPP procedures are so good, why not provide them in all cases?
7
7
2
1
4
3
126
127
. The Future of News: More and more Americans get their news online, frequently through aggregators like Facebook and Apple News. Newspaper
advertising and circulation are down significantly. What will happen to
news reporting if traditional offline news outlets disappear entirely? Is the
Internet the source of this problem, or the solution?
B. What is Speech?
Computers also raise surprising difficulties in defining “speech.” Bland and Bernstein both turn on the threshold question of whether the challenged behavior contains protected “speech.” (Before reading Bernstein, it may be helpful to review the
Technical Primer on Cryptography from the Background chapter.)
TEXAS V. JOHNSON
491 U.S. 397 (1989)
Justice Brennan delivered the opinion of the Court: …
In deciding whether particular conduct possesses sufficient communicative
elements to bring the First Amendment into play, we have asked whether “[a]n
intent to convey a particularized message was present, and [whether] the likelihood was great that the message would be understood by those who viewed it.”
Spence v. Washington,
U.S.
,
(
).
Johnson burned an American flag as part — indeed, as the culmination — of a
political demonstration that coincided with the convening of the Republican Party
and its renomination of Ronald Reagan for President. The expressive, overtly political nature of this conduct was both intentional and overwhelmingly apparent.
… In these circumstances, Johnson's burning of the flag was conduct “sufficiently
imbued with elements of communication,” Spence,
U.S. at
, to implicate
the First Amendment.
BLAND V. ROBERTS [I]
857 F. Supp. 2d 599 (E.D. Va. 2012)
9
0
4
8
1
4
4
7
9
1
1
1
4
0
1
4
y
5
r
o
0
t
4
s
i
l
8
a
1
r
4
u
d
e
c
o
r
9
0
l
0
a
9
2
u
0
t
0
c
2
Jackson, District Judge: …
I. F
&P
H
Plaintiffs … were employed in the Hampton Sheriff ’s Office (”the Office”). … The
Sheriff of the Office, B.J. Roberts (“the Sheriff ”), was slated for re-election in November
. The Plaintiffs claim that during his tenure the Sheriff used his authority to bolster his reelection efforts, including using employees to manage his
political activities, using prisoners to set up campaign events and forcing his employees to sell and buy tickets to campaign fundraisers. Plaintiffs contend that in
late
, the Sheriff learned that a number of his employees were actively supporting Jim Adams, one of the Sheriff ’s opponents in the election. …
The Plaintiffs further allege that the Sheriff learned that each of them affirmatively expressed their support for Adams by informing other individuals of their
support, attending a cookout which Adams also attended and “liking” Adams’
Facebook page. According to the Plaintiffs, after learning of their support of his
opponent, the Sheriff called a meeting in which he informed his employees that
they should get on the “long train” with him rather than riding the “short train”
with his opponent.
a
5
Chapter 3: Speech
128
Internet Law
1
1
2
0
2
0
2
1
5
0
1
6
2
4
0
0
1
1
1
1
0
2
4
1
0
3
1
1
1
0
2
1
0
1
9
1
4
0
0
3
2
1
1
0
2
9
3
2
2
n
o
i
s
3
s
8
u
2
c
4
s
8
i
1
5
2
The Sheriff won the November
election, and he decided not to retain the
six Plaintiffs as well as six other employees. …
III. D
A. Freedom of Speech Retaliation Claim
Plaintiffs first allege that the Sheriff failed to reappoint them in retaliation for
their exercise of their right to freedom of speech when they choose to support the
Sheriff ’s opponent in the election. … Plaintiffs Carter, McCoy, and Woodward
have not sufficiently alleged that they engaged in expressive speech … . Therefore,
these Plaintiffs’ claims fail as a matter of law.
a. Daniel Ray Carter, Jr. & Robert McCoy …
Carter and McCoy each allege that they engaged in constitutionally protected
speech when they “made statements” on Adams’ Facebook page. …
Carter alleged that he sent a statement of support and attached the statement
as an exhibit to his declaration in this case. However, after reviewing the record,
the Court has not found any evidence of the “statement of support” Carter allegedly made. In fact, the only evidence regarding Carter’s activity on Adams’ Facebook
page is that he “liked” Adams’ page.
It is clear, based on the Sheriff ’s own admissions, that at some point he became
aware of McCoy and Carter’s presence on Adams’ Facebook page. However, the
Sheriff ’s knowledge of the posts only becomes relevant if the Court finds the activity of liking a Facebook page to be constitutionally protected. It is the Court’s conclusion that merely “liking” a Facebook page is insufficient speech to merit constitutional protection. In cases where courts have found that constitutional speech
protections extended to Facebook posts, actual statements existed within the
record. For example, in Mattingly v. Milligan, Mattingly posted on her Facebook
wall referring directly to the firing of various employees. No. : CV
,
WL
, at * –* (E.D. Ark. Nov. ,
) (“Two minutes after this post, Mattingly posted another comment: ‘I am trying [sic] my heart goes out to the ladies
in my office that were told by letter they were no longer needed ... It’s sad.’”).
There, the court held that Mattingly’s specific post was an expression of constitutionally protected speech. Id. at * –* . Similarly, in Gresham v. City of Atlanta, the
plaintiff posted: “Who would like to hear the story of how I arrested a forgery perp
at Best Buy online to find out later at the precinct that he was the nephew of an
Atlanta Police Investigator ... ?” No. : –CV–
–RWS–ECS,
WL
,
at * (N.D. Ga. Aug. ,
). In Gresham, the district court adopted the Magistrate Judge’s recommendation that although the statement was a close question, it
constituted enough speech to be considered speaking out as a matter of public
concern.
These illustrative cases differ markedly from the case at hand in one crucial
way: Both Gresham and Mattingly involved actual statements. No such statements exist in this case. Simply liking a Facebook page is insufficient. It is not the
kind of substantive statement that has previously warranted constitutional protection. The Court will not attempt to infer the actual content of Carter’s posts from
one click of a button on Adams’ Facebook page. For the Court to assume that the
Plaintiffs made some specific statement without evidence of such statements is
improper. Facebook posts can be considered matters of public concern; however,
the Court does not believe Plaintiffs Carter and McCoy have alleged sufficient
speech to garner First Amendment protection.
129
BLAND V. ROBERTS [II]
730 F.3d 368 (4th Cir. 2013)
Traxler, Chief Judge: …
Here, Carter visited the Jim Adams’s campaign Facebook page (the “Campaign
Page”), which was named “Jim Adams for Hampton Sheriff,” and he clicked the
“like” button on the Campaign Page. When he did so, the Campaign Page’s name
and a photo of Adams – which an Adams campaign representative had selected as
the Page’s icon – were added to Carter’s profile, which all Facebook users could
view. On Carter’s profile, the Campaign Page name served as a link to the Campaign Page. Carter’s clicking on the “like” button also caused an announcement
that Carter liked the Campaign Page to appear in the news feeds of Carter’s
friends. And it caused Carter’s name and his profile photo to be added to the
Campaign Page’s “People [Who] Like This” list.
Once one understands the nature of what Carter did by liking the Campaign
Page, it becomes apparent that his conduct qualifies as speech. On the most basic
level, clicking on the “like” button literally causes to be published the statement
that the User “likes” something, which is itself a substantive statement. In the context of a political campaign’s Facebook page, the meaning that the user approves of
the candidacy whose page is being liked is unmistakable. That a user may use a
single mouse click to produce that message that he likes the page instead of typing
the same message with several individual key strokes is of no constitutional significance.
Aside from the fact that liking the Campaign Page constituted pure speech, it
also was symbolic expression. The distribution of the universally understood
"thumbs up" symbol in association with Adams’s campaign page, like the actual
text that liking the page produced, conveyed that Carter supported Adams’s candidacy. See Spence v. Washington,
U.S.
,
- (
) (per curiam) (holding that person engaged in expressive conduct when there was “[a]n intent to convey a particularized message ... , and in the surrounding circumstances the likelihood was great that the message would be understood by those who viewed it”).
In sum, liking a political candidate’s campaign page communicates the user’s
approval of the candidate and supports the campaign by associating the user with
it. In this way, it is the Internet equivalent of displaying a political sign in one’s
front yard, which the Supreme Court has held is substantive speech. See City of
Ladue v. Gilleo,
U.S. , - (
). Just as Carter’s placing an “Adams for
Sheriff ” sign in his front yard would have conveyed to those passing his home that
he supported Adams’s campaign, Carter’s liking Adams’s Campaign Page conveyed
that message to those viewing his profile or the Campaign Page. In fact, it is hardly
surprising that the record reflects that this is exactly how Carter’s action was understood. See J.A.
(McCoy’s testimony that in light of Carter’s liking Adams’s
Campaign Page, “everybody was saying that ... Carter is out of there because he
supported Adams openly”); see also J.A.
(Sheriff ’s Office employee stating that
Roberts had said that “certain employees were on the Facebook page of his opponent, Jim Adams, indicating their support of Adams for Sheriff ”).
8
6
4
8
7
6
9
0
1
1
1
2
1
0
1
4
8
1
5
0
0
2
4
3
9
9
4
7
3
3
9
9
8
1
1
7
4
6
1
5
4
5
3
0
6
2
1
1
5
8
1
0
2
4
QUESTIONS
Interpreting Likes: D.R. v. D. A., No. -P,
WL
(Mass. App.
Ct. May ,
), held that a like on a birthday message posted by someone
else on a third person’s Facebook timeline was a threat of imminent physical
harm. What set of circumstances could justify that interpretation? What
else can a like mean?
.
8
1
Chapter 3: Speech
Internet Law
. Interpreting Emoji: Even when something is “speech,” there is also the problem of determining what it communicates. Is 👊 👉 🚑 a threat? How do you
know? Suppose that that the sender’s computer displays an emoji as 🔫 and
the recipient’s displays it as
. Is this a threat?
. Coverage and Protection: There is a threshold question of whether something
is “speech” at all (coverage), which is different from the ultimate question of
whether the First Amendment protects that speech (protection). For example, if I knowingly falsely call you a murderer, that’s speech, but not protected speech. Is Bland a coverage case or a protection case?
. Workplace Speech: The National Labor Relations Act allows employees “to
engage in … concerted activities for the purpose of collective bargaining or
other mutual aid or protection,”
U.S.C. §
. Employers may not “interfere with, restrain, or coerce” employees from exercising those rights. Id. §
(a)( ).. A bartender at a sports bar posts to Twitter “Maybe someone
should do the owners of Triple Play a favor and buy it from them. They can’t
even do the tax paperwork correctly!!! Now I OWE money . . . Wtf!!!!” A
cook retweets it. Are these protected “concerted activities” or can the two be
fired? If the Triple Play’s owner tweets, “Get back to work or I’ll send you
back to the salt mine,” is this prohibited coercion?
BERNSTEIN V. U.S. DEPT. OF JUSTICE
176 F.3d 1132 (9th Cir.),
withdrawn and reh’g en banc granted, 192 F.3d 1308 (9th Cir. 1999)
Fletcher, Circuit Judge: …
7
5
1
9
2
d
n
u
o
1
r
g
k
c
8
5
B
A. Facts and Procedural History
Bernstein is currently a professor in the Department of Mathematics, Statistics,
and Computer Science at the University of Illinois at Chicago. As a doctoral candidate at the University of California, Berkeley, he developed an encryption method
– “a zero-delay private-key stream encryptor based upon a one-way hash function”
that he dubbed “Snuffle.” Bernstein described his method in two ways: in a paper
containing analysis and mathematical equations (the “Paper”) and in two computer programs written in “C,” a high-level computer programming language (“Source
Code”). Bernstein later wrote a set of instructions in English (the “Instructions”)
explaining how to program a computer to encrypt and decrypt data utilizing a
one-way hash function, essentially translating verbatim his Source Code into prose
form.
Seeking to present his work on Snuffle within the academic and scientific
communities, Bernstein asked the State Department whether he needed a license
to publish Snuffle in any of its various forms. The State Department responded
that Snuffle was a munition under the [Export Administration Regulations
(“EAR”) administered by the Bureau of Export Administration (“BXA”)], and that
Bernstein would need a license to “export” the Paper, the Source Code, or the Instructions.
There followed a protracted and unproductive series of letter communications
between Bernstein and the government, wherein Bernstein unsuccessfully attempted to determine the scope and application of the export regulations to Snuffle. [Bernstein sued, and the District Court held that the EAR constituted a constitutionally impermissible prior restraint on speech.]
a
4
3
2
1
130
131
1
3
9
1
9
3
1
7
7
2
9
4
6
3
7
3
8
2
5
1
6
7
9
1
9
5
5
9
5
3
1
5
2
4
7
7
2
4
1
7
9
1
5
1
9
1
4
n
5
1
o
4
i
s
s
u
c
s
i
2
B. Overview of Cryptography …
It is, of course, encryption’s secrecy applications that concern the government. The
interception and deciphering of foreign communications has long played an important part in our nation’s national security efforts. In the words of a high-ranking State Department official:
Policies concerning the export control of cryptographic products are
based on the fact that the proliferation of such products will make it
easier for foreign intelligence targets to deny the United States Government access to information vital to national security interests.
Cryptographic products and software have military and intelligence
applications. As demonstrated throughout history, encryption has
been used to conceal foreign military communications, on the battlefield, aboard ships and submarines, or in other military settings. Encryption is also used to conceal other foreign communications that
have foreign policy and national security significance for the United
States. For example, encryption can be used to conceal communications of terrorists, drug smugglers, or others intent on taking hostile
action against U.S. facilities, personnel, or security interests.
As increasingly sophisticated and secure encryption methods are developed, the
government’s interest in halting or slowing the proliferation of such methods has
grown keen. The EAR regulations at issue in this appeal evidence this interest.
C. The EAR regulations
The EAR contain specific regulations to control the export of encryption software,
expressly including computer source code. [The “export” of encryption software
was defined] to preclude the use of the internet and other global mediums if such
publication would allow passive or active access by a foreign national within the
United States or anyone outside the United States.
C.F.R. §
. (b)( )(B)(ii).
…
If encryption software falls within the ambit of the relevant EAR provisions,
the “export” of such software requires a prepublication license. When a prepublication license is requested, the relevant agencies undertake a “case-by-case” analysis
to determine if the export is “consistent with U.S. national security and foreign
policy interests.” C.F.R. §
. (b). …
D
I. Prior Restraint
The parties and amici urge a number of theories on us. We limit our attention
here, for the most part, to only one: whether the EAR restrictions on the export of
encryption software in source code form constitute a prior restraint in violation of
the First Amendment. We review de novo the district court’s affirmative answer to
this question.
It is axiomatic that “prior restraints on speech and publication are the most
serious and least tolerable infringement on First Amendment rights.” Nebraska
Press Ass’n v. Stuart,
U.S.
,
(
). Indeed, the Supreme Court has
opined that “it is the chief purpose of the [First Amendment] guaranty to prevent
previous restraints upon publication.” Near v. Minnesota,
U.S.
,
(
).
Accordingly, “[a]ny prior restraint on expression comes . . . with a ‘heavy presumption’ against its constitutional validity.” Organization for a Better Austin v. Keefe,
U.S.
,
(
). …
0
4
Chapter 3: Speech
It must be emphasized, however, that source code is merely text, albeit text that conforms to stringent formatting and punctuation requirements. For example, the following is an excerpt from Bernstein’s Snuffle source code:
for (; ;)
(
uch = gtchr( );
if (!(n & 31))
(
for (i = 0; i<64; i + +)
l[ctr[i]] = k[i] + h[n - 64 + i]
Hash512 (wm, wl, level, 8);
)
5
1
2
4
7
3
6
7
5
1
9
5
7
As source code goes, Snuffle is quite compact; the entirety of the Snuffle source code
occupies fewer than four printed pages.
1
1
Internet Law
A. Is Bernstein entitled to bring a facial attack?
A licensing regime is always subject to facial challenge as a prior restraint where it
“gives a government official or agency substantial power to discriminate based on
the content or viewpoint of speech by suppressing disfavored speech or disliked
speakers,” and has “a close enough nexus to expression, or to conduct commonly
associated with expression, to pose a real and substantial threat of . . . censorship
risks.” Id. at
.
The EAR regulations at issue plainly satisfy the first requirement – “the determination of who may speak and who may not is left to the unbridled discretion of
a government official.” Id. at
. BXA administrators are empowered to deny licenses whenever export might be inconsistent with “U.S. national security and
foreign policy interests.”
C.F.R. §
. (b). No more specific guidance is provided. Obviously, this constraint on official discretion is little better than no constraint at all. …
The more difficult issue arises in relation to the second requirement – that the
challenged regulations exhibit “a close enough nexus to expression.” We are called
on to determine whether encryption source code is expression for First Amendment purposes.
We begin by explaining what source code is. “Source code,” at least as currently
understood by computer programmers, refers to the text of a program written in a
“high-level” programming language, such as “PASCAL” or “C.” The distinguishing
feature of source code is that it is meant to be read and understood by humans and
that it can be used to express an idea or a method. A computer, in fact, can make
no direct use of source code until it has been translated (”compiled”) into a “lowlevel” or “machine” language, resulting in computer-executable “object code.” That
source code is meant for human eyes and understanding, however, does not mean
that an untutored lay-person can understand it. Because source code is destined
for the maw of an automated, ruthlessly literal translator – the compiler – a programmer must follow stringent grammatical, syntactical, formatting, and punctuation conventions. As a result, only those trained in programming can easily understand source code.
Also important for our purposes is an understanding of how source code is
used in the field of cryptography. Bernstein has submitted numerous declarations
1
1
132
Source code’s power to convey algorithmic information is illustrated by the declaration of MIT Professor Harold Abelson:
The square root of a number X is the number Y such that Y times Y
equals X. This is declarative knowledge. It tells us something about
square roots. But it doesn’t tell us how to find a square root. In
contrast, consider the following ancient algorithm, attributed to Heron
of Alexandria, for approximating square roots:
To approximate the square root of a positive number X,
• Make a guess for the square root of X.
• Compute an improved guess as the average of the guess
and X divided by the guess.
• Keep improving the guess until it is good enough.
Heron’s method doesn’t say anything about what square roots are, but
it does say how to approximate them. This is a piece of imperative
“how to” knowledge.
Computer science is in the business of formalizing imperative
knowledge – developing formal notations and ways to reason and
talk about methodology. Here is Heron’s method formalized as a
procedure in the notation of the Lisp computer language:
(define (sqrtx)
(define (good-enough? guess)
(<(abs ( - (square guess) x)) tolerance))
(define (improve guess)
(average guess (/ x guess)))
(define (try guess)
(if (good-enough? guess)
guess
(try (improve guess))))
(try 1))
2
1
133
from cryptographers and computer programmers explaining that cryptographic
ideas and algorithms are conveniently expressed in source code.
That this should be so is, on reflection, not surprising. As noted earlier, the
chief task for cryptographers is the development of secure methods of encryption.
While the articulation of such a system in layman’s English or in general mathematical terms may be useful, the devil is, at least for cryptographers, often in the
algorithmic details. By utilizing source code, a cryptographer can express algorithmic ideas with precision and methodological rigor that is otherwise difficult to
achieve. This has the added benefit of facilitating peer review – by compiling the
source code, a cryptographer can create a working model subject to rigorous security tests. The need for precisely articulated hypotheses and formal empirical testing, of course, is not unique to the science of cryptography; it appears, however,
that in this field, source code is the preferred means to these ends.
Thus, cryptographers use source code to express their scientific ideas in much
the same way that mathematicians use equations or economists use graphs. Of
course, both mathematical equations and graphs are used in other fields for many
purposes, not all of which are expressive. But mathematicians and economists
have adopted these modes of expression in order to facilitate the precise and rigorous expression of complex scientific ideas. Similarly, the undisputed record here
makes it clear that cryptographers utilize source code in the same fashion.
2
1
Chapter 3: Speech
Nelson, Circuit Judge, Dissenting: …
The basic error which sets the majority and the district court adrift is the failure to fully recognize that the basic function of encryption source code is to act as
a method of controlling computers. As defined in the EAR regulations, encryption
source code is “[a] precise set of operating instructions to a computer, that when
We express no opinion regarding whether object code manifests a “close enough
nexus to expression” to warrant application of the prior restraint doctrine. Bernstein’s Snuffle did not involve object code, nor does the record contain any information regarding expressive uses of object code in the field of cryptography.
5
1
Internet Law
In light of these considerations, we conclude that encryption software, in its
source code form and as employed by those in the field of cryptography, must be
viewed as expressive for First Amendment purposes, and thus is entitled to the
protections of the prior restraint doctrine. If the government required that mathematicians obtain a prepublication license prior to publishing material that included mathematical equations, we have no doubt that such a regime would be
subject to scrutiny as a prior restraint. The availability of alternate means of expression, moreover, does not diminish the censorial power of such a restraint –
that Adam Smith wrote Wealth of Nations without resorting to equations or
graphs surely would not justify governmental prepublication review of economics
literature that contain these modes of expression.
The government, in fact, does not seriously dispute that source code is used by
cryptographers for expressive purposes. Rather, the government maintains that
source code is different from other forms of expression (such as blueprints, recipes,
and “how-to” manuals) because it can be used to control directly the operation of a
computer without conveying information to the user. In the government’s view, by
targeting this unique functional aspect of source code, rather than the content of
the ideas that may be expressed therein, the export regulations manage to skirt
entirely the concerns of the First Amendment. This argument is flawed for at least
two reasons.
First, it is not at all obvious that the government’s view reflects a proper understanding of source code. As noted earlier, the distinguishing feature of source code
is that it is meant to be read and understood by humans, and that it cannot be
used to control directly the functioning of a computer. While source code, when
properly prepared, can be easily compiled into object code by a user, ignoring the
distinction between source and object code obscures the important fact that
source code is not meant solely for the computer, but is rather written in a language intended also for human analysis and understanding.
Second, and more importantly, the government’s argument, distilled to its essence, suggests that even one drop of “direct functionality” overwhelms any constitutional protections that expression might otherwise enjoy. This cannot be so. The
distinction urged on us by the government would prove too much in this era of
rapidly evolving computer capabilities. The fact that computers will soon be able
to respond directly to spoken commands, for example, should not confer on the
government the unfettered power to impose prior restraints on speech in an effort
to control its “functional” aspects. The First Amendment is concerned with expression, and we reject the notion that the admixture of functionality necessarily puts
expression beyond the protections of the Constitution. …
[The court held that the export restrictions were a constitutionally impermissible prior restraint on speech.]
5
1
134
Chapter 3: Speech
135
5
1
3
1
0
4
7
5
1
0
1
2
2
7
compiled, allows for the execution of an encryption function on a computer.”
C.F.R. pt.
. Software engineers generally do not create software in object codethe series of binary digits ( ’s and ’s) – which tells a computer what to do because
it would be enormously difficult, cumbersome and time-consuming. Instead,
software engineers use high-level computer programming languages such as “C” or
“Basic” to create source code as a shorthand method for telling the computer to
perform a desired function. In this respect, lines of source code are the building
blocks or the tools used to create an encryption machine. Encryption source code,
once compiled, works to make computer communication and transactions secret;
it creates a lockbox of sorts around a message that can only be unlocked by someone with a key. It is the function or task that encryption source code performs
which creates its value in most cases. This functional aspect of encryption source
code contains no expression; it is merely the tool used to build the encryption machine. …
This is not to say that this very same source code is not used expressively in
some cases. Academics, such as Bernstein, seek to convey and discuss their ideas
concerning computer encryption. As noted by the majority, Bernstein must actually use his source code textually in order to discuss or teach cryptology. In such circumstances, source code serves to express Bernstein’s scientific methods and
ideas.
While it is conceptually difficult to categorize encryption source code under our
First Amendment framework, I am still inevitably led to conclude that encryption
source code is more like conduct than speech. Encryption source code is a building
tool. Academics and computer programmers can convey this source code to each
other in order to reveal the encryption machine they have built. But, the ultimate
purpose of encryption code is, as its name suggests, to perform the function of encrypting messages. Thus, while encryption source code may occasionally be used
in an expressive manner, it is inherently a functional device. …
The activity or conduct at issue here is the export of encryption source code. As
I noted above, the basic nature of encryption source code lies in its functional capacity as a method to build an encryption device. Export of encryption source code
is not conduct commonly associated with expression. Rather, it is conduct that is
normally associated with providing other persons with the means to make their
computer messages secret. The overwhelming majority of people do not want to
talk about the source code and are not interested in any recondite message that
may be contained in encryption source code. Only a few people can actually understand what a line of source code would direct a computer to do. Most people
simply want to use the encryption source code to protect their computer communications. Export of encryption source code simply does not fall within the bounds
of conduct commonly associated with expression such as picketing or handbilling.
…
[Following this decision, the Ninth Circuit granted rehearing en banc. While
the rehearing was pending, the government exempted “publicly available encryption source code” from most of the EAR’s restrictions, see
C.F.R. §
. (e),
mooting the case. The export control laws continue to be enforced against other
computer products: the Xbox.com website terms of service, for example, require
users to agree to comply with export controls.]
.
.
.
.
.
.
.
Internet Law
QUESTIONS
This Website Is a Munition: How did encryption software end up on the export
control list along with surface-to-air missiles? How does the Internet make
this a harder case?
Object Code: After Bernstein, how does the the First Amendment apply to
object code?
Software vs. Hardware: The United States restricts the export of high-speed
computer chips to various countries, including China. Do these restrictions
raise a First Amendment issue under Bernstein?
Exploits: There is a thriving grey market in “exploits”: short programs that
take advantage of security vulnerabilities in commonly-used software to let
an attacker take control of a computer. Secrecy is key, because once an exploit is known, the company whose software it targets can fix the vulnerability. Some of the biggest exploit buyers are governments – including the
United States government – looking to spy on each other, or on their own
citizens. Some critics think that the sale of exploits should be criminalized,
but others argue that they are protected by the First Amendment. Who is
right? What should be done about exploits? To make matters even more
complicated, consider the Second Amendment, which protects “the right of
the people to keep and bear Arms.” Does it also protect the right to keep and
bear exploits?
Flashing Images: A Twitter user with username @jew_goldstein tagged journalist Kurt Eichenwald in a tweet containing a flashing image and the words
“You deserve a seizure for your posts’. Eichenwald, who is epileptic, suffered
a seizure. Prosecutors identified @jew_goldstein and charged him with assault. Does the First Amendment stand in the way?
The Information Professions: Many professions are regulated: you need a medical license to perform surgery and your license can be revoked if you do it
badly. What justifies these restrictions, and how far does the logic go in restricting not just professional conduct but professional speech, especially on
the Internet? Consider, for example, Vizaline, a startup that takes digital
satellite photos and draws colored lines on them to indicate approximate
property boundaries. Is this the unauthorized practice of surveying?
Liable Language Models? Rachael Tyrell trains an AI chatbot, which she
names Leon, on text from millions of webpages. Roy Deckard asks Leon
some questions about rewiring a broken lamp. When he follows the instructions in Leon’s output, the lamp explodes, injuring him. If Deckard sues
Tyrell, will the First Amendment apply? What if Deckard sues Leon? (Does
this even make sense?) What if the government decides that chatbots are
inherently dangerous and requires programmers to obtain a license before
deploying one to the public?
9
1
3
fl
3
4
9
1
4
2
NOTE ON COMPELLED SPEECH AND 303 CREATIVE
In addition to protecting the freedom to speak, the First Amendment also protects
the freedom not to speak. Laws requiring people to engage in compelled speech
typically must satisfy strict scrutiny. In West Virginia Bd. of Ed. v. Barnette,
U.S.
,(
), the Supreme Court invalidated a West Virginia law that compelled schoolchildren to salute the United States ag and recite, “I pledge alle-
6
7
6
5
4
3
2
1
136
137
9
1
1
5
1
1
ff
3
2
0
2
0
3
1
ff
7
4
5
0
0
6
fi
7
9
9
1
fi
1
0
0
6
7
8
4
3
4
4
4
8
2
3
fi
0
ff
3
1
2
2
3
5
7
4
fi
6
9
1
ffi
0
giance to the Flag of the United States of America and to the Republic for which it
stands; one Nation, indivisible, with liberty and justice for all.” As Justice Jackson’s
famous opinion for the Court explained,
If there is any xed star in our constitutional constellation, it is that
no o cial, high or petty, can prescribe what shall be orthodox in politics, nationalism, religion, or other matters of opinion or force citizens
to confess by word or act their faith therein.
Id. at
.
Issues sometimes arise whether a law requires businesses to engage in conduct
or speech. In
Creative LLC v. Elenis,
U.S.
(
), the Supreme Court
considered the Colorado Anti-Discrimination Act, which prohibits businesses
open to the general public from refusing their services “because of disability, race,
creed, color, sex, sexual orientation, marital status, national origin, or ancestry.”
Colo. Rev. Stat. § – –
. Lorie Smith, a graphic designer, stated that she was
willing to create a wedding website for any customer, but not to make a website
that “contradicts biblical truth” as she understood it – i.e. featuring any couple
other than one man and one woman. The Court held that as applied to Smith, the
Colorado ADA violated the First Amendment because it compelled her to engage
in “pure speech.”
A hundred years ago, Ms. Smith might have furnished her services
using pen and paper. Those services are no less protected speech today because they are conveyed with a “voice that resonates farther
than it could from any soapbox.” Reno v. American Civil Liberties
Union,
U. S.
,
(
). All manner of speech—from “pictures, lms, paintings, drawings, and engravings,” to “oral utterance
and the printed word”—qualify for the First Amendment’s protections; no less can hold true when it comes to speech like Ms. Smith’s
conveyed over the Internet. Kaplan v. California,
U. S.
,
–
(
). …
Consider what a contrary approach would mean. Under Colorado’s
logic, the government may compel anyone who speaks for pay on a
given topic to accept all commissions on that same topic—no matter
the underlying message—if the topic somehow implicates a customer’s
statutorily protected trait. Taken seriously, that principle would allow
the government to force all manner of artists, speechwriters, and
others whose services involve speech to speak what they do not believe
on pain of penalty. The government could require “an unwilling
Muslim movie director to make a lm with a Zionist message,” or “an
atheist muralist to accept a commission celebrating Evangelical zeal,”
so long as they would make lms or murals for other members of the
public with di erent messages. Equally, the government could force a
male website designer married to another man to design websites for
an organization that advocates against same-sex marriage.
In dissent, Justice Sotomayor argued that the Colorado ADA compelled conduct,
not speech:
Crucially, the law does not dictate the content of speech at all, which is
only “compelled” if, and to the extent, the company o ers such speech
to other customers. … The company could, for example, o er only
wedding websites with biblical quotations describing marriage as be-
2
1
Chapter 3: Speech
Internet Law
tween one man and one woman. The company could also refuse to
include the words “Love is Love” if it would not provide those words
to any customer. All the company has to do is o er its services without
regard to customers’ protected characteristics. Any e ect on the company’s speech is therefore incidental to the State’s content-neutral
regulation of conduct.
Once these features of the law are understood, it becomes clear
that petitioners’ freedom of speech is not abridged in any meaningful
sense, factual or legal. Petitioners remain free to advocate the idea
that same-sex marriage betrays God’s laws. Even if Smith believes
God is calling her to do so through her for-pro t company, the
company need not hold out its goods or services to the public at large.
Many lmmakers, visual artists, and writers never do. (That is why
the law does not require Steven Spielberg or Banksy to make lms or
art for anyone who asks.) Finally, and most importantly, even if the
company o ers its goods or services to the public, it remains free
under state law to decide what messages to include or not to include.
… All the company may not do is o er wedding websites to the public
yet refuse those same websites to gay and lesbian couples.
QUESTIONS
. Is Compelled Coding Compelled Speech? Would the result in
Creative be
the same if Smith were a programmer rather than a graphic designer? Could
she refuse to write an accounting database for a client she disapproved of?
Or is the kind of speech at issue in Bernstein not the same kind of speech at
issue in
Creative?
. Off the Rack vs. Bespoke: Does it matter whether Smith creates each website
from scratch or from a template into which she inserts a couple’s name, the
date and location of their ceremony, some photos, and other wedding-specific details? Could Colorado force her to provide the HTML source code to one
of her existing websites to a same-sex couple so that they could customize it?
. Compelled Disclosure: Disclosure laws are a form of compelled speech. The
Slothrop Candy Corporation might prefer not to tell the public that its Marmalade Surprises contain no actual fruit, but it is required by law to label
them with a list of ingredients. See
C.F.R. §
. (a)( ). Mandatory disclosure requirements are generally limited to “purely factual and uncontroversial information.” Zauderer v. O ce of Disciplinary Counsel of Supreme
Court of Ohio,
U.S.
,
(
). Can the government require a company’s website to have a privacy policy disclosing how it uses consumers’ personal information? Can it require liquor-companies’ websites to have banners warning consumers about the dangers of drinking?
C. Harmful Speech
3
fi
0
3
1
fi
ff
4
1
ff
0
1
5
1
8
ff
2
9
ffi
1
1
5
6
6
2
6
1
7
4
ff
3
0
3
Concluding that something is “speech” does not end the First Amendment inquiry.
The Supreme Court has recognized several types of unprotected speech, which
typically combine serious harms with few offsetting benefits for society. Government restrictions on such “low value” speech must still thread the needle of overbreadth and vagueness.
fi
1
3
2
138
139
Importantly, the list of categories of low value speech is closed. In United States
v. Stevens,
U.S.
(
), the government argued that “crush videos” that
featured the “intentional torture and killing of helpless animals” ought to be regarded as unprotected. Id. at
. The Supreme Court disagreed. It listed a few
“historic and traditional categories” of unprotected speech, “including obscenity,
defamation, fraud, incitement, and speech integral to criminal conduct.” It refused
to add a new one. Id. at
. While “the prohibition of animal cruelty itself has a
long history in American law,” it explained, “we are unaware of any similar tradition excluding depictions of animal cruelty from ‘the freedom of speech.’” Id. at
.
This section provides a survey organized around the different categories of restrictions the Supreme Court has traditionally allowed. An early generation of theorists believed that these restrictions were either unenforceable or unnecessary on
the Internet. They argued that online speech could and should be utterly uninhibited. As you read the following materials, ask what this view gets right and what it
gets wrong. Does the Internet make these speech harms more or less severe?
danah boyd
DANAH BOYD, IT’S COMPLICATED
THE SOCIAL LIVES OF NETWORKED TEENS
(Yale University Press 2014)
5
6
4
0
1
0
8
2
6
4
0
6
4
9
5
5
9
To understand what is new and what is not, it’s important to understand how
technology introduces new social possibilities and how these challenge assumptions people have about everyday interactions. The design and architecture of environments enable certain types of interaction to occur. Round tables with chairs
make chatting with someone easier than classroom-style seating. Even though
students can twist around and talk to the person behind them, a typical classroom
is designed to encourage everyone to face the teacher. The particular properties or
characteristics of an environment can be understood as affordances because they
make possible – and, in some cases, are used to encourage – certain types of practices, even if they do not determine what practices will unfold. Understanding the
affordances of a particular technology or space is important because it sheds light
on what people can leverage or resist in achieving their goals. For example, the
affordances of a thick window allow people to see each other without being able to
hear each other. To communicate in spite of the window, they may pantomime,
hold up signs with written messages, or break the glass. The window’s affordances
don’t predict how people will communicate, but they do shape the situation nonetheless.
Because technology is involved, networked publics have different characteristics than traditional physical public spaces. Four affordances, in particular, shape
many of the mediated environments that are created by social media. Although
these affordances are not in and of themselves new, their relation to one another
because of networked publics creates new opportunities and challenges. They are:
• persistence: the durability of online expressions and content;
• visibility: the potential audience who can bear witness;
• spreadability: the ease with which content can be shared;
• and searchability: the ability to find content.
Content shared through social media often sticks around because technologies are
designed to enable persistence. The fact that content often persists has significant
6
4
Chapter 3: Speech
140
Internet Law
implications. Such content enables interactions to take place over time in an asynchronous fashion. Alice may write to Bob at midnight while Bob is sound asleep;
but when Bob wakes up in the morning or comes back from summer camp three
weeks later, that message will still be there waiting for him, even if Alice had forgotten about it. Persistence means that conversations conducted through social
media are far from ephemeral; they endure. Persistence enables different kinds of
interactions than the ephemerality of a park. Alice’s message doesn’t expire when
Bob reads it, and Bob can keep that message for decades. What persistence also
means, then, is that those using social media are often “on the record” to an unprecedented degree.
Through social media, people can easily share with broad audiences and access
content from greater distances, which increases the potential visibility of any particular message. More often than not, what people put up online using social media is widely accessible because most systems are designed such that sharing with
broader or more public audiences is the default. Many popular systems require
users to take active steps to limit the visibility of any particular piece of shared
content. This is quite different from physical spaces, where people must make a
concerted effort to make content visible to sizable audiences. In networked
publics, interactions are often public by default, private through effort.
Social media is often designed to help people spread information, whether by
explicitly or implicitly encouraging the sharing of links, providing reblogging or
favoriting tools that repost images or texts, or by making it easy to copy and paste
content from one place to another. Thus, much of what people post online is easily
spreadable with the click of a few keystrokes. Some systems provide simple buttons to “forward,” “repost,” or “share” content to articulated or curated lists. Even
when these tools aren’t built into the system, content can often be easily downloaded or duplicated and then forwarded along. The ease with which everyday
people can share media online is unrivaled, which can be both powerful and problematic. Spreadability can be leveraged to rally people for a political cause or to
spread rumors.
Last, since the rise of search engines, people’s communications are also often
searchable. My mother would have loved to scream, “Find!” and see where my
friends and I were hanging out and what we were talking about. Now, any inquisitive onlooker can query databases and uncover countless messages written by and
about others. Even messages that were crafted to be publicly accessible were not
necessarily posted with the thought that they would reappear through a search
engine. Search engines make it easy to surface esoteric interactions. These tools
are often designed to eliminate contextual cues, increasing the likelihood that
searchers will take what they find out of context.
None of the capabilities enabled by social media are new. The letters my grandparents wrote during their courtship were persistent. Messages printed in the
school newspaper or written on bathroom walls have long been visible. Gossip and
rumors have historically spread like wildfire through word of mouth. And although search engines certainly make inquiries more efficient, the practice of asking after others is not new, even if search engines mean that no one else knows.
What is new is the way in which social media alters and amplifies social situations
by offering technical features that people can use to engage in these well-established practices.
As people use these different tools, they help create new social dynamics. For
example, teens “stalk” one another by searching for highly visible, persistent data
141
about people they find interesting. “Drama” starts when teens increase the visibility of gossip by spreading it as fast as possible through networked publics. And
teens seek attention by exploiting searchability, spreadability, and persistence to
maximize the visibility of their garage band’s YouTube video. The particular practices that emerge as teens use the tools around them create the impression that
teen sociality is radically different even though the underlying motivations and
social processes have not changed that much.
QUESTIONS
. Examples: Is a handwritten letter persistent? Visible? Spreadable? Searchable? What about an email? A blog post?
. Harms: How do these four affordances change the ways in which speech can
inflict harms on listeners? On speakers? On third parties?
. boyd vs. Barlow: John Perry Barlow argues that online speech is different because the Internet is all speech. How does this play into his argument that
governments should keep their hands off the Internet? Do boyd’s claims
support his argument, or undercut it?
. Public Shaming: Before boarding a plane flight to Cape Town in
, Justine
Sacco tweeted, “Going to Africa. Hope I don’t get AIDS. Just kidding. I’m
white!” By the time her flight landed eleven hours later, her tweet had received tens of thousands of angry replies, and users were digging through
her past tweets for other offensive jokes. She was fired from her PR job at
the next day (but later rehired for a similar position). How many other such
stories do you know of? How do they illustrate boyd’s four affordances? Is
mass public shaming by Internet users a good thing or a bad thing?
LOCKDOWN PROBLEM
Several popular video-streaming services, including Lion and Galactic, use a standardized copy-protection technology known as Lockdown. Each video file is encrypted, so that it appears to contain only a large sequence of random bits. An authorized player, however, can use a secret “processing key” to decrypt the sequence
of bits into a viewable movie. The Lockdown Licensing Administrator (“Lockdown
LA”), the organization that controls the Lockdown standard, gives out processing
keys to hardware manufacturers and software developers vendors player manufacturers and requires them to sign licensing agreements that (a) restrict what their
players will do (e.g. no making unencrypted copies of Lockdown-protected content) and (b) promise to keep the processing key secret.
It now appears that a processing key has leaked. An unknown user by the username of BluRazor has managed to discover the processing key by reverse-engineering the Galactic app for Android. They posted the key, the thirty-two-digit
hexadecimal number
-F - - - D- -E - B-D - - -C - - - -C , to
the Video Technical Forum, a web discussion board for digital video programmers.
Three days later, Lockdown LA sued the Video Technical Forum and BluRazor for
breach of trade secrecy and violation of Section
of the Copyright Act, which
prohibits “trafficking” in “devices” designed to facilitate copyright infringement by
disabling “technological protection measures.”* The Forum and BluRazor immediately agreed to the entry of an injunction preventing them from distributing the
0
8
8
6
5
3
3
1
6
0
2
5
6
5
1
4
8
1
0
2
1
5
7
3
4
7
9
2
0
1
1
9
9
* For more on this provision, see infra Chapter .
0
4
3
2
1
Chapter 3: Speech
142
Internet Law
processing key. The Forum
replaced the post with a
brief note that read, “This
post has been deleted at the
request of the Locdown
LA.”
Hu n d r e d s o f V i d e o
Technical Forum users,
however, had already seen
the post and were furious at
what they saw as censorship
of their community. Some
of them had copied down
the number. Dozens of
users reposted the number
in threads all across the
Video Technical Forum. In
addition, a user with the
Forum username Video
Mo n k e y c o n s i d e r e d i t
ridiculous that anyone
could try to “own” a number. They created and posted this image. * Here’s a
partial explanation of the
symbolism:
Beginning at the top, with the goose egg on the right, then proceeding
clockwise we see a roman numeral. Next up is a function key. Then
there’s salt (I wonder what the atomic weight of sodium is?) followed
by another goose egg. The monkey’s holding up a couple of fingers,
and his tail is making a funny shape too! What’s that on the flag?
Down from there we see a tungsten bulb (again, what’s the atomic
weight of tungsten?). ...
If you were advising the Lockdown LA, what actions would you suggest?
1. Violent Speech
This section includes discussion of violent threats.
Our survey of harmful categories of speech begins with one of the most dramatic:
violent speech. The basic rule here is that true threats, i.e. “unequivocal, unconditional and specific expressions of intention immediately to inflict injury,” United
States v. Kelner,
F. d
,
( d Cir.
), are unprotected speech. Such
threats are widely criminalized. The federal threat statute, for example, states,
6
7
9
1
2
0
7
2
2
0
1
0
2
0
1
2
4
3
5
* The image is Mnemonic MonKey Pirate by ApeLad, posted to Flickr at http://
www.flickr.com/photos/apelad/487654055/ and is available under a Creative
Commons Attribution Noncommercial . license. The full license details are available at http://creativecommons.org/licenses/by-nc/2.0/deed.en.
143
“Whoever transmits … any threat to kidnap any person or any threat to injure the
person of another [shall be punished].” U.S.C. §
(c).
Whether a statement constitutes a threat is an objective question, to be judged
from the perspective of a reasonable person. As the Supreme Court explained in
Virginia v. Black,
U.S.
,
– (
):
“True threats” encompass those statements where the speaker means
to communicate a serious expression of an intent to commit an act of
unlawful violence to a particular individual or group of individuals.
The speaker need not actually intend to carry out the threat. Rather, a
prohibition on true threats protects individuals from the fear of violence and from the disruption that fear engenders in addition to protecting people from the possibility that the threatened violence will
occur.
Even though the speaker need not have any intent to carry out the threat, the
speaker must still have some intent to make the threat. In Counterman v. Colorado,
U.S. ,
(
), the Supreme Court held
The State must show that the defendant consciously disregarded a
substantial risk that his communications would be viewed as threatening violence. The State need not prove any more demanding form
of subjective intent to threaten another.
Thus, the First Amendment protects a defendant who made a negligent threat (i.e.,
who did not realize the statement would be interpreted as a threat even though a
reasonable person would have). Instead, according to Counterman, the First
Amendment allows a true-threats prosecution only when the defendant has some
subjective awareness that their communications will be perceived as a threat. This
subjective awareness can be an intent to communicate a threat, knowledge that the
statement would be interpreted as a threat, or a reckless disregard of a known risk
that the statement could be interpreted as a threat.
Another recurring pattern in threat law involves conditional threats: “I will
hurt you unless you do X.” An overly pedantic view of threats might say that victim
hasn’t actually been threatened unless and until they don’t do X, because they have
nothing to fear for now. But this overlooks the other way that threats are harmful,
because they can wrongfully coerce victims into doing things the speaker has no
right to make them do. Extortion is often a crime of threatening.
A related but narrow category of speech that can be restricted under the First
Amendment consists of fighting words: “those which by their very utterance …
tend to incite an immediate breach of the peace.” Chaplinsky v. New Hampshire,
U.S.
(
). In other words, they incite violence against the speaker.
5
7
5
1
8
0
2
3
3
0
2
7
0
2
8
1
0
6
5
7
9
5
5
3
3
4
3
3
2
0
2
9
8
3
6
5
6
2
6
4
9
1
8
0
6
5
0
6
5
QUESTIONS
. Elonis: In Elonis v. United States,
U.S.
(
), Anthony Elonis’s exwife obtained a restraining order based on the tone of some of his Facebook
posts. Elonis responded with another post:
Fold up your [protection-from-abuse order] and put it in your
pocket
Is it thick enough to stop a bullet?
Two FBI agents visited Elonis, after which he posted:
Little Agent lady stood so close
Took all the strength I had not to turn the b**** ghost
1
3
1
Chapter 3: Speech
Internet Law
ffl
fi
fi
Pull my knife, ick my wrist, and slit her throat
Leave her bleedin’ from her jugular in the arms of her partner
Elonis argued that he did not intend to threaten anyone, that the posts were
rap lyrics in the style of Eminem, some of whose raps are violent murderrevenge fantasies. Were Elonis’s Facebook posts threats? And do you think
he intended or knew that they would be perceived as threats?
. Threats? After Counterman, are the following sufficient to support a truethreats conviction?
• A private email by a college student to an unknown Internet pen pal, describing the student’s fantasy of abducting, raping, and murdering another
student in his dorm:
As I said before, my room is right across from the girl’s bathroom. Wiat until late at night. grab her when she goes to unlock
the dorr. Knock her unconscious. and put her into one of those
portable lockers (forget the word for it). or even a du e bag.
Then hurry her out to the car and take her away … What do you
think?
• A Facebook post complaining about the Drug Enforcement Agency:
I’ll kill whoever I deem to be in the way of harmony to the human reace … Policeman all deserve to be tortured to death and
videos made n sent to their families … BE WARNED IF U
PULL LE OVER!! IM LIKE JASON VOORHEES WITH A
BLOODLUST FOR PIG BLOOD.
• A tweet responding to the closure of an airport due to bad weather:
Crap! LAX airport is closed. You’ve got a week and a bit to get
your shit together otherwise I’m blowing the airport sky high!!
. Notice and Desist? Anti-harassment organizations have criticized Counterman for making more difficult to prosecute defendants who unreasonably,
or even delusionally, do not realize that their words could be perceived as
threatening. Is this accurate? What does it take to give a defendant the necessary “conscious[ness]” of this possibility? Consider the following dialogue:
Harasser (to Victim): I hope you die in a re.
Victim (to Police): Hi, I’d like to report a violent threat.
Police (to Victim): Sorry, there’s nothing we can do.
…
Victim (to Harasser): Stop threatening me.
Harasser (to Victim): I hope you die in a re.
Victim (to Police): Hi, I’d like to report a violent threat.
Police (to Harasser): OK, buddy, you’re under arrest for
making violent threats. You have the right to remain silent. …
Have the police correctly interpreted Counterman?
. Gender: Counterman and Elonis are men; they were charged with posting
allegedly threatening messages to women. Is this a coincidence, or is it part
of a larger pattern? Would society be better or worse off with less First
Amendment protection for people like them?
fl
2
3
4
144
145
. Fighting Emails? Will the fighting words exception ever apply online?
2. Speech Integral to Criminal Conduct
6
3
3
5
3
5
9
6
9
1
4
4
4
9
1
3
7
9
9
1
4
3
3
2
3
8
2
1
8
0
0
2
9
5
4
7
7
9
8
9
1
2
2
0
5
0
9
5
8
4
2
When a group of mobsters meet in a social club to plan a bank heist, they are obviously “speaking” to each other in the sense that they are exchanging mutually
meaningful messages. But even the mobsters who don’t personally barge into the
bank brandishing guns can be prosecuted for conspiracy to commit robbery. Robbing the bank is criminal conduct, and the planning is unprotected speech integral
to criminal conduct. The leading case is Giboney v. Empire Storage & Ice Co.,
U.S.
(
). Unionized ice peddlers persuaded a cartel of ice wholesalers to
sell only to union members, then organized an illegal boycott of the only holdout
wholesaler. When a court enjoined them from picketing in front of the holdout,
they objected that this abridged their First Amendment rights. Not so, said the
Supreme Court:
But placards used as an essential and inseparable part of a grave offense against an important public law cannot immunize that unlawful
conduct from state control. … For their sole, unlawful immediate objective was to induce Empire to violate the Missouri law by acquiescing in unlawful demands to agree not to sell ice to nonunion peddlers.
It is true that the agreements and course of conduct here were as in
most instances brought about through speaking or writing. But it has
never been deemed an abridgment of freedom of speech or press to
make a course of conduct illegal merely because the conduct was in
part initiated, evidenced, or carried out by means of language, either
spoken, written, or printed.
Id. at
.
What kinds of speech are “integral” to crimes? Some crimes, like threats and
extortion, can only be carried out through speech. The federal extortion statute,
for example, reads:
Whoever, with intent to extort from any person, firm, association, or
corporation, any money or other thing of value, transmits in interstate
or foreign commerce any communication containing any threat to
injure the property or reputation of the addressee or of another or the
reputation of a deceased person or any threat to accuse the addressee
or any other person of a crime, shall be fined under this title or imprisoned not more than two years, or both.
U.S.C. §
(d).
Other crimes are coordinated with speech: Giboney involved an illegal conspiracy. There is also solicitation: just as you can’t commit arson yourself, you can’t
offer to pay someone to commit arson for you. See United States v. Williams,
U.S.
,
(
) (“Offers to engage in illegal transactions are categorically
excluded from First Amendment protection.”) And then there is incitement: “advocacy … directed to inciting or producing imminent lawless action [that] is likely
to incite or produce such action.” Brandenburg v. Ohio,
U.S.
(
). For
example, Rice v. Paladin
F. d
( th Cir.
) allowed a civil wrongfuldeath suit against the publisher of Hit Man: A Technical Manual for Independent
Contractors, after one reader followed its step-by-step advice in committing a
triple murder for hire.
8
5
1
Chapter 3: Speech
Internet Law
On the other hand, mere advocacy of criminal conduct, without the resulting
likelihood of imminent lawless action, is fully protected under the First Amendment. See, e.g., Brandenburg v. Ohio,
U.S.
,
(
) (reversing the conviction of a Ku Klux Klan leader who said, “We're not a revengent organization,
but if our President, our Congress, our Supreme Court, continues to suppress the
white, Caucasian race, it's possible that there might have to be some revengeance
taken.”) And speech about criminal conduct is usually fully protected. For example,
a New York law that a “convicted criminal's income from works describing his
crime be deposited in an escrow account” for the benefit of victims was unconstitutional. Simon & Schuster, Inc. v. Members of New York State Crime Victims
Board,
U.S.
,
(
), as was a federal law prohibiting the sale of videos
depicting cruelty to animals, United States v. Stevens,
U.S.
(
). Do you
see the difference?
QUESTIONS
. Bad Service? “Give me a refund and a
gift certificate or I’ll post a negative Yelp review!” Extortion?
. Mugshots: mugshots.com and similar websites obtain booking photos from
police departments under public records laws and then post them online
along with the arrestees’ names and arrest details. For a fee of
, an
individual can pay to have their photo and arrest details removed from the
site. Is this extortion? California Civil Code §
. . makes it unlawful
to charge a fee to remove a booking photograph from being published. Is
this constitutional?
The following case includes discussion of suicide and emotional abuse.
COMMONWEALTH V. CARTER
481 Mass. 352 (2019)
1
1
0
0
1
2
9
0
2
9
3
0
$
6
4
9
6
9
1
9
5
1
6
5
1
4
6
4
9
1
8
0
4
9
2
4
7
1
4
4
2
6
1
5
0
1
9
2
0
3
$
2
4
7
4
1
9
9
1
8
0
1
5
0
1
2
0
5
4
1
0
3
2
1
3
Kafker, Justice:
At age seventeen, Michelle Carter was charged with involuntary manslaughter
as a youthful offender for the suicide death of Conrad Roy, age eighteen [The following recitation of facts is taken from an earlier opinion in the same case, Commonwealth v. Carter (Carter I),
Mass.
(
).] On the afternoon of July
,
, an officer with the Fairhaven police department located the deceased in
his truck, parked in a store parking lot. The medical examiner concluded that the
victim had died after inhaling carbon monoxide that was produced by a gasoline
powered water pump located in the truck. The manner of death was suicide.
The victim had been receiving treatment for mental health issues since
. In
, the victim attempted to commit suicide by overdosing on acetaminophen. A
friend saved his life by contacting emergency services. …
The victim and the defendant met in
and had been dating at various times
during that period, including at the time of the victim's death. Because they did
not live in the same town, the majority of their contact took place through the exchange of voluminous text messages and cellular telephone calls. The grand jury
heard testimony and were presented with transcripts concerning the content of
those text messages in the minutes, days, weeks, and months leading up to the defendant's suicide. The messages revealed that the defendant was aware of the victim's history of mental illness, and of his previous suicide attempt, and that much
of the communication between the defendant and the victim focused on suicide.
0
1
2
1
2
146
Chapter 3: Speech
147
1
1
6
3
6
4
1
0
2
2
1
Specifically, the defendant encouraged the victim to kill himself, instructed him as
to when and how he should kill himself, assuaged his concerns over killing himself
and chastised him when he delayed doing so. The theme of those text messages
can be summed up in the phrase used by the defendant four times between July
and July ,
(the day on which the victim committed suicide): “You just
[have] to do it.” …
c. Free speech claims.
The defendant argues that her conviction of involuntary manslaughter violated
her right to free speech under the First Amendment … . We disagree and thus reaffirm our conclusion in Carter I that no constitutional violation results from convicting a defendant of involuntary manslaughter for reckless and wanton, pressuring text messages and phone calls, preying upon well-known weaknesses, fears,
anxieties and promises, that finally overcame the willpower to live of a mentally ill,
vulnerable, young person, thereby coercing him to commit suicide. …
The crime of involuntary manslaughter proscribes reckless or wanton conduct
causing the death of another. The statute makes no reference to restricting or regulating speech, let alone speech of a particular content or viewpoint: the crime is
directed at a course of conduct, rather than speech, and the conduct it proscribes
is not necessarily associated with speech. The defendant cannot escape liability
just because she happened to use words to carry out her illegal act. Although numerous crimes can be committed verbally, they are intuitively and correctly understood not to raise First Amendment concerns. It has never been deemed an
abridgment of freedom of speech to make a course of conduct illegal merely because the conduct was in part initiated, evidenced, or carried out by means of language, either spoken, written, or printed.
The defendant contends nonetheless that prosecuting and convicting her of
involuntary manslaughter for encouraging suicide effected a content-based restriction on speech that does not withstand strict scrutiny.
In particular, she acknowledges the Commonwealth's compelling interest in
preserving human life but argues that we failed to determine in Carter I that the
restriction on speech was narrowly tailored to further that interest. We disagree.
The only speech made punishable in Carter I was speech integral to a course of
criminal conduct, that is, a “systematic campaign of coercion on which the virtually present defendant embarked — captured and preserved through her text messages — that targeted the equivocating young victim's insecurities and acted to
subvert his willpower in favor of her own,” Carter I, supra at
. Other involuntary manslaughter prosecutions and convictions have similarly targeted a course of
criminal conduct undertaken through manipulative wanton or reckless speech
directed at overpowering the will to live of vulnerable victims. …
Regardless, even if we were to apply strict scrutiny to the verbal conduct at issue because it might implicate other constitutionally protected speech regarding
suicide or the end of life, we would conclude that the restriction on speech here
has been narrowly circumscribed to serve a compelling purpose. As we explained
in Carter I, and reemphasize today, this case does not involve the prosecution of
end-of-life discussions between a doctor, family member, or friend and a mature,
terminally ill adult confronting the difficult personal choices that must be made
when faced with the certain physical and mental suffering brought upon by impending death. Nor does it involve prosecutions of general discussions about euthanasia or suicide targeting the ideas themselves. Nothing in Carter I, our decision today, or our earlier involuntary manslaughter cases involving verbal conduct
Internet Law
suggests that involuntary manslaughter prosecutions could be brought in these
very different contexts without raising important First Amendment concerns. …
Only the wanton or reckless pressuring of a person to commit suicide that overpowers that person's will to live has been proscribed.
QUESTIONS
. Speakers and Listeners: Would convicting Carter or freeing her be more respectful of Roy’s autonomy to make important life decisions?
. #IceCreamChallenge: Louisiana has a statute prohibiting criminals from posting images of themselves committing their crimes “for the purpose of gaining
notoriety, publicity, or the attention of the public.” § La. Rev. Stat.
:
. (A). It was enacted to deter people from taking part in dangerous
and illegal viral video challenges, such as the “knockout game” (try to knock
out an unsuspecting victim with one punch) and the “ice cream challenge”
(open a tub of ice cream in a store, lick it, and return it to the shelf ). Is this
law constitutional?
. Livestreams: On March ,
, a white supremacist entered the Al Noor
Mosque in Christchurch, New Zealand during Friday prayers and opened
fire, killing
people and wounding . He live-streamed the attack to
Facebook Live for
minutes from a camera attached to his helmet; Facebook took down the video minutes later. New Zealand classified the video
as “objectionable,” making it a criminal offense to possess or distribute. Less
than a month later, Australia enacted a law requiring social media companies to “ensure the expeditious removal” of such live-streams, i.e. while they
are underway. Would these laws be constitutional in the United States?
. Pro-Ana: Most scientists and doctors regard anorexia nervosa — a strong desire to be extremely thin by restricting one’s food intake — as an eating disorder that carries severe health risks. But some online “pro-ana” communities disagree: they provide members with advice on how to lose weight, endorsements of an anorexic lifestyle, and supportive discussion forums. Is this
protected speech under the First Amendment?
. The Nuremburg Files: An anti-abortion website features the names of doctors
who perform abortions, along with their home addresses and photographs.
Beneath each picture, in an Old West-style font, is the logo “WANTED.” A
legend at the top of the page explains, “Black font (working); Greyed-out
Name (wounded); Strikethrough (fatality).” Incitement? True threat?
3. False Speech
4
1
7
2
1
1
0
5
2
9
1
7
9
9
1
0
0
7
2
2
1
5
1
7
6
7
1
5
4
0
7
9
4
4
8
7
1
0
1
There is no general First Amendment exception for false speech. Instead, the
Supreme Court has generally allowed the government to prohibit lies only when
there is some “legally cognizable harm associated with a false statement.” United
States v. Alvarez,
U.S.
,
(
). In Alvarez, Xavier Alvarez falsely
claimed to have played hockey for the Detroit Red Wings and to have been awarded the Congressional Medal of Honor. He was convicted under the Stolen Valor
Act,
U.S.C. §
, which made it a crime to lie about having received a United
States military honor. But the Court held the Act unconstitutional. According to a
three-Justice plurality, Alvarez’s lies “were but a pathetic attempt to gain respect
that eluded him,” not an attempt “to secure employment or financial benefits or
admission to privileges reserved for those who had earned the Medal.” Id. at
.
4
1
2
1
3
5
4
148
149
Another two Justices ran through a list of laws prohibiting various forms of lying –
including fraud, perjury, impersonation of public officials, and trademark infringement – and found that “they limit the scope of their application, sometimes
by requiring proof of specific harm to identifiable victims, sometimes by specifying that the lies be made in contexts in which a tangible harm to others is especially likely to occur; and sometimes by limiting the prohibited lies to those that are
particularly likely to produce harm.” Id. at
.
Suppose Alvarez had sent emails claiming to be a Medal of Honor winner in
possession of
million stolen from the Red Wings, and offering to give the
recipient a
finder’s fee if they wired him
,
to help unfreeze the funds.
That would have been fraud, and he could have been prosecuted: the financial
angle qualifies as “specific harm to identifiable victims.” (Why are frauds like this
so common online?) The elements of fraud are rigorous, but commercial speech
can be regulated if it is merely misleading. So, for example, the Federal Trade
Commission requires Instagram influencers to disclose when they are being paid
to post about products. A sponsored post with no #ad disclaimer is not exactly
false, but it could mislead consumers into thinking that a model is disinterestedly
endorsing the dress she is wearing.
As another example of false speech that can be criminalized with no great difficulty, consider “swatting”: the practice of provoking an armed police response
against an unsuspecting victim by reporting a non-existent emergency. For example, in
, a man identifying himself as “Brian” called Wichita police and
claimed to be holding his family hostage. Officers who responded to the address he
gave shot and killed the man who came to the door. But “Brian” was actually a prolific swatter named Tyler Barriss, who lived in Los Angeles and had been recruited
online by a Call of Duty player who wanted revenge on another player over a .
wager. Barris pleaded guilty to making a false report resulting in death, see
U.S.C. §
(a)( )(C), among other counts. Is there a reason that swatting has
become dramatically more common in the Internet age?
QUESTION
James McAllister creates a Twitter profile under the name “Paul Metzler” and
amasses a following of
,
users by posting political memes. One week before
an election, he posts a photo of a woman standing in front of a “Flick for President” yard sign, with the caption “Avoid the Line. Vote from Home. Text ‘Tracy’ to
.” (The United States has never allowed for voting by text message.) If McAllister is indicted for election interference, will Alvarez bar the prosecution?
0
8
5
1
1
$
0
0
0
0
1
$
4
3
7
fi
0
0
0
0
0
1
0
1
5
1
$
%
8
0
1
7
3
1
0
0
1
2
5
2
8
9
5
5
9
9
5
RESTATEMENT (SECOND) OF TORTS [DEFAMATION]
§
– Elements [of Defamation] Stated
To create liability for defamation there must be:
(a) a false and defamatory statement concerning another;
(b) an unprivileged publication to a third party;
(c) fault amounting at least to negligence on the part of the publisher; and
(d) [harm].
§
– Defamatory Communication De ned
A communication is defamatory if it tends so to harm the reputation of another as
to lower him in the estimation of the community or to deter third persons from
associating or dealing with him.
5
5
Chapter 3: Speech
150
Internet Law
§
– Libel and Slander Distinguished
( ) Libel consists of the publication of defamatory matter by written or printed
words, by its embodiment in physical form or by any other form of communication that has the potentially harmful qualities characteristic of written
or printed words.
( ) Slander consists of the publication of defamatory matter by spoken words,
transitory gestures or by any form of communication other than those stated
in Subsection ( ).
( ) The area of dissemination, the deliberate and premeditated character of its
publication and the persistence of the defamation are factors to be considered in determining whether a publication is a libel rather than a slander.
§
A – Liability for Publication of Injurious Falsehood—General Principle
One who publishes a false statement harmful to the interests of another is subject
to liability for pecuniary loss resulting to the other if
(a) he intends for publication of the statement to result in harm to interests of
the other having a pecuniary value, or either recognizes or should recognize
that it is likely to do so, and
(b) he knows that the statement is false or acts in reckless disregard of its truth
or falsity.
§
– Expressions of Opinion
A defamatory communication may consist of a statement in the form of an opinion, but a statement of this nature is actionable only if it implies the allegation of
undisclosed defamatory facts as the basis for the opinion.
4
7
9
1
1
7
7
5
7
0
4
5
3
0
6
2
9
3
1
2
3
4
5
5
2
8
9
5
1
8
1
6
4
9
5
4
6
7
1
7
3
9
7
4
3
1
7
3
2
2
7
1
4
5
1
8
3
6
6
2
1
3
2
6
5
6
5
NOTE ON DEFAMATION
In a few crucial respects, the Restatement (Second) of Torts’s sections on defamation cannot be taken at face value. The issue is that the First Amendment puts
some sharp limits on when defamatory speech can be actionable. Most importantly, where the plaintiff is a public figure – i.e., someone who has “pervasive fame or
notoriety” or who “voluntarily injects himself or is drawn into a particular public
controversy,” Gertz v. Robert Welch, Inc.,
U.S.
,
(
) – he or she has
the burden of showing not just negligence but actual malice – i.e., that the defendant knew the speech was false or acted with reckless disregard of its possible falsity. The actual-malice rule is commonly identified with the case that introduced
it, New York Times Co. v. Sullivan,
U.S.
(
), in which the Supreme
Court protected the New York Times from defamation liability for some minor
misstatements in an advertisement criticizing segregationist Southern officials. A
plurality of the Supreme Court has held that the actual-malice standard does not
apply to “speech on matters of purely private concern.” Dun & Bradstreet, Inc. v.
Greenmoss Builders, Inc.,
U.S.
,
(
).
Online defamation also raises issues of when a communication is “published.”
Under the Restatement, “Any one edition of a book or newspaper, or any one radio
or television broadcast, exhibition of a motion picture or similar aggregate communication” and thus counts as a single publication that starts the statute of limitations running. Restatement (Second) of Torts §
A. Courts have consistently applied this rule to Internet publications. E.g., Nationwide Bi-Weekly Admin., Inc. v. Belo Corp.,
F. d
,
( th Cir.
). That is, rather than
treating a defamatory blog post as a series of separate defamatory publications,
one to each reader over the years, the courts expect a plaintiff to bring suit when
151
the post first goes live. This is a defamation-specific rule. By way of contrast, copyright law treats each new download as a separate act of infringement with its own
statute of limitations period. E.g., APL Microscopic, LLC v. United States,
Fed.
Cl.
(
).
4
4
1
8
1
2
8
1
0
2
9
1
0
#
2
1
0
9
1
9
1
5
0
8
0
6
#
2
9
5
1
1
2
1
9
7
1
3
2
6
0
1
0
2
2
8
1
3
4
9
0
8
8
4
.
8
.
9
.
9
.
3
QUESTIONS
Twibel: On May ,
, Amanda Bonnen used Twitter to tweet:
@JessB
You should just come anyway. Who said sleeping in
a moldy apartment was bad for you? Horizon realty thinks it’s
okay.
Horizon Group Management, her former landlord, sued for defamation. Is
Bonnen’s
-character tweet legally actionable, or is this just par for the
course on Twitter?
Public Figures? In
, Andy Warhol wrote, “In the future, everyone will be
world-famous for
minutes.” In
, the musician Momus added, “In the
future everyone will be famous for fifteen people.” Were they just describing
X and Facebook, respectively? Is everyone a public figure on the Internet?
Amateur Hour: Nancy Stratemeyer is a TikTok detective. She does Internet
research on unsolved murders and posts videos in which she explains her
theories about unsolved murders. In one series of twenty-eight videos, she
presents at great length a theory that college professor Carolyn Drew killed
four students over a period of years to cover up her affair with one of them.
As she explains in detail, Stratemeyer’s theory is based upon her “supernatural intuition,” numerological coincidences such as common digits in the
students’ license plates, and her belief that Drew has been leading a double
life as an insurance agent for years under the name Franklin McFarlane.
Will defamation law provide Drew with meaningful recourse?
Yeah, Well, You Know, That's Just, Like, Your Opinion, Man: Distinguishing
statements of fact from statements of opinion can be tricky. In Boulger v.
Woods,
F. Supp. d
(S.D. Ohio
), the actor James Woods
tweeted “So-called Trump ‘Nazi’ is a BernieSanders agitator/operative?”
This, held the court, was protected opinion: it “invite[d] the reader to reach
his or her own conclusions” as to whether a photograph of a woman giving a
Nazi salute depicted the plaintiff. But in Unsworth v. Musk, No. : cv-SVW-JC (C.D. Cal. May ,
), the businessman Elon Musk
tweeted “Sorry pedo guy, you really did ask for it.” This, held the court, was
an actionable statement of fact that falsely claimed the plaintiff was a pedophile. Is the lesson here that you should always end your defamatory
tweets with a question mark? What is it about Twitter/X that seems to generate these kinds of cases?
The Defaming Machine: Charlie MacKenzie, a poet, and Harriet Michaels, a
city councilmember, are about to meet for a first date. MacKenzie asks an AI
chatbot, “Tell me something interesting about Harriet Michaels.” The chatbot’s response, which is based on general patterns of English usage on the
Internet, and not on any information about Michaels in particular, is that
she is an axe murderer who has killed multiple romantic partners. If
Michaels sues Myers Technologies, the creator of the chatbot, for defamation, what result?
.
0
1
2
4
3
5
Chapter 3: Speech
Internet Law
. Negative Reviews: The owners of the Kebapi Cafe have been frustrated by a
series of bad Yelp reviews, which they suspect were written by the owners of
the competing Cafe Ćevapi across the street. They are considering having all
their customers sign an agreement stating, “By dining here, you agree not to
post online reviews of this restaurant without permission of management.”
Is this a good idea? Congress thought not: the Consumer Review Fairness
Act of
, U.S.C. § b, voids provisions in form contracts that purport
to restrict consumers’ rights to publish reviews. How else should businesses
deal with negative (often anonymous) online reviews?
. Defamation Is Forever: The New York World publishes in its print edition and
on its website a story falsely stating that union leader Spot Conlon physically
assaulted a strikebreaker, Michael Wiesel. Several years later, Sarah Jacobs
posts a tweet reading “Reading about Spot Conlon’s history” with a hyperlink to the story on the World website. Jack Kelly clicks a “share on Facebook” button on the story, which posts to his News Feed an excerpt from
story including the false statement. Can Conlon now sue Jacobs, Kelly, and
the World, or are his claims barred by the single publication rule?
. Is Defamation Dead? Some commentators have argued that the tort of
defamation is outdated in the digital world and should be abolished. They
claim that victims can now take to the Internet to tell their side of the story,
so they don’t need legal remedies. Do you agree?
4. Harassment
This section includes discussion of harassment.
“Harassment” is not a recognized category of speech under standard First
Amendment analyses. Instead, laws protecting people from harassing conduct
must fit within existing doctrinal categories. As the following materials show, this
can make it difficult to draft such laws constitutionally.
§
RESTATEMENT (SECOND) OF TORTS [EMOTIONAL DISTRESS]
– Outrageous Conduct Causing Severe Emotional Distress
( ) One who by extreme and outrageous conduct intentionally or recklessly
causes severe emotional distress to another is subject to liability for such
emotional distress, and if bodily harm to the other results from it, for such
bodily harm. …
SNYDER V. PHELPS
562 U.S. 443 (2011)
5
5
9
1
0
0
0
1
5
4
0
0
3
0
5
0
1
2
6
1
0
2
1
6
Chief Justice Roberts delivered the opinion of the Court. …
I…
Fred Phelps founded the Westboro Baptist Church in Topeka, Kansas, in
. The
church’s congregation believes that God hates and punishes the United States for
its tolerance of homosexuality, particularly in America’s military. [The church
picketed the funeral of Marine Lance Corporal Matthew Snyder, who was killed in
Iraq. The picketing took place on public land between ,
feet from the funeral
service and
to
feet from the funeral procession; the picketers “complied
with police instructions, … did not yell or use profanity, and there was no violence
associated with the picketing.”] Although Snyder testified that he could see the
4
6
8
7
152
Chapter 3: Speech
153
2
7
4
8
8
9
1
6
4
1
8
5
1
$
8
4
9
5
8
9
1
0
6
7
9
9
4
2
7
$
tops of the picket signs as he drove to the funeral, he did not see what was written
on the signs until later that night, while watching a news broadcast covering the
event. [Snyder sued Phelps and Westboro in federal court for state-law tort claims
including intentional infliction of emotional distress, and obtained a jury verdict
for . in compensatory damages and
million in punitive damages.]
II
To succeed on a claim for intentional infliction of emotional distress in Maryland,
a plaintiff must demonstrate that the defendant intentionally or recklessly engaged in extreme and outrageous conduct that caused the plaintiff to suffer severe
emotional distress. The Free Speech Clause of the First Amendment – “Congress
shall make no law ... abridging the freedom of speech” – can serve as a defense in
state tort suits, including suits for intentional infliction of emotional distress. See,
e.g., Hustler Magazine, Inc. v. Falwell,
U.S.
(
).
Whether the First Amendment prohibits holding Westboro liable for its speech
in this case turns largely on whether that speech is of public or private concern, as
determined by all the circumstances of the case. … The First Amendment reflects a
profound national commitment to the principle that debate on public issues
should be uninhibited, robust, and wide-open. … Accordingly, speech on public
issues occupies the highest rung of the hierarchy of First Amendment values, and
is entitled to special protection.
Not all speech is of equal First Amendment importance, however, and where
matters of purely private significance are at issue, First Amendment protections
are often less rigorous. That is because restricting speech on purely private matters
does not implicate the same constitutional concerns as limiting speech on matters
of public interest: “There is no threat to the free and robust debate of public issues; there is no potential interference with a meaningful dialogue of ideas”; and
the “threat of liability” does not pose the risk of “a reaction of self-censorship” on
matters of public import. Dun & Bradstreet, Inc. v. Greenmoss Builders, Inc.,
U.S.
,
(
). …
Speech deals with matters of public concern when it can be fairly considered as
relating to any matter of political, social, or other concern to the community, or
when it is a subject of legitimate news interest; that is, a subject of general interest
and of value and concern to the public. …
The content of Westboro’s signs plainly relates to broad issues of interest to society at large, rather than matters of“purely private concern. The placards read
“God Hates the USA/Thank God for / ,” “America is Doomed,” “Don’t Pray for
the USA,” “Thank God for IEDs,” “Fag Troops,” “Semper Fi Fags,” “God Hates Fags,”
“Maryland Taliban,” “Fags Doom Nations,” “Not Blessed Just Cursed,” “Thank God
for Dead Soldiers,” “Pope in Hell,” “Priests Rape Boys,” “You’re Going to Hell,” and
“God Hates You.” While these messages may fall short of refined social or political
commentary, the issues they highlight – the political and moral conduct of the
United States and its citizens, the fate of our Nation, homosexuality in the military,
and scandals involving the Catholic clergy – are matters of public import. The
signs certainly convey Westboro’s position on those issues, in a manner designed,
unlike the private speech in Dun & Bradstreet [involving a particular individual’s
credit report], to reach as broad a public audience as possible. And even if a few of
the signs – such as “You’re Going to Hell” and “God Hates You” – were viewed as
containing messages related to Matthew Snyder or the Snyders specifically, that
would not change the fact that the overall thrust and dominant theme of Westboro’s demonstration spoke to broader public issues. …
Internet Law
Westboro’s choice to convey its views in conjunction with Matthew Snyder’s
funeral made the expression of those views particularly hurtful to many, especially
to Matthew’s father. The record makes clear that the applicable legal term – “emotional distress” – fails to capture fully the anguish Westboro’s choice added to Mr.
Snyder’s already incalculable grief. But Westboro conducted its picketing peacefully on matters of public concern at a public place adjacent to a public street. Such
space occupies a special position in terms of First Amendment protection. We
have repeatedly referred to public streets as the archetype of a traditional public
forum, noting that time out of mind public streets and sidewalks have been used
for public assembly and debate. … Simply put, the church members had the right
to be where they were. …
Given that Westboro’s speech was at a public place on a matter of public concern, that speech is entitled to “special protection” under the First Amendment.
Such speech cannot be restricted simply because it is upsetting or arouses contempt. If there is a bedrock principle underlying the First Amendment, it is that
the government may not prohibit the expression of an idea simply because society
finds the idea itself offensive or disagreeable. Texas v. Johnson,
U.S.
,
(
). Indeed, “the point of all speech protection ... is to shield just those choices
of content that in someone’s eyes are misguided, or even hurtful.” Hurley v. IrishAmerican Gay, Lesbian and Bisexual Group of Boston, Inc.,
U.S.
,
(
).
The jury here was instructed that it could hold Westboro liable for intentional
infliction of emotional distress based on a finding that Westboro’s picketing was
“outrageous.” “Outrageousness,” however, is a highly malleable standard with “an
inherent subjectiveness about it which would allow a jury to impose liability on the
basis of the jurors’ tastes or views, or perhaps on the basis of their dislike of a particular expression.” Hustler,
U.S. at . In a case such as this, a jury is unlikely
to be neutral with respect to the content of the speech, posing a real danger of becoming an instrument for the suppression of vehement, caustic, and sometimes
unpleasant expression. Such a risk is unacceptable; “in public debate [we] must
tolerate insulting, and even outrageous, speech in order to provide adequate
breathing space to the freedoms protected by the First Amendment.” Boos v. Barry,
U.S.
,
(
). What Westboro said, in the whole context of how
and where it chose to say it, is entitled to “special protection” under the First
Amendment, and that protection cannot be overcome by a jury finding that the
picketing was outrageous.
For all these reasons, the jury verdict imposing tort liability on Westboro for
intentional infliction of emotional distress must be set aside. …
Justice Alito, dissenting:
Our profound national commitment to free and open debate is not a license for
the vicious verbal assault that occurred in this case. …
4
4
1
7
4
5
7
7
9
5
3
5
1
9
5
1
4
5
5
5
5
8
4
8
8
9
1
2
2
3
2
1
3
5
8
9
5
8
9
4
9
9
1
QUESTIONS
. IIED: After Snyder, is the IIED tort a dead letter?
. Online Protests: What result if Westboro’s “picketing” takes place online
rather than on a public street?
1
2
1
154
Chapter 3: Speech
155
LEBO V. STATE
474 S.W.3d 402 (Tex. Ct. App. 2015)
7
7
0
2
3
7
7
1
0
0
4
4
0
0
2
2
2
4
4
2
1
0
2
6
2
0
1
0
2
2
1
0
2
1
2
2
2
1
6
0
6
2
5
3
2
2
2
3
3
1
0
d
2
n
n
6
u
1
o
o
i
s
r
0
s
g
1
u
k
0
c
c
2
s
i
a
7
Martinez, Justice:
Sean Lebo appeals his conviction for harassment through electronic communications, a Class B Misdemeanor. Lebo asserts on appeal that the statute proscribing harassment by electronic communications is unconstitutional on its face, and
therefore his conviction is void and must be reversed. We disagree, and affirm the
trial court's judgment.
B
In
, Bexar County Sheriff 's Detective Jason Layman investigated a criminal
case involving Lebo. On December ,
, Lebo contacted Layman by email and
accused him of destroying evidence and being a felon, corrupt, and incompetent.
Lebo threatened to seek Layman's arrest. Two days later, Lebo emailed Layman
twice, again accusing him of being corrupt, threatening to sue Layman and have
him arrested, and stating, “Do you know what they do to Police Officers in
prison?” On December
,
, Lebo sent five emails to Layman calling him
names, threatening him with civil and criminal proceedings, and threatening his
family. Layman responded to Lebo by email on December
,
, requesting
that Lebo stop sending emails for non-official business and referring him to the
appropriate contact to make a complaint about his professional conduct. Lebo
continued sending Layman threatening and combative emails during
, along
with letters through the regular mail. Layman received a total of almost
emails
from Lebo.
On April ,
, Lebo was charged with harassing Detective Layman through
repeated electronic communications [under Tex. Penal Code Ann. § . (a)( ),
which states, “A person commits an offense if, with intent to harass, annoy, alarm,
abuse, torment, or embarrass another, the person … sends repeated electronic
communications in a manner reasonably likely to harass, annoy, alarm, abuse,
torment, embarrass, or offend another.”] …
D
…
Constitutionality of Section 42.07(a)(7) …
Lebo’s overbreadth and vagueness challenges hinge on whether section
. (a)
( ) proscribes communications which fall within the scope of protected free
speech. …
In Scott v. State,
S.W. d
, (Tex .Crim. App.
), the court addressed
the question of whether the telephone harassment portion of section . implicates the free-speech guarantee of the First Amendment in the context of an overbreadth/vagueness challenge. The court first analyzed the scope of protection
granted by the First Amendment's free speech clause, stating that it “generally protects the free communication and receipt of ideas, opinions, and information” but
also noting that “[t]he State may lawfully proscribe communicative conduct (i.e.,
the communication of ideas, opinions, and information) that invades the substantial privacy interests of another in an essentially intolerable manner.” Id. (emphasis added). … The court interpreted the statute's plain text as requiring the actor to
have the specific intent “to inflict harm on the victim in the form of one of the listed types of emotional distress.” Id. In addition, the court stated the statute requires
the actor to make repeated telephone calls to the victim, and to make the calls in a
manner reasonably likely to harass, annoy, alarm, abuse, torment, embarrass, or
offend an average person. Id. (also noting the statute's text does not require the use
Internet Law
4
7
0
2
4
4
4
7
7
0
2
4
4
7
0
2
4
4
5
7
6
6
0
7
4
7
9
3
6
6
7
7
0
0
7
2
2
2
of spoken words). The court then concluded that section . (a)( ) does not implicate the First Amendment's guarantee of free speech. Id. The court explained its
reasoning as follows:
The statutory subsection, by its plain text, is directed only at persons
who, with the specific intent to inflict emotional distress, repeatedly
use the telephone to invade another person's personal privacy and do
so in a manner reasonably likely to inflict emotional distress. Given
that plain text, we believe that the conduct to which the statutory subsection is susceptible of application will be, in the usual case, essentially noncommunicative, even if the conduct includes spoken words.
That is to say, in the usual case, persons whose conduct violates §
. (a)( ) will not have an intent to engage in the legitimate communication of ideas, opinions, or information; they will have only the
intent to inflict emotional distress for its own sake. To the extent that
the statutory subsection is susceptible of application to communicative conduct, it is susceptible of such application only when that
communicative conduct is not protected by the First Amendment because, under the circumstances presented, that communicative conduct invades the substantial privacy interests of another (the victim)
in an essentially intolerable manner.
Id. at
– .…
We consider the free-speech analysis in Scott equally applicable to section
. (a)( ). The statutory text in subsection (a)( ) dealing with electronic communications is identical to the text in subsection (a)( ) dealing with telephone
communications, with the sole exception that (a)( ) provides an alternative manner of committing the offense by making repeated telephone calls “anonymously.”
Tex. Penal Code Ann. § . (a)( ) (providing that a person commits harassment
by causing the telephone of another to ring repeatedly or by making repeated telephone communications anonymously or in a manner reasonably likely to harass,
annoy, alarm, abuse, torment, embarrass, or offend another). The difference in text
is inconsequential to the First Amendment analysis. In addition, the Scott analysis
dealt with the same manner of committing harassment as Lebo's case. See Scott,
S.W. d at
(defendant was not charged with making repeated anonymous
calls, but with making repeated calls in a manner likely to harass, annoy, alarm,
etc.). All of the subsections of section
.
have the same subjective intent requirement, i.e., that the actor engage in the particular form of communicative
conduct with the specific intent to “inflict harm on the victim in the form of one of
the listed types of emotional distress,” i.e., “harass, annoy, alarm, abuse, torment,
embarrass, or offend.” Therefore, an actor whose email communications run afoul
of subsection (a)( ) will have no more of an intent to engage in legitimate communication of ideas, opinions, or information than an actor whose telephone calls
violate subsection (a)( ). As Scott stated with respect to telephone harassment,
repeated emails made with the specific intent to inflict one of the designated types
of emotional distress “for its own sake” invade the substantial privacy interests of
the victim in “an essentially intolerable manner;” thus, they are not the type of legitimate communication that is protected by the First Amendment. Based on this
reasoning, we hold that the electronic communications proscribed by subsection
(a)( ) do not implicate protected speech under the First Amendment. …
2
4
4
3
156
157
QUESTIONS
. Circularity: Critique the following argument: “Section . criminalizes electronic harassment, so Lebo’s emails are speech integral to criminal conduct,
and therefore are unprotected by the First Amendment.”
. Telephone vs. Email: Lebo treats emails and phone calls as basically indistinguishable. Is that right?
. One-to-One vs. One-to-Many: Lebo sent emails directly to Layman. What result if Lebo posted his comments on his blog, where anyone could read
them? Should the choice of a one-to-one medium like email or a one-tomany medium like a blog matter if the speaker’s intent is the same?
5. Sexually Explicit Speech
This section includes discussion of sexual conduct and exploitation of minors.
9
2
5
fi
7
fi
0
2
4
3
7
9
1
5
1
2
5
2
3
9
1
6
2
9
4
1
ff
7
5
5
fi
8
1
ff
4
9
3
0
0
0
2
7
7
2
fi
The courts have recognized several categories of harmful sexually explicit speech:
• Obscenity is material that fails the three-part Miller test:
“(a) whether the average person, applying contemporary community standards would nd that the work, taken as a whole,
appeals to the prurient interest; (b) whether the work depicts or
describes, in a patently o ensive way, sexual conduct speci cally
de ned by the applicable state law; and (c) whether the work,
taken as a whole, lacks serious literary, artistic, political, or scienti c value.” Miller v. California,
U.S. (
).
Obscene material can constitutionally be regulated because it has no
redeeming social value and its o ensiveness provides a positive justi cation
for banning it. The mere possession of obscenity cannot be criminalized, see
Stanley v. Georgia,
U.S.
(
), because doing do would intrude on
the privacy of the home, but the government can constitutionally prohibit its
distribution and sale.
• The states have traditionally prohibited public nudity: exposing one’s genitals in a public place. There are at least three possible rationales. The most
libertarian is that these bans protect others from being offended; the most
conservative is that public nudity is immoral; somewhere in the middle is a
concern about “secondary effects,” such as increased crime in red-light districts near adult theaters. The speech angle comes in because some nudity is
expressive: e.g., nude protests and nude dancing. In Erie v. Pap's A. M.,
U.S.
(
), a plurality of the Court upheld a ban on nude dancing by
applying the O’Brien test for conduct restrictions that incidentally burden
speech.
• Closely related is indecent exposure: showing your genitals to someone (especially a child) who does not want to see them, whether it takes place in
public or private. State v. Decker, in the Jurisdiction chapter, considers how
to apply an indecent-exposure statute to online conduct.
• Child sexual abuse material (CSAM, frequently also called “child pornography”) is material that depicts children engaging in sexual acts. It can constitutionally be prohibited outright – it is contraband – and mere possession
of it is criminal. See, e.g.,
U.S.C. §
A. Two rationales are usually given
fi
1
3
2
Chapter 3: Speech
4
3
2
2
0
0
5
2
3
5
8
1
0
8
5
0
2
4
8
6
5
9
2
2
0
0
5
2
8
2
5
4
3
5
3
2
0
3
0
0
5
5
0
5
6
3
5
1
9
9
1
5
7
5
0
0
0
6
0
5
0
6
2
6
0
1
9
0
0
QUESTIONS
. Whose Standards? Which community’s “contemporary community standards”
define whether material appeals to the prurient interest under the Miller
test? Pre-Internet law was clear:
There is no constitutional barrier under Miller to prohibiting communications that are obscene in some communities under local standards even though they are not obscene in others. If the speaker’s audience is comprised of different communities with different local
standards, the speaker ultimately bears the burden of complying with
the prohibition on obscene messages.
Ashcroft v. American Civil Liberties Union,
U.S.
,
(
). The
rule was developed in an age of in-person sales and postal mail. Is it still
workable for email and the web?
. Consenting Adults? Justice Scalia once wrote, “The purpose of Indiana's nudity law would be violated, I think, if
,
fully consenting adults crowded
into the Hoosier Dome to display their genitals to one another, even if there
were not an offended innocent in the crowd.” Barnes v. Glen Theatre, Inc.,
U.S.
,
(
) (Scalia, J., concurring in the judgment). What if
these “ ,
fully consenting adults” are crowded into one Zoom session?
What if they are having a fully clothed discussion of generally accepted accounting principles when a naked hacker enters the session and exposes
themself to the others?
. Computer-Generated Pornography: The Child Pornography Prevention Act of
(CPPA) prohibited “any visual depiction, including any … computergenerated image or picture” that “is, or appears to be, of a minor engaging in
sexually explicit conduct.” In Ashcroft v. Free Speech Coalition,
U.S.
(
), the Supreme Court held that this portion of the CPPA was unconstitutional, because it could apply to “virtual child pornography,” which was
generated without the involvement of any actual child, and some such material might have serious redeeming value. Is this reasoning sound? What effects will it have on CSAM prosecutions if “real” and “virtual” CSAM are vi-
9
1
2
5
1
Internet Law
for this rule: “First, as a permanent record of a child’s abuse, the continued
circulation itself would harm the child who had participated. … Second, because the traffic in child pornography was an economic motive for its production, the State had an interest in closing the distribution network.”
Ashcroft v. Free Speech Coalition,
U.S.
(
). Many CSAM prosecutions, like many drug possession prosecutions, turn on highly factual
questions of whether the defendant had sufficient knowledge of or control
over the material to “possess” it. The government can prohibit pandering
(offering CSAM to others) and solicitation (asking someone else for
CSAM), even if the material being transferred is not actually CSAM, based
on “the principle that offers to give or receive what it is unlawful to possess
have no social value and thus, like obscenity, enjoy no First Amendment
protection. United States v. Williams,
U. S.
,
(
).
Note what isn’t on this list: “pornography.” It’s not usually a meaningful category
for First Amendment purposes. Instead, arguments typically need to work within
one of the above three categories – that the material has no redeeming value, that
it depicts children, or that it is being shown to minors.
2
3
158
159
sually indistinguishable? How should Free Speech Coalition apply to images
of actual children’s faces Photoshopped onto images of adults’ bodies?
. Underage Sexting: The definition of CSAM contemplates situations in which
an adult abuses a minor by circulating sexual images of them or sending sexual material to them, respectively. But what if it is a minor circulating images
of themself? In re S.K.,
A. d
(Md.
) upheld the conviction of a
-year-old who sent two friends a video of herself performing oral sex on a
male partner, reasoning. “[A] minor legally engaged in consensual sexual
activity [can] be his or her own pornographer through the act of sexting.”
Does it make sense that two minors can legally have sex with each other but
not share sexual images of themselves with each other?
. Virtual Prostitution: Prostitution is usually defined as the exchange of payment
for sexual activity; it is criminalized in most jurisdictions. F.H. has an account on OnlyFans, where she sells subscriptions for
/month. Subscribers receive access to pornographic pictures and videos she posts of herself, along with access to daily livestreams, in some of which she engages in
sexual activity. Is this illegal prostitution? Does it violate any other laws?
Should it?
. Virtual Exposure: J.D. is playing an online multiplayer game. He modifies the
design on his character’s shirt so that it appears to have an erect penis. Is this
public nudity? If he has his character put its hands on other players’ characters’ breasts, is this sexual assault? Would the result be different if this were a
VR game, so that other players saw his character’s hands in D reaching towards their actual chests?
6. Harm to Minors
This section includes graphic descriptions of violence.
1
2
4
0
0
0
2
3
2
1
$
1
1
0
2
6
8
7
9
1
0
2
4
6
5
8
7
9
1
0
0
6
3
2
7
3
5
1
2
8
3
8
4
1
6
0
0
2
0
6
7
2
Some material that is legal for adults is nonetheless harmful to minors. Sexually
explicit material often qualifies, so does indecent exposure to a minor. Thus, for
example, the government can prohibit the use of George Carlin’s “seven words you
can’t say on television” on the radio, see Federal Communications Commission v.
Pacifica Foundation,
U.S.
(
), and fine television stations for airing
Janet Jackson’s breast-baring “wardrobe malfunction,” see Complaints Against
Various Television Licensees Concerning Their February ,
Broadcast,
FCC Rcd.
(
). In both cases, though it is lawful for adults to receive and
exchange such material, children might be watching, and the government can pass
laws that restrict minors’ access to it.
This said, minors do have First Amendment rights, and the government cannot
simply impose on them its beliefs about what they should and should not see. In
Brown v. Entertainment Merchants Ass’n,
U.S.
(
), the Supreme Court
struck down a California law prohibiting the sale of violent video games to children under the age of . Justice Scalia’s opinion for the Court observed that children have long been exposed to violence in other media:
Certainly the books we give children to read – or read to them when
they are younger – contain no shortage of gore. Grimm’s Fairy Tales,
for example, are grim indeed. As her just deserts for trying to poison
Snow White, the wicked queen is made to dance in red hot slippers
“till she fell dead on the floor, a sad example of envy and jealousy.” The
6
4
1
5
6
Chapter 3: Speech
160
Internet Law
6
0
0
2
8
9
1
Complete Brothers Grimm Fairy Tales
(
ed.). Cinderella's evil stepsisters have their eyes pecked out by doves. And Hansel
and Gretel (children!) kill their captor by baking her in an oven.
High-school reading lists are full of similar fare. Homer's Odysseus
blinds Polyphemus the Cyclops by grinding out his eye with a heated
stake. In the Inferno, Dante and Virgil watch corrupt politicians
struggle to stay submerged beneath a lake of boiling pitch, lest they be
skewered by devils above the surface. And Golding’s Lord of the Flies
recounts how a schoolboy called Piggy is savagely murdered by other
children while marooned on an island. Id. at 795-96.
Justice Alito’s concurrence argued that video games really are different:
Today's most advanced video games create realistic alternative worlds
in which millions of players immerse themselves for hours on end.
These games feature visual imagery and sounds that are strikingly
realistic, and in the near future video-game graphics may be virtually
indistinguishable from actual video footage. Many of the games already on the market can produce high definition images, and it is
predicted that it will not be long before video-game images will be
seen in three dimensions. It is also forecast that video games will soon
provide sensory feedback. By wearing a special vest or other device, a
player will be able to experience physical sensations supposedly felt by
a character on the screen. Some amici who support respondents foresee the day when “virtual-reality shoot-‘em-ups” will allow children to
“actually feel the splatting blood from the blown-off head” of a victim.
Persons who play video games also have an unprecedented ability
to participate in the events that take place in the virtual worlds that
these games create. Players can create their own video-game
characters and can use photos to produce characters that closely
resemble actual people. A person playing a sophisticated game can
make a multitude of choices and can thereby alter the course of the
action in the game. In addition, the means by which players control
the action in video games now bear a closer relationship to the means
by which people control action in the real world. While the action in
older games was often directed with buttons or a joystick, players
dictate the action in newer games by engaging in the same motions
that they desire a character in the game to perform. For example, a
player who wants a video-game character to swing a baseball bat—
either to hit a ball or smash a skull—could bring that about by
simulating the motion of actually swinging a bat. …
In some of these games, the violence is astounding. Victims by the
dozens are killed with every imaginable implement, including
machine guns, shotguns, clubs, hammers, axes, swords, and
chainsaws. Victims are dismembered, decapitated, disemboweled, set
on fire, and chopped into little pieces. They cry out in agony and beg
for mercy. Blood gushes, splatters, and pools. Severed body parts and
gobs of human remains are graphically shown. In some games, points
are awarded based, not only on the number of victims killed, but on
the killing technique employed. Id. at 816–18.
Thus, most statutes dealing with harmful-to-minors speech raise one two issues.
First, has the government specifically identified a category of speech that genuine-
161
ly is harmful to minors in particular? And second, has it drawn the line around
that category with sufficient care to ensure that it does not also restrict adults’
ability to receive that speech?
QUESTIONS
. What Are Games? Speaking in
, film director Steven Spielberg argued
that video games were not yet an art form: “I think the real indicator will be
when somebody confesses that they cried at level .” Are games there yet?
What about non-narrative games? Is Tetris art? Is it speech? What about
online poker?
. Virtual Reality and Augmented Reality: Does the arrival of mass-market VR
hardware like the Oculus Rift affect the analysis in Brown? What about AR
games like Pokémon GO?
The following case includes discussion of harassment.
STATE V. BISHOP
787 S.E.2d 814 (N.C. 2016)
1
1
0
2
1
1
0
2
5
1
0
2
7
1
1
1
8
5
4
d
n
4
u
1
o
4
r
0
g
1
0
1
2
k
c
0
a
2
1
l
a
1
r
8
u
2
5
d
1
2
4
1
e
0
c
2
0
4
o
2
1
1
r
1
0
2
d
n
1
a
8
5
s
t
4
c
9
4
a
Hudson, Justice:
On February
, defendant Robert Bishop was arrested and charged with
one count of cyberbullying under North Carolina's cyberbullying statute, N.C.G.S.
§ . . Under that statute, it is “unlawful for any person to use a computer or
computer network to ... [p]ost or encourage others to post on the Internet private,
personal, or sexual information pertaining to a minor” “[w]ith the intent to intimidate or torment a minor.” N.C.G.S. § . (a)( )(d) (
). … We now conclude
that N.C.G.S. § . (a)( )(d) restricts speech, not merely nonexpressive conduct; that this restriction is content based, not content neutral; and that the cyberbullying statute is not narrowly tailored to the State's asserted interest in protecting children from the harms of online bullying. Accordingly, we … hold that
the statute violates the First Amendment as applied to the states through the
Fourteenth Amendment.
I. F
P
B
During the
school year, defendant and Dillion Price were students at
Southern Alamance High School. Starting in the fall of
, some of Price's
classmates began to post negative pictures and comments about Price on Facebook, including on Price's own Facebook page. In September
, a male classmate posted on Facebook a screenshot of a sexually themed text message Price had
inadvertently sent him. Below that post, several individuals commented, including
Price and defendant. Price accused the posting student of altering or falsifying the
screenshot and threatened to fight him over the matter; defendant commented
that the text was “excessively homoerotic’ and accused others of being “defensive”
and “pathetic for taking the [I]nternet so seriously.”
At least two other Facebook postings with similar tone and attitude followed,
all involving Price, defendant, and other commenters. Many of the messages that
ensued included comments and accusations about each other's sexual proclivities,
along with name-calling and insults.
Late one night in December
, Price’s mother found him very upset in his
room, crying, throwing things, and hitting himself in the head. She saw on his
cellphone some of the comments and pictures that his classmates had posted.
Fearing for his well-being and concerned that Price might harm himself, Price’s
1
1
2
Chapter 3: Speech
Internet Law
1
1
8
5
4
4
1
1
1
1
1
8
8
5
5
4
4
4
4
1
1
1
8
5
4
4
1
5
0
0
2
2
1
1
0
5
2
5
s
1
i
s
3
y
l
4
1
5
a
8
n
9
5
4
mother contacted the police, who used undercover Facebook accounts to view the
Facebook postings and take screenshots of postings relevant to the investigation.
On February
, defendant was arrested and charged with one count of
cyberbullying in violation of N.C.G.S. § . .…
II. A
…
A. The Statute Burdens Speech, Not Just Nonexpressive Conduct. …
Posting information on the Internet — whatever the subject matter — can constitute speech as surely as stapling flyers to bulletin boards or distributing pamphlets
to passers-by — activities long protected by the First Amendment. Such communication does not lose protection merely because it involves the “act” of posting
information online, for much speech requires an “act” of some variety – whether
putting ink to paper or paint to canvas, or hoisting a picket sign, or donning a
message-bearing jacket. Nor is such communication subject to any lesser protection simply because it occurs online. …
B. The Statute is Content Based. …
Here, it is clear that the cyberbullying statute is content based, on its face and by
its plain text, because the statute defines regulated speech by its particular subject
matter. The provision under which defendant was arrested and prosecuted prohibits “post[ing] or encourag[ing] others to post ... private, personal, or sexual
information pertaining to a minor.” N.C.G.S. § . (a)( )(d). The statute criminalizes some messages but not others, and makes it impossible to determine
whether the accused has committed a crime without examining the content of his
communication. …
C. The Statute Fails Strict Scrutiny.
Because we have concluded that N.C.G.S. § . (a)( )(d) creates a content
based restriction on protected speech, we can uphold this portion of the cyberbullying statute only if the State can demonstrate that it satisfies strict scrutiny. To do
so, the State must show that the statute serves a compelling governmental interest,
and that the law is narrowly tailored to effectuate that interest.
That protecting children from online bullying is a compelling governmental
interest is undisputed. … [T]he State asserts, and defendant agrees, that the General Assembly has a compelling interest in protecting children from physical and
psychological harm. We also note that the special status of minors is a subject for
which the Supreme Court of the United States has shown a particular solicitude.
That Court's long-standing recognition that youth is more than a chronological
fact, has led it, on one hand, to recognize a compelling interest in the protection of
minors, and, on the other, to prohibit the imposition of the most serious criminal
punishments for offenses committed before the age of eighteen, see Roper v. Simmons,
U.S.
(
) (holding that the death penalty cannot be imposed for
offenses committed by a juvenile). Accordingly, in line with these consistent and
converging strands of precedent, we reaffirm that the State has a compelling interest in protecting the physical and psychological well-being of minors. …
With these principles in mind, we now turn to sub-subdivision . (a)( )
(d) of the cyberbullying statute. Again, that provision makes it a criminal offense
"for any person to use a computer or computer network to... [p]ost or encourage
others to post on the Internet private, personal, or sexual information pertaining
to a minor" "[w]ith the intent to intimidate or torment a minor." N.C.G.S. §
. (a)( )(d). The central question then becomes whether this language em-
4
1
162
Chapter 3: Speech
163
bodies the least restrictive means of advancing the State's compelling interest in
protecting minors from this potential harm.
We hold that it does not. At the outset, it is apparent that the statute contains
no requirement that the subject of an online posting suffer injury as a result, or
even that he or she become aware of such a posting. In addition, as to both the
motive of the poster and the content of the posting, the statute sweeps far beyond
the State's legitimate interest in protecting the psychological health of minors. Regarding motive, the statute prohibits anyone from posting forbidden content with
the intent to "intimidate or torment" a minor. However, neither “intimidate” nor
"torment" is defined in the statute, and the State itself contends that we should
define “torment” broadly to reference conduct intended “to annoy, pester, or harass.” The protection of minors' mental well-being may be a compelling governmental interest, but it is hardly clear that teenagers require protection via the
criminal law from online annoyance.
The description of the proscribed subject matter is similarly expansive. The
statute criminalizes posting online “private, personal, or sexual information pertaining to a minor.” Id. Again, these terms are not defined by the statute. The State
has suggested that we interpret this language by defining “private” to mean “secluded from the sight, presence, or intrusion of others,” or “of or confined to the
individual.” The State would then define “personal” as “of or relating to a particular person,” or “concerning a particular person and his or her private business, interests, or activities.” And it would define “sexual” as “of, relating to, involving, or
characteristic of sex, sexuality, the sexes, or the sex organs and their functions,” or
“implying or symbolizing erotic desires or activity.” While all of these definitions
are broad, the State’s proposed definition of “personal” as “of or relating to a particular person” is especially sweeping. Were we to adopt the State’s position, it
could be unlawful to post on the Internet any information “relating to a particular
[minor].” Such an interpretation would essentially criminalize posting any information about any specific minor if done with the requisite intent.
Finally, we note that, while adding a mens rea requirement can sometimes limit
the scope of a criminal statute, reading the motive and subject matter requirements in tandem here does not sufficiently narrow the extensive reach of the cyberbullying statute. Even under the State's proposed construction of the statutory
terms, N.C.G.S. § . (a)( )(d) could criminalize behavior that a robust contemporary society must tolerate because of the First Amendment, even if we do
not approve of the behavior. Civility, whose definition is constantly changing, is a
laudable goal but one not readily attained or enforced through criminal laws. …
QUESTION
Would the following statute be constitutional?
A minor commits the offense of cyberbullying if the minor knowingly
transmits or disseminates any electronic communication, including a
visual depiction of himself or any other person in a state of nudity, to
another minor with the knowledge or intent that the communication
would coerce, intimidate, torment, harass or otherwise cause emotional distress to the other minor.
1
1
8
5
4
4
1
NOTE ON SCHOOL DISCIPLINE
Schools may not discipline students for speech at school unless the speech “will
materially and substantially disrupt the work and discipline of the school.” Tinker
Internet Law
v. Des Moines Independent Community School Dist.,
U.S.
,
(
). In
Mahanoy Area School District v. B.L.,
U.S.
(
), the Supreme Court
held a school’s ability to discipline students for off-campus speech is “diminished.”
The case involved a student who was suspended from the cheerleading team for a
year after she posted “Fuck school fuck softball fuck cheer fuck everything.” to a
Snapchat Story where other students at the school read it. The Court explained:
Putting aside the vulgar language, the listener would hear criticism, of
the team, the team’s coaches, and the school—in a word or two, criticism of the rules of a community of which B.L. forms a part. This criticism did not involve features that would place it outside the First
Amendment’s ordinary protection. B.L.’s posts, while crude, did not
amount to fighting words. And while B.L. used vulgarity, her speech
was not obscene as this Court has understood that term. To the contrary, B.L. uttered the kind of pure speech to which, were she an adult,
the First Amendment would provide strong protection.
Consider too when, where, and how B.L. spoke. Her posts
appeared outside of school hours from a location outside the school.
She did not identify the school in her posts or target any member of
the school community with vulgar or abusive language. B.L. also
transmitted her speech through a personal cellphone, to an audience
consisting of her private circle of Snapchat friends. These features of
her speech, while risking transmission to the school itself, nonetheless diminish the school’s interest in punishing B.L.’s utterance.
Mahanoy,
U.S., at
– . But the Court listed “some off-campus circumstances” in which the “school’s regulatory interests remain significant”:
These include serious or severe bullying or harassment targeting particular individuals; threats aimed at teachers or other students; the
failure to follow rules concerning lessons, the writing of papers, the
use of computers, or participation in other online school activities;
and breaches of school security devices, including material maintained within school computers.
Id. at
.
9
6
9
1
9
0
5
3
0
5
1
2
3
0
2
9
3
0
8
1
4
9
5
1
9
0
9
1
ffi
4
9
5
8
8
1
0
QUESTION
How should Tinker and Mahanoy apply to the following cases?
• L.W., a student at Douglas High School, sends text messages to a friend, who
is concerned enough to forward them to a school administrator:
its pretty simple / i have a sweet gun / my neighbor is giving me
rounds / dhs is gay / ive watched these kinds of movies so i
know how NOT to go wrong / i just cant decide who will be on
my hit list / and thats totally deminted and it scares even my
self
• J.S. and K.L., both eighth graders, create a fake public Instagram profile
using their principal’s official photograph from the school’s website (although not his name or the school’s name), and listing his interests as:
detention, being a tight ass, riding the fraintrain, spending time
with my child (who looks like a gorilla), baseball, my golden
pen, fucking in my o ce, hitting on students and their parents.
0
5
164
Chapter 3: Speech
165
• K.C., a high school student, creates a private Instagram account that has
thirteen followers. One of his posts is captioned “Ku klux starter pack” and
includes pictures of pictures of a noose, a white hood, a burning torch, and a
Black doll. Another post is a photograph of a Black classmate sitting in class
and is captioned “The gorilla exhibit is nice today.” One of the account’s followers, another student at the school, shows some of them to other students,
and knowledge of them spreads widely.
RENO V. AMERICAN CIVIL LIBERTIES UNION
521 US 844 (1997)
9
8
9
1
6
5
2
1
4
7
5
5
1
1
7
3
7
2
2
9
1
8
2
1
9
1
0
4
7
8
7
6
1
8
1
3
4
6
9
9
1
8
7
5
9
1
6
3
2
3
7
2
2
2
2
8
3
4
7
4
3
2
2
Justice Stevens delivered the opinion of the Court.
At issue is the constitutionality of two statutory provisions enacted to protect
minors from “indecent” and “patently offensive” communications on the Internet.
Notwithstanding the legitimacy and importance of the congressional goal of protecting children from harmful materials, we agree with the three-judge District
Court that the statute abridges “the freedom of speech” protected by the First
Amendment. …
II
The Telecommunications Act of
was an unusually important legislative enactment. … An amendment offered in the Senate was the source of the two statutory provisions challenged in this case. They are informally described as the "indecent transmission" provision and the "patently offensive display" provision … The
first,
U.S.C. §
(a), prohibits the knowing transmission of obscene or indecent messages to any recipient under
years of age. … The second provision,
§
(d), prohibits the knowing sending or displaying of patently offensive messages in a manner that is available to a person under
years of age. The breadth
of these prohibitions is qualified by two affirmative defenses. One covers those
who take “good faith, reasonable, effective, and appropriate actions” to restrict
access by minors to the prohibited communications. §
(e)( )(A). The other
covers those who restrict access to covered material by requiring certain designated forms of age proof, such as a verified credit card or an adult identification
number or code. §
(e)( )(B). …
VII
We are persuaded that the CDA lacks the precision that the First Amendment requires when a statute regulates the content of speech. In order to deny minors access to potentially harmful speech, the CDA effectively suppresses a large amount
of speech that adults have a constitutional right to receive and to address to one
another. That burden on adult speech is unacceptable if less restrictive alternatives
would be at least as effective in achieving the legitimate purpose that the statute
was enacted to serve.
In evaluating the free speech rights of adults, we have made it perfectly clear
that “[s]exual expression which is indecent but not obscene is protected by the
First Amendment.” Sable Comm’s of Calif. v. F.C.C.,
U.S.
,
(
). See
also Carey v. Population Services Int’l,
U.S.
,
(
) (“[W]here obscenity is not involved, we have consistently held that the fact that protected speech
may be offensive to some does not justify its suppression”). Indeed, F.C.C. v. Pacifica Found.,
U.S.
(
), … admonished that “the fact that society may find
speech offensive is not a sufficient reason for suppressing it.” Id. at
.
166
Internet Law
8
2
1
4
5
8
0
0
1
3
8
9
1
5
7
4
7
0
6
3
6
9
6
9
4
1
9
5
7
7
2
7
It is true that we have repeatedly recognized the governmental interest in protecting children from harmful materials. But that interest does not justify an unnecessarily broad suppression of speech addressed to adults. As we have explained,
the Government may not “reduc[e] the adult population … to … only what is fit
for children.” Denver Area Ed. Telecommunications Consortium, Inc. v. F.C.C.,
U.S.
,
(
). “[R]egardless of the strength of the government’s interest” in
protecting children, “[t]he level of discourse reaching a mailbox simply cannot be
limited to that which would be suitable for a sandbox.” Bolger v. Youngs Drug
Products Corp.,
U.S. , – (
). …
In arguing that the CDA does not so diminish adult communication, the Government relies on the incorrect factual premise that prohibiting a transmission
whenever it is known that one of its recipients is a minor would not interfere with
adult-to-adult communication. The findings of the District Court make clear that
this premise is untenable. Given the size of the potential audience for most messages, in the absence of a viable age verification process, the sender must be
charged with knowing that one or more minors will likely view it. Knowledge that,
for instance, one or more members of a
-person chat group will be a minor –
and therefore that it would be a crime to send the group an indecent message –
would surely burden communication among adults.
The District Court found that at the time of trial existing technology did not
include any effective method for a sender to prevent minors from obtaining access
to its communications on the Internet without also denying access to adults. The
Court found no effective way to determine the age of a user who is accessing material through e-mail, mail exploders, newsgroups, or chat rooms. As a practical
matter, the Court also found that it would be prohibitively expensive for noncommercial – as well as some commercial – speakers who have Web sites to verify that
their users are adults. These limitations must inevitably curtail a significant
amount of adult communication on the Internet. By contrast, the District Court
found that “[d]espite its limitations, currently available user-based software suggests that a reasonably effective method by which parents can prevent their children from accessing sexually explicit and other material which parents may believe is inappropriate for their children will soon be widely available.” Id. at
(emphases added).
The breadth of the CDA’s coverage is wholly unprecedented. Unlike the regulations upheld in Ginsberg and Pacifica, the scope of the CDA is not limited to
commercial speech or commercial entities. Its open-ended prohibitions embrace
all nonprofit entities and individuals posting indecent messages or displaying
them on their own computers in the presence of minors. The general, undefined
terms “indecent” and “patently offensive” cover large amounts of nonpornographic
material with serious educational or other value. Moreover, the “community standards” criterion as applied to the Internet means that any communication available to a nationwide audience will be judged by the standards of the community
most likely to be offended by the message. The regulated subject matter includes
any of the seven “dirty words” used in the Pacifica monologue, the use of which the
Government’s expert acknowledged could constitute a felony. … It may also extend
to discussions about prison rape or safe sexual practices, artistic images that include nude subjects, and arguably the card catalog of the Carnegie Library. …
The breadth of this content-based restriction of speech imposes an especially
heavy burden on the Government to explain why a less restrictive provision would
not be as effective as the CDA. It has not done so. The arguments in this Court
Chapter 3: Speech
167
3
3
2
2
2
2
8
1
5
3
2
2
1
7
1
3
2
2
8
1
7
4
8
1
5
3
3
2
2
2
2
have referred to possible alternatives such as requiring that indecent material be
“tagged” in a way that facilitates parental control of material coming into their
homes, making exceptions for messages with artistic or educational value, providing some tolerance for parental choice, and regulating some portions of the Internet – such as commercial Web sites – differently from others, such as chat rooms.
Particularly in the light of the absence of any detailed findings by the Congress, or
even hearings addressing the special problems of the CDA, we are persuaded that
the CDA is not narrowly tailored if that requirement has any meaning at all.
VIII …
The Government also asserts that the “knowledge” requirement of both §§
(a)
and (d), especially when coupled with the “specific child” element found in
§
(d), saves the CDA from overbreadth. Because both sections prohibit the dissemination of indecent messages only to persons known to be under , the Government argues, it does not require transmitters to “refrain from communicating
indecent material to adults; they need only refrain from disseminating such materials to persons they know to be under .” This argument ignores the fact that
most Internet forums – including chat rooms, newsgroups, mail exploders, and
the Web – are open to all comers. The Government’s assertion that the knowledge
requirement somehow protects the communications of adults is therefore untenable. Even the strongest reading of the “specific person” requirement of §
(d)
cannot save the statute. It would confer broad powers of censorship, in the form of
a “heckler’s veto,” upon any opponent of indecent speech who might simply log on
and inform the would-be discoursers that his -year-old child – a “specific
person . . . under years of age,”
U.S.C. §
(d)( )(A) – would be present. …
IX
The Government’s three remaining arguments focus on the defenses provided in
§
(e)( ). First, relying on the “good faith, reasonable, effective, and appropriate
actions” provision, the Government suggests that “tagging” provides a defense that
saves the constitutionality of the CDA. The suggestion assumes that transmitters
may encode their indecent communications in a way that would indicate their
contents, thus permitting recipients to block their reception with appropriate
software. It is the requirement that the good-faith action must be “effective” that
makes this defense illusory. The Government recognizes that its proposed screening software does not currently exist. Even if it did, there is no way to know
whether a potential recipient will actually block the encoded material. Without the
impossible knowledge that every guardian in America is screening for the “tag,”
the transmitter could not reasonably rely on its action to be “effective.”
For its second and third arguments concerning defenses – which we can consider together – the Government relies on the latter half of §
(e)( ), which applies when the transmitter has restricted access by requiring use of a verified credit card or adult identification. Such verification is not only technologically available but actually is used by commercial providers of sexually explicit material.
These providers, therefore, would be protected by the defense. Under the findings
of the District Court, however, it is not economically feasible for most noncommercial speakers to employ such verification. Accordingly, this defense would not
significantly narrow the statute’s burden on noncommercial speech. Even with
respect to the commercial pornographers that would be protected by the defense,
the Government failed to adduce any evidence that these verification techniques
actually preclude minors from posing as adults. Given that the risk of criminal
Internet Law
sanctions “hovers over each content provider, like the proverbial sword of Damocles,” the District Court correctly refused to rely on unproven future technology to
save the statute. The Government thus failed to prove that the proffered defense
would significantly reduce the heavy burden on adult speech produced by the prohibition on offensive displays.
We agree with the District Court’s conclusion that the CDA places an unacceptably heavy burden on protected speech, and that the defenses do not constitute the
sort of “narrow tailoring” that will save an otherwise patently invalid unconstitutional provision. In Sable,
U.S. at
, we remarked that the speech restriction
at issue there amounted to “burn[ing] the house to roast the pig.” The CDA, casting a far darker shadow over free speech, threatens to torch a large segment of the
Internet community. …
QUESTIONS
. The Internet is for Porn: How easy would it be for a ten-year-old to find
pornography on the Internet? How likely are they to stumble on it by accident? How effectively could parents prevent this from happening? How easy
would it be for a child molester to find the ten-year-old?
. Age-Based Targeting: In a famous concurrence in part, Justice O’Connor described the CDA as an attempt to create a “zoning law” for the Internet, dividing it into child-safe and adults-only zones. Is it easier to zone online
spaces or offline spaces? If you wanted to post something online and be confident that only adults would see it, what would you do? How confident
could you be that no minors were seeing it? How many adults would be
wrongfully screened out?
ONLINE PORNOGRAPHY VIEWING AGE REQUIREMENTS ACT
Title 78B, Utah Code
fi
fi
fi
fi
fi
7
2
1
ff
2
9
4
fi
fi
fi
1
0
0
1
3
8
2
5
§ B- – De nitions.
As used in this chapter: …
( ) “Digitized identi cation card” means a data le available on any mobile device which has connectivity to the Internet through a state-approved application that allows the mobile device to download the data le from a state
agency or an authorized agent of a state agency that contains all of the data
elements visible on the face and back of a license or identi cation card and
displays the current status of the license or identi cation card. …
( ) “Material harmful to minors” is de ned as all of the following:
(a) any material that the average person, applying contemporary community standards, would nd, taking the material as a whole and with
respect to minors, is designed to appeal to, or is designed to pander to,
the prurient interest;
(b) material that exploits, is devoted to, or principally consists of descriptions of actual, simulated, or animated display or depiction of any of
the following, in a manner patently o ensive with respect to minors:
(i) pubic hair, anus, vulva, genitals, or nipple of the female breast;
(ii) touching, caressing, or fondling of nipples, breasts, buttocks,
anuses, or genitals; or
7
2
1
168
Chapter 3: Speech
169
fi
fi
fi
fi
ff
fi
%
3
1
3
fi
3
8
1
ffi
fi
8
1
fi
fi
fi
fi
2
0
fi
0
1
fl
3
6
9
8
1
2
5
3
6
0
1
7
(iii) sexual intercourse, masturbation, sodomy, bestiality, oral copulation, agellation, excretory functions, exhibitions, or any other
sexual act; and
(c) the material taken as a whole lacks serious literary, artistic, political,
or scienti c value for minors.
( ) “Minor” means any person under years old. …
( ) “Reasonable age veri cation methods” means verifying that the person seeking to access the material is
years old or older by using any of the following methods:
(a) use of a digitized information card as de ned in this section;
(b) veri cation through an independent, third-party age veri cation service that compares the personal information entered by the individual
who is seeking access to the material that is available from a commercially available database, or aggregate of databases, that is regularly
used by government agencies and businesses for the purpose of age
and identity veri cation; or
(c) any commercially reasonable method that relies on public or private
transactional data to verify the age of the person attempting to access
the material.
( ) “Substantial portion” means more than - /
of total material on a website, which meets the de nition of “material harmful to minors” as de ned
in this section. …
§ B- – Liability for publishers and distributors -- Age veri cation -Retention of data -- Exceptions.
( ) A commercial entity that knowingly and intentionally publishes or distributes material harmful to minors on the Internet from a website that contains a substantial portion of such material shall be held liable if the entity
fails to perform reasonable age veri cation methods to verify the age of an
individual attempting to access the material.
( ) A commercial entity or third party that performs the required age veri cation shall not retain any identifying information of the individual after access has been granted to the material. …
( ) A commercial entity that is found to have violated this section shall be liable
to an individual for damages resulting from a minor's accessing the material, including court costs and reasonable attorney fees as ordered by the
court.
( ) This section shall not apply to any bona de news or public interest broadcast, website video, report, or event and shall not be construed to a ect the
rights of a news-gathering organization.
( ) No Internet service provider, a liate or subsidiary of an Internet service
provider, search engine, or cloud service provider shall be held to have violated the provisions of this section solely for providing access or connection
to or from a website or other information or content on the Internet, or a
facility, system, or network not under that provider's control, including
transmission, downloading, storing, or providing access, to the extent that
such provider is not responsible for the creation of the content of the communication that constitutes material harmful to minors.
Internet Law
QUESTIONS
. But See Reno: These provisions became effective on May ,
. The same
day, a pornography-industry trade group, the Free Speech Coalition, filed a
lawsuit arguing that the age-verification requirements were unconstitutional
under Reno. How should the court rule?
. State and Federal: Does the fact that this is a state law, rather than the federal
anti-pornography law at issue in Reno, make the First Amendment issues
better or worse? Does it change how companies can comply? How will it affect users in Utah, and in other states?
7. Intellectual Property
6
8
1
7
3
5
3
2
0
2
3
3
0
0
2
1
Speech that infringes a copyright isn’t harmful in the sense that it makes the listener worse off, as fraud and true threats do. Nor does it harm the copyright owner
in the same direct way that defamation and public disclosure of private facts harm
the people they are about. Instead, infringing speech is harmful because it undermines the copyright system itself: if people can copy a book with impunity, copyright’s economic incentives to write books break down. Thus copyright infringement — and trademark infringement and other kinds of infringing speech — is
among the recognized categories of harmful speech, notwithstanding the usual
rules against content-based speech restrictions.
To be sure, copyright claims can be used to suppress speech. See, for example,
Katz v. Google in the Copyright chapter, in which a businessman brought a copyright suit against a blog featuring an unflattering photo of him. Various copyright
doctrines, especially fair use, balance defendants’ speech interests against plaintiffs’ copyright interests. (Katz lost.) But for the most part, these doctrines are internal to intellectual property law itself. See, e.g., Eldred v. Ashcroft,
U.S.
,
(
) (“But when, as in this case, Congress has not altered the traditional
contours of copyright protection, further First Amendment scrutiny is unnecessary.”)
2
1
2
2
170
This chapter explores the vexed problem of online privacy. On the one hand, the
Internet seems to offer new and unprecedented opportunities for interacting discreetly. As a dog in a New Yorker cartoon famously put it, “On the Internet, nobody
knows you’re a dog.”* On the other hand, online activities leave behind a trail of
data in the hands of websites, ISPs, and others. That trail can be used to identify
individual users, and in some cases to build detailed profiles of what they have
been doing.
The first half of the chapter focuses on criminal investigations, examining constitutional and statutory restrictions on how law enforcement can gain access to
individuals’ data. Governmental control provides the thematic backbone. The second half then shifts to the problem of what private parties know and can learn
abut Internet users. Here, intermediary power comes to the fore: if knowledge is
power, then these intermediaries have quite a lot, indeed.
A. The Fourth and Fifth Amendments
We begin with criminal procedure: the body of law that regulates investigation,
prosecution, and criminal trials. The overriding concern here is evidentiary. The
police are looking to gather evidence that can be used against a defendant at trial;
the defendant is looking either to keep the police from getting access to the evidence, or to keep the prosecutors from presenting it to the jury. The Fourth
Amendment exclusionary rule provides the legal backdrop for this struggle: police
must respect the defendant’s privacy rights during the investigation, or the resulting evidence will be inadmissible. It fits together with the Fifth Amendment,
which prevents the police from shortcutting their own investigation by compelling
the defendant to tell the complete story of what happened.
This section considers how the Fourth and Fifth Amendments apply when
there are computers involved. It is divided into two subsections: one on searches of
defendants’ own devices, and one on remote searches of data stored with third
parties. The distinction is not completely clear-cut, but it is a useful way to divide
up the territory.
FOURTH AND FIFTH AMENDMENT OVERVIEW
The Fourth Amendment
The Fourth Amendment reads:
The right of the people to be secure in their persons, houses, papers,
and effects, against unreasonable searches and seizures, shall not be
violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to
be searched, and the persons or things to be seized.
At the outset, two threshold issues are particularly important. First, only searches
by the government implicate the Fourth Amendment; it does not apply to “a
3
of the July ,
9
9
1
5
y
c
1
6
a
v
i
r
P
r
e
t
p
a
* The cartoon, by Peter Steiner, appeared on page
h
C
4:
issue.
8
2
1
4
8
4
9
1
8
5
9
4
3
1
4
1
9
0
1
0
1
6
0
3
2
1
$
0
6
0
2
6
4
7
9
2
3
8
0
3
0
2
8
3
2
3
9
1
5
6
4
6
4
9
3
8
3
3
4
3
8
3
7
2
3
7
1
0
2
2
7
0
6
0
9
4
1
7
4
3
5
8
6
1
5
0
2
0
9
7
9
4
5
8
9
9
3
Internet Law
search or seizure, even an unreasonable one, effected by a private individual not
acting as an agent of the Government or with the participation or knowledge of
any governmental official.” United States v. Jacobsen,
U.S.
,
(
). If
you take your computer for repairs and the technician finds CSAM on the hard
drive, this is a private search and the Fourth Amendment is uninterested. Indeed,
the technician can take the computer to the police to show them what he found.
Note, however, that the police cannot examine more files on the computer than
the technician did; that would be a fresh governmental search. Similarly, it would
be a governmental search again if the police ask the technician to examine more
files for them, because then the technician is acting as a governmental agent. See
United States v. Jarrett,
F. d
( th Cir.
).
Second, unless the governmental action violates your reasonable expectation of
privacy, no “search” has taken place. If a police officer sees you run out of a bank
wearing a ski mask and waving a gun, the officer’s act of looking at you is not a
“search” for Fourth Amendment purposes, and the officer is free to testify at trial
that she saw you leaving the bank – or to arrest you.
The “reasonable expectation of privacy” test comes from Katz v. United States,
U.S.
(
). Older cases had held that there was no search without an
“actual physical invasion” of a defendant’s property. The leading case was Olmstead v. United States,
U.S.
,
(
), in which the Supreme Court held
it was not a search when the police listened to the defendants’ conversations by
installing wiretaps on the telephone wires in the streets near their houses, but not
actually on their property. Physical invasions are still searches: in United States v.
Jones,
U.S.
(
), the Supreme Court held that the police committed a
search when they secretly attached a tracking device to the defendant’s car. But
under Katz, the police can commit a search even when they don’t physically trespass. In Katz itself, the police bugged a phone booth the defendant regularly used;
the Supreme Court held that this constituted a search. Katz was a watershed in
criminal procedure: it shifted the focus of the Fourth Amendment from spaces
and objects protected against trespassers to “expectation[s] of privacy … that society is prepared to recognize as reasonable.” Katz,
U.S. at
(Harlan, J., concurring).
Drawing the line that defines a “reasonable expectation of privacy” is extremely
hard, but a few examples are relatively clear. You have a reasonable expectation of
privacy in your home and in sealed containers, such as locked suitcases within
your control. By contrast, you have no reasonable expectation of privacy in anything you have voluntarily exposed to public view. As an example of the line-drawing issues, consider Kyllo v. United States,
U.S.
(
), where investigators
used an infrared thermal imaging camera to observe that the defendant’s garage
roof was hotter than the rest of his house, correctly surmising that he had a marijuana grow lab inside. The Supreme Court held it was a search because “the Government use[d] a device that is not in general public use, to explore details of the
home that would previously have been unknowable without physical intrusion” Id.
at . (Today, anyone can buy a thermal imaging camera for
. Same result?)
Another line-drawing problem involves what is called Fourth Amendment
standing, that is, who has a privacy interest in particular “houses, papers, and effects?” The owner of a car who is driving it has Fourth Amendment standing to
object to a search; a car thief or passenger does not. Rakas v. Illinois,
U.S.
(
). What about a driver of a rented car? In Byrd v. United States,
U. S.
(
), the Supreme Court held that “someone in otherwise lawful possession
1
3
172
Chapter 4: Privacy
173
and control of a rental car has a reasonable expectation of privacy in it even if the
rental agreement does not list him or her as an authorized driver.”
Complicating things still further, the Fourth Amendment prohibits only “unreasonable” searches and seizures. A search is automatically reasonable if it is carried out pursuant to a search warrant, a judicial order that gives the police permission to carry out the search.* A court can issue a warrant after the police provide probable cause, i.e., “a fair probability that contraband or evidence of a crime
will be found in a particular place.” Illinois v. Gates,
U.S.
,
(
).
Warrants must satisfy the particularity requirement, that they “describ[e] the
place to be searched, and the persons or things to be seized.” A search or seizure
that goes beyond those limits is invalid.
Three exceptions are important for our purposes. The first is the consent exception. If the owner or someone else with authority over the property consents,
the police may search it. If you invite the police into your basement meth lab, you
may not later argue that it was a private space they needed a warrant to enter. The
same goes if your housemate invites them into the shared meth lab. The second is
the plain view rule. If the police are executing a valid search warrant, they may
also search and seize evidence whose incriminating nature is “immediately apparent.” If the police are searching the basement meth lab pursuant to a valid warrant,
they can also follow the trail of blood up the stairs. The third is the third-party
doctrine. There is no reasonable expectation of privacy in information voluntarily
exposed to third parties. If you brag about your bank heist to the guys down at the
bar, you have no Fourth Amendment right to complain if one of them rats you out
to the police. (Carpenter v. United States, excerpted below, places some significant
limits on the third-party doctrine and discusses it in more detail). These three exceptions have a lot in common with the basic reasonable expectation of privacy
test. Can you articulate a general principle that unites them?
Some warrantless searches can still be “reasonable” and thus permissible. Some
of these exceptions (each of which has its own tests) would take us well outside the
scope of this course – at the U.S. border, in government workplaces, in schools and
prisons, and as part of a lawful stop or arrest. (You might pause to ask how these
contexts change when there are computers involved.) The police may also conduct
warrantless searches and seizures when exigent circumstances make obtaining a
warrant infeasible – most commonly, when there is a risk that evidence will be destroyed if they do not act. An unreasonable search is illegal, and the exclusionary
rule governs any evidence the police obtain as a result: it may not be introduced at
trial.
The Fourth Amendment also applies to seizures. A seizure of your person is an
arrest or other involuntary restriction of your liberty to leave. A seizure of your
property takes place when there is “some meaningful interference with [your]
possessory interest.” United States v. Jacobsen,
U.S.
,
(
). Again, a
search warrant, issued by a judge, with a probable-cause standard of evidence, and
particularly describing who or what is to be seized, is ordinarily required.
Warrant Jurisdiction
Another important limit on search warrants is that they are only valid where the
issuing court has territorial authority. In a world where most crimes are planned
and committed locally and where most search warrants describe houses and other
buildings, this last constraint is rarely likely to pose an obstacle. But modern tech-
3
8
9
1
8
3
4
2
8
9
3
1
1
2
3
1
1
9
2
0
6
1
4
6
6
4
* A sample search warrant and application are available in the online Appendix.
174
Internet Law
nologies create difficulties. For example, cars drive around. In United States v.
Jones (discussed below), investigators obtained a warrant to install a GPS tracker
on the defendant’s car from a federal court in the District of Columbia but actually
installed the tracker in Maryland. Whoops. (This is why the case reached the
Supreme Court as a case on whether a warrant was necessary at all.)
Computers pose even more vexing issues. In one notable case, the FBI took
over a sexual child abuse website and used it to install tracking software on the
computers of users who visited it so they could be identified and prosecuted. It
obtained a warrant from a magistrate judge in the Eastern District of Virginia allowing a search of the “computers … of any user or administrator who logs into
the TARGET WEBSITE by entering a username and password.” But those computers were located all over the United States. Judges in the resulting prosecutions
split over whether the warrant was valid under the current version of the Federal
Rules of Criminal Procedure, which allowed only a “magistrate judge with authority in the district” to issue a warrant. Fed. R. Crim. Proc. (b)( ) (emphasis
added). But within the U.S. federal judicial system, where Congress controls the
jurisdictional rules and can change them, such problems (if they really are problems) are solvable. An amendment to Rule that explicitly authorized nationwide
warrants in such cases went into effect on December ,
.
The Fifth Amendment
The Fifth Amendment provides:
No person shall be held to answer for a capital, or otherwise infamous
crime, unless on a presentment or indictment of a Grand Jury, except
in cases arising in the land or naval forces, or in the Militia, when in
actual service in time of War or public danger; nor shall any person be
subject for the same offence to be twice put in jeopardy of life or limb;
nor shall be compelled in any criminal case to be a witness against
himself, nor be deprived of life, liberty, or property, without due
process of law; nor shall private property be taken for public use,
without just compensation. (emphasis added)
This is the “right to remain silent”: a criminal defendant has an absolute privilege
to refuse to testify. She is also free to refuse to answer questions from police, grand
juries, even Congress – anything that might potentially incriminate her. The government can compel her testimony only by offering the defendant immunity: a
promise that neither the testimony, nor anything discovered using the testimony,
will be used against the defendant at trial. Some of the hard questions, as Spencer
illustrates, depend on the question of what actions count as “testimony.”
1. Device Searches
RILEY V. CALIFORNIA
573 U.S. 373 (2014)
1
1
4
6
1
0
2
1
1
4
Chief Justice Roberts delivered the opinion of the Court.
These two cases raise a common question: whether the police may, without a
warrant, search digital information on a cell phone seized from an individual who
has been arrested.
Chapter 4: Privacy
175
4
1
9
1
2
9
3
3
8
3
2
3
2
9
6
9
1
2
5
7
5
9
3
4
1
9
1
I
A
In the first case, petitioner David Riley was stopped by a police officer for driving
with expired registration tags. In the course of the stop, the officer also learned
that Riley’s license had been suspended. The officer impounded Riley’s car, pursuant to department policy, and another officer conducted an inventory search of
the car. Riley was arrested for possession of concealed and loaded firearms when
that search turned up two handguns under the car’s hood.
An officer searched Riley incident to the arrest and found items associated with
the “Bloods” street gang. He also seized a cell phone from Riley’s pants pocket.
According to Riley’s uncontradicted assertion, the phone was a “smart phone,” a
cell phone with a broad range of other functions based on advanced computing
capability, large storage capacity, and Internet connectivity. The officer accessed
information on the phone and noticed that some words (presumably in text messages or a contacts list) were preceded by the letters “CK”-a label that, he believed,
stood for “Crip Killers,” a slang term for members of the Bloods gang.
At the police station about two hours after the arrest, a detective specializing in
gangs further examined the contents of the phone. The detective testified that he
“went through” Riley’s phone “looking for evidence, because . . . gang members will
often video themselves with guns or take pictures of themselves with the guns.”
Although there was “a lot of stuff ” on the phone, particular files that “caught [the
detective’s] eye” included videos of young men sparring while someone yelled encouragement using the moniker “Blood.” The police also found photographs of
Riley standing in front of a car they suspected had been involved in a shooting a
few weeks earlier. …
Riley was ultimately charged, in connection with that earlier shooting, with
firing at an occupied vehicle, assault with a semiautomatic firearm, and attempted
murder. …
[In the companion case, police arrested Brima Wurie, then noticed that his flip
phone was receiving calls from a number identified as “my house.” They opened
the phone, pressed a button to access the call log, and then another to retrieve the
associated phone number,. Using the phone number, they identified his apartment, where a subsequent search (with a warrant) revealed illegal drugs and a
firearm.]
II …
The two cases before us concern the reasonableness of a warrantless search incident to a lawful arrest. In
, this Court first acknowledged in dictum “the right
on the part of the Government, always recognized under English and American
law, to search the person of the accused when legally arrested to discover and seize
the fruits or evidences of crime.” Weeks v. United States,
U.S.
,
(
).
Since that time, it has been well accepted that such a search constitutes an exception to the warrant requirement. …
Although the existence of the exception for such searches has been recognized
for a century, its scope has been debated for nearly as long. … That debate has focused on the extent to which officers may search property found on or near the
arrestee. Three related precedents set forth the rules governing such searches:
The first, Chimel v. California,
U.S.
(
), laid the groundwork for
most of the existing search incident to arrest doctrine. Police officers in that case
arrested Chimel inside his home and proceeded to search his entire three-bed-
176
Internet Law
5
1
3
7
9
1
8
1
2
4
1
4
7
0
0
2
3
6
7
2
6
7
room house, including the attic and garage. In particular rooms, they also looked
through the contents of drawers.
The Court crafted the following rule for assessing the reasonableness of a
search incident to arrest:
When an arrest is made, it is reasonable for the arresting officer to
search the person arrested in order to remove any weapons that the
latter might seek to use in order to resist arrest or effect his escape.
Otherwise, the officer’s safety might well be endangered, and the arrest itself frustrated. In addition, it is entirely reasonable for the arresting officer to search for and seize any evidence on the arrestee’s
person in order to prevent its concealment or destruction. . . . There is
ample justification, therefore, for a search of the arrestee’s person and
the area ‘within his immediate control’-construing that phrase to
mean the area from within which he might gain possession of a
weapon or destructible evidence.
Id., at
. The extensive warrantless search of Chimel’s home did not fit
within this exception, because it was not needed to protect officer safety or to preserve evidence.
Four years later, in United States v. Robinson,
U.S.
(
), the Court …
rejected the notion that “case-by-case adjudication” was required to determine
“whether or not there was present one of the reasons supporting the authority for
a search of the person incident to a lawful arrest.” …
The Court thus concluded that the search of Robinson was reasonable even
though there was no concern about the loss of evidence, and the arresting officer
had no specific concern that Robinson might be armed. …
III
These cases require us to decide how the search incident to arrest doctrine applies
to modern cell phones, which are now such a pervasive and insistent part of daily
life that the proverbial visitor from Mars might conclude they were an important
feature of human anatomy. A smart phone of the sort taken from Riley was unheard of ten years ago; a significant majority of American adults now own such
phones. Even less sophisticated phones like Wurie’s, which have already faded in
popularity since Wurie was arrested in
, have been around for less than
years. Both phones are based on technology nearly inconceivable just a few
decades ago, when Chimel and Robinson were decided. …
But while Robinson’s categorical rule strikes the appropriate balance in the
context of physical objects, neither of its rationales has much force with respect to
digital content on cell phones. On the government interest side, Robinson concluded that the two risks identified in Chimel – harm to officers and destruction of
evidence-are present in all custodial arrests. There are no comparable risks when
the search is of digital data. In addition, Robinson regarded any privacy interests
retained by an individual after arrest as significantly diminished by the fact of the
arrest itself. Cell phones, however, place vast quantities of personal information
literally in the hands of individuals. A search of the information on a cell phone
bears little resemblance to the type of brief physical search considered in Robinson.
We therefore decline to extend Robinson to searches of data on cell phones, and
hold instead that officers must generally secure a warrant before conducting such
a search.
Digital data stored on a cell phone cannot itself be used as a weapon to harm an
arresting officer or to effectuate the arrestee’s escape. Law enforcement officers
remain free to examine the physical aspects of a phone to ensure that it will not be
used as a weapon-say, to determine whether there is a razor blade hidden between
the phone and its case. Once an officer has secured a phone and eliminated any
potential physical threats, however, data on the phone can endanger no one. …
0
1
1
7
4
1
The United States and California focus primarily on the second Chimel rationale:
preventing the destruction of evidence.
Both Riley and Wurie concede that officers could have seized and secured their
cell phones to prevent destruction of evidence while seeking a warrant. That is a
sensible concession. And once law enforcement officers have secured a cell phone,
there is no longer any risk that the arrestee himself will be able to delete incriminating data from the phone.
The United States and California argue that information on a cell phone may
nevertheless be vulnerable to two types of evidence destruction unique to digital
data-remote wiping and data encryption. Remote wiping occurs when a phone,
connected to a wireless network, receives a signal that erases stored data. This can
happen when a third party sends a remote signal or when a phone is preprogrammed to delete data upon entering or leaving certain geographic areas (socalled “geofencing”). Encryption is a security feature that some modern cell
phones use in addition to password protection. When such phones lock, data becomes protected by sophisticated encryption that renders a phone all but “unbreakable” unless police know the password. …
We have also been given little reason to believe that either problem is prevalent.
The briefing reveals only a couple of anecdotal examples of remote wiping triggered by an arrest. Similarly, the opportunities for officers to search a passwordprotected phone before data becomes encrypted are quite limited. Law enforcement officers are very unlikely to come upon such a phone in an unlocked state
because most phones lock at the touch of a button or, as a default, after some very
short period of inactivity. See, e.g., iPhone User Guide for iOS . Software
(
) (default lock after about one minute). …
Moreover, in situations in which an arrest might trigger a remote-wipe attempt
or an officer discovers an unlocked phone, it is not clear that the ability to conduct
a warrantless search would make much of a difference. The need to effect the arrest, secure the scene, and tend to other pressing matters means that law enforcement officers may well not be able to turn their attention to a cell phone right
away. Cell phone data would be vulnerable to remote wiping from the time an individual anticipates arrest to the time any eventual search of the phone is completed, which might be at the station house hours later. Likewise, an officer who seizes
a phone in an unlocked state might not be able to begin his search in the short
time remaining before the phone locks and data becomes encrypted.
In any event, as to remote wiping, law enforcement is not without specific
means to address the threat. Remote wiping can be fully prevented by disconnecting a phone from the network. There are at least two simple ways to do this: First,
law enforcement officers can turn the phone off or remove its battery. Second, if
0
2
177
A
We first consider each Chimel concern in turn. …
2
1
Chapter 4: Privacy
Internet Law
they are concerned about encryption or other potential problems, they can leave a
phone powered on and place it in an enclosure that isolates the phone from radio
waves. Such devices are commonly called “Faraday bags,” after the English scientist Michael Faraday. They are essentially sandwich bags made of aluminum foil:
cheap, lightweight, and easy to use. They may not be a complete answer to the
problem, but at least for now they provide a reasonable response. In fact, a number of law enforcement agencies around the country already encourage the use of
Faraday bags.
To the extent that law enforcement still has specific concerns about the potential loss of evidence in a particular case, there remain more targeted ways to address those concerns. If the police are truly confronted with a now or never situation – for example, circumstances suggesting that a defendant’s phone will be the
target of an imminent remote-wipe attempt – they may be able to rely on exigent
circumstances to search the phone immediately. Or, if officers happen to seize a
phone in an unlocked state, they may be able to disable a phone’s automatic-lock
feature in order to prevent the phone from locking and encrypting data. Such a
preventive measure could be analyzed under the principles set forth in our decision in McArthur,
U.S.
,
– (
), which approved officers’ reasonable steps to secure a scene to preserve evidence while they awaited a warrant.
B
The search incident to arrest exception rests not only on the heightened government interests at stake in a volatile arrest situation, but also on an arrestee’s reduced privacy interests upon being taken into police custody. …
Robinson is the only decision from this Court applying Chimel to a search of
the contents of an item found on an arrestee’s person. … Lower courts applying
Robinson and Chimel, however, have approved searches of a variety of personal
items carried by an arrestee. See, e.g., United States v. Carrion,
F. d
,
,
( th Cir.
) (billfold and address book); United States v. Watson,
F. d
,
–
( th Cir.
) (wallet); United States v. Lee,
F. d
,
(D.C. Cir.
) (purse).
The United States asserts that a search of all data stored on a cell phone is “materially indistinguishable” from searches of these sorts of physical items. That is
like saying a ride on horseback is materially indistinguishable from a flight to the
moon. Both are ways of getting from point A to point B, but little else justifies
lumping them together. Modern cell phones, as a category, implicate privacy concerns far beyond those implicated by the search of a cigarette pack, a wallet, or a
purse. A conclusion that inspecting the contents of an arrestee’s pockets works no
substantial additional intrusion on privacy beyond the arrest itself may make
sense as applied to physical items, but any extension of that reasoning to digital
data has to rest on its own bottom.
0
2
2
1
1
1
0
2
5
9
0
8
1
0
0
2
2
3
8
3
9
1
1
3
3
6
2
1
1
3
4
7
8
8
3
9
1
4
1
3
1
7
3
9
5
1
8
3
1
4
5
7
3
8
1
2
1
2
2
1
9
8
3
2
9
1
6
Cell phones differ in both a quantitative and a qualitative sense from other objects
that might be kept on an arrestee’s person. The term “cell phone” is itself misleading shorthand; many of these devices are in fact minicomputers that also happen
to have the capacity to be used as a telephone. They could just as easily be called
cameras, video players, rolodexes, calendars, tape recorders, libraries, diaries, albums, televisions, maps, or newspapers.
One of the most notable distinguishing features of modern cell phones is their
immense storage capacity. Before cell phones, a search of a person was limited by
9
1
6
8
1
178
179
physical realities and tended as a general matter to constitute only a narrow intrusion on privacy. Most people cannot lug around every piece of mail they have received for the past several months, every picture they have taken, or every book or
article they have read-nor would they have any reason to attempt to do so. …
But the possible intrusion on privacy is not physically limited in the same way
when it comes to cell phones. The current top-selling smart phone has a standard
capacity of
gigabytes (and is available with up to
gigabytes). Sixteen gigabytes translates to millions of pages of text, thousands of pictures, or hundreds of
videos. Cell phones couple that capacity with the ability to store many different
types of information: Even the most basic phones that sell for less than
might
hold photographs, picture messages, text messages, Internet browsing history, a
calendar, a thousand-entry phone book, and so on. We expect that the gulf between physical practicability and digital capacity will only continue to widen in the
future.
The storage capacity of cell phones has several interrelated consequences for
privacy. First, a cell phone collects in one place many distinct types of information
– an address, a note, a prescription, a bank statement, a video – that reveal much
more in combination than any isolated record. Second, a cell phone’s capacity allows even just one type of information to convey far more than previously possible.
The sum of an individual’s private life can be reconstructed through a thousand
photographs labeled with dates, locations, and descriptions; the same cannot be
said of a photograph or two of loved ones tucked into a wallet. Third, the data on a
phone can date back to the purchase of the phone, or even earlier. A person might
carry in his pocket a slip of paper reminding him to call Mr. Jones; he would not
carry a record of all his communications with Mr. Jones for the past several
months, as would routinely be kept on a phone.
Finally, there is an element of pervasiveness that characterizes cell phones but
not physical records. Prior to the digital age, people did not typically carry a cache
of sensitive personal information with them as they went about their day. Now it is
the person who is not carrying a cell phone, with all that it contains, who is the
exception. According to one poll, nearly three-quarters of smart phone users report being within five feet of their phones most of the time, with
admitting
that they even use their phones in the shower. A decade ago police officers searching an arrestee might have occasionally stumbled across a highly personal item
such as a diary. But those discoveries were likely to be few and far between. Today,
by contrast, it is no exaggeration to say that many of the more than
of American adults who own a cell phone keep on their person a digital record of nearly
every aspect of their lives-from the mundane to the intimate. Allowing the police
to scrutinize such records on a routine basis is quite different from allowing them
to search a personal item or two in the occasional case.
Although the data stored on a cell phone is distinguished from physical records
by quantity alone, certain types of data are also qualitatively different. An Internet
search and browsing history, for example, can be found on an Internet-enabled
phone and could reveal an individual’s private interests or concerns-perhaps a
search for certain symptoms of disease, coupled with frequent visits to WebMD.
0
2
$
%
%
0
2
1
9
4
6
6
Because the United States and California agree that these cases involve searches incident to arrest, these cases do not implicate the question whether the collection or
inspection of aggregated digital information amounts to a search under other circumstances.
1
1
1
Chapter 4: Privacy
Internet Law
Data on a cell phone can also reveal where a person has been. Historic location
information is a standard feature on many smart phones and can reconstruct
someone’s specific movements down to the minute, not only around town but also
within a particular building.
Mobile application software on a cell phone, or “apps,” offer a range of tools for
managing detailed information about all aspects of a person’s life. There are apps
for Democratic Party news and Republican Party news; apps for alcohol, drug, and
gambling addictions; apps for sharing prayer requests; apps for tracking pregnancy symptoms; apps for planning your budget; apps for every conceivable hobby or
pastime; apps for improving your romantic life. There are popular apps for buying
or selling just about anything, and the records of such transactions may be accessible on the phone indefinitely. There are over a million apps available in each of
the two major app stores; the phrase “there’s an app for that” is now part of the
popular lexicon. The average smart phone user has installed
apps, which together can form a revealing montage of the user’s life.
In
, Learned Hand observed … that it is “a totally different thing to search
a man’s pockets and use against him what they contain, from ransacking his house
for everything which may incriminate him.” United States v. Kirschenblatt, F. d
,
( nd Cir.
). If his pockets contain a cell phone, however, that is no
longer true. Indeed, a cell phone search would typically expose to the government
far more than the most exhaustive search of a house: A phone not only contains in
digital form many sensitive records previously found in the home; it also contains
a broad array of private information never found in a home in any form – unless
the phone is.
2
4
5
4
6
1
3
5
4
3
3
6
2
9
1
1
8
2
9
1
3
6
0
4
2
2
9
1
2
0
0
To further complicate the scope of the privacy interests at stake, the data a user
views on many modern cell phones may not in fact be stored on the device itself.
Treating a cell phone as a container whose contents may be searched incident to
an arrest is a bit strained as an initial matter. See New York v. Belton,
U.S.
,
, n. (
) (describing a “container” as “any object capable of holding another
object”). But the analogy crumbles entirely when a cell phone is used to access
data located elsewhere, at the tap of a screen. That is what cell phones, with increasing frequency, are designed to do by taking advantage of “cloud computing.”
Cloud computing is the capacity of Internet-connected devices to display data
stored on remote servers rather than on the device itself. Cell phone users often
may not know whether particular information is stored on the device or in the
cloud, and it generally makes little difference. Moreover, the same type of data may
be stored locally on the device for one user and in the cloud for another.
The United States concedes that the search incident to arrest exception may
not be stretched to cover a search of files accessed remotely – that is, a search of
files stored in the cloud. Such a search would be like finding a key in a suspect’s
pocket and arguing that it allowed law enforcement to unlock and search a house.
But officers searching a phone’s data would not typically know whether the information they are viewing was stored locally at the time of the arrest or has been
pulled from the cloud.
Although the Government recognizes the problem, its proposed solutions are
unclear. It suggests that officers could disconnect a phone from the network before
searching the device – the very solution whose feasibility it contested with respect
to the threat of remote wiping. Alternatively, the Government proposes that law
enforcement agencies “develop protocols to address” concerns raised by cloud
6
2
2
4
180
Chapter 4: Privacy
181
9
7
9
1
5
3
7
2
4
4
computing. Probably a good idea, but the Founders did not fight a revolution to
gain the right to government agency protocols. The possibility that a search might
extend well beyond papers and effects in the physical proximity of an arrestee is
yet another reason that the privacy interests here dwarf those in Robinson.
C
Apart from their arguments for a direct extension of Robinson, the United States
and California offer various fallback options for permitting warrantless cell phone
searches under certain circumstances. Each of the proposals is flawed and contravenes our general preference to provide clear guidance to law enforcement
through categorical rules. …
The United States also proposes a rule that would restrict the scope of a cell
phone search to those areas of the phone where an officer reasonably believes that
information relevant to the crime, the arrestee’s identity, or officer safety will be
discovered. This approach would again impose few meaningful constraints on officers. The proposed categories would sweep in a great deal of information, and
officers would not always be able to discern in advance what information would be
found where.
We also reject the United States’ final suggestion that officers should always be
able to search a phone’s call log, as they did in Wurie’s case. The Government relies
on Smith v. Maryland,
U.S.
(
), which held that no warrant was required to use a pen register at telephone company premises to identify numbers
dialed by a particular caller. The Court in that case, however, concluded that the
use of a pen register was not a “search” at all under the Fourth Amendment. There
is no dispute here that the officers engaged in a search of Wurie’s cell phone.
Moreover, call logs typically contain more than just phone numbers; they include
any identifying information that an individual might add, such as the label “my
house” in Wurie’s case.
Finally, at oral argument California suggested a different limiting principle,
under which officers could search cell phone data if they could have obtained the
same information from a pre-digital counterpart. But the fact that a search in the
pre-digital era could have turned up a photograph or two in a wallet does not justify a search of thousands of photos in a digital gallery. The fact that someone could
have tucked a paper bank statement in a pocket does not justify a search of every
bank statement from the last five years. And to make matters worse, such an analogue test would allow law enforcement to search a range of items contained on a
phone, even though people would be unlikely to carry such a variety of information in physical form. In Riley’s case, for example, it is implausible that he would
have strolled around with video tapes, photo albums, and an address book all
crammed into his pockets. But because each of those items has a pre-digital analogue, police under California’s proposal would be able to search a phone for all of
those items-a significant diminution of privacy.
In addition, an analogue test would launch courts on a difficult line-drawing
expedition to determine which digital files are comparable to physical records. Is
an e-mail equivalent to a letter? Is a voicemail equivalent to a phone message slip?
It is not clear how officers could make these kinds of decisions before conducting a
search, or how courts would apply the proposed rule after the fact. An analogue
test would keep defendants and judges guessing for years to come.
Internet Law
IV …
Our holding, of course, is not that the information on a cell phone is immune from
search; it is instead that a warrant is generally required before such a search, even
when a cell phone is seized incident to arrest. Our cases have historically recognized that the warrant requirement is an important working part of our machinery of government, not merely an inconvenience to be somehow ‘weighed’ against
the claims of police efficiency. Recent technological advances similar to those discussed here have, in addition, made the process of obtaining a warrant itself more
efficient.
Moreover, even though the search incident to arrest exception does not apply to
cell phones, other case-specific exceptions may still justify a warrantless search of
a particular phone. One well-recognized exception applies when the exigencies of
the situation make the needs of law enforcement so compelling that a warrantless
search is objectively reasonable under the Fourth Amendment. Such exigencies
could include the need to prevent the imminent destruction of evidence in individual cases, to pursue a fleeing suspect, and to assist persons who are seriously
injured or are threatened with imminent injury. In United States v. Chadwick,
U.S. ,
(
), for example, the Court held that the exception for searches incident to arrest did not justify a search of [a
-pound footlocker], but noted that
“if officers have reason to believe that luggage contains some immediately dangerous instrumentality, such as explosives, it would be foolhardy to transport it to the
station house without opening the luggage.”
U.S. at n. .
In light of the availability of the exigent circumstances exception, there is no
reason to believe that law enforcement officers will not be able to address some of
the more extreme hypotheticals that have been suggested: a suspect texting an
accomplice who, it is feared, is preparing to detonate a bomb, or a child abductor
who may have information about the child’s location on his cell phone. The defendants here recognize – indeed, they stress – that such fact-specific threats may justify a warrantless search of cell phone data. The critical point is that, unlike the
search incident to arrest exception, the exigent circumstances exception requires a
court to examine whether an emergency justified a warrantless search in each particular case. …
Modern cell phones are not just another technological convenience. With all
they contain and all they may reveal, they hold for many Americans the privacies
of life. The fact that technology now allows an individual to carry such information
in his hand does not make the information any less worthy of the protection for
which the Founders fought. Our answer to the question of what police must do
before searching a cell phone seized incident to an arrest is accordingly simple –
get a warrant. …
QUESTIONS
Digital Exceptionalism? Does Riley translate familiar Fourth Amendment
principles from the physical world to the digital one? Or does it create new,
distinctive principles for computers?
. In-Person Searches: A police officer arrests Wiley and finds a phone in his
pocket. Just then, a text message from one of Wiley’s co-conspirators arrives,
listing the location for a drug buy. The police drive to the location and arrest
the co-conspirator. Legal? (Does it matter whether Wiley is using a flip
phone or a smartphone that displays incoming texts on the lock screen?)
What if the co-conspirator calls Wiley instead, and the police officer picks
3
3
4
9
5
1
0
3
3
0
4
2
7
7
9
1
5
1
.
1
2
1
182
7
3
5
5
8
9
1
8
3
5
3
.
5
.
1
.
3
.
7
183
up the phone and successfully impersonates Wiley long enough to arrange
the drug buy?
Remote Searches: The police dial what they think is the defendant’s phone
number to see whether the phone in his pocket rings. Search? Or what if
they use a cell-site simulator (sometimes called a “stingray”): a device that
pretends to be a cell tower and records the identifying information and location of cell phones that attempt to connect to it?
Probable Cause: In addition to raising new issues about when probable cause
is needed, computers also raise new issues about what counts as probable
cause. Suppose the government (with a warrant) seizes the server of a website hosting CSAM, and that inspection of the server’s logs shows an access
to an explicit image from an IP address assigned to the defendant’s house. Is
that sufficient probable cause to obtain a warrant for a search of defendant’s
house and computer? What if the government can also show that on the
same day of the access from defendant’s IP address a link to the image was
posted to a discussion forum devoted to sharing CSAM, and that the link
clearly described the nature of the image? If that is insufficient, what would
be?
When I Get to the Border: What about when someone is trying to bring an
electronic device into the United States? Traditionally, “Routine searches of
the persons and effects of entrants are not subject to any requirement of reasonable suspicion, probable cause, or warrant.” United States v. Montoya de
Hernandez,
U.S.
,
(
). The usual explanation is that such
searches are necessary “to regulate the collection of duties and to prevent
the introduction of contraband.” Id. at
. Do those rationales apply to
computer searches?
2 Fast 2 Warrantless: Dom Toretto was involved in an automobile collision
and his badly-damaged car was impounded while he was in the hospital receiving treatment for his injuries. The police suspect that the crash occurred
during an illegal high-speed drift-racing competition. They would like to
inspect the car’s electronic data recorder, a/k/a “black box,” a small onboard
computer which automatically records the car’s speed, engine RPM, steering
wheel position, brake status, and other data. Obtaining the data will require
inserting a cable into the car’s dashboard, and decoding it will require specialized software available only to mechanics certified by the car’s manufacturer. Do the police need a warrant?
Computer Search Pragmatics: The police arrest Bill Maplewood for possession
of CSAM. Having read Riley, they plan to obtain a warrant to seize his laptop computer and search it for evidence. The laptop’s hard drive also contains his tax records, his emails, and patient records from his psychiatric
practice. Which of these can the police examine? How should they carry out
the examination? Can they also look for evidence of tax evasion? How long
can they retain the laptop? Which of these limits should be detailed in the
warrant itself?
.
4
5
4
3
7
6
Chapter 4: Privacy
Internet Law
UNITED STATES V. SPENCER
No. 17-cr-00259-CRB-1, 2018 WL 1964588, (Apr. 26, 2018, N.D. Cal.)
3
1
5
1
6
6
1
7
5
8
9
1
8
0
4
1
8
9
2
3
9
5
2
0
4
4
2
1
7
1
d
r
0
2
7
a
1
d
d
0
n
n
2
a
u
t
o
6
3
2
r
l
g
a
0
7
1
4
k
g
4
c
e
2
a
1
8
1
Breyer, District Judge:
Ryan Michael Spencer moves for relief from an order by a magistrate judge
compelling him to decrypt several electronic devices. Because the magistrate judge
properly applied the foregone conclusion doctrine to the facts of the case, the motion is DENIED.
I. B
On April ,
, a magistrate judge authorized a warrant for the FBI to search a
residence believed to be inhabited by Spencer. Specifically, the warrant authorized
the search of the premises and any computers, storage media, routers, modems,
and network equipment contained within, as well as Spencer himself, for evidence
of child pornography.
The FBI searched the residence and seized
electronic media items. It determined that some of these contained child pornography. However, several of the
devices were encrypted, and their contents were therefore inaccessible.
The United States sought an order under the All Writs Act,
U.S.C. §
,
compelling Spencer to decrypt three of these devices: a smartphone, a laptop, and
an external hard drive. Spencer admitted ownership of the smartphone and laptop, and provided passwords to bypass the lock screens (though not to decrypt
portions of the devices' hard drives).
The external hard drive was seized from the same desk as the laptop. Spencer
said he owned a hard drive matching the description of the one seized, and that he
had encrypted the hard drive using the same encryption software as that found on
the recovered drive. …
II. L
S
The Fifth Amendment to the United States Constitution provides that “No
person ... shall be Compelled in any criminal case to be a Witness against himself.”
It applies “only when the accused is compelled to make a Testimonial Communication that is incriminating.” Fisher v. United States,
U.S.
,
(
). Accordingly, the Fifth Amendment is not violated whenever the government compels
a person to turn over incriminating evidence. Id. at
. Instead, it is only implicated when the act of production itself is both “testimonial” and “incriminating.”
Id. at
.
The act of production is neither testimonial nor incriminating when the concession implied by the act “adds little or nothing to the sum total of the Government’s information by conceding that he in fact has the [evidence]”—that is, where
the information conveyed by the act of production is a “foregone conclusion.” Id. at
. It is important to stress the limited scope of the “foregone conclusion” rule. It
only applies where the testimony at issue is an implied statement inhering in the
act of production itself. See United States v. Apple MacPro Computer,
F. d
,
( d Cir.
). Otherwise, the government cannot compel a self-incriminating statement, regardless of whether the contents of the statement are a “foregone conclusion.”
For instance, the government could not compel Spencer to state the password
itself, whether orally or in writing. But the government is not seeking the actual
passcode. Rather, it seeks the decrypted devices. Spencer argues that production of
the devices would not fall within the act-of-production doctrine because producing the devices would require him to enter the decryption password. In other
3
4
2
184
185
6
4
0
1
3
4
1
3
5
3
3
0
1
9
7
6
3
5
0
1
2
2
4
0
7
6
1
1
0
2
7
8
5
4
2
9
1
2
4
8
9
1
7
1
8
7
4
6
9
4
6
0
2
1
1
4
7
0
6
2
4
7
4
5
1
3
2
words, Spencer argues that because the government cannot compel him to state
the passwords to the devices, it cannot compel him to decrypt the devices using
the passwords, either. This argument has some superficial appeal, and finds support in a dissent by Justice John Paul Stevens, who once contended that a defendant could “not ... be compelled to reveal the combination to his wall safe” either
“by word or deed.” Doe,
U.S. at
(Stevens, J., dissenting) (emphasis added).
While the analogy is not perfect, we may assume that storing evidence in encrypted devices is equivalent to securing items in a safe protected by a combination,
and that Justice Stevens' reasoning applies equally to the situation at hand. See In
re Grand Jury Subpoena Duces Tecum Dated March ,
,
F. d
,
( th Cir.
).
But a rule that the government can never compel decryption of a passwordprotected device would lead to absurd results. Whether a defendant would be required to produce a decrypted drive would hinge on whether he protected that
drive using a fingerprint key or a password composed of symbols. See New York v.
Quarles,
U.S.
,
(
). Similarly, accepting the analogy to the combination-protected safe, whether a person who receives a subpoena for documents
may invoke the Fifth Amendment would hinge on whether he kept the documents
at issue in a combination safe or a key safe. See Doe,
U.S. at
n. . But this
should make no difference, because opening the safe does not require producing
the combination to the government. Whether turning over material, either in the
form of documents or bits, implicates the Fifth Amendment should not turn on
the manner in which the defendant stores the material.
So: the government’s request for the decrypted devices requires an act of production. Nevertheless, this act may represent incriminating testimony within the
meaning of the Fifth Amendment because it would amount to a representation
that Spencer has the ability to decrypt the devices. See Fisher,
U.S. at
.
Such a statement would potentially be incriminating because having that ability
makes it more likely that Spencer encrypted the devices, which in turn makes it
more likely that he himself put the sought-after material on the devices.
The next question is whether the foregone conclusion rule applies. There is
some confusion in the case law regarding what exactly the relevant “foregone conclusion” must be where the government seeks decryption of hard drives. The
Eleventh Circuit has held that the government must show that it is a foregone conclusion not only that the defendant has the ability to decrypt the device(s), but also
that certain files are on the device(s). In re Grand Jury Subpoena,
F. d at
. The In re Grand Jury Subpoena court denied the government’s attempt to
compel the defendant to decrypt the device at issue in that case because it “‘ha[d]
not shown that it had any prior knowledge of either the existence or the whereabouts of the [files]’ ” on the device. Id.
The Eleventh Circuit was relying on precedent in which the government requested specific documents from a defendant pursuant to subpoena. See Fisher,
U.S. at
. In Fisher, “Compliance with the subpoena tacitly concede[d] the
existence of the papers demanded and their possession or control” by the defendant. Id. Not so in cases like the one at hand, in which the government seeks entire
hard drives. Turning over the decrypted devices would not be tantamount to an
admission that specific files, or any files for that matter, are stored on the devices,
because the government has not asked for any specific files. Accordingly, the government need only show it is a foregone conclusion that Spencer has the ability to
decrypt the devices. That the government may have access to more materials
1
1
4
Chapter 4: Privacy
Internet Law
where it seeks a hard drive through a search warrant than it would have had if it
sought specific files through subpoena is simply a matter of the legal tool the government uses to seek access. To the extent Spencer contends that the government
has not adequately identified the files it seeks, that is an issue properly raised under the Fourth Amendment, not the Fifth.
The only remaining question insofar as the applicable legal framework goes is
what standard the Court must apply in evaluating whether Spencer’s knowledge of
the passwords is a “foregone conclusion.” …
The appropriate standard is … clear and convincing evidence. This places a
high burden on the government to demonstrate that the defendant’s ability to decrypt the device at issue is a foregone conclusion. But a high burden is appropriate
given that the “foregone conclusion” rule is an exception to the Fifth Amendment’s
otherwise jealous protection of the privilege against giving self-incriminating testimony.
III. D
The question, accordingly, is whether the government has shown by clear and convincing evidence that Spencer’s ability to decrypt the three devices is a foregone
conclusion. It has. All three devices were found in Spencer’s residence. Spencer has
conceded that he owns the phone and laptop, and has provided the login passwords to both. Moreover, he has conceded that he purchased and encrypted an
external hard drive matching the description of the one found by the government.
This is sufficient for the government to meet its evidentiary burden.
The government may therefore compel Spencer to decrypt the devices. Once
Spencer decrypts the devices, however, the government may not make direct use of
the evidence that he has done so. If it really is a foregone conclusion that he has
the ability to do so, such that his decryption of the device is not testimonial, then
the government of course should have no use for evidence of the act of production
itself. …
QUESTIONS
. Analogies: Is the password to a computer like the key to a locked box? The
combination to a safe? Would it be “testimonial” to require the production
of a key or a combination?
. Biometric Locks: When Al Bertillon is arrested for conspiracy to distribute a
controlled substance, the police seize an iPhone from his backpack, which is
secured not with a passcode but with a fingerprint lock. Can the police compel him to put his thumb on the phone’s fingerprint sensor?
. Keyloggers: The government can also try to obtain passwords surreptitiously.
This works surprisingly often. In United States v. Scarfo,
F. Supp. d
(D.N.J.
), the FBI broke into the defendant’s office and installed a
device on his computer keyboard that recorded his keystrokes. The FBI
thereby obtained the password he used to encrypt his files, which contained
evidence of gambling and loansharking. Do you see any Fourth Amendment
issues with this procedure? If so, how would you carry it out so that the resulting evidence would be admissible in court?
2
0
8
1
1
n
0
o
i
0
2
s
s
u
c
s
i
2
COFFEESHOP PROBLEM
Officer Augusta Zenobia from the King County Sheriff ’s Office is ordering an
americano at a Tully’s Coffee Shop in Seattle when she notices that one of the oth-
7
3
2
1
5
186
Chapter 4: Privacy
187
er patrons has left an unattended laptop sitting on a table. It has shifted over into
the screensaver, which appears to be pulling random pictures from the computer’s
hard drive. Some of them show people who appear to be naked and underage.
A few seconds later, a man emerges from the men’s room and walks towards the
table with the laptop. He makes brief eye contact with Officer Zenobia, then looks
back to the laptop, which has just flashed up another photo of someone without
clothes on. He runs for the computer and slams it shut. Officer Zenobia is a few
steps behind; she orders him away from the computer and places him under arrest. He turns out to be one Lucius Aurelian; he has a clean criminal record. The
computer, along with the other items he had on his person (a wallet, keys, a laptop
bag, some papers for work), are currently sitting in the evidence locker at the police station.
You work in the King County Prosecuting Attorney’s office, and you have been
assigned the case. Officer Zenobia is willing to testify that the images she saw were
clearly child sexual abuse material. How good a case will you be able to build?
What should the next steps in the investigation be?
2. Remote Searches
UNITED STATES V. WARSHAK
631 F.3d 266 (6th Cir. 2010)
Boggs, Circuit Judge: …
8
1
5
2
0
0
5
$
s
t
c
a
e
h
t
f
o
1
t
0
s
0
0
n
i
7
e
0
s
2
m
y
7
l
2
e
t
a
a
n
t
I. S
F
A. Factual Background
[Steven Warshak owned and operated Berkeley Premium Neutraceuticals, Inc.,
which sold Enzyte, a nutritional supplement “purported to increase the size of a
man’s erection.” Enzyte’s sales were sustained by a series of frauds: Warshak and
Berkeley fabricated customer studies and medical endorsements, enrolled customers in a monthly subscription program without notice or consent, and engaged
in fake transactions to hide the high rate of at which consumers disputed Berkeley’s credit-card charges. Warshak was convicted of mail fraud, bank fraud, and
money laundering, among other crimes. He was sentenced to
years of imprisonment and ordered to surrender over
million in ill-gotten gains. The government proved its case against him, in part, using emails obtained from his
ISPs.]
II. A
A. The Search & Seizure of Warshak’s Emails
Warshak argues that the government’s warrantless, ex parte seizure of approximately ,
of his private emails constituted a violation of the Fourth Amendment’s prohibition on unreasonable searches and seizures. The government counters that, even if government agents violated the Fourth Amendment in obtaining
the emails, they relied in good faith on the Stored Communications Act (“SCA”),
U.S.C. §§
et seq., a statute that allows the government to obtain certain electronic communications without procuring a warrant. The government also argues
that any hypothetical Fourth Amendment violation was harmless. We find that the
government did violate Warshak’s Fourth Amendment rights by compelling his
Internet Service Provider (“ISP”) to turn over the contents of his emails. …
Internet Law
3
2
5
3
3
0
7
4
8
2
9
2
3
1
5
1
3
1
0
1
7
4
2
0
9
0
0
2
1
6
6
5
6
8
4
8
0
1
0
9
1
2
7
0
6
2
0
0
6
2
6
8
7
0
7
0
5
4
0
5
7
7
2
5
3
5
0
5
0
9
0
2
2
0
4
2
3
0
7
. The Stored Communications Act
The Stored Communications Act (“SCA”),
U.S.C. §§
et seq., “permits a
‘governmental entity’ to compel a service provider to disclose the contents of [electronic] communications in certain circumstances.” Warshak II,
F. d at
.…
. Factual Background
Email was a critical form of communication among Berkeley personnel. As a consequence, Warshak had a number of email accounts with various ISPs, including
an account with NuVox Communications. In October
, the government formally requested that NuVox prospectively preserve the contents of any emails to or
from Warshak’s email account. … NuVox acceded to the government’s request and
began preserving copies of Warshak’s incoming and outgoing emails – copies that
would not have existed absent the prospective preservation request. Per the government’s instructions, Warshak was not informed that his messages were being
archived.
In January
, the government obtained a subpoena under §
(b) and
compelled NuVox to turn over the emails that it had begun preserving the previous
year. In May
, the government served NuVox with an ex parte court order
under §
(d) that required NuVox to surrender any additional email messages
in Warshak’s account. In all, the government compelled NuVox to reveal the contents of approximately ,
emails. Warshak did not receive notice of either the
subpoena or the order until May
.
. The Fourth Amendment …
Not all government actions are invasive enough to implicate the Fourth Amendment. “The Fourth Amendment’s protections hinge on the occurrence of a ‘search,’
a legal term of art whose history is riddled with complexity.” Widgren v. Maple
Grove Twp.,
F. d
,
( th Cir.
). A “search” occurs when the government infringes upon “an expectation of privacy that society is prepared to consider reasonable.” United States v. Jacobsen,
U.S.
,
(
). This standard breaks down into two discrete inquiries: “first, has the [target of the investigation] manifested a subjective expectation of privacy in the object of the challenged search? Second, is society willing to recognize that expectation as reasonable?” California v. Ciraolo,
U.S.
(
).
Turning first to the subjective component of the test, we find that Warshak
plainly manifested an expectation that his emails would be shielded from outside
scrutiny. As he notes in his brief, his “entire business and personal life was contained within the . . . emails seized.” Given the often sensitive and sometimes
damning substance of his emails, we think it highly unlikely that Warshak expected them to be made public, for people seldom unfurl their dirty laundry in plain
view. …
The next question is whether society is prepared to recognize that expectation
as reasonable. This question is one of grave import and enduring consequence,
given the prominent role that email has assumed in modern communication.
Since the advent of email, the telephone call and the letter have waned in importance, and an explosion of Internet-based communication has taken place. People
are now able to send sensitive and intimate information, instantaneously, to
friends, family, and colleagues half a world away. Lovers exchange sweet nothings,
and businessmen swap ambitious plans, all with the click of a mouse button.
Commerce has also taken hold in email. Online purchases are often documented
in email accounts, and email is frequently used to remind patients and clients of
2
1
2
3
188
Chapter 4: Privacy
189
1
5
3
9
8
3
0
3
6
2
2
5
3
0
3
1
9
8
3
imminent appointments. In short, “account” is an apt word for the conglomeration
of stored messages that comprises an email account, as it provides an account of
its owner’s life. By obtaining access to someone’s email, government agents gain
the ability to peer deeply into his activities. Much hinges, therefore, on whether
the government is permitted to request that a commercial ISP turn over the contents of a subscriber’s emails without triggering the machinery of the Fourth
Amendment.
In confronting this question, we take note of two bedrock principles. First, the
very fact that information is being passed through a communications network is a
paramount Fourth Amendment consideration. Second, the Fourth Amendment
must keep pace with the inexorable march of technological progress, or its guarantees will wither and perish.
With those principles in mind, we begin our analysis by considering the manner in which the Fourth Amendment protects traditional forms of communication.
In Katz, the Supreme Court was asked to determine how the Fourth Amendment
applied in the context of the telephone. There, government agents had affixed an
electronic listening device to the exterior of a public phone booth, and had used
the device to intercept and record several phone conversations. The Supreme
Court held that this constituted a search under the Fourth Amendment, notwithstanding the fact that the telephone company had the capacity to monitor and
record the calls, In the eyes of the Court, the caller was “surely entitled to assume
that the words he utter[ed] into the mouthpiece w[ould] not be broadcast to the
world.” Katz,
U.S. at
. The Court’s holding in Katz has since come to stand
for the broad proposition that, in many contexts, the government infringes a reasonable expectation of privacy when it surreptitiously intercepts a telephone call
through electronic means.
Letters receive similar protection. While a letter is in the mail, the police may
not intercept it and examine its contents unless they first obtain a warrant based
on probable cause. This is true despite the fact that sealed letters are handed over
to perhaps dozens of mail carriers, any one of whom could tear open the thin paper envelopes that separate the private words from the world outside. Put another
way, trusting a letter to an intermediary does not necessarily defeat a reasonable
expectation that the letter will remain private. See Katz,
U.S. at
(“[W]hat
[a person] seeks to preserve as private, even in an area accessible to the public,
may be constitutionally protected.”).
Given the fundamental similarities between email and traditional forms of
communication, it would defy common sense to afford emails lesser Fourth
Amendment protection. … Email is the technological scion of tangible mail, and it
plays an indispensable part in the Information Age. Over the last decade, email
has become “so pervasive that some persons may consider [it] to be [an] essential
means or necessary instrument[] for self-expression, even self-identification.” City
of Ontario v. Quon,
S. Ct. at
. It follows that email requires strong protection under the Fourth Amendment; otherwise, the Fourth Amendment would
prove an ineffective guardian of private communication, an essential purpose it
has long been recognized to serve. … As some forms of communication begin to
diminish, the Fourth Amendment must recognize and protect nascent ones that
arise.
If we accept that an email is analogous to a letter or a phone call, it is manifest
that agents of the government cannot compel a commercial ISP to turn over the
contents of an email without triggering the Fourth Amendment. An ISP is the in-
4
2
8
6
2
9
4
9
8
9
7
3
6
2
5
9
3
6
3
3
7
5
6
0
1
7
4
6
4
7
0
1
0
2
2
2
1
4
4
7
6
9
1
9
0
9
0
2
8
7
4
9
6
9
1
3
4
6
6
We note that the access granted to NuVox was also temporally limited, as Warshak’s
email account was configured to delete his emails from NuVox’s servers as soon as he
opened them on his personal computer.
6
1
Internet Law
termediary that makes email communication possible. Emails must pass through
an ISP’s servers to reach their intended recipient. Thus, the ISP is the functional
equivalent of a post office or a telephone company. As we have discussed above,
the police may not storm the post office and intercept a letter, and they are likewise forbidden from using the phone system to make a clandestine recording of a
telephone call – unless they get a warrant, that is. It only stands to reason that, if
government agents compel an ISP to surrender the contents of a subscriber’s
emails, those agents have thereby conducted a Fourth Amendment search, which
necessitates compliance with the warrant requirement absent some exception.
In Warshak I, the government argued that this conclusion was improper, pointing to the fact that NuVox contractually reserved the right to access Warshak’s
emails for certain purposes. While we acknowledge that a subscriber agreement
might, in some cases, be sweeping enough to defeat a reasonable expectation of
privacy in the contents of an email account, … we doubt that will be the case in
most situations, and it is certainly not the case here.
As an initial matter, it must be observed that the mere ability of a third-party
intermediary to access the contents of a communication cannot be sufficient to
extinguish a reasonable expectation of privacy. In Katz, the Supreme Court found
it reasonable to expect privacy during a telephone call despite the ability of an operator to listen in. See Smith,
U.S. at
- (Stewart, J., dissenting). Similarly, the ability of a rogue mail handler to rip open a letter does not make it unreasonable to assume that sealed mail will remain private on its journey across the
country. Therefore, the threat or possibility of access is not decisive when it comes
to the reasonableness of an expectation of privacy.
Nor is the right of access. As the Electronic Frontier Foundation points out in
its amicus brief, at the time Katz was decided, telephone companies had a right to
monitor calls in certain situations. Specifically, telephone companies could listen
in when reasonably necessary to “protect themselves and their properties against
the improper and illegal use of their facilities.” Bubis v. United States,
F. d
,
( th Cir.
). In this case, the NuVox subscriber agreement tracks that
language, indicating that ”NuVox may access and use individual Subscriber information in the operation of the Service and as necessary to protect the Service.” Acceptable Use Policy, available at http://business.windstream.com/Legal/acceptableUse.htm (last visited Aug. ,
). Thus, under Katz, the degree of access
granted to NuVox does not diminish the reasonableness of Warshak’s trust in the
privacy of his emails.
Our conclusion finds additional support in the application of Fourth Amendment doctrine to rented space. Hotel guests, for example, have a reasonable expectation of privacy in their rooms. See United States v. Allen,
F. d
,
( th
Cir.
). This is so even though maids routinely enter hotel rooms to replace the
towels and tidy the furniture. Similarly, tenants have a legitimate expectation of
privacy in their apartments. See United States v. Washington,
F. d
,
( th Cir.
). That expectation persists, regardless of the incursions of handymen to fix leaky faucets. Consequently, we are convinced that some degree of routine access is hardly dispositive with respect to the privacy question.
6
1
190
191
Again, however, we are unwilling to hold that a subscriber agreement will never
be broad enough to snuff out a reasonable expectation of privacy. As the panel
noted in Warshak I, if the ISP expresses an intention to “audit, inspect, and monitor” its subscriber’s emails, that might be enough to render an expectation of privacy unreasonable. See
F. d at
- (quoting United States v. Simons,
F. d
,
( th Cir.
)). But where, as here, there is no such statement, the
ISP’s “control over the [emails] and ability to access them under certain limited
circumstances will not be enough to overcome an expectation of privacy.” Id. at
.
We recognize that our conclusion may be attacked in light of the Supreme
Court’s decision in United States v. Miller,
U.S.
(
). In Miller, the
Supreme Court held that a bank depositor does not have a reasonable expectation
of privacy in the contents of bank records, checks, and deposit slips. Id. at
.
The Court’s holding in Miller was based on the fact that bank documents, “including financial statements and deposit slips, contain only information voluntarily
conveyed to the banks and exposed to their employees in the ordinary course of
business.” Id. The Court noted,
The depositor takes the risk, in revealing his affairs to another, that
the information will be conveyed by that person to the
Government. . . . [T]he Fourth Amendment does not prohibit the obtaining of information revealed to a third party and conveyed by him
to Government authorities, even if the information is revealed on the
assumption that it will be used only for a limited purpose and the confidence placed in the third party will not be betrayed.
Id. at
(citations omitted).
But Miller is distinguishable. First, Miller involved simple business records, as
opposed to the potentially unlimited variety of “confidential communications” at
issue here. See id. Second, the bank depositor in Miller conveyed information to
the bank so that the bank could put the information to use “in the ordinary course
of business.” Id. By contrast, Warshak received his emails through NuVox. NuVox
was an intermediary, not the intended recipient of the emails. See Bellia & Freiwald, Stored E-Mail,
U. Chi. Legal F. at
(“[W]e view the best analogy for
this scenario as the cases in which a third party carries, transports, or stores property for another. In these cases, as in the stored e-mail case, the customer grants
access to the ISP because it is essential to the customer’s interests.”). Thus, Miller
is not controlling.
Accordingly, we hold that a subscriber enjoys a reasonable expectation of privacy in the contents of emails “that are stored with, or sent or received through, a
commercial ISP.” Warshak I,
F. d at
. … The government may not compel
a commercial ISP to turn over the contents of a subscriber’s emails without first
obtaining a warrant based on probable cause. Therefore, because they did not obtain a warrant, the government agents violated the Fourth Amendment when they
obtained the contents of Warshak’s emails. Moreover, to the extent that the SCA
purports to permit the government to obtain such emails warrantlessly, the SCA is
unconstitutional.
6
0
2
4
2
4
6
7
9
1
5
3
4
5
5
2
6
4
1
3
7
3
4
7
2
7
4
3
0
9
3
4
0
0
0
9
0
8
4
2
0
2
4
8
9
3
3
2
4
9
4
3
3
3
0
QUESTIONS
Local vs. Cloud Searches: Presumably, Warshak’s computer also contained
copies of his emails. Why didn’t the government simply seize the computer
and search through the emails on it?
.
7
4
1
Chapter 4: Privacy
Internet Law
. Third-Party Cases: If you send an email to a friend describing your plans to
assassinate the mayor of Metropolis, does the Fourth Amendment prohibit
your friend from turning over the email to the Metropolis Police Department? If you send sexually explicit instant messages to “WetRiffs ,” who
turns out to be a
-year-old FBI agent, have your Fourth Amendment
rights been violated? Are these hypotheticals on point with Warshak? Or
consider United States v. Morel,
DNH
,
WL
(D.N.H.
Apr. ,
), in which the defendant uploaded several images containing
child sexual abuse material to the file-sharing site Imgur, where anyone with
the URL could view them. This, the court held, was inconsistent with “taking affirmative steps to protect the information” — even without further
proof that the defendant had actually shared the URL with anyone. Is this
result consistent with Warshak?
. Cloud Syncing: Google’s Chrome web browser has a “sync” feature that will
transfer your bookmarks from one computer to another. To make it work,
your copy of Chrome on the first computer needs to transmit the list of
bookmarks to Google’s servers, from which your second computer can then
download it. After Warshak, would the government need a search warrant
to get the list of your bookmarks from Google?
. Human vs. Computer Review: If you were reading the quoted language from
NuVox’x subscriber agreement, when, if ever, would you expect a human
employee of NuVox to read your emails? Gmail uses computers to automatically scan image and video attachments to users’ emails to identify CSAM.
After Warshak, do Gmail users have an expectation of privacy in their
emails? What about people who sent email to Gmail users?
. Terms of Service: Other courts have been more willing to hold that terms of
service can destroy an expectation of privacy. For example, in Holmes v.
Petrovich Development Co.,
Cal. App. th
(Ct. App.
), the court
held that a company’s acceptable use policy (which stated that work computers were not to be used for personal purposes and that all computer use
could be monitored) meant that an employee waived the attorney-client
privilege by using her work computer to email her lawyer. Can Holmes be
reconciled with Warshak?
CARPENTER V. UNITED STATES
585 U.S. 296 (2018)
3
1
3
6
1
3
1
6
0
7
2
3
1
7
1
0
2
7
4
2
0
7
1
0
4
7
1
0
2
1
9
1
5
3
6
7
1
9
3
0
6
2
2
3
4
Chief Justice Roberts delivered the opinion of the Court.
This case presents the question whether the Government conducts a search
under the Fourth Amendment when it accesses historical cell phone records that
provide a comprehensive chronicle of the user’s past movements.
I
A
There are
million cell phone service accounts in the United States—for a Nation of
million people. Cell phones perform their wide and growing variety of
functions by connecting to a set of radio antennas called “cell sites.” Although cell
sites are usually mounted on a tower, they can also be found on light posts, flagpoles, church steeples, or the sides of buildings. Cell sites typically have several
directional antennas that divide the covered area into sectors.
1
2
5
4
3
192
Chapter 4: Privacy
193
2
7
5
2
1
1
4
9
9
1
8
9
8
2
1
1
0
1
3
0
7
2
5
1
8
1
1
1
0
2
Cell phones continuously scan their environment looking for the best signal,
which generally comes from the closest cell site. Most modern devices, such as
smartphones, tap into the wireless network several times a minute whenever their
signal is on, even if the owner is not using one of the phone’s features. Each time
the phone connects to a cell site, it generates a time-stamped record known as cellsite location information (CSLI). The precision of this information depends on the
size of the geographic area covered by the cell site. The greater the concentration
of cell sites, the smaller the coverage area. As data usage from cell phones has increased, wireless carriers have installed more cell sites to handle the traffic. That
has led to increasingly compact coverage areas, especially in urban areas.
Wireless carriers collect and store CSLI for their own business purposes, including finding weak spots in their network and applying “roaming” charges when
another carrier routes data through their cell sites. In addition, wireless carriers
often sell aggregated location records to data brokers, without individual identifying information of the sort at issue here. While carriers have long retained CSLI
for the start and end of incoming calls, in recent years phone companies have also
collected location information from the transmission of text messages and routine
data connections. Accordingly, modern cell phones generate increasingly vast
amounts of increasingly precise CSLI.
B
In
, police officers arrested four men suspected of robbing a series of Radio
Shack and (ironically enough) T-Mobile stores in Detroit. One of the men confessed that, over the previous four months, the group (along with a rotating cast of
getaway drivers and lookouts) had robbed nine different stores in Michigan and
Ohio. The suspect identified
accomplices who had participated in the heists
and gave the FBI some of their cell phone numbers; the FBI then reviewed his call
records to identify additional numbers that he had called around the time of the
robberies.
Based on that information, the prosecutors applied for court orders under the
Stored Communications Act to obtain cell phone records for petitioner Timothy
Carpenter and several other suspects. That statute, as amended in
, permits
the Government to compel the disclosure of certain telecommunications records
when it “offers specific and articulable facts showing that there are reasonable
grounds to believe” that the records sought “are relevant and material to an ongoing criminal investigation.”
U.S.C. §
(d). Federal Magistrate Judges issued
two orders directing Carpenter’s wireless carriers—MetroPCS and Sprint—to disclose “cell/site sector [information] for [Carpenter’s] telephone[] at call origination and at call termination for incoming and outgoing calls” during the fourmonth period when the string of robberies occurred. The first order sought
days of cell-site records from MetroPCS, which produced records spanning
days. The second order requested seven days of CSLI from Sprint, which produced
two days of records covering the period when Carpenter’s phone was “roaming” in
northeastern Ohio. Altogether the Government obtained ,
location points
cataloging Carpenter’s movements—an average of
data points per day.
Carpenter was charged with six counts of robbery and an additional six counts
of carrying a firearm during a federal crime of violence. Prior to trial, Carpenter
moved to suppress the cell-site data provided by the wireless carriers. He argued
that the Government’s seizure of the records violated the Fourth Amendment because they had been obtained without a warrant supported by probable cause. The
District Court denied the motion. …
194
Internet Law
5
5
6
1
4
5
3
8
9
1
6
7
8
2
2
6
5
1
7
0
9
6
4
1
4
2
3
8
2
4
4
4
1
4
7
8
5
2
3
3
4
4
7
5
2
4
8
2
2
4
4
4
6
2
4
0
3
4
1
5
8
0
2
4
4
0
4
II …
B
The case before us involves the Government’s acquisition of wireless carrier cellsite records revealing the location of Carpenter’s cell phone whenever it made or
received calls. This sort of digital data—personal location information maintained
by a third party—does not fit neatly under existing precedents. Instead, requests
for cell-site records lie at the intersection of two lines of cases, both of which inform our understanding of the privacy interests at stake.
The first set of cases addresses a person’s expectation of privacy in his physical
location and movements. In United States v. Knotts,
U.S.
(
), we considered the Government’s use of a “beeper” to aid in tracking a vehicle through
traffic. Police officers in that case planted a beeper in a container of chloroform
before it was purchased by one of Knotts’s co-conspirators. The officers (with intermittent aerial assistance) then followed the automobile carrying the container
from Minneapolis to Knotts’s cabin in Wisconsin, relying on the beeper’s signal to
help keep the vehicle in view. The Court concluded that the “augment[ed]” visual
surveillance did not constitute a search because “[a] person traveling in an automobile on public thoroughfares has no reasonable expectation of privacy in his
movements from one place to another.” id. at
,
. Since the movements of the
vehicle and its final destination had been “voluntarily conveyed to anyone who
wanted to look,” Knotts could not assert a privacy interest in the information obtained. Id. at
.…
Three decades later, the Court considered more sophisticated surveillance of
the sort envisioned in Knotts and found that different principles did indeed apply.
In United States v. Jones, FBI agents installed a GPS tracking device on Jones’s
vehicle and remotely monitored the vehicle’s movements for
days. The Court
decided the case based on the Government’s physical trespass of the vehicle.
U.S. at
–
. At the same time, five Justices agreed that related privacy concerns would be raised by, for example, “surreptitiously activating a stolen vehicle
detection system” in Jones’s car to track Jones himself, or conducting GPS tracking
of his cell phone. Id., at
,
(Alito, J., concurring in judgment); id. at
(Sotomayor, J., concurring). Since GPS monitoring of a vehicle tracks “every
movement” a person makes in that vehicle, the concurring Justices concluded that
“longer term GPS monitoring in investigations of most offenses impinges on expectations of privacy”—regardless whether those movements were disclosed to the
public at large. Id. at
(opinion of Alito, J.); id. at
(opinion of Sotomayor,
J.).
In a second set of decisions, the Court has drawn a line between what a person
keeps to himself and what he shares with others. We have previously held that “a
person has no legitimate expectation of privacy in information he voluntarily turns
over to third parties.” Smith,
U.S. at
–
. That remains true “even if the
information is revealed on the assumption that it will be used only for a limited
purpose.” United States v. Miller,
U.S.
,
(
). As a result, the Government is typically free to obtain such information from the recipient without
triggering Fourth Amendment protections.
This third-party doctrine largely traces its roots to Miller. While investigating
Miller for tax evasion, the Government subpoenaed his banks, seeking several
months of canceled checks, deposit slips, and monthly statements. The Court rejected a Fourth Amendment challenge to the records collection. For one, Miller
could “assert neither ownership nor possession” of the documents; they were
Chapter 4: Privacy
195
3
4
4
3
4
5
7
4
4
4
7
7
2
4
4
9
2
7
4
7
9
1
0
2
4
4
4
4
“business records of the banks.” Id. at
. For another, the nature of those records
confirmed Miller’s limited expectation of privacy, because the checks were “not
confidential communications but negotiable instruments to be used in commercial
transactions,” and the bank statements contained information “exposed to [bank]
employees in the ordinary course of business.” Id. at
. The Court thus concluded that Miller had “take[n] the risk, in revealing his affairs to another, that the
information [would] be conveyed by that person to the Government.” Id. at
.
Three years later, Smith applied the same principles in the context of information conveyed to a telephone company. The Court ruled that the Government’s use
of a pen register—a device that recorded the outgoing phone numbers dialed on a
landline telephone—was not a search. Noting the pen register’s “limited capabilities,” the Court “doubt[ed] that people in general entertain any actual expectation
of privacy in the numbers they dial.”
U.S. at
. Telephone subscribers know,
after all, that the numbers are used by the telephone company “for a variety of legitimate business purposes,” including routing calls. Id. at
. And at any rate,
the Court explained, such an expectation “is not one that society is prepared to
recognize as reasonable.” Id. When Smith placed a call, he “voluntarily conveyed”
the dialed numbers to the phone company by “expos[ing] that information to its
equipment in the ordinary course of business.” Id. at
(internal quotation
marks omitted). Once again, we held that the defendant “assumed the risk” that
the company’s records “would be divulged to police.” Id. at
.
III
The question we confront today is how to apply the Fourth Amendment to a new
phenomenon: the ability to chronicle a person’s past movements through the
record of his cell phone signals. Such tracking partakes of many of the qualities of
the GPS monitoring we considered in Jones. Much like GPS tracking of a vehicle,
cell phone location information is detailed, encyclopedic, and effortlessly compiled.
At the same time, the fact that the individual continuously reveals his location
to his wireless carrier implicates the third-party principle of Smith and Miller. But
while the third-party doctrine applies to telephone numbers and bank records, it is
not clear whether its logic extends to the qualitatively different category of cell-site
records. After all, when Smith was decided in
, few could have imagined a
society in which a phone goes wherever its owner goes, conveying to the wireless
carrier not just dialed digits, but a detailed and comprehensive record of the person’s movements.
We decline to extend Smith and Miller to cover these novel circumstances. Given the unique nature of cell phone location records, the fact that the information is
held by a third party does not by itself overcome the user’s claim to Fourth
Amendment protection. Whether the Government employs its own surveillance
technology as in Jones or leverages the technology of a wireless carrier, we hold
that an individual maintains a legitimate expectation of privacy in the record of his
196
Internet Law
physical movements as captured through CSLI. The location information obtained from Carpenter’s wireless carriers was the product of a search.
A
A person does not surrender all Fourth Amendment protection by venturing into
the public sphere. … A majority of this Court has already recognized that individuals have a reasonable expectation of privacy in the whole of their physical movements. Prior to the digital age, law enforcement might have pursued a suspect for
a brief stretch, but doing so “for any extended period of time was difficult and
costly and therefore rarely undertaken.” Jones,
U.S. at
(opinion of Alito,
J.). For that reason, “society’s expectation has been that law enforcement agents
and others would not— and indeed, in the main, simply could not—secretly monitor and catalogue every single movement of an individual’s car for a very long period.” Id. at
.
Allowing government access to cell-site records contravenes that expectation.
Although such records are generated for commercial purposes, that distinction
does not negate Carpenter’s anticipation of privacy in his physical location. Mapping a cell phone’s location over the course of
days provides an all-encompassing record of the holder’s whereabouts. As with GPS information, the timestamped data provides an intimate window into a person’s life, revealing not only
his particular movements, but through them his “familial, political, professional,
religious, and sexual associations.” Id. at
(opinion of Sotomayor, J.). … And like
GPS monitoring, cell phone tracking is remarkably easy, cheap, and efficient compared to traditional investigative tools. With just the click of a button, the Government can access each carrier’s deep repository of historical location information at practically no expense.
In fact, historical cell-site records present even greater privacy concerns than
the GPS monitoring of a vehicle we considered in Jones. Unlike the bugged container in Knotts or the car in Jones, a cell phone—almost a feature of human
anatomy—tracks nearly exactly the movements of its owner. While individuals
regularly leave their vehicles, they compulsively carry cell phones with them all the
time. A cell phone faithfully follows its owner beyond public thoroughfares and
into private residences, doctor’s offices, political headquarters, and other potentially revealing locales. Accordingly, when the Government tracks the location of a
cell phone it achieves near perfect surveillance, as if it had attached an ankle monitor to the phone’s user.
Moreover, the retrospective quality of the data here gives police access to a category of information otherwise unknowable. In the past, attempts to reconstruct a
person’s movements were limited by a dearth of records and the frailties of recollection. With access to CSLI, the Government can now travel back in time to re*
9
2
6
5
4
5
5
5
6
5
7
2
1
5
1
4
4
2
0
3
4
2
1
3
3
The parties suggest as an alternative to their primary submissions that the acquisition of CSLI becomes a search only if it extends beyond a limited period. See Reply
Brief
(proposing a
-hour cutoff ); Brief for United States – (suggesting a
seven-day cutoff ). As part of its argument, the Government treats the seven days of
CSLI requested from Sprint as the pertinent period, even though Sprint produced
only two days of records. … [W]e need not decide whether there is a limited period
for which the Government may obtain an individual’s historical CSLI free from
Fourth Amendment scrutiny, and if so, how long that period might be. It is sufficient
for our purposes today to hold that accessing seven days of CSLI constitutes a Fourth
Amendment search.
Chapter 4: Privacy
197
7
2
1
0
0
4
0
5
trace a person’s whereabouts, subject only to the retention polices of the wireless
carriers, which currently maintain records for up to five years. Critically, because
location information is continually logged for all of the
million devices in the
United States—not just those belonging to persons who might happen to come
under investigation—this newfound tracking capacity runs against everyone.
Unlike with the GPS device in Jones, police need not even know in advance
whether they want to follow a particular individual, or when.
Whoever the suspect turns out to be, he has effectively been tailed every moment of every day for five years, and the police may—in the Government’s view—
call upon the results of that surveillance without regard to the constraints of the
Fourth Amendment. Only the few without cell phones could escape this tireless
and absolute surveillance.
The Government and Justice Kennedy contend, however, that the collection of
CSLI should be permitted because the data is less precise than GPS information.
Not to worry, they maintain, because the location records did “not on their own
suffice to place [Carpenter] at the crime scene”; they placed him within a wedgeshaped sector ranging from one-eighth to four square miles. Yet the Court has already rejected the proposition that inference insulates a search. From the
days
of location data it received, the Government could, in combination with other information, deduce a detailed log of Carpenter’s movements, including when he
was at the site of the robberies. And the Government thought the CSLI accurate
enough to highlight it during the closing argument of his trial.
At any rate, the rule the Court adopts must take account of more sophisticated
systems that are already in use or in development. While the records in this case
reflect the state of technology at the start of the decade, the accuracy of CSLI is
rapidly approaching GPS-level precision. As the number of cell sites has proliferated, the geographic area covered by each cell sector has shrunk, particularly in
urban areas. In addition, with new technology measuring the time and angle of
signals hitting their towers, wireless carriers already have the capability to pinpoint a phone’s location within
meters.
Accordingly, when the Government accessed CSLI from the wireless carriers, it
invaded Carpenter’s reasonable expectation of privacy in the whole of his physical
movements.
B
The Government’s primary contention to the contrary is that the third-party doctrine governs this case. In its view, cell-site records are fair game because they are
“business records” created and maintained by the wireless carriers. The Government … recognizes that this case features new technology, but asserts that the legal
question nonetheless turns on a garden-variety request for information from a
third-party witness.
The Government’s position fails to contend with the seismic shifts in digital
technology that made possible the tracking of not only Carpenter’s location but
also everyone else’s, not for a short period but for years and years. Sprint Corporation and its competitors are not your typical witnesses. Unlike the nosy neighbor
who keeps an eye on comings and goings, they are ever alert, and their memory is
nearly infallible. There is a world of difference between the limited types of personal information addressed in Smith and Miller and the exhaustive chronicle of
location information casually collected by wireless carriers today. The Government
thus is not asking for a straightforward application of the third-party doctrine, but
instead a significant extension of it to a distinct category of information.
Internet Law
1
5
8
2
2
4
6
1
0
6
4
0
3
4
3
7
5
5
6
5
9
4
2
2
4
4
5
1
4
5
2
4
3
3
7
8
2
5
2
4
4
3
The third-party doctrine partly stems from the notion that an individual has a
reduced expectation of privacy in information knowingly shared with another. But
the fact of “diminished privacy interests does not mean that the Fourth Amendment falls out of the picture entirely.” Riley,
U.S. at ___ (slip op., at ). Smith
and Miller, after all, did not rely solely on the act of sharing. Instead, they considered “the nature of the particular documents sought” to determine whether “there
is a legitimate ‘expectation of privacy’ concerning their contents.” Miller,
U.S.
at
. Smith pointed out the limited capabilities of a pen register; as explained in
Riley, telephone call logs reveal little in the way of “identifying information.” Riley,
U.S. at ___ (slip op., at ). Miller likewise noted that checks were “not confidential communications but negotiable instruments to be used in commercial
transactions.”
U.S. at
. In mechanically applying the third-party doctrine
to this case, the Government fails to appreciate that there are no comparable limitations on the revealing nature of CSLI.
The Court has in fact already shown special solicitude for location information
in the third-party context. In Knotts, the Court relied on Smith to hold that an individual has no reasonable expectation of privacy in public movements that he
“voluntarily conveyed to anyone who wanted to look.” Knotts,
U.S. at
; see
id. at
(discussing Smith). But when confronted with more pervasive tracking,
five Justices agreed that longer term GPS monitoring of even a vehicle traveling on
public streets constitutes a search. Jones,
U.S. at
(Alito, J., concurring in
judgment); id., at
(Sotomayor, J., concurring). Justice Gorsuch wonders why
“someone’s location when using a phone” is sensitive, and Justice Kennedy assumes that a person’s discrete movements “are not particularly private.” Yet this
case is not about “using a phone” or a person’s movement at a particular time. It is
about a detailed chronicle of a person’s physical presence compiled every day,
every moment, over several years. Such a chronicle implicates privacy concerns far
beyond those considered in Smith and Miller.
Neither does the second rationale underlying the third-party doctrine—voluntary exposure—hold up when it comes to CSLI. Cell phone location information is
not truly “shared” as one normally understands the term. In the first place, cell
phones and the services they provide are “such a pervasive and insistent part of
daily life” that carrying one is indispensable to participation in modern society.
Riley,
U.S. at ___ (slip op., at ). Second, a cell phone logs a cell-site record by
dint of its operation, without any affirmative act on the part of the user beyond
powering up. Virtually any activity on the phone generates CSLI, including incoming calls, texts, or e-mails and countless other data connections that a phone automatically makes when checking for news, weather, or social media updates.
Apart from disconnecting the phone from the network, there is no way to avoid
leaving behind a trail of location data. As a result, in no meaningful sense does the
user voluntarily assume the risk of turning over a comprehensive dossier of his
physical movements.
We therefore decline to extend Smith and Miller to the collection of CSLI. Given the unique nature of cell phone location information, the fact that the Government obtained the information from a third party does not overcome Carpenter’s
claim to Fourth Amendment protection. The Government’s acquisition of the cellsite records was a search within the meaning of the Fourth Amendment.
***
Our decision today is a narrow one. We do not express a view on matters not before us: real-time CSLI or “tower dumps” (a download of information on all the
7
5
198
Chapter 4: Privacy
199
1
6
7
1
9
0
1
2
1
0
6
6
5
4
3
0
0
2
6
7
5
2
3
5
4
0
7
3
2
4
5
3
6
5
4
4
8
9
8
2
1
4
1
0
0
3
2
9
2
2
2
3
devices that connected to a particular cell site during a particular interval). We do
not disturb the application of Smith and Miller or call into question conventional
surveillance techniques and tools, such as security cameras. Nor do we address
other business records that might incidentally reveal location information. Further, our opinion does not consider other collection techniques involving foreign
affairs or national security. As Justice Frankfurter noted when considering new
innovations in airplanes and radios, the Court must tread carefully in such cases,
to ensure that we do not “embarrass the future.” Northwest Airlines, Inc. v. Minnesota,
U.S.
,
(
).
IV
Having found that the acquisition of Carpenter’s CSLI was a search, we also conclude that the Government must generally obtain a warrant supported by probable
cause before acquiring such records. …
The Government acquired the cell-site records pursuant to a court order issued
under the Stored Communications Act, which required the Government to show
“reasonable grounds” for believing that the records were “relevant and material to
an ongoing investigation.”
U.S.C. §
(d). That showing falls well short of the
probable cause required for a warrant. The Court usually requires “some quantum
of individualized suspicion” before a search or seizure may take place. United
States v. Martinez-Fuerte,
U.S.
,
–
(
). Under the standard in
the Stored Communications Act, however, law enforcement need only show that
the cell-site evidence might be pertinent to an ongoing investigation—a “gigantic”
departure from the probable cause rule, as the Government explained below. Consequently, an order issued under Section
(d) of the Act is not a permissible
mechanism for accessing historical cell-site records. Before compelling a wireless
carrier to turn over a subscriber’s CSLI, the Government’s obligation is a familiar
one—get a warrant. …
This is certainly not to say that all orders compelling the production of documents will require a showing of probable cause. The Government will be able to
use subpoenas to acquire records in the overwhelming majority of investigations.
We hold only that a warrant is required in the rare case where the suspect has a
legitimate privacy interest in records held by a third party.
Further, even though the Government will generally need a warrant to access
CSLI, case-specific exceptions may support a warrantless search of an individual’s
cell-site records under certain circumstances. “One well-recognized exception applies when the exigencies of the situation make the needs of law enforcement so
compelling that a warrantless search is objectively reasonable under the Fourth
Amendment.” Kentucky v. King,
U.S.
,
(
). Such exigencies include
the need to pursue a fleeing suspect, protect individuals who are threatened with
imminent harm, or prevent the imminent destruction of evidence.
As a result, if law enforcement is confronted with an urgent situation, such
fact-specific threats will likely justify the warrantless collection of CSLI. Lower
courts, for instance, have approved warrantless searches related to bomb threats,
active shootings, and child abductions. Our decision today does not call into doubt
warrantless access to CSLI in such circumstances. While police must get a warrant
when collecting CSLI to assist in the mine- run criminal investigation, the rule we
set forth does not limit their ability to respond to an ongoing emergency.
***
Internet Law
As Justice Brandeis explained in his famous dissent, the Court is obligated—as
“[s]ubtler and more far-reaching means of invading privacy have become available
to the Government”—to ensure that the “progress of science” does not erode
Fourth Amendment protections. Olmstead v. United States,
U.S.
,
–
(
). Here the progress of science has afforded law enforcement a powerful
new tool to carry out its important responsibilities. At the same time, this tool
risks Government encroachment of the sort the Framers, after consulting the
lessons of history, drafted the Fourth Amendment to prevent.
We decline to grant the state unrestricted access to a wireless carrier’s database
of physical location information. In light of the deeply revealing nature of CSLI, its
depth, breadth, and comprehensive reach, and the inescapable and automatic nature of its collection, the fact that such information is gathered by a third party
does not make it any less deserving of Fourth Amendment protection. The Government’s acquisition of the cell-site records here was a search under that
Amendment. …
3
7
4
8
3
4
7
7
2
7
2
8
2
9
1
4
QUESTIONS
. Warshak vs. Carpenter: Why doesn’t Warshak’s holding help Carpenter?
Would Carpenter’s holding have helped Warshak?
. Third Parties: How much is left of the third-party doctrine after Carpenter?
Would Smith and Miller come out the same way if they weren’t already on
the books?
. How Long? In Jones, five Justices suggested that twenty-eight days of GPS
tracking were a search. Carpenter holds that seven days of CLSI tracking are
a search. What about one day? One minute?
. Metadata: Is it a search under Carpenter for the police to obtain SMS messaging metadata from your cellular provider, such as whom you sent a text message to and when? What about Facebook Messages metadata? Email metadata? Telephone-call metadata? Skype metadata?
. IP Addresses: Is it a Carpenter search for the police to obtain a list of IP addresses you communicated with from your ISP? To obtain the IP address you
were assigned by your ISP? Does it matter whether it’s a wireline or a wireless ISP?
. Online Services: Is it a Carpenter search for the police to obtain your PayPal
transactions? Your Amazon purchases? Your Lyft rides? Your Instagram
likes? Your Google Docs documents?
. Particularity: Carpenter is about what qualifies as a search at all, but does it
also speak to the scope of a search? If the police have probable cause that
Luther used his Facebook account to plan the murder of a member of the
Gramercy Riffs street gang, can the warrant authorize the search and seizure
of all contents of the account since its creation, or does the warrant need to
be restricted to certain types of information over a narrower timeframe?
. Reverse Keyword Searches: The police are investigating a possible arson. They
serve Google with a search warrant to identify the IP addresses of any users
who searched for “ Union Street”, the location of the fire, in the past fifteen
days. Is this a Fourth Amendment violation?
7
4
8
7
6
5
4
3
2
1
200
Chapter 4: Privacy
201
BANK ROBBERY PROBLEM
At : PM on June , a group of four thieves robbed the First Bank of Atlanta
and then fled northward in a stolen car, which they abandoned in a parking garage
half a mile away at roughly : PM. The police served Google with a search warrant, requesting a list of all accounts associated with mobile devices that logged in
to Google’s services (e.g. Google Maps) between : and : PM within
feet of the bank, and another similar list within
feet of the parking garage between :
and :
PM. Google produced the lists, each of which contained
approximately
account IDs. The police compared the two lists and identified
twelve IDs on both lists. They then served Google with a second search warrant for
the IP addresses, account-owner names, communications contents, and full location history of those accounts. Google again produced the requested information.
Your client, Miles Elgort, has been arrested and charged with serving as the
getaway driver in the June robbery. His cell phone was one of the twelve devices
identified in the second warrant, and the indictment relies on emails exchanged
between Elgort’s Gmail account and his alleged co-conspirators. Do you have a
basis to challenge the search warrant and exclude the contents of his Gmail account?
B. Wiretapping
0
8
1
0
5
8
8
1
1
5
3
2
1
5
2
2
0
1
0
5
5
4
2
1
8
6
8
9
8
0
1
5
2
1
0
7
0
2
5
1
2
2
2
1
2
0
1
5
7
3
4
2
2
0
2
1
1
0
3
1
0
5
7
2
1
2
2
The Constitution is hardly the only source of communications privacy law. A variety of federal and state statutes also regulate the use and disclosure of information
stored in computers or transmitted on networks. This section examines three
principal federal statutes on point: the Wiretap Act (codified at
U.S.C.
§§
–
), the Stored Communications Act (the SCA, codified at
U.S.C.
§§
–
) and the Pen Register and Trap and Trace statute (codified at
U.S.C. §§
– ). All three were heavily amended by the Electronic Communications Privacy Act of
, or ECPA, which is sometimes used to refer to the field
as a whole and sometimes used as a synonym for the SCA. These statutes have two
interlocking roles:
• To protect individuals from having their private communications seen by
other private parties.
• To regulate the process by which the government acquires private communications during investigations.
Unfortunately for statutory clarity, these two roles are utterly intermingled in the
federal communications privacy statutes. All three take the form of a general prohibition on unauthorized access, together with exceptions for private and governmental access under certain circumstances. Figuring out what law applies to a given situation is often a matter of extensive back-and-forth cross-referencing. As you
read through the statutes, keep in mind the private/governmental distinction and,
also, whether the communications are being intercepted while in transit
(“prospectively”), or retrieved after the fact (“retrospectively”). A third crucial distinction, familiar from the Fourth Amendment materials, is between the “contents” of a communication and other “non-content” information about it.
International jurisdictional overlaps can be messy. If Microsoft, a U.S. company
with subsidiaries and operations around the world, stores a user’s emails on a
server in Ireland, can United States authorities compel Microsoft to turn over the
202
Internet Law
emails? What about Irish authorities? Does it matter whether the user is American or Irish? In In the Matter of a Warrant to Search a Certain E-Mail Account
Controlled and Maintained by Microsoft Corporation,
F. d
( d Cir.
),
the court held that a warrant issued by a federal court under the Stored Communications Act could not reach emails stored in Ireland. The Supreme Court took
the case, but before it could rule, Congress passed the Clarifying Lawful Overseas
Use of Data (or “CLOUD”) Act, which mooted the case by making clear that SCA
warrants do not depend on where the server is,
U.S.C. §
. It also added
provisions to allow United States courts to engage in comity analyses to take into
account other governments’ interests when issuing SCA warrants, id. §
(h),
and to give other governments reciprocal access when they satisfy various complex
threshold due process conditions, id. §
. Other legal processes, such as Mutual Legal Assistance Treaties (MLATs), establish detailed procedures for law enforcement agencies in one country to take advantage of other countries’ investigatory powers, but the details frequently depend on the specifics of the agreement
between each pair of countries. The Hague Convention on the Taking of Evidence
Abroad in Civil or Commercial Matters, Mar. ,
,
U.N.T.S.
, to which
sixty-six countries (including the United States) are parties, provides procedures
for civil litigants to use subpoenas (or local equivalents) in other countries.
WIRETAP ACT
Title 18, United States Code
6
1
0
3
2
0
7
2
1
4
2
2
7
3
1
9
1
7
2
3
7
9
4
2
8
8
0
7
8
9
1
1
8
1
3
2
5
2
fi
0
1
5
8
4
2
1
2
1
– De nitions
( ) “wire communication” means any aural transfer made in whole or in part
through the use of facilities for the transmission of communications by the
aid of wire, cable, or other like connection between the point of origin and
the point of reception (including the use of such connection in a switching
station) furnished or operated by any person engaged in providing or operating such facilities for the transmission of interstate or foreign communications or communications affecting interstate or foreign commerce;
( ) “oral communication” means any oral communication uttered by a person
exhibiting an expectation that such communication is not subject to interception under circumstances justifying such expectation, but such term does
not include any electronic communication; …
( ) “intercept” means the aural or other acquisition of the contents of any wire,
electronic, or oral communication through the use of any electronic, mechanical, or other device. …
( ) “contents”, when used with respect to any wire, oral, or electronic communication, includes any information concerning the substance, purport, or
meaning of that communication; …
( ) “electronic communication” means any transfer of signs, signals, writing,
images, sounds, data, or intelligence of any nature transmitted in whole or
in part by a wire, radio, electromagnetic, photoelectronic or photooptical
system that affects interstate or foreign commerce, but does not include –
(A) any wire or oral communication;
(B) any communication made through a tone-only paging device;
2
§
Chapter 4: Privacy
203
7
1
1
3
4
1
1
4
5
7
5
1
2
1
1
1
2
(C) any communication from a tracking device (as defined in section
of this title); or
(D) electronic funds transfer information stored by a financial institution
in a communications system used for the electronic storage and transfer of funds; …
( ) “electronic communications system” means any wire, radio, electromagnetic,
photooptical or photoelectronic facilities for the transmission of wire or
electronic communications, and any computer facilities or related electronic
equipment for the electronic storage of such communications; …
( ) “electronic communication service” means any service which provides to
users thereof the ability to send or receive wire or electronic communications; …
( ) “electronic storage” means –
(A) any temporary, intermediate storage of a wire or electronic communication incidental to the electronic transmission thereof; and
(B) any storage of such communication by an electronic communication
service for purposes of backup protection of such communication; …
§
– Interception and disclosure of wire, oral, or electronic
communications prohibited
( ) Except as otherwise specifically provided in this chapter any person who –
(a) intentionally intercepts, endeavors to intercept, or procures any other
person to intercept or endeavor to intercept, any wire, oral, or electronic communication; …
shall be punished as provided in subsection ( ). …
( )
(a)
(i) It shall not be unlawful under this chapter for an operator of a
switchboard, or an officer, employee, or agent of a provider of
wire or electronic communication service, whose facilities are
used in the transmission of a wire or electronic communication,
to intercept, disclose, or use that communication in the normal
course of his employment while engaged in any activity which is
a necessary incident to the rendition of his service or to the protection of the rights or property of the provider of that service,
except that a provider of wire communication service to the
public shall not utilize service observing or random monitoring
except for mechanical or service quality control checks. …
(c) It shall not be unlawful under this chapter for a person acting under
color of law to intercept a wire, oral, or electronic communication,
where such person is a party to the communication or one of the parties to the communication has given prior consent to such interception.
(d) It shall not be unlawful under this chapter for a person not acting under color of law to intercept a wire, oral, or electronic communication
where such person is a party to the communication or where one of
the parties to the communication has given prior consent to such interception unless such communication is intercepted for the purpose
204
Internet Law
1
2
1
1
1
ffi
6
1
5
2
5
8
1
1
5
5
3
1
2
2
of committing any criminal or tortious act in violation of the Constitution or laws of the United States or of any State. …
(g) It shall not be unlawful under this chapter or chapter
of this title
for any person –
(i) to intercept or access an electronic communication made
through an electronic communication system that is configured
so that such electronic communication is readily accessible to
the general public …
§
– Prohibition of use as evidence of intercepted wire or oral
communications
Whenever any wire or oral communication has been intercepted, no part of the
contents of such communication and no evidence derived therefrom may be received in evidence in any trial, hearing, or other proceeding in or before any court,
grand jury, department, o cer, agency, regulatory body, legislative committee, or
other authority of the United States, a State, or a political subdivision thereof if the
disclosure of that information would be in violation of this chapter.
§
– Procedure for interception of wire, oral, or electronic
communications
( ) Each application for an order authorizing or approving the interception of a
wire, oral, or electronic communication under this chapter shall be made in
writing upon oath or affirmation to a judge of competent jurisdiction and
shall state the applicant’s authority to make such application. Each application shall include the following information:
(a) the identity of the investigative or law enforcement officer making the
application, and the officer authorizing the application;
(b) a full and complete statement of the facts and circumstances relied
upon by the applicant, to justify his belief that an order should be issued …
(c) a full and complete statement as to whether or not other investigative
procedures have been tried and failed or why they reasonably appear
to be unlikely to succeed if tried or to be too dangerous; …
( ) Upon such application the judge may enter an ex parte order, as requested
or as modified, authorizing or approving interception of wire, oral, or electronic communications … if the judge determines on the basis of the facts
submitted by the applicant that –
(a) there is probable cause for belief that an individual is committing, has
committed, or is about to commit a particular offense enumerated in
section
of this chapter;
(b) there is probable cause for belief that particular communications concerning that offense will be obtained through such interception;
(c) normal investigative procedures have been tried and have failed or
reasonably appear to be unlikely to succeed if tried or to be too dangerous;
(d) except as provided in subsection ( ), there is probable cause for belief
that the facilities from which, or the place where, the wire, oral, or
electronic communications are to be intercepted are being used, or are
about to be used, in connection with the commission of such offense,
205
or are leased to, listed in the name of, or commonly used by such person. …
0
2
0
1
1
0
5
5
2
2
2
3
6
fi
1
1
5
1
0
5
1
0
5
2
2
0
.
8
.
1
.
5
.
QUESTIONS
Wiretap Act Hypotheticals: The core prohibition of the Wiretap Act is in
§
( ), which must be read together with the relevant definitions in
§
. Which of the following are illegal under the Wiretap Act?
• Planting a hidden digital voice recorder in a meeting room used by
corporate executives?
• Standing on a toilet seat to overhear a conversation between two other
people in the bathroom without being noticed?
• Having a conversation with a houseguest without rst disclosing that
there is an Amazon Alexa voice-activated device in the room?
• Setting up a camera in the apartment you rent out on Airbnb to take a
picture every thirty seconds?
• Using a program surreptitiously installed on another person’s
computer to capture audio and video recordings of their Zoom calls?
• Using a radio receiver to listen in on cordless phone conversations
from nearby houses (but not saving a copy of the audio).
• Answering a cell phone call from a relative, realizing that they have
accidentally dialed you, and listening in on an argument they are
having with their partner?
Super-Warrants: The Wiretap Act contains many exceptions. The most important of these is set forth in §
, which outlines a procedure for submitting an application to a court to install a wiretap. Who is allowed to
make the application? What evidence do they need to provide? Is it easier to
obtain a search warrant or a wiretap order? Can private parties obtain judicial authorization for one?
The Provider Exception: To whom does the “provider exception” in §
( )
(a) apply, and how broad is it? Is it a Wiretap Act violation for Gmail to deliver email to users? To use emails to train its artificial intelligence models?
One-Party vs. All-Party Consent: States have their own wiretapping laws. New
York, for example, prohibits “recording of a telephonic … communication by
a person other than a sender or a receiver thereof.” N.Y. Penal L. §§
. ,
. . In California, it is illegal to record a “confidential communication”
without the “consent of all parties.” Cal. Pen. Code §
(a). If Linda, in California, tape-records her phone calls with Monica, in New York, and Monica
doesn’t know about it, is this a violation of the Wiretap Act? New York law?
California law?
National Security Surveillance: Should the standards for wiretaps (and other
electronic surveillance) be different when used for national security than for
law enforcement? The Foreign Intelligence Surveillance Act, or FISA, says
“yes.” It allows for a special and largely secret Foreign Intelligence Surveillance Court to issue orders allowing the surveillance of communications
of “foreign powers” and their agents to obtain “foreign intelligence information.” Is this a good idea? Why might it be necessary to relax the usual Wiretap Act super-warrant standards here? What kind of safeguards might be
necessary to keep this surveillance authority from being abused?
2
.
5
1
2
3
4
2
5
Chapter 4: Privacy
206
Internet Law
The following case includes discussion of stalking.
O’BRIEN V. O’BRIEN
899 So. 2d 1133 (Fla. Dist. Ct. App. 5th 2005)
3
2
0
4
3
9
3
0
0
2
4
3
3
1
9
0
3
0
0
2
3
4
0
3
0
9
2
3
0
1
0
3
2
0
1
4
3
3
0
9
4
3
9
Sawaya, Chief Judge:
Emanating from a rather contentious divorce proceeding is an issue we must
resolve regarding application of certain provisions of the Security of Communications Act (the Act) found in Chapter
, Florida Statutes (
). Specifically, we
must determine whether the trial court properly concluded that pursuant to section
. ( ), Florida Statutes (
), certain communications were inadmissible because they were illegally intercepted by the Wife who, unbeknownst to the
Husband, had installed a spyware program on a computer used by the Husband
that copied and stored electronic communications between the Husband and another woman.
When marital discord erupted between the Husband and the Wife, the Wife
secretly installed a spyware program called Spector on the Husband’s computer. It
is undisputed that the Husband engaged in private on-line chats with another
woman while playing Yahoo Dominoes on his computer. The Spector spyware secretly took snapshots of what appeared on the computer screen, and the frequency
of these snapshots allowed Spector to capture and record all chat conversations,
instant messages, e-mails sent and received, and the websites visited by the user of
the computer. When the Husband discovered the Wife’s clandestine attempt to
monitor and record his conversations with his Dominoes partner, the Husband
uninstalled the Spector software and filed a Motion for Temporary Injunction,
which was subsequently granted, to prevent the Wife from disclosing the communications. …
… The Wife argues that the electronic communications do not fall under the
umbra [sic] of the Act because these communications were retrieved from storage
and, therefore, are not “intercepted communications” as defined by the Act. In
opposition, the Husband contends that the Spector spyware installed on the computer acquired his electronic communications real-time as they were in transmission and, therefore, are intercepts illegally obtained under the Act.
The trial court found that the electronic communications were illegally obtained in violation of section
. ( )(a)-(e), and so we begin our analysis with
the pertinent provisions of that statute, which subjects any person to criminal
penalties who engages in the following activities:
(a) Intentionally intercepts, endeavors to intercept, or procures any
other person to intercept or endeavor to intercept any wire, oral, or
electronic communication; …
§
. ( )(a)-(e), Fla. Stat. (
).
… It is beyond doubt that what the trial court excluded from evidence are “electronic communications.” The core of the issue lies in whether the electronic communications were intercepted. The term “intercept” is defined by the Act as “the
aural or other acquisition of the contents of any wire, electronic, or oral communication through the use of any electronic, mechanical, or other device.” §
. ( ),
Fla. Stat. (
). We discern that there is a rather fine distinction between what is
transmitted as an electronic communication subject to interception and the storage of what has been previously communicated. It is here that we tread upon new
ground. Because we have found no precedent rendered by the Florida courts that
considers this distinction, and in light of the fact that the Act was modeled after
Chapter 4: Privacy
207
8
1
3
7
9
9
1
3
8
0
1
9
7
0
1
8
4
0
5
0
1
3
1
1
8
1
9
3
3
0
1
3
the Federal Wiretap Act, we advert to decisions by the federal courts that have addressed this issue for guidance.
The federal courts have consistently held that electronic communications, in
order to be intercepted, must be acquired contemporaneously with transmission
and that electronic communications are not intercepted within the meaning of the
Federal Wiretap Act if they are retrieved from storage. United States v. Steiger,
F. d
( th Cir.), … [T]he particular facts and circumstances of the instant
case reveal that the electronic communications were intercepted contemporaneously with transmission.
The Spector spyware program that the Wife surreptitiously installed on the
computer used by the Husband intercepted and copied the electronic communications as they were transmitted. We believe that particular method constitutes interception within the meaning of the Florida Act, and the decision in Steiger supports this conclusion. In Steiger, an individual was able to hack into the defendant’s computer via a Trojan horse virus that allowed the hacker access to pornographic materials stored on the hard drive. The hacker was successful in transferring the pornographic material from that computer to the hacker’s computer. The
court held that because the Trojan horse virus simply copied information that had
previously been stored on the computer’s hard drive, the capture of the electronic
communication was not an interception within the meaning of the Federal Wiretap Act. The court did indicate, however, that interception could occur if the virus
or software intercepted the communication as it was being transmitted and copied
it. The court stated:
[T]here is only a narrow window during which an E-mail interception may occur – the seconds or mili-seconds before which a newly
composed message is saved to any temporary location following a
send command. Therefore, unless some type of automatic routing
software is used (for example, a duplicate of all of an employee’s messages are automatically sent to the employee’s boss), interception of Email within the prohibition of [the Wiretap Act] is virtually impossible.
Steiger,
F. d at
(quoting Jarrod J. White, E-Mail@Work.com: Employer
Monitoring of Employee E-Mail,
Ala. L.Rev.
,
(
)). Hence, a valid
distinction exists between a spyware program similar to that in Steiger, which
simply breaks into a computer and retrieves information already stored on the
hard drive, and a spyware program similar to the one installed by the Wife in the
instant case, which copies the communication as it is transmitted and routes the
copy to a storage file in the computer.
The Wife argues that the communications were in fact stored before acquisition because once the text image became visible on the screen, the communication
was no longer in transit and, therefore, not subject to intercept. We disagree. We
do not believe that this evanescent time period is sufficient to transform acquisition of the communications from a contemporaneous interception to retrieval
from electronic storage. We conclude that because the spyware installed by the
Wife intercepted the electronic communication contemporaneously with transmission, copied it, and routed the copy to a file in the computer’s hard drive, the
electronic communications were intercepted in violation of the Florida Act.
[The court held that the trial court did not abuse its discretion in excluding the
illegally intercepted messages from being admitted as evidence.]
Internet Law
QUESTIONS
. Email: Email works by successively copying the entire message from one
computer to another until it reaches its destination. Once it has been copied
to the final computer, a program called a “mail delivery agent” (MDA)
makes one last copy, adding the email to a particular user’s inbox file, which
her own email program can then read. Umberto Causabon, a rare-book
dealer, runs a small email service that gives accounts to other rare book
dealers. He configures the MDA on his server to scan each incoming email.
If the email contains the word “book, ” the MDA saves a copy of the email in
Causabon’s account as well as copying it to the user’s inbox file. Neither
Causabon nor any other person has ever examined the copies made this way.
Has Causabon violated the Wiretap Act?
. Interception Devices: The Wiretap Act includes a prohibition on the manufacture or sale in interstate commerce of “any electronic, mechanical, or other
device … primarily useful for the purpose of the surreptitious interception of
wire, oral, or electronic communications.”
U.S.C. §
( )(a). What does
this prohibition add to the prohibition on wiretapping itself? Is Spector
such a device?
STORED COMMUNICATIONS ACT
Title 18, United States Code
1
2
1
5
2
8
1
1
8
1
5
2
4
0
7
2
3
0
7
2
s
n
s
o
n
i
o
t
e
i
i
s
t
b
i
n
p
e
e
h
1
1
1
f
2
c
3
2
o
3
f
x
r
1
2
0
0
7
7
– Unlawful access to stored communications
(a) O
. – Except as provided in subsection (c) of this section whoever –
( ) intentionally accesses without authorization a facility through which
an electronic communication service is provided; or
( ) intentionally exceeds an authorization to access that facility;
and thereby obtains, alters, or prevents authorized access to a wire or electronic communication while it is in electronic storage in such system shall
be punished as provided in subsection (b) of this section. …
(c) E
. – Subsection (a) of this section does not apply with respect to
conduct authorized –
( ) by the person or entity providing a wire or electronic communications
service;
( ) by a user of that service with respect to a communication of or intended for that user; or
( ) in section
,
or
of this title.
§
– Voluntary disclosure of customer communications or records
(a) P
. – Except as provided in subsection (b) or (c) –
( ) a person or entity providing an electronic communication service to
the public shall not knowingly divulge to any person or entity the contents of a communication while in electronic storage by that service;
…
( ) a provider of … electronic communication service to the public shall
not knowingly divulge a record or other information pertaining to a
subscriber to or customer of such service (not including the contents
of communications covered by paragraph ( ) …) to any governmental
entity.
2
§
2
2
1
208
Chapter 4: Privacy
209
c
i
n
o
r
t
3
c
0
e
7
l
2
n
i
s
s
n
s
2
d
o
n
r
i
t
o
1
o
a
i
1
c
t
e
c
5
i
a
2
n
c
i
u
7
r
n
1
e
3
m
u
5
m
0
m
m
2
7
o
o
2
m
t
s
o
c
u
c
i
n
f
o
f
o
o
r
t
e
e
c
r
r
e
u
u
l
s
s
o
l
o
l
r
c
c
o
s
i
s
i
e
d
r
i
r
r
o
f
o
f
f
s
s
o
n
n
s
o
o
i
i
t
t
t
n
p
p
e
e
e
t
1
c
2
8
7
5
4
3
c
1
6
4
3
2
n
x
x
o
e
g
3
a
0
r
7
o
2
t
(b) E
. – A provider described in subsection (a) may divulge the contents of a communication –
( ) to an addressee or intended recipient of such communication or an
agent of such addressee or intended recipient;
( ) as otherwise authorized in section
,
( )(a), or
of this
title;
( ) with the lawful consent of the originator or an addressee or intended
recipient of such communication … ;
( ) to a person employed or authorized or whose facilities are used to
forward such communication to its destination;
( ) as may be necessarily incident to the rendition of the service or to the
protection of the rights or property of the provider of that service; …
( ) to a law enforcement agency –
(A) if the contents –
(i) were inadvertently obtained by the service provider; and
(ii) appear to pertain to the commission of a crime; or
( ) to a governmental entity, if the provider, in good faith, believes that an
emergency involving danger of death or serious physical injury to any
person requires disclosure without delay of communications relating
to the emergency.
(c) E
D
C
R
. – A provider described in subsection (a) may divulge a record or other information pertaining to a subscriber to or customer of such service… –
( ) as otherwise authorized in section
;
( ) with the lawful consent of the customer or subscriber;
( ) as may be necessarily incident to the rendition of the service or to the
protection of the rights or property of the provider of that service;
( ) to a governmental entity, if the provider, in good faith, believes that an
emergency involving danger of death or serious physical injury to any
person requires disclosure without delay of information relating to the
emergency; … or
( ) to any person other than a governmental entity.
§
– Required disclosure of customer communications or records
(a) C
W
E
C
E
S
. – A governmental entity may require the disclosure by a provider
of electronic communication service of the contents of a wire or electronic
communication, that is in electronic storage in an electronic communications system for one hundred and eighty days or less, only pursuant to a
warrant issued using the procedures described in the Federal Rules of Criminal Procedure by a court with jurisdiction over the offense under investigation or equivalent State warrant. A governmental entity may require the disclosure by a provider of electronic communications services of the contents
of a wire or electronic communication that has been in electronic storage in
an electronic communications system for more than one hundred and eighty
days by the means available under subsection (b) of this section.
Internet Law
e
c
i
v
r
s
e
n
o
i
0
n
t
o
8
i
a
1
c
t
i
a
2
n
c
i
u
n
m
u
m
m
o
m
o
c
i
n
c
i
o
n
r
o
t
r
c
t
e
c
l
e
l
r
o
g
n
e
i
r
i
n
r
e
c
f
n
o
o
s
s
t
n
d
e
r
t
o
1
n
1
c
2
o
e
5
0
(b) C
W
E
C
[stored with an
electronic communication service]. –
( ) A governmental entity may require a provider of [electronic communication service] to disclose the contents of any wire or electronic
communication [held in electronic storage for more than
days] –
(A) without required notice to the subscriber or customer, if the
governmental entity obtains a warrant issued using the procedures described in the Federal Rules of Criminal Procedure by a
court with jurisdiction over the offense under investigation or
equivalent State warrant; or
(B) with prior notice from the governmental entity to the subscriber
or customer if the governmental entity –
(i) uses an administrative subpoena authorized by a Federal
or State statute or a Federal or State grand jury or trial
subpoena; or
(ii) obtains a court order for such disclosure under subsection (d) of this section;
except that delayed notice may be given pursuant to section
of this title. …
(c) R
C
E
C
S
.–
( ) A governmental entity may require a provider of electronic communication service … to disclose a record or other information pertaining
to a subscriber to or customer of such service (not including the contents of communications) only when the governmental entity –
(A) obtains a warrant issued using the procedures described in the
Federal Rules of Criminal Procedure by a court with jurisdiction over the offense under investigation or equivalent State
warrant;
(B) obtains a court order for such disclosure under subsection (d) of
this section;
(C) has the consent of the subscriber or customer to such disclosure; … or
(E) seeks information under paragraph ( ).
( ) A provider of electronic communication service … shall disclose to a
governmental entity the –
(A) name;
(B) address;
(C) local and long distance telephone connection records, or
records of session times and durations;
(D) length of service (including start date) and types of service utilized;
(E) telephone or instrument number or other subscriber number or
identity, including any temporarily assigned network address;
and
(F) means and source of payment for such service (including any
credit card or bank account number)
7
2
210
211
of a subscriber to or customer of such service when the governmental
entity uses an administrative subpoena authorized by a Federal or
State statute or a Federal or State grand jury or trial subpoena or any
means available under paragraph ( ).
( ) A governmental entity receiving records or information under this
subsection is not required to provide notice to a subscriber or customer.
(d) R
C
O
. – A court order for disclosure under
subsection (b) or (c) may be issued by any court that is a court of competent
jurisdiction and shall issue only if the governmental entity offers specific
and articulable facts showing that there are reasonable grounds to believe
that the contents of a wire or electronic communication, or the records or
other information sought, are relevant and material to an ongoing criminal
investigation. In the case of a State governmental authority, such a court
order shall not issue if prohibited by the law of such State. A court issuing
an order pursuant to this section, on a motion made promptly by the service
provider, may quash or modify such order, if the information or records requested are unusually voluminous in nature or compliance with such order
otherwise would cause an undue burden on such provider.
(e) N C
A
A
P
D
I
U
T
C
. – No cause of action shall lie in any court against
any provider of wire or electronic communication service, its officers, employees, agents, or other specified persons for providing information, facilities, or assistance in accordance with the terms of a court order, warrant,
subpoena, statutory authorization, or certification under this chapter. …
n
o
i
t
a
m
r
o
f
2
n
0
7
2
g
n
i
s
o
l
c
s
i
1
0
7
2
r
e
d
1
i
v
o
r
2
0
r
e
a
7
2
d
r
t
s
n
1
t
i
a
r
u
g
1
o
0
3
n
7
0
o
2
7
r
i
2
o
t
f
c
r
s
e
t
f
t
n
p
o
e
a
e
h
m
e
s
r
u
i
s
a
i
u
h
3
q
e
o
r
e
d
QUESTIONS
. SCA vs. Wiretap Act: What is the difference between the SCA and the Wiretap Act? They have a similar structure – prohibition with exceptions – but
different coverage. Explain.
. Reading the SCA: The SCA is dense. Here is a suggested walkthrough:
First The key provisions of the SCA that control access to the contents of
communications are in §§
(a) and
(a)( ). What is the difference between them? Do these sections prohibit actions by private parties, by the government, or by both? And do these sections make
Gmail illegal? After all, doesn’t it “access” stored emails all the time?
Next There are important exceptions in §§
(c) and
(b). Which
situations do they apply to? For whose benefit were they drafted?
Which ones do you think are the most important and most frequently
used in practice? Are they broader or narrower than the exceptions
under the Wiretap Act?
Then The provisions that allow the police to require the disclosure of stored
communications are in §
. What showing must the police make?
Under what circumstances can the government gain access to stored
electronic communications with less than a full search warrant? Can
private parties avail themselves of this required disclosure procedure?
. Suppression: The SCA does not have a suppression remedy: evidence obtained in violation of it can still be used in court. Would a suppression remedy be a good idea?
n
2
1
3
Chapter 4: Privacy
Internet Law
. Retrospective vs. Prospective Requests: The Agatha County Sheriff ’s Department is investigating John Anderton’s role in a drug distribution ring. It
would like to obtain an order requiring Google to disclose the current contents of Anderton’s Gmail account. What level of process is required: an SCA
§
(d) order, a search warrant, or a Wiretap Act §
super-warrant?
What if the ACSD wants Google to disclose the contents of Anderton’s account every fifteen minutes for the next thirty days, starting now?
EHLING V. MONMOUTH-OCEAN HOSPITAL SERVICE CORP.
872 F. Supp. 2d 369 (D.N.J. 2012)
8
1
5
2
2
2
8
8
1
1
9
4
0
0
2
1
9
0
1
0
0
0
0
3
2
2
9
2
8
0
d
0
2
0
n
0
2
u
2
1
o
8
r
g
3
k
c
8
0
a
8
7
Martini, District Judge:
Plaintiff Deborah Ehling filed this action against Monmouth–Ocean Hospital
Service Corp. (“MONOC”), Vincent Robbins, and Stacy Quagliana.This matter
comes before the Court on Defendants’ motion for summary judgment …
I. B
Plaintiff Deborah Ehling is a registered nurse and paramedic. Defendant MONOC
is a non-profit hospital service corporation dedicated to providing emergency
medical services to the citizens of the State of New Jersey. Defendant Vincent
Robbins is the President and CEO of MONOC. Defendant Stacy Quagliana is the
Executive Director of Administration at MONOC.
Plaintiff was hired by MONOC in
as a registered nurse and paramedic. …
A. The Facebook Incident …
During the
–
timeframe, Plaintiff maintained a Facebook account and
had approximately
Facebook friends. Plaintiff selected privacy settings for her
account that limited access to her Facebook wall to only her Facebook friends.
Plaintiff did not add any MONOC managers as Facebook friends. However, Plaintiff added many of her MONOC coworkers as friends, including a paramedic
named Tim Ronco. Plaintiff posted on Ronco’s Facebook wall, and Ronco had access to Plaintiff ’s Facebook wall. Unbeknownst to Plaintiff, Ronco was taking
screenshots of Plaintiff ’s Facebook wall and printing them or emailing them to
MONOC manager Andrew Caruso. …
On June ,
, Plaintiff posted the following statement to her Facebook
wall:
An
yr old sociopath white supremacist opened fire in the Wash
D.C. Holocaust Museum this morning and killed an innocent guard
(leaving children). Other guards opened fire. The
yr old was shot.
He survived. I blame the DC paramedics. I want to say things to the
DC medics. . WHAT WERE YOU THINKING? and . This was your
opportunity to really make a difference! WTF!!!! And to the other
guards .... go to target practice.
After MONOC management was alerted to the post, Plaintiff was temporarily suspended with pay, and received a memo stating that MONOC management was
concerned that Plaintiff ’s comment reflected a “deliberate disregard for patient
safety.” …
[Ehling accumulated numerous warning notices and disciplinary points for
“unauthorized late swipe-outs, excessive call-outs, failing to have sufficient paid
time off to cover hours not worked, refusing – – calls, and failing to submit the
proper documentation for her ambulance shifts.” She was issued a notice of termination on July ,
, but it was never enforced. Instead, her employment was
2
4
212
Chapter 4: Privacy
213
terminated on February ,
medical leave of absence.]
, following a dispute about her eligibility for a
8
1
2
8
1
8
1
1
7
1
0
1
5
2
4
1
1
1
0
7
8
2
1
1
2
1
0
2
7
5
7
0
2
1
7
8
2
1
0
1
1
1
5
5
2
2
2
7
n
1
o
i
8
0
s
1
1
s
5
u
1
8
8
1
1
2
2
c
1
s
i
1
3
0
0
1
7
5
2
2
III. D
A. Count 1: Federal Stored Communications Act
In Count , Plaintiff asserts a claim for violation of the Federal Stored Communications Act (or “SCA”),
U.S.C. § §
– . Plaintiff argues that Defendants violated the SCA by improperly accessing her Facebook wall post about the museum
shooting. Plaintiff argues that her Facebook wall posts are covered by the SCA because she selected privacy settings limiting access to her Facebook page to her
Facebook friends. Defendants disagree and argue that, even if the SCA applies, the
facts in this case fall under one of the SCA’s statutory exceptions. For the reasons
set forth below, the Court finds that non-public Facebook wall posts are covered
by the SCA, and that one of the exceptions to the SCA applies. …
i. The SCA Covers Non–Public Facebook Wall Posts …
The SCA provides that whoever “( ) intentionally accesses without authorization a
facility through which an electronic communication service is provided; or ( ) intentionally exceeds an authorization to access that facility; and thereby obtains,
alters or prevents the authorized access to a wire or electronic communication
while in electronic storage in such a system” shall be liable for damages.
U.S.C.
§
(a);
U.S.C. §
(providing for civil liability under the statute). The
statute further provides that “[i]t shall not be unlawful ... [to] access an electronic
communication made through an electronic communication system that is configured so that such electronic communication is readily accessible to the general
public.”
U.S.C. §
( )(g)(i). In other words, the SCA covers: ( ) electronic
communications, ( ) that were transmitted via an electronic communication service, ( ) that are in electronic storage, and ( ) that are not public. Facebook wall
posts that are configured to be private meet all four criteria.
First, Facebook wall posts are electronic communications. The SCA defines
“electronic communication” as “any transfer of signs, signals, writing, images,
sounds, data, or intelligence of any nature transmitted in whole or in part by a
wire, radio, electromagnetic, photoelectronic or photooptical system.”
U.S.C.
§
( ). To create Facebook wall posts, Facebook users transmit writing, images, or other data via the Internet from their computers or mobile devices to
Facebook’s servers. Thus, Facebook wall posts are electronic communications.
Second, Facebook wall posts are transmitted via an electronic communication
service. The SCA defines “electronic communication service” as “any service which
provides to users thereof the ability to send or receive wire or electronic communications.”
U.S.C. §
( ). Facebook provides its users with the ability to send
and receive electronic communications, including private messages and Facebook
wall posts.
Third, Facebook wall posts are in electronic storage. The SCA distinguishes
between two different types of electronic storage. The first is defined as “any temporary, intermediate storage of a wire or electronic communication incidental to
the electronic transmission thereof.”
U.S.C. §
( )(A). The second type of
storage is defined as “any storage of such communication by an electronic communication service for purposes of backup protection of such communication.”
U.S.C. §
( )(B). Unlike email, Facebook wall posts are not held somewhere
temporarily before they are delivered. Rather, the website itself is the final destina-
Internet Law
2
1
1
5
1
1
6
2
9
3
2
9
1
7
6
5
1
5
6
4
1
7
2
2
9
3
1
1
1
5
3
2
2
0
3
5
5
4
2
8
1
7
1
7
6
8
9
1
8
0
6
0
1
0
0
1
0
0
0
9
tion for the information. Thus, Facebook wall posts are not held in temporary, intermediate storage.
However, Facebook does store electronic communications for backup purposes.
When Facebook users post information, the information is immediately saved to a
Facebook server. When new posts are added, Facebook archives older posts on
separate pages that are accessible, but not displayed. Because Facebook saves and
archives wall posts indefinitely, the Court finds that wall posts are stored for backup purposes. Accordingly, Facebook wall posts are in electronic storage.
Fourth, Facebook wall posts that are configured to be private are, by definition,
not accessible to the general public. The touchstone of the Electronic Communications Privacy Act is that it protects private information. The language of the
statute makes clear that the statute’s purpose is to protect information that the
communicator took steps to keep private. See
U.S.C. §
( )(g)(i) (there is no
protection for information that is “configured [to be] readily accessible to the general public”). Cases interpreting the SCA confirm that information is protectable
as long as the communicator actively restricts the public from accessing the information. See Viacom Int’l Inc. v. Youtube Inc.,
F.R.D.
,
(S.D.N.Y.
) (holding that SCA prevented Viacom from accessing YouTube “videos that
[users] have designated as private and chosen to share only with specified recipients”); [Crispin v. Christian Audigier Inc.,
F. Supp. d at
,
(C.D. Cal.
)] (finding that SCA protection for Facebook wall posts depends on plaintiff ’s
use of privacy settings); cf. Snow v. DirecTV, Inc.,
F. d
,
( th Cir.
) (“an express warning, on an otherwise publicly accessible webpage” is insufficient to give rise to SCA protection).
Facebook allows users to select privacy settings for their Facebook walls. Access
can be limited to the user’s Facebook friends, to particular groups or individuals,
or to just the user. The Court finds that, when users make their Facebook wall
posts inaccessible to the general public, the wall posts are “configured to be private” for purposes of the SCA. The Court notes that when it comes to privacy protection, the critical inquiry is whether Facebook users took steps to limit access to
the information on their Facebook walls. Privacy protection provided by the SCA
does not depend on the number of Facebook friends that a user has. “Indeed, basing a rule on the number of users who can access information would result in arbitrary line-drawing” and would be legally unworkable. Crispin,
F. Supp. d at
.
At least one other court has determined that non-public Facebook wall posts
are covered by the SCA, albeit in a slightly different context. In Crispin, the District Court for the Central District of California was asked to decide whether a
third-party subpoena should be quashed under the SCA. The defendants in
Crispin subpoenaed information located on the plaintiff ’s MySpace and Facebook
pages, including the plaintiff ’s Facebook wall posts and MySpace comments. The
plaintiff sought to quash the subpoena, arguing that the SCA prohibited Facebook
and MySpace from disclosing the information. To determine whether the SCA applied to these communications, the court analogized a Facebook wall post to technology that existed in
: a posting on a BBS. A BBS could be configured to be
public or private. If a BBS was configured to be private, access to the BBS was restricted to a particular community of users, and the messages posted to the BBS
were only viewable by those users. The Crispin court recognized that there was a
long line of cases finding that the SCA was intended to reach private BBS’s. Id. at
(collecting cases). The court then found that there was “no basis for distin-
8
2
2
2
9
9
214
215
2
8
8
1
1
1
1
3
1
0
1
5
2
2
1
3
8
1
1
9
0
7
2
8
1
9
2
8
0
1
0
2
1
0
8
7
2
2
©
1
0
8
1
7
2
2
2
1
1
0
0
7
7
2
2
guishing between a restricted-access BBS and a user’s Facebook wall or MySpace
comments”: both technologies allowed users to post content to a restricted group
of people, but not the public at large. Id. at
. The court therefore concluded
that, if the plaintiff ’s Facebook page was configured to be private, then his wall
posts were covered by the SCA. This Court agrees in all respects with the reasoning of Crispin.
Accordingly, the Court finds that non-public Facebook wall posts are covered
by the SCA. Because Plaintiff in this case chose privacy settings that limited access
to her Facebook wall to only her Facebook friends, the Court finds that Plaintiff ’s
Facebook wall posts are covered by the SCA.
ii. The SCA’s Authorized User Exception Applies in this Case
Having concluded that the SCA applies to the type of communication at issue in
this case, the Court next evaluates whether either of the SCA’s statutory exceptions
apply. The SCA “does not apply with respect to conduct authorized ( ) by the person or entity providing a wire or electronic communications service; [or] ( ) by a
user of that service with respect to a communication of or intended for that user.”
U.S.C. §
. For the reasons set forth below, the Court finds that the authorized user exception (the second exception) applies in this case.
The authorized user exception applies where ( ) access to the communication
was “authorized,” ( ) “by a user of that service,” ( ) “with respect to a communication ... intended for that user.”
U.S.C. §
(c)( ). Access is not authorized if
the purported “authorization” was coerced or provided under pressure. In this
case, all three elements of the authorized user exception are present.
First, access to Plaintiff ’s Facebook wall post was “authorized.”
U.S.C.
§
(c)( ). The undisputed evidence establishes that Ronco voluntarily provided
Plaintiff ’s Facebook posts to MONOC management without any coercion or pressure. Caruso testified at his deposition that Plaintiff ’s Facebook friend Ronco voluntarily took screenshots of Plaintiff ’s Facebook page and either emailed those
screenshots to Caruso or printed them out for him. This information was completely unsolicited. Caruso never asked Ronco for any information about Plaintiff
and never requested that Ronco keep him apprised of Plaintiff ’s Facebook activity;
in fact, Caruso was surprised that Ronco showed him Plaintiff ’s Facebook postings. Caruso never had the password to Ronco’s Facebook account, Plaintiff ’s
Facebook account, or any other employee’s Facebook account. …
Second, access to Plaintiff ’s Facebook wall post was authorized “by a user of
that service.”
U.S.C. §
(c)( ). A “user” is “any person or entity who (A) uses
an electronic communications service; and (B) is duly authorized by the provider
of such service to engage in such use.”
U.S.C. §
( ). It is undisputed that
Ronco was a Facebook user: Plaintiff acknowledged that she added Ronco as a
Facebook friend and posted on Ronco’s Facebook wall.
Third, Plaintiff ’s Facebook wall post was “intended for that user.”
U.S.C.
§
(c)( ). Based on the privacy settings that Plaintiff selected for her Facebook
page, Plaintiff ’s wall posts were visible to, and intended to be viewed by, Plaintiff ’s
Facebook friends. On June ,
, when Plaintiff posted the comment about the
museum shooting, Ronco was one of Plaintiff ’s Facebook friends. Thus, the post
was intended for Ronco.
In conclusion, access to Plaintiff ’s Facebook wall post was authorized by a
Facebook user with respect to a communication intended for that user. Therefore,
the authorized user exception applies and Defendants are not liable under the
SCA. Accordingly, the motion for summary judgment on Count is GRANTED. …
8
1
Chapter 4: Privacy
Internet Law
QUESTIONS
. SCA Scope: Does the SCA protect emails? Text messages? Skype calls taped
and saved by one of the participants? Shared spreadsheets on Google Docs?
. Facebook Settings: How much work are Facebook’s privacy controls doing in
this opinion? The court points to them to show both that Ehling’s posts were
not “readily accessible to the general public” and that access to them was
“authorized.” Are these holdings consistent?
. Incomprehensible Interfaces: Would the result change if Ehling testified that
she misunderstood Facebook’s privacy controls and had not meant to share
the post in question with Ronco? What if she made the post visible only to a
few family members, but Facebook’s privacy settings subsequently changed
so that it became visible to Ronco and her other co-workers?
. Civil Discovery: What does the SCA do to the discovery process in civil litigation? Suppose you represent the defendant in a personal-injury suit and you
suspect that the plaintiff ’s emails to a friend discussing a recent vacation
will demonstrate that her injuries are less severe than she claims. What will
happen if you send a subpoena to her email provider?
PEN REGISTERS AND TRAP AND TRACE DEVICES
Title 18, United States Code
3
2
1
3
8
l
7
9
n
a
1
n
o
r
o
i
e
i
t
t
n
a
p
t
e
e
i
c
3
2
1
m
x
i
n
1
2
1
§
– General prohibition on pen register and trap and trace device use;
exception
(a) I G
. – Except as provided in this section, no person may install or
use a pen register or a trap and trace device without first obtaining a court
order under section
of this title or under the Foreign Intelligence Surveillance Act of
.
(b) E
. – The prohibition of subsection (a) does not apply with respect
to the use of a pen register or a trap and trace device by a provider of electronic or wire communication service –
( ) relating to the operation, maintenance, and testing of a wire or electronic communication service or to the protection of the rights or
property of such provider, or to the protection of users of that service
from abuse of service or unlawful use of service; or
( ) to record the fact that a wire or electronic communication was initiated or completed in order to protect such provider, another provider
furnishing service toward the completion of the wire communication,
or a user of that service, from fraudulent, unlawful or abusive use of
service; or
( ) where the consent of the user of that service has been obtained.
(c) L
. – A government agency authorized to install and use a pen
register or trap and trace device under this chapter or under State law shall
use technology reasonably available to it that restricts the recording or decoding of electronic or other impulses to the dialing, routing, addressing,
and signaling information utilized in the processing and transmitting of
wire or electronic communications so as not to include the contents of any
wire or electronic communications.
(d) Penalty. – Whoever knowingly violates subsection (a) shall be fined under
this title or imprisoned not more than one year, or both.
3
4
3
2
1
216
217
§
– Application for an order for a pen register or a trap and trace device
(a) A
.–
( ) An attorney for the Government may make application for an order or
an extension of an order under section
of this title authorizing or
approving the installation and use of a pen register or a trap and trace
device under this chapter, in writing under oath or equivalent affirmation, to a court of competent jurisdiction.
( ) Unless prohibited by State law, a State investigative or law enforcement officer may make application for an order or an extension of an
order under section
of this title authorizing or approving the
installation and use of a pen register or a trap and trace device under
this chapter, in writing under oath or equivalent affirmation, to a
court of competent jurisdiction of such State.
(b) C
A
. – An application under subsection (a) of this
section shall include –
( ) the identity of the attorney for the Government or the State law enforcement or investigative officer making the application and the
identity of the law enforcement agency conducting the investigation;
and
( ) a certification by the applicant that the information likely to be obtained is relevant to an ongoing criminal investigation being conducted by that agency.
§
- De nitions for chapter
As used in this chapter – …
( ) the term “pen register” means a device or process which records or
decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic
communication is transmitted, provided, however, that such information shall not include the contents of any communication, but such
term does not include any device or process used by a provider or customer of a wire or electronic communication service for billing, or
recording as an incident to billing, for communications services provided by such provider or any device or process used by a provider or
customer of a wire communication service for cost accounting or other like purposes in the ordinary course of its business;
( ) the term “trap and trace device” means a device or process which captures the incoming electronic or other impulses which identify the
originating number or other dialing, routing, addressing, and signaling information reasonably likely to identify the source of a wire or
electronic communication, provided, however, that such information
shall not include the contents of any communication; …
3
2
1
3
n
o
i
t
a
c
i
3
l
p
2
1
3
f
n
o
o
i
s
t
t
a
n
c
i
e
fi
l
t
1
p
1
2
n
2
4
3
p
o
2
7
2
2
1
1
3
p
QUESTIONS
Definitions: What is a pen register? A trap and trace device? How significant
is the difference, if any, between the two? The statute refers to “dialing, routing, addressing, or signaling information”; what are these for a telephone?
For a home Internet connection? For a VoIP service like Skype?
.
3
1
Chapter 4: Privacy
Internet Law
. PR/TT Orders: What legal standard must the government satisfy to obtain a
pen register order? How does this compare to the standard for a wiretap
order?
. PR/TT in Action: The police suspect Perry Tutt of tampering with his former
employer’s computers. They obtain a pen register order to install a device on
the Comcast router in the basement of his apartment building which
records the IP addresses his computer connects to, and the times at which it
does so. Is this permissible under the pen register/trap and trace statute?
And is it permissible under the Fourth Amendment?
4
2
7
1
4
3
3
0
0
2
8
1
9
2
3
1
1
3
4
8
9
1
5
4
3
8
2
1
5
2
8
1
8
1
5
2
2
0
NOTE ON TECHNICAL ASSISTANCE
Sometimes the government needs help to install a wiretap, a pen register, or other
surveillance device. The best way to tap a phone line, for example, is at the phone
company’s facilities, using its equipment. Thus, surveillance statutes generally
contain provisions requiring that specified private parties provide “technical assistance” to the government. Consider, for example, the technical assistance provision of the Wiretap Act, U.S.C. §
( ):
An order authorizing the interception of a wire, oral, or electronic
communication under this chapter shall, upon request of the applicant, direct that a provider of wire or electronic communication service, landlord, custodian or other person shall furnish the applicant
forthwith all information, facilities, and technical assistance necessary
to accomplish the interception unobtrusively and with a minimum of
interference with the services that such service provider, landlord,
custodian, or person is according the person whose communications
are to be intercepted.
In The Company v. United States,
F. d
( th Cir.
), the appellant
operated a network for on-board navigation systems in luxury cars. The FBI obtained a §
order compelling the appellant to activate the system in a particular car, turn on the microphone, and allow the FBI to listen in. The court held
(over a dissent) that although §
could apply to the appellant, this particular
order required more than “a minimum of interference with the services” because it
would disable the other functions of the navigation system.
There is a similar provision in the pen register statute,
U.S.C. §
, and
you have already seen that the Stored Communications Act requires providers
simply to turn over the target’s communications on receipt of a proper court order.
The Communications Assistance to Law Enforcement Act (CALEA) goes even further: it requires that a “telecommunications carrier” (i.e. someone who provides
“the transmission or switching of wire or electronic communications as a common
carrier for hire”) be capable of complying with interception orders.
U.S.C. §
So the phone company must design and operate its network so that it can
provide the necessary technical assistance under Wiretap Act and pen register orders. CALEA provides, however, that it does not apply to “information services”
(i.e., “generating, acquiring, storing, transforming, processing, retrieving, utilizing,
or making available information via telecommunications”), so as a result only
providers of physical infrastructure tend to be subject to CALEA. It also provides
that “A telecommunications carrier shall not be responsible for decrypting, or ensuring the government’s ability to decrypt, any communication encrypted by a
0
3
2
1
218
219
subscriber or customer, unless the encryption was provided by the carrier and the
carrier possesses the information necessary to decrypt the communication.”
Finally, there is the All Writs Act, initially enacted as part of the Judiciary Act
of
, gives the federal courts the power to issue “all writs necessary or appropriate in aid of their respective jurisdictions and agreeable to the usages and principles of law.”
U.S.C. §
. In United States v. New York Telephone Co.,
U.S.
(
), the FBI wanted to install pen registers on two suspects’ telephone
lines, but could only do so unobtrusively if the telephone company provided some
additional wiring. The Supreme Court held that the FBI could obtain an order
under the All Writs Act directing the company to do so. The Court appeared to
balance three factors: the closeness of the relationship of the company to the matter being investigated, the necessity of the order, and the burden on the company.
Most recently, the technical assistance debate arisen in fights over smartphone
encryption. The FBI attempted to compel Apple to assist in unlocking an iPhone
used by Syed Farook, who killed people in San Bernadino on December ,
.
That case was mooted when the FBI paid more than . million to a third party
for software that unlocked the phone. In another case, a magistrate judge rejected
an All Writs Act demand for Apple’s assistance because between CALEA and the
SCA (neither of which imposed such a duty on device manufacturers) there was no
legislatively unforseen gap for the court to fill with the All Writs Act. In re Apple,
Inc.,
F. Supp. d
(E.D.N.Y.
).
QUESTIONS
. Objections: In court and in the press, Apple has made broader arguments
against compelled technical assistance: that the Apple is an uninvolved party
and the burden on it is excessive, that requiring it to bypass the encryption
on its devices creates a “backdoor” that makes everyone’s devices less secure,
that requiring it to write software it disagrees with is a form of compelled
speech prohibited by the First Amendment, and that compelling its engineers to write software for the government takes property without due
process of law. How persuasive are these objections? If Apple has a constitutional right not to write encryption-cracking software, does Tesla have a constitutional right not to write software that makes left-turn signals?
. Gag Orders and Warrant Canaries: How much can and should companies say
when they receive surveillance orders? Many of the authorizing statutes allow the government to obtain nondisclosure orders prohibiting the company
from disclosing the contents of the surveillance order? Are these orders unconstitutional restrictions on freedom of speech? Can a company subject to
one publish an aggregate report listing the number and type of orders it has
received for customer data in the past year? How about a so-called “warrant
canary” stating, “We have not received any court orders for customer data.
Watch closely for the removal of this notice.”?
4
5
3
1
4
0
2
2
3
1
$
6
1
0
2
4
1
1
5
6
1
1
4
3
3
8
2
7
7
9
1
9
9
9
5
4
8
1
1
7
ZIPPER PROBLEM
Senator Bernard Abbott (R-TX) has become concerned about the balance of power in the cryptography world. He is afraid that criminals, terrorists, and foreign
powers can too easily spy on Americans’ communications – and that they’re also
using encryption to keep their own nefarious plans hidden. Accordingly, he is preparing legislation to standardize American cryptography. His bill would:
1
2
1
Chapter 4: Privacy
220
Internet Law
1. Require all telephones (land-line and cellular) and Internet connections in
the U.S. to be built with a new, standard encryption technology called Zipper. Devices using Zipper would have unique ID numbers; whenever two
Zipper devices establish a connection, they will use their unique IDs to negotiate a secret key to encrypt their communications. The two Zipper devices will be able to turn the encrypted message back into intelligible
sounds, images, text or whatever, but anyone eavesdropping on the connection will see only random 1s and 0s.
2. Well, almost anyone. The U.S. government will manage a “key escrow database” that contains a second secret key for each unique Zipper ID number.
Zipper will be designed in such a way that the government, using the second
secret key, can also decrypt the communications. This database will be kept
secure; a court order will be needed to allow law enforcement to look up the
secret key for any given Zipper device.
3. In order to keep the system from breaking down, it will also be necessary to
restrict the use of non-Zipper cryptography. Accordingly, after the implementation of Zipper, it will be illegal to encrypt communications using any
other method.
You are on the legal staff of SETEC, a non-profit advocacy group whose mission is
to “keep the Internet open, free, and safe.” You have just learned about Senator
Abbott’s proposal. You are flying to Washington for a meeting with the Senator’s
staff tomorrow. Is the bill a good idea? Should you support it, oppose it, or push
for modifications? What arguments will you make to the Senator’s staff, and how
do you expect them to respond?
C. Anonymity
Our next topic has to do not with the contents of online communications, but
rather with the identity of individuals using the Internet. The materials in this
section consider what legal tests apply when one Internet user seeks to learn the
real-life identity of another.
NOTE ON ONLINE IDENTIFICATION
A short review of some of the technical aspects of Internet identity may be helpful.
To communicate on the Internet, you need at the very least an IP address – and
that address can then be used as a crucial link in identifying you. IP addresses are
assigned to ISPs in blocks; ISPs generally keep records of which IP addresses they
assigned to which subscribers and when.
To be sure, it is often possible to forge your IP address when sending messages.
But then anyone trying to respond to your message will send their response to the
wrong address. Thus, forged IP addresses are nearly useless for any interactive
protocol – including, for example, HTTP for web browsing. The biggest use of
forged IP addresses is in committing denial of service attacks: if your only goal is
to overload a target computer, you don’t particularly care what it has to say in response.
There are other, more robust ways to communicate while obscuring your IP
address from the computer you are trying to reach. They all require giving your IP
address to an intermediary – here called a proxy – that forwards your packets on
221
to the destination, listing its own IP address as the place to send responses. The
proxy stands between the two endpoints; each talks only to the proxy, rather than
directly to the other. Particularly if your traffic is encrypted on its way to the proxy
(as it is on a “virtual private network” or “VPN”), this is good enough for many
purposes. The BBC, for example, makes its shows available online, but only to
viewers inside the United Kingdom, so American fans of the BBC have been
known to use proxies that make it appear they are inside the U.K.
Proxies, however, require that the user trust the proxy at least with her IP address. For some, this is too much trust. More sophisticated systems will bounce
messages through multiple proxies, so that anyone trying to track down a user
must work through all of the proxies. At the highest level of security, onion routing
systems like Tor separately encrypt each layer of the communication: each proxy
except the last knows only that it is somewhere in the middle of a chain, and has
no idea of the contents of the message. But even these systems don’t guarantee
anonymity. In December
, Harvard University received a bomb threat during
final exams; the threat was emailed by a Tor user. Rather than trying to trace him
back one hop at a time (through many potentially uncooperative nodes), Harvard
checked its own network records and found that exactly one student had been using Tor at the relevant time. When questioned by an FBI agent, the student confessed.
IP addresses are hardly the only digital identifiers at work online. Email addresses are an obvious example; so are usernames. Cookies (discussed below in the
next section) identify a web user’s browser uniquely over time; it is also possible to
use other details, such as the list of fonts a user has installed, to uniquely finger
print a particular web user’s browser. Cell phones and other mobile devices have
unique hardware identifiers, as do the SIM cards they use to connect to a cellular
network. And any device communicating on an Ethernet or Wi-Fi network has a
unique “media access control” address, commonly known as a MAC address. But
because these are local rather than global networks, it is technically easy to change
one’s MAC address with few untoward consequences.
STORED COMMUNICATIONS ACT
[Refer back to the SCA excerpts, supra.]
QUESTIONS
Voluntary Disclosures: The basic rule on voluntarily disclosing the identity of a
user is set forth in §
(a)( ). Suppose that you work for Hotmail. You
have just received a letter from the NYPD requesting the real name, address,
and any other relevant contact information of the user with the email address “ThinBlueLiar@hotmail.com.” How should you respond? What if the
letter came from the Whole Foods Market corporation instead?
. Required Disclosures: A second rule in §
deals with required disclosures.
If you work for the NYPD and you want to compel Hotmail to disclose the
subscriber information for ThinBlueLiar, can you, and if so, how? What if
you work for Whole Foods Market?*
.
3
0
7
2
3
3
1
0
2
2
0
3
7
0
2
7
* A sample SCA §
(d) order for subscriber information and application are available in the online Appendix.
2
1
2
Chapter 4: Privacy
Internet Law
JUKT MICRONICS PROBLEM
You are are the general counsel of Jukt Micronics, which designs and manufactures circuit boards for high-performance scientific computing in physics and
chemistry labs. Recently, someone has managed to gain access to – and overwrite
– a file containing the prototype design for the JK, the company’s next big
project. The file was replaced with a pornographic picture which was captioned,
“THE BIG BAD BIONIC BOY HAS BEEN HERE BABY.”
This morning, the firm’s CEO received an email from eatmyjukt@hiert.com.
Hiert.com is an ad-supported web email system: users don’t need to supply anything more than a desired username and password to create an account. The
email’s author, “Ian,” claimed to be responsible for the computer intrusion and to
have the original file in his possession. He demanded
million for its return.
The number is obviously outrageous – Jukt’s entire annual revenues are only about
million. That’s promptly called the FBI. You and your point of contact there,
Special Agent Glass, are starting to suspect you’re dealing with a talented (and
possibly underage) amateur.
Leaving aside other possible investigative avenues, how should you attempt to
turn “eatmyjukt” into an actual name and address? What can you do on your own?
What can the FBI do? How likely is this process to succeed? What could go
wrong? Your strategy should consider both the technical and legal aspects of the
problem. (Hint: The technical part will take more than one step. The legal part is
straightforward, if you do things right. Refer back to the Stored Communications
Act, supra, as needed.)
The following case includes discussion of harassment and threats.
DOE I V. INDIVIDUALS, WHOSE TRUE NAMES ARE UNKNOWN
561 F. Supp. 2d 249 (D. Conn. 2008)
Droney, District Judge:
On February ,
, the plaintiffs, Jane Doe I and Jane Doe II (the “Does”)
issued a subpoena duces tecum* to SBC Internet Services, Inc., now known as
AT&T Internet Services (“AT&T”), the internet service provider, for information
relating to the identity of the person assigned to the Internet Protocol (“IP”) address from which an individual using the pseudonym “AK ” posted comments on
a website. The individual whose internet account is associated with the IP address
at issue, referring to himself as John Doe , has moved to quash that subpoena.
John Doe
has also moved for permission to proceed anonymously in this matter.
* [Ed: A subpoena is a court order demanding that the recipient appear or produce
specified documents. Subpoenas aren’t subject to judicial oversight before they issue.
See Fed. R. Civ. Proc. (a)( ) (“The clerk must issue a subpoena, signed but otherwise in blank, to a party who requests it. That party must complete it before
service.”) Instead, the proper response from the recipient of an improper subpoena is
a motion to quash (not “squash”) it. A sample subpoena for the identity of an Internet user is available in the online Appendix.)]
0
7
5
4
8
2
7
$
4
1
2
3
1
2
1
8
5
2
4
1
0
2
0
2
1
1
2
0
Because John Doe
chose a male pseudonymous name to proceed under, the Court
will refer to John Doe
using male pronouns. This does not reflect a finding by the
Court that John Doe is indeed male.
4
$
1
1
222
223
7
9
7
4
4
7
0
0
7
2
0
0
7
2
1
5
0
0
2
0
0
0
0
0
8
7
7
0
4
7
0
0
2
0
2
8
7
d
0
n
0
u
2
o
1
r
3
g
k
c
a
7
7
0
0
0
I. B
This action was brought by Doe I and Doe II, both female students at Yale Law
School, against unknown individuals using thirty-nine different pseudonymous
names to post on a law school admissions website named AutoAdmit.com (“AutoAdmit”). The plaintiffs allege that they were the targets of defamatory, threatening, and harassing statements posted on AutoAdmit from
to
.
AutoAdmit is an internet discussion board on which participants post and review comments and information about undergraduate colleges, graduate schools,
and law schools. It draws between
,
and one million visitors per month.
Anyone who can access the internet can access AutoAdmit and view the messages
posted on its discussion boards. Individuals who register with AutoAdmit, which
can be done under real or assumed names, may post new messages and respond to
the messages of other registered users. When a participant posts a new message,
any further comments or responses to that message are collected as a “thread.”
Messages and threads containing certain words or subject matter can be found by
searching for those words using an internet search engine.
The first message about Doe II that appeared on AutoAdmit was posted on
January ,
, by an anonymous poster. The message linked to a photograph of
Doe II and encouraged others to “Rate this HUGE breasted cheerful big tit girl
from YLS.” After this message was posted, dozens of additional messages about
Doe II appeared in the thread. These messages contained comments on Doe II’s
breasts and the posters’ desire to engage in sexual relations with her. Certain of the
posters appeared to be Doe II’s classmates at Yale Law School because of personal
information they revealed. The posts regarding Doe II continued throughout the
winter and spring of
, and included statements, for example, that she fantasized about being raped by her father, that she enjoyed having sex while family
members watched, that she encouraged others to punch her in the stomach while
seven months pregnant, that she had a sexually transmitted disease, that she had
abused heroin, and that a poster “hope[s] she gets raped and dies.” On March ,
, a poster sent an email directly to Doe II and at least one member of the Yale
Law School faculty describing the alleged criminal history of Doe II’s father. This
message was also posted on AutoAdmit.
By March, nearly two hundred threads had been posted about Doe II on AutoAdmit. It is in this context that an anonymous poster under the moniker “AK ,”
known on AutoAdmit for posting threatening and derogatory comments about
minority groups, posted a message falsely stating “Alex Atkind, Stephen Reynolds,
[Doe II], and me: GAY LOVERS.”
The posting of comments regarding Doe II continued into April and May of
, including one message which the poster claimed had also been sent to Doe
II’s future employer which recounted some of the claims made about Doe II on
AutoAdmit. On June ,
, Doe II, along with Doe I, filed the complaint in the
instant action, alleging libel, invasion of privacy, negligent and intentional infliction of emotional distress, and copyright violations. Doe II’s complaint described
the harm and results she experienced because of the comments about her on AutoAdmit, including treatment for severe emotional distress, interference with her
educational progress, reputational harm, and pecuniary harm.
The news of the filing of the Does’ complaint quickly became a subject of discussion on AutoAdmit. AK , for example, wrote a post concerning his opinion on
the merits of the plaintiffs’ case, and wondered whether posters were “allowed to
use [Doe II’s] name in thread’s anymore.” Subsequently, on June ,
, AK
0
2
2
Chapter 4: Privacy
Internet Law
1
6
2
2
8
8
3
0
1
1
8
0
2
0
4
2
0
1
3
2
5
5
8
4
0
0
8
2
0
0
1
4
2
0
2
1
0
2
1
0
1
2
0
5
2
2
1
2
7
4
6
2
2
4
7
0
3
0
0
2
1
1
2
0
1
0
2
h
0
s
8
8
0
a
1
0
0
0
u
6
0
0
5
2
2
7
2
1
6
0
4
1
8
2
o
5
7
9
t
5
2
0
5
0
n
0
7
4
2
1
o
2
9
7
2
8
8
i
0
0
0
t
0
7
1
1
1
0
0
2
0
o
2
2
2
2
2
9
4
5
6
1
posted the statement “Women named Jill and Doe II should be raped.” On June
,
, AK started a thread entitled “Inflicting emotional distress on cheerful
girls named [Doe II].”
On February ,
, the plaintiffs issued a subpoena duces tecum to AT&T for
information relating to the identity of the person assigned to the IP address from
which an individual using the pseudonym “AK ” posted comments on AutoAdmit about Doe II. This subpoena was issued in accordance with this Court’s order
of January ,
, which granted the Does’ motion to engage in limited, expedited discovery to uncover the identities of the defendants in this case. On February ,
, AT&T sent a letter to the person whose internet account corresponded with the IP address at issue, John Doe
(“Doe ”), notifying Doe
that it had received a subpoena ordering it to produce certain information relating
to Doe ’s internet account. The letter stated that Doe
could file a motion to
quash or for a protective order before the date of production, which was February
,
, and that AT&T must receive a copy of such a motion prior to that date.
Doe
filed the instant motion to quash on February ,
, and on February
,
, AT&T complied with the subpoena. On March ,
, Doe
filed
his motion to proceed anonymously.
Because Doe
does not have counsel and his true identity is yet unknown to
the Court, the Court appointed pro bono counsel to represent the interests of Doe
at oral argument on the instant motions, which took place on May ,
.
II. M
Q
A. Threshold Issues …
. Mootness
Doe II argues that the motion to quash is moot because the information sought
has already been turned over to the plaintiffs by AT&T. However, the Court rejects
this argument because the plaintiffs can be ordered to return the information and
be prohibited from using it. See Sony Music Entertainment Inc. v. Does - ,
F. Supp. d
,
(S.D.N.Y.
).
B. Merits of the Motion to Quash
A subpoena shall be quashed if it “requires disclosure of privileged or other protected matter and no exception or waiver applies.” Fed.R.Civ.P.
(c)( )(A)(iii).
Doe
moves to quash the subpoena because he claims disclosure of his identity
would be a violation of his First Amendment right to engage in anonymous
speech.
The First Amendment generally protects anonymous speech. … The United
States Supreme Court has also made clear that the First Amendment’s protection
extends to speech on the internet. … Courts also recognize that anonymity is a particularly important component of Internet speech. “Internet anonymity facilitates
the rich, diverse, and far ranging exchange of ideas[;] . . . the constitutional rights
of Internet users, including the First Amendment right to speak anonymously,
must be carefully safeguarded.” Doe v. TheMart.com Inc.,
F. Supp. d
,
,
(W.D. Wash.
). However, the right to speak anonymously, on the
internet or otherwise, is not absolute and does not protect speech that otherwise
would be unprotected. See, e.g., … In re Subpoena Duces Tecum to America Online,
Inc., No.
,
WL
, at * (Va. Cir. Ct.
) (“Those who suffer
damages as a result of tortious or other actionable communications on the Internet should be able to seek appropriate redress by preventing the wrongdoers from
hiding behind an illusory shield of purported First Amendment rights.”). …
0
2
2
2
2
2
1
224
225
6
1
5
2
7
1
2
2
5
7
7
3
1
2
1
2
1
2
7
4
7
4
5
5
2
1
0
0
2
8
1
0
7
The forgoing principles and decisions make clear that Doe
has a First
Amendment right to anonymous Internet speech, but that the right is not absolute
and must be weighed against Doe II’s need for discovery to redress alleged wrongs.
Courts have considered a number of factors in balancing these two competing interests. This balancing analysis ensures that the First Amendment rights of
anonymous Internet speakers are not lost unnecessarily, and that plaintiffs do not
use discovery to “harass, intimidate or silence critics in the public forum opportunities presented by the Internet.” Dendrite Intern. Inc. v. Doe No. ,
A. d
,
(
). The Court will address each factor in turn.
First, the Court should consider whether the plaintiff has undertaken efforts to
notify the anonymous posters that they are the subject of a subpoena and withheld
action to afford the fictitiously named defendants a reasonable opportunity to file
and serve opposition to the application. … In this case, the plaintiffs have satisfied
this factor by posting notice regarding the subpoenas on AutoAdmit in January of
, which allowed the posters ample time to respond, as evidenced by Doe ’s
activity in this action.
Second, the Court should consider whether the plaintiff has identified and set
forth the exact statements purportedly made by each anonymous poster that the
plaintiff alleges constitutes actionable speech. … Doe II has identified the allegedly
actionable statements by AK /Doe : the first such statement is “Alex Atkind,
Stephen Reynolds,
[Doe II], and me: GAY LOVERS;” and the second such
statement is “Women named Jill and Doe II should be raped.” The potential liability for at least the first statement is more fully discussed below.
The Court should also consider the specificity of the discovery request and
whether there is an alternative means of obtaining the information called for in
the subpoena. … Here, the subpoena sought, and AT&T provided, only the name,
address, telephone number, and email address of the person believed to have posted defamatory or otherwise tortious content about Doe II on AutoAdmit, and is
thus sufficiently specific. Furthermore, there are no other adequate means of obtaining the information because AT&T’s subscriber data is the plaintiffs’ only
source regarding the identity of AK .
Similarly, the Court should consider whether there is a central need for the
subpoenaed information to advance the plaintiffs’ claims. … Here, clearly the defendant’s identity is central to Doe II’s pursuit of her claims against him.
Next, the Court should consider the subpoenaed party’s expectation of privacy
at the time the online material was posted. … Doe ’s expectation of privacy here
was minimal because AT&T’s Internet Services Privacy Policy states, in pertinent
part: “We may, where permitted or required by law, provide personal identifying
information to third parties . . . without your consent . . . To comply with court
orders, subpoenas, or other legal or regulatory requirements.” Thus, Doe
has
little expectation of privacy in using AT&T’s service to engage in tortious conduct
that would subject him to discovery under the federal rules.
Finally, and most importantly, the Court must consider whether the plaintiffs
have made an adequate showing as to their claims against the anonymous defendant. Courts have differed on what constitutes such an adequate showing. Several
courts have employed standards fairly deferential to the plaintiff, requiring that
the plaintiff show a “good faith basis” to contend it may be the victim of conduct
actionable in the jurisdiction where the suit was filed; … ; or to show that there is
probable cause for a claim against the anonymous defendant. … The Court finds
these standards set the threshold for disclosure too low to adequately protect the
0
7
2
Chapter 4: Privacy
Internet Law
First Amendment rights of anonymous defendants, and thus declines to follow
these approaches.
Other courts have required that a plaintiff show its claims can withstand a motion to dismiss. … However, other courts have rejected this procedural label as potentially confusing because of the variations in the motion to dismiss standard in
different jurisdictions. … Similarly, but more burdensome, some courts have used
a standard which required plaintiffs to show their claims could withstand a motion for summary judgment. … The Court finds this standard to be both potentially confusing and also difficult for a plaintiff to satisfy when she has been unable to
conduct any discovery at this juncture. Indeed, it would be impossible to meet this
standard for any cause of action which required evidence within the control of the
defendant.
Several courts have required that a plaintiff make a concrete showing as to each
element of a prima facie case against the defendant. … Under such a standard,
“[w]hen there is a factual and legal basis for believing [actionable speech] has
occurred, the writer’s message will not be protected by the First Amendment.” …
The Court finds such a standard strikes the most appropriate balance between the
First Amendment rights of the defendant and the interest in the plaintiffs of pursuing their claims, ensuring that the plaintiff “is not merely seeking to harass or
embarrass the speaker or stifle legitimate criticism.” …
Doe II has presented evidence constituting a concrete showing as to each element of a prima facie case of libel against Doe . Libel is written defamation. To
establish a prima facie case of defamation under Connecticut law, the Doe II must
demonstrate that: ( ) Doe published a defamatory statement; ( ) the defamatory statement identified the plaintiff to a third person; ( ) the defamatory statement was published to a third person; and ( ) the plaintiffs reputation suffered
injury as a result of the statement. …
A defamatory statement is defined as a communication that tends to “harm the
reputation of another as to lower him in the reputation of the community or to
deter third persons from associating or dealing with him . . .” … Doe II alleges, and
has presented evidence tending to show that, AK ’s statement, “Alex Atkind,
Stephen Reynolds, [Doe II], and me: GAY LOVERS,” is defamatory, because any
discussion of Doe II’s sexual behavior on the internet tends to lower her reputation
in the community, particular in the case of any potential employers who might
search for her name online. In fact, in the similar context of slander (spoken
defamation), any statement that imputes “serious sexual misconduct” to a person
subjects the publisher to liability, without any need to prove the special harms required for other slanderous speech. See Restatement (Second), Torts §
,
at
– .
Doe II has also alleged and presented evidence that Doe ’s statement clearly
identified Doe II by name and was available to a large number of third persons
(peers, colleagues, potential employers), whether they were on Autoadmit for their
4
7
5
3
2
1
2
3
7
4
1
2
4
3
1
2
1
2
3
6
1
1
3
6
5
6
9
5
9
Context is relevant in determining the meaning of a statement. See Restatement
(Second), Torts
, at
. Doe
suggests that the context in which the statements were made also shows that they were not defamatory, because AutoAdmit is
well-known as a place for inane discussion and meaningless derogatory postings,
such that one would not take such a statement seriously. However, not everyone who
searched for Doe II’s name on the internet, or who came across the postings on AutoAdmit, would be aware of the site’s alleged reputation. Thus, Doe II has put forth
sufficient evidence for a prima facie case of defamation.
1
7
7
226
227
own purposes, or searched for Doe II via a search engine. Finally, Doe II has alleged and provided evidence that her reputation did suffer injury because of this
comment. In her interviews with potential employers in the Fall of
, Doe II
felt she needed to disclose that existence of this and other such comments on AutoAdmit and explain that she had been targeted by pseudonymous online posters.
In addition, this statement has contributed to difficulties in Doe II’s relationships
with her family, friends, and classmates at Yale Law School.
Thus, the plaintiff has shown sufficient evidence supporting a prima facie case
for libel, and thus the balancing test of the plaintiff ’s interest in pursuing discovery
in this case outweighs the defendant’s First Amendment right to speak anonymously. The defendant’s motion to quash is denied.
7
0
0
2
1
2
0
.
fi
.
fi
.
1
.
2
QUESTIONS
Anonymous Plaintiffs vs. Anonymous Defendants: Note the case caption: Doe v.
Individuals. The plaintiffs are attempting to proceed anonymously, while
asking the court to reveal publicly the identities of the defendants. Is this
fair? Why does each side seek to remain anonymous?
Unmasking Procedure: Doe
has filed a motion to quash but the subpoena
was actually issued to AT&T. Why didn’t AT&T move to quash? Could it
have? How did Doe find out about the subpoena?
Choosing a Standard: The critical question of law in Doe v. Individuals is the
standard the court should use in deciding whether the plaintiffs have made
an “adequate showing as to their claims against the anonymous defendant.”
Civil procedure gives us plenty of familiar standards. For example, the court
could use a motion to dismiss standard, asking whether the plaintiff has
pleaded all the elements of a valid cause of action. Or the court could use a
summary judgment standard: the plaintiff must introduce sufficient uncontroverted evidence to prove every element of her claim. What are the advantages and disadvantages of these different tests? What standard does the
court settle on?
Judicial Hesitation: Courts are usually good at fact-finding, but courts in unmasking cases are often visibly uncomfortable. Why? What’s missing in a
John Doe case that makes the judicial task significantly more difficult?
Skanks of Los Angeles: You have been retained by Rowena Torrens, a fashion
model who lives in Los Angeles. Someone created a blog named “Skanks of
LA” on Medium. It consists entirely of posts about Torrens, such as:
I would have to say that the rst place award for “Skankiest in
LA” would have to go to Rowena Torrens. How old is this
skank?
something? She’s a psychotic, lying, whoring, still
going to clubs at her age, skank. …
Yeah she may have been hot 10 years ago, but is it really
attractive to watch this old hag straddle dudes in a nightclub or
lounge? Desperation seeps from her soul, if she even has one.
Your client strongly suspects that the author of the blog is someone she
knows. She is not interested in litigating a full case, but she would like to
nd out who is responsible for this “disgusting, scurrilous trash,” as she calls
it. A friend of hers suggested ling a John Doe suit for defamation against
the anonymous author, serving a subpoena for the author’s identity on
.
4
2
1
5
4
3
fi
Chapter 4: Privacy
228
Internet Law
Medium, and then dropping the lawsuit once the poster’s identity has been
revealed. Is this a good idea?
ARISTA RECORDS, LLC, V. DOES 1–19
551 F. Supp. 2d 1 (D.D.C. 2008)
7
0
0
2
3
3
9
#
1
5
4
7
0
0
2
9
1
n
o
i
s
s
u
c
s
i
d
n
a
s
d
r
a
d
d
n
n
a
u
t
o
r
l
g
a
k
g
c
e
a
Kollar-Kotelly, District Judge:
This is a copyright infringement case in which Plaintiffs, ten music and recording entities, allege that nineteen unidentified “John Doe” Defendants infringed
their copyrighted recordings by downloading and/or distributing the recordings
using an online media distribution system. Simultaneous with the filing of their
Complaint, Plaintiffs filed an ex parte Motion for Leave to Take Immediate Discovery by serving a subpoena on non-party Internet Service Provider, The George
Washington University (“GW”), to obtain identifying information for each Defendant. The Court initially granted the Motion for Leave and Plaintiffs served a subpoena on GW. Prior to GW’s response, Counsel for John Doe
filed a Motion
with the Court seeking to (i) vacate the Court’s Order granting leave to take immediate discovery, (ii) quash Plaintiffs’ subpoena, and (iii) dismiss Plaintiffs’ Complaint. …
I. B
Plaintiffs filed their Complaint on September ,
, alleging that “each Defendant, without the permission or consent of Plaintiffs, has continuously used, and
continues to use, an online media distribution system to download and/or distribute to the public certain” musical recordings. … Plaintiffs’ Complaint identifies
each Defendant by an Internet Protocol (“IP”) address, and includes corresponding lists of the recordings allegedly infringed by each Defendant.
Simultaneous with the filing of their Complaint on September ,
, Plaintiffs filed an ex parte Motion for Leave to Take Immediate Discovery. The Motion
explained that Plaintiffs had identified each Defendant by an IP address assigned
on the date and the time of each Defendant’s allegedly infringing conduct. The
Motion also explained that Plaintiffs gathered evidence of each Defendant’s infringing activities,including evidence of “every file (at times numbering in the
thousands) that each Defendant illegally distributed to the public.” Without the
ability to serve immediate discovery on the Internet Service Provider (“ISP”), however, Plaintiffs indicated that they were unable to ascertain the true identities of
the Defendants. Accordingly, the Motion sought leave of Court to serve a subpoena
on GW, the ISP, to obtain identifying information for each Defendant. …
II. L
S
D
…
Equally unavailing is Defendant’s argument that Plaintiffs should not be permitted
to serve their subpoena because the information possessed by GW is unreliable
(e.g., GW student IDs and passwords may be lost or stolen) and that Plaintiffs
must show a “real evidentiary basis” that Defendants have “engaged in wrongful
conduct” prior to being allowed to conduct discovery. Defendant attaches the Declaration of Thomas J. Swanton who provides various explanations as to why Defendants may not be liable for the conduct alleged in Plaintiffs’ Complaint. The
Court declines to review Defendant’s factual and technical arguments based on
Mr. Swanton’s declaration because they are unrelated to any appropriate inquiry
associated with a motion to quash. See [Fed. R. Civ. P.
(d)( )] (describing
grounds for quashing a subpoena). “If Defendant believes that he or she has been
improperly identified by the ISP, Defendant may raise, at the appropriate time,
229
any and all defenses, and may seek discovery in support of its defenses.” Fonovisa,
Inc v. Does – , Civ. A. No. –
,
WL
,* ,
U.S. Dist. LEXIS
at * , (W.D. Pa. Apr. ,
).
Defendant’s final argument with respect to Plaintiffs’ subpoena is that file sharing is protected speech under the First Amendment and that Defendants have the
right to speak anonymously. Accordingly, Defendant invites the Court to quash
Plaintiffs’ subpoena based on “the multi-part test” adopted by the Arizona Court of
Appeals in Mobilisa, Inc. v. John Doe ,
Ariz.
,
P. d
(
) (setting
forth a multipart test requiring a plaintiff to show, among other elements, that its
claims could survive a motion for summary judgment). The Court declines Defendant’s invitation because Mobilisa, Inc. involved actual speech. See Mobilisa, Inc.,
P. d at
(describing an intimate email sent from plaintiff ’s protected computer system that was the focus of the lawsuit’s trespass to chattels claim). The
“speech” at issue in this case is Defendant’s alleged infringement of Plaintiffs’ copyrights. Not surprisingly, courts have routinely held that a defendant’s First
Amendment privacy interests are exceedingly small where the “speech” is the alleged infringement of copyrights. See Fonovisa, Inc.,
WL
,* ,
U.S. Dist. LEXIS
at *
(“a Doe Defendant, who allegedly used the internet
to unlawfully download and disseminate copyrighted sound recordings, has a minimal expectation of privacy in remaining anonymous”); Sony Music Entm’t Inc.,
F. Supp. d at
(examining defendant’s First Amendment claims on facts
materially similar to the present and concluding that “defendants’ First Amendment right to remain anonymous must give way to plaintiffs’ right to use the judicial process to pursue what appear to be meritorious copyright infringement
claims”); Arista Records LLC v. Does – , Civ. A. No. –
(W.D. Okla. Nov. ,
) (Order holding that “[t]he Doe Defendants’ First Amendment rights are
not implicated because the information sought by the subpoena does not infringe
their rights to engage in protected speech”). In fact, the Mobilisa, Inc. court even
recognized that the right to speak anonymously is not absolute, and there are situations that require lesser degrees of First Amendment protection, citing Sony Music Entertainment, Inc. Consistent with Sony Music Entertainment, Inc. and the
other cases cited by the Court above, the Court finds that Plaintiffs’ need for disclosure outweighs any First Amendment interest claimed by Defendant.
For these reasons, the Court denies Defendant’s Motion insofar as it seeks to
quash Plaintiffs’ subpoena. …
B. M
D
…
In the present case, Plaintiffs’ Complaint alleges that “each Defendant, without the
permission or consent of Plaintiffs, has continuously used, and continues to use,
8
0
4
1
0
2
9
7
0
1
0
0
2
7
9
1
2
1
9
7
8
0
3
0
3
8
2
6
#
8
0
5
8
0
7
0
7
1
2
0
0
7
3
9
0
1
1
9
7
8
1
0
2
1
1
0
1
2
1
5
8
1
0
5
0
1
2
7
2
3
0
3
0
7
s
s
7
6
i
1
5
7
m
2
s
i
9
5
1
2
o
t
1
8
7
2
n
o
i
t
3
0
o
7
7
1
0
6
0
7
7
2
… Defendant asks the Court to take into account that Doe
is a university student
who has a high expectation of privacy, that he must spend time defending this lawsuit rather than focusing on his studies, that Plaintiffs have not employed other
means to obtain Defendant’s identity, and that the IP address information obtained
by Plaintiffs may not be reliable. … Nevertheless, the Court notes that Defendant’s
privacy interest as a student does not allow him to infringe others’ intellectual property, and that, if Plaintiffs’ allegations are correct, Defendant has already taken time
away from his studies by infringing on Plaintiffs’ copyrights. Defendant also fails to
explain how Plaintiffs could otherwise obtain Defendant’s identity and why that
would even matter in the context of Defendant’s First Amendment rights. Finally,
whether or not the information supplied by GW is reliable is an area into which Defendant may inquire at the appropriate time in discovery.
0
2
1
3
2
8
8
Chapter 4: Privacy
IN RE BITTORRENT ADULT FILM COPYRIGHT INFRINGEMENT CASES
Nos. 11-3995(DRH)(GRB) et al.
2012 U.S. Dist. LEXIS 61447, 2012 WL 1570765 (E.D.N.Y. May 1, 2012)
Brown, Magistrate Judge:
These actions are part of a nationwide blizzard of civil actions brought by purveyors of pornographic films alleging copyright infringement by individuals utilizing a computer protocol known as BitTorrent. The putative defendants are identified only by Internet Protocol (“IP”) addresses. These four civil actions involve
more than
John Doe defendants; these same plaintiffs have filed another nineteen cases in this district involving more than thrice that number of defendants.
One media outlet reports that more than
,
individuals have been sued
since mid–
in mass BitTorrent lawsuits, many of them based upon alleged
downloading of pornographic works.
This Order addresses ( ) applications by plaintiffs in three of these actions for
immediate discovery, consisting of Rule
subpoenas directed at non-party Internet Service Providers (“ISPs”) to obtain identifying information about subscribers
to the named IP addresses and ( ) motions to quash similar subpoenas by several
putative John Doe defendants in the remaining action. …
B
1. Allegations in the Complaints
The four complaints that are subject to this Order are nearly identical, though
each involves a different pornographic film, to wit: Gang Bang Virgins, Veronica
Wet Orgasm, Maryjane Young Love and Gangbanged. … Each defendant is identified only by an IP address purportedly corresponding to a physical address in this
district, defined in the complaint as “a number that is assigned by an ISP to devices, such as computers, that are connected to the Internet.” The Complaints fur-
4
4
5
0
5
5
8
6
5
7
0
0
0
0
0
2
2
1
1
5
1
4
2
1
6
0
1
0
0
d
8
2
n
7
0
u
o
0
2
r
g
7
4
k
1
0
c
0
a
2
Defendant repeatedly highlights the fact that Plaintiffs have identified several of the
same IP addresses as different John Doe Defendants. According to Defendant,
“[t]his discrepancy calls into question both Plaintiffs’ modus operendi and bona
fides.” Def.’s Reply at . The Court finds that it does neither, as Plaintiffs explain that
the same Defendant may have engaged in multiple acts of infringement or the same
IP address may have been issued to different individuals at different date and times.
The fact remains that this inquiry is an appropriate one after Defendants have been
identified and once such arguments may be explored using actual facts and not
speculation. See Arista Records LLC v. Does – , Civ. A. No.
–
(W.D. Okla.
Nov. ,
) (“[i]f [defendants] claim someone else used their computers without
their knowledge, that is a matter for their defense. But the Plaintiffs do not have to
prove the merits of their case to obtain the discovery sought.”).
1
1
Internet Law
an online media distribution system to download and/or distribute to the public
certain” musical recordings. The Complaint further alleges that each Plaintiff is a
“copyright owner[ ] or licensee[ ] of exclusive rights” of the recordings, and that
each of the recordings is “the subject of a valid Certificate of Registration issued by
the Register of Copyrights to each Plaintiff.” Plaintiffs’ Complaint identifies each
Defendant by IP address, and includes a corresponding list of recordings allegedly
infringed by each Defendant. At this early stage of the case, these allegations (taken as true) are more than sufficient to find that Plaintiffs’ right to relief rises
“above the speculative level” described in Bell Atlantic v. Twombly [
U.S.
(
)].
1
1
230
231
ther allege that “[t]he ISP to which each Defendant subscribes can correlate the
Defendant’s IP address to the Defendant’s true identity.”
The complaints describe, in some detail, a peer-to-peer filing sharing protocol
known as BitTorrent … . [Refer to Columbia Pictures v. Fung in Section .A for
the technical details.] BitTorrent also uses a “tracker” computer that tracks the
pieces of the files as those pieces are shared among various computers. This tracking feature allows the plaintiffs to identify the IP addresses from which the films
were downloaded, the subscribers to which have become the defendants in these
actions. …
4. Additional Facts
a. Factual Defenses Raised by the Moving John Doe Defendants
The factual defenses presented are vastly different and highly individualized. One
movant – John Doe
– has stated that he was at work at the time of the alleged
download. John Doe
states under oath that he closed the subject Earthlink
account, which had been compromised by a hacker, before the alleged download.
John Doe
’s counsel represents that his client is an octogenarian with neither
the wherewithal nor the interest in using BitTorrent to download Gang Bang Virgins. John Doe
represents that downloading a copy of this film is contrary to
her “religious, moral, ethical and personal views.” Equally important, she notes
that her wireless router was not secured and she lives near a municipal parking lot,
thus providing access to countless neighbors and passersby.
b. The Use of IP Address to Identify the Alleged Infringers
The complaints assert that the defendants – identified only by IP address – were
the individuals who downloaded the subject “work” and participated in the BitTorrent swarm. However, the assumption that the person who pays for Internet access
at a given location is the same individual who allegedly downloaded a single sexually explicit film is tenuous, and one that has grown more so over time. An IP address provides only the location at which one of any number of computer devices
may be deployed, much like a telephone number can be used for any number of
telephones. …
Thus, it is no more likely that the subscriber to an IP address carried out a particular computer function – here the purported illegal downloading of a single
pornographic film – than to say an individual who pays the telephone bill made a
specific telephone call.
Indeed, due to the increasingly popularity of wireless routers, it much less likely. While a decade ago, home wireless networks were nearly non-existent,
of
U.S. homes now have wireless access. Several of the ISPs at issue in this case provide a complimentary wireless router as part of Internet service. As a result, a single IP address usually supports multiple computer devices – which unlike traditional telephones can be operated simultaneously by different individuals. Different family members, or even visitors, could have performed the alleged downloads.
Unless the wireless router has been appropriately secured (and in some cases, even
if it has been secured), neighbors or passersby could access the Internet using the
IP address assigned to a particular subscriber and download the plaintiff ’s film. …
%
1
2
6
2
6
1
#
#
0
1
#
9
2
While Plaintiffs claim that they can amend their complaints to allege negligence
against the owner of a WiFi router who failed to password-protect the device which
was then used by an intruder to infringe its copyright, this assertion flies in the face
of common sense.
#
3
3
Chapter 4: Privacy
Internet Law
0
3
3
6
1
#
1
3
9
4
3
6
2
0
2
6
2
0
2
1
0
0
6
2
1
1
0
2
6
3
0
3
6
7
1
1
1
%
0
3
2
2
#
#
2
1
0
2
1
1
0
Some of these IP addresses could belong to businesses or entities which provide
access to its employees, customers and sometimes (such as is common in libraries
or coffee shops) members of the public.
These developments cast doubt on plaintiffs’ assertions that “[t]he ISP to
which each Defendant subscribes can correlate the Defendant’s IP address to the
Defendant’s true identity.” or that the subscribers to the IP addresses listed were
actually the individuals who carried out the complained of acts. As one judge observed:
The Court is concerned about the possibility that many of the names
and addresses produced in response to Plaintiff ’s discovery request
will not in fact be those of the individuals who downloaded “My Little
Panties
.” The risk is not purely speculative; Plaintiff ’s counsel
estimated that
of the names turned over by ISPs are not
those of individuals who actually downloaded or shared copyrighted material. Counsel stated that the true offender is often the
“teenaged son . . . or the boyfriend if it’s a lady.” Alternatively, the perpetrator might turn out to be a neighbor in an apartment building
that uses shared IP addresses or a dormitory that uses shared wireless
networks. This risk of false positives gives rise to the potential for coercing unjust settlements from innocent defendants such as individuals who want to avoid the embarrassment of having their names publicly associated with allegations of illegally downloading “My Little
Panties
.”
Digital Sin, Inc. v. Does –
, __ F.R.D. __,
WL
, at * (S.D.N.Y. Jan.
,
). Another court noted:
the ISP subscriber to whom a certain IP address was assigned may
not be the same person who used the Internet connection for illicit
purposes . . . By defining Doe Defendants as ISP subscribers who were
assigned certain IP addresses, instead of the actual Internet users who
allegedly engaged in infringing activity, Plaintiff ’s sought-after discovery has the potential to draw numerous innocent internet users into
the litigation, placing a burden upon them that weighs against allowing the discovery as designed.
SBO Pictures, Inc. v. Does –
,
WL
, at * (N.D .Cal. Nov.
,
).
In sum, although the complaints state that IP addresses are assigned to “devices” and thus by discovering the individual associated with that IP address will
reveal “defendants’ true identity,” this is unlikely to be the case. Most, if not all, of
the IP addresses will actually reflect a wireless router or other networking device,
meaning that while the ISPs will provide the name of its subscriber, the alleged
infringer could be the subscriber, a member of his or her family, an employee, invitee, neighbor or interloper.
c. Indicia of Unfair Litigation Tactics
One moving defendant has provided concrete evidence of improper litigation tactics employed by K–Beech. In a sworn declaration, John Doe
states the following:
Upon receipt of the Complaint, I reached out to Plaintiff and spoke to
a self-described “Negotiator” in an effort to see if I could prove to
them (without the need for publicly tying my name to the Complaint)
0
3
2
232
233
that I had nothing to do with the alleged copyright infringements.
The Negotiator was offered unfettered access to my computer, my
employment records, and any other discovery they may need to
show that I was not the culpable party. Instead, the Negotiator refused and was only willing to settle the Complaint for thousands of
dollars. While the Negotiator said on October ,
that he would
check to see if he could come down from the thousands of dollar settlement amount, the Negotiator has not responded to two voice mails
that were left on October ,
. Notably, the Negotiator justified
the settlement amount because, in part, I would incur legal fees in
hiring an attorney.
Significantly, since plaintiff has not yet been provided with the identities of the
moving John Does, this record exists only because John Doe
proactively contacted counsel for K–Beech (who is also representing Patrick Collins, Inc. in another matter), rather than await a determination by the Court. John Doe
’s
experience directly mirrors that of defendants in a separate action by plaintiff K–
Beech regarding Gang Bang Virgins, as well as another action filed by Patrick
Collins, Inc. relating to a film entitled Cuties.
Remarkably, plaintiff ’s opposition to John Doe
’s motion, encompassing
pages of material, does not provide any evidentiary response to these sworn assertions of improper conduct. Rather, counsel attempts to dismiss this evidence as
“mere denials”, and unabashedly argues that “[d]efendant’s] assertion that the
negotiations between him and Plaintiff have ended further supports the need for
litigation.” Moreover, K–Beech has filed “Notices of Settlement and Voluntary
Dismissal” as to three of the John Does in this action. “This course of conduct indicates that the plaintiffs have used the offices of the Court as an inexpensive
means to gain the Doe defendants’ personal information and coerce payment from
them. The plaintiffs seemingly have no interest in actually litigating the cases, but
rather simply have used the Court and its subpoena powers to obtain sufficient
information to shake down the John Does.” Raw Films,
WL
, at * .
In a similar case by plaintiff Patrick Collins filed in this district, after being
granted discovery of the IP subscribers, counsel for that entity described in motion
papers the intended approach to the John Doe defendants:
Plaintiff requested and was granted additional time within which to
effectuate service upon the Doe Defendants to accommodate Plaintiff ’s need for obtaining their identifying information, as well as its
further settlement and litigation strategy. The latter involves Plaintiff
contacting Doe Defendants once their identities are known and attempting to reach a settlement with them. In cases where a settlement
6
1
2
2
#
6
5
2
0
2
8
1
6
6
1
#
1
1
0
2
1
1
0
2
6
1
4
2
#
1
1
0
2
5
Plaintiff K–Beech’s rambling motion papers often lapse into the farcical. In its papers, counsel for K–Beech equate its difficulties with alleged piracy of its adult films
with those faced by the producers of the Harry Potter books, Beatles songs and Microsoft software, and compare its efforts to collect from alleged infringers of its
rights to the efforts of the FBI to combat child pornography. In an ironic turn, the
purveyors of such works as Gang Bang Virgins, explain how its efforts in this matter
will help empower parents to prevent minors from watching “movies that are not age
appropriate” by ensuring that viewers must pay for plaintiffs products, and thereby
effectively notify parents of such activity because “many parents would surely notice
if they showed up on billing statements.” It is difficult to accord the plaintiff, which
features “Teen” pornography on its website, the moral high-ground in this regard.
2
7
7
Chapter 4: Privacy
Internet Law
2
1
1
6
0
2
2
4
0
0
6
2
2
6
1
3
1
0
#
1
0
6
2
2
5
6
2
4
6
5
9
1
1
6
5
0
5
1
1
1
2
3
1
1
0
6
2
2
4
2
0
7
5
6
2
3
6
2
3
4
0
4
1
2
n
3
2
o
i
1
s
s
4
2
u
c
4
7
s
i
6
1
6
1
cannot be reached, Plaintiff would then consider the feasibility of filing suit, and proceed with service upon those Doe Defendants against
whom it chooses to proceed.
On a cold record, this overview could be viewed as a reasoned approach. However,
when viewed against undisputed experience of John Doe
, described above,
and findings by other courts, this suggests an approach that is highly inappropriate.
D
The Legal Standard
Federal Rule of Civil Procedure
(d)( ) forbids a party from seeking discovery
“from any source before the parties have conferred as required by Rule (f ) except as “authorized . . . by court order.” Fed. R. Civ. P. (d)( ). This is generally
viewed as requiring a showing of good cause. Plaintiffs rely principally upon the
five factor Sony Music test, adopted by the Second Circuit, which requires the
Court to weigh:
( ) [the] concrete[ness of the plaintiff ’s] showing of a prima facie
claim of actionable harm, . . . ( )[the] specificity of the discovery request, . . . ( ) the absence of alternative means to obtain the subpoenaed information, . . . ( )[the] need for the subpoenaed information
to advance the claim, . . . and ( ) the [objecting] party’s expectation of
privacy.
Arista Records, LLC v. Doe ,
F. d
,
( d Cir.
) (citing Sony Music
Entm’t Inc. v. Does – ,
F. Supp. d
,
– (S.D.N.Y.
)). This test,
articulated in the context of evaluating a motion to quash, frames the inquiry in
evaluating defendants’ motions in K–Beech. Additionally, plaintiffs correctly note
that the test is also instructive in evaluating the motions for early discovery. …
Element : Prima Facie Claim of Actionable Harm
[The court held that three of the four plaintiffs had sufficiently made out prima
facie cases of copyright infringement.]
Element[] : The Specificity of the Discovery Requests
With respect to the specificity of discovery requests, the Sony Music court explained that this factor requires that “Plaintiffs’ discovery request is also sufficiently specific to establish a reasonable likelihood that the discovery request would
lead to identifying information that would make possible service upon particular
defendants who could be sued in federal court.” Sony Music,
F. Supp. d at
. While the discovery propounded by plaintiffs is specific, for the reasons discussed above, it does not establish a reasonable likelihood it will lead to the identity of defendants who could be sued. See Pacific Century Int’l Ltd. v. Does,
WL
, at * (N.D. Cal. Oct. ,
) (“Plaintiff must go beyond the ‘limited discovery’ that it earlier asserted would lead to Defendants’ identities . . . [p]resumably, every desktop, laptop, smartphone, and tablet in the subscriber’s residence,
and perhaps any residence of any neighbor, houseguest or other sharing his internet access, would be fair game. Beyond such an inspection, [the plaintiff] might
require still more discovery, including interrogatories, document requests and
even depositions.”).
1
5
5
234
235
In this regard, the instant matter is factually distinguishable from the Arista
Records decision.[*] In that case, the sought after discovery involved an Internet
service provider located at a university. Based on that setting, and at that time, it
was almost certain that the end user at an IP address was a particular individual,
rather than a wireless network. The instant case involves broadband Internet service in a largely residential suburban area at a time when wireless is widely available. Furthermore, it is alleged that each John Doe in the instant case downloaded
only a single pornographic film. By contrast, in Arista Records, the plaintiff alleged
that a file sharing folder located at the IP address in question contained
audio
files, containing at least a half-dozen copyrighted songs owned by the plaintiff.
Arista Records,
F. d at
. In fact, in that case, plaintiffs’ investigator was
able to “download[ ] music files from the user’s computer,” which is not the case
here. Arista Records LLC v. Does – ,
WL
, at * (N.D.N.Y. Feb. ,
) aff ’d
F. d
( d Cir.
). Clearly, the level of activity in Arista
Records made it far more likely that the subscriber to the IP address would have
conducted or at least been aware of the illegal downloading. In sum, it is not clear
that plaintiffs have satisfied this factor. …
Element : The Absence of Alternative Means
As one court observed, “[b]ecause the transactions in question occurred online,
the defendants have been elusive and the IP addresses and ISP are the only available identifying information. Without the requested discovery, there are no other
measures Plaintiff can take to identify the personal information for the Doe defendants.” Raw Films, Ltd. v. Does – ,
WL
, at * (S.D. Cal. Mar. ,
). Plaintiffs retained a company that provides forensic investigation services
including the identification of IP addresses using BitTorrent protocol. Since plaintiffs have only been able to identify IP addresses used for potential infringement,
they have established to the satisfaction of the Court that there are not alternative
means available to identify the alleged infringers.
Element : The Need for Subpoenaed Information to Advance the Claim
Plaintiffs clearly need identification of the putative John Does in order to serve
process on them and prosecute their claims. However, not all the information
sought is required to advance the claim. For example, in addition to names and
addresses, plaintiffs seek both the home telephone numbers and email addresses
of the putative John Does, information which is clearly not required to proceed
with this action. In particular, obtaining the home telephone numbers seems calculated to further plaintiffs’ settlement strategies, discussed above, rather than
advancing their claims by allowing them to effect service.
Element : Defendants’ Expectation of Privacy
In Arista Records, the John Doe defendant, conceding that he had engaged in the
alleged improper downloading, sought to quash the subpoena on First Amendment grounds. While recognizing the protected nature of anonymous speech, the
Court rejected the challenge, concluding that the “First Amendment does not . . .
provide a license for copyright infringement.” Arista Records,
F. d at
. In
examining this factor, the Sony Music court noted “defendants have little expectation of privacy in downloading and distributing copyrighted songs without permission.” Sony Music,
F. Supp. d at
– . Here it is uncertain – indeed, it
8
2
1
8
1
1
6
3
2
3
4
0
1
6
2
0
6
3
6
0
7
4
1
4
8
4
6
7
6
6
9
6
0
2
1
5
0
2
0
0
1
2
0
6
1
2
1
2
1
1
1
2
2
1
2
0
6
1
2
1
3
3
3
4
0
6
4
0
6
3
5
4
9
2
0
1
0
[*] [Ed: This is a different infringement lawsuit brought by Arista Records against
anonymous defendants, not the one excerpted supra.]
0
2
2
Chapter 4: Privacy
Internet Law
may be unlikely – that the subscribers sought to be identified downloaded the
plaintiffs’ copyrighted works. Cf. Pacific Century,
WL
, at * (denying
discovery to protect “innocent internet users”). Thus, this Court cannot conclude
with any reasonable certainty that plaintiffs have overcome the expectation of privacy by putative defendants.
Abusive Litigation Tactics Employed by the Plaintiffs
The most persuasive argument against permitting plaintiffs to proceed with early
discovery arises from the clear indicia, both in this case and in related matters,
that plaintiffs have employed abusive litigations tactics to extract settlements from
John Doe defendants. Indeed, this may be the principal purpose of these actions,
and these tactics distinguish these plaintiffs from other copyright holders with
whom they repeatedly compare themselves (arguing that this decision “will affect
the rights of intellectual property holders across all segments of society”). While
not formally one of the Sony Music factors, these facts could be viewed as a
heightened basis for protecting the privacy of the putative defendants, or simply
grounds to deny the requested discovery on the basis of fundamental fairness. …
It would be unrealistic to ignore the nature of plaintiffs’ allegations – to wit: the
theft of pornographic films – which distinguish these cases from garden variety
copyright actions. Concern with being publicly charged with downloading pornographic films is, understandably, a common theme among the moving defendants.
As one woman noted in K–Beech, “having my name or identifying or personal information further associated with the work is embarrassing, damaging to my reputation in the community at large and in my religious community.” … This consideration is not present in infringement actions involving, for example, popular music downloads. See Arista Records,
F. d at
, (“Teenagers and young adults
who have access to the Internet like to swap computer files containing popular
music . . . The swappers . . . are ignorant or more commonly disdainful of copyright.).
The Federal Rules direct the Court to deny discovery “to protect a party or person from annoyance, embarrassment, oppression, or undue burden or expense.”
Fed. R. Civ. P. (c)( ). This situation cries out for such relief. …
C
…
For all of the reasons set forth herein, the Court is not inclined to grant the broad
early discovery sought by Malibu and Patrick Collins. At the same time, these
plaintiffs are allegedly the owners of copyrighted works who should not be left
without any remedy. Given the record in this case, however, this must be done in a
fashion that will ensure that the rights of all parties are adequately protected.
Thus, the Court is prepared to grant these plaintiffs limited early discovery, to wit:
the names and addresses (not email addresses or phone numbers) of only the subscribers designated as John Doe in Malibu
, Malibu , and Patrick Collins.
Following service of subpoenas, under the terms and conditions set forth below,
the identifying information will be provided to plaintiffs at a status conference,
with each John Doe present, giving them an opportunity to be heard, to obtain
counsel and, if appropriate, request appointment of counsel from this Court’s pro
bono panel. …
2
4
2
4
7
1
1
1
5
1
1
1
0
2
2
2
1
6
2
3
4
0
6
1
1
6
2
n
o
i
s
u
l
c
n
1
QUESTIONS
Reconciling the Cases: What explains the divergent results in Bittorrent Adult
Film and Arista?
.
o
1
236
237
. Unsecured WiFi: Should the subscriber to an Internet connection be held
legally responsible for any use of it? Should she be required to secure her
WiFi router to prevent strangers from using it?
. Sue First and Ask Questions Later: Suing anonymous defendants has its risks.
Consider Brianna LaHara, Gertrude Walton, and Sarah Seabury Ward, all
named as defendants in RIAA lawsuits. LaHara was
at the time; Walton
was deceased; Ward was a “computer neophyte” grandmother accused of
downloading gangster rap. All three suits were quickly withdrawn or settled.
How did the RIAA end up suing them? If you were in charge of a copyright
owner’s litigation against individual file-sharers, whom would you try to
target?
D. Personal Privacy
There is a large and not always orderly body of law that protects individuals from
invasions of their privacy by other individuals. Some of this law long predates the
Internet and must be applied to new fact patterns. Some of it consists of modern
attempts to deal with new forms of online harm.
ff
2
1
ff
2
5
RESTATEMENT (SECOND) OF TORTS [PRIVACY TORTS]
§
B – Intrusion upon Seclusion
One who intentionally intrudes, physically or otherwise, upon the solitude or
seclusion of another or his private a airs or concerns, is subject to liability to the
other for invasion of his privacy, if the intrusion would be highly o ensive to a reasonable person.
Comments
b. The invasion may be by physical intrusion into a place in which the plaintiff
has secluded himself, as when the defendant forces his way into the plaintiff ’s room in a hotel or insists over the plaintiff ’s objection in entering his
home. It may also be by the use of the defendant’s senses, with or without
mechanical aids, to oversee or overhear the plaintiff ’s private affairs, as by
looking into his upstairs windows with binoculars or tapping his telephone
wires. It may be by some other form of investigation or examination into his
private concerns, as by opening his private and personal mail, searching his
safe or his wallet, examining his private bank account, or compelling him by
a forged court order to permit an inspection of his personal documents. …
c. The defendant is subject to liability under the rule stated in this Section only
when he has intruded into a private place, or has otherwise invaded a private seclusion that the plaintiff has thrown about his person or affairs. Thus
there is no liability for the examination of a public record concerning the
plaintiff, or of documents that the plaintiff is required to keep and make
available for public inspection. Nor is there liability for observing him or
even taking his photograph while he is walking on the public highway, since
he is not then in seclusion, and his appearance is public and open to the
public eye. Even in a public place, however, there may be some matters
about the plaintiff, such as his underwear or lack of it, that are not exhibited
to the public gaze; and there may still be invasion of privacy when there is
intrusion upon these matters.
6
3
2
Chapter 4: Privacy
Internet Law
§
D - Publicity Given to Private Life
One who gives publicity to a matter concerning the private life of another is subject to liability to the other for invasion of his privacy, if the matter publicized is of
a kind that
(a) would be highly offensive to a reasonable person, and
(b) is not of legitimate concern to the public.
PENNSYLVANIA RIGHT OF PUBLICITY
Title 42, Pennsylvania Consolidated Statutes
– Unauthorized use of name or likeness
(a) C
.–Any natural person whose name or likeness has commercial value and is used for any commercial or advertising
purpose without the written consent of such natural person … may bring an
action to enjoin such unauthorized use and to recover damages for any loss
or injury sustained by such use. …
(c) R
.–No action shall be commenced under this section more than
years after the death of such natural person. …
(e) D
.–As used in this section, the following words and phrases
shall have the meanings given to them in this subsection:
“Commercial or advertising purpose.”
( ) Except as provided in paragraph ( ), the term shall include the public
use or holding out of a natural person’s name or likeness:
(i) on or in connection with the offering for sale or sale of a product, merchandise, goods, services or businesses;
(ii) for the purpose of advertising or promoting products, merchandise, goods or services of a business; or
(iii) for the purpose of fundraising.
( ) The term shall not include the public use or holding out of a natural
person’s name or likeness in a communications medium when:
(i) the natural person appears as a member of the public and the
natural person is not named or otherwise identified;
(ii) it is associated with a news report or news presentation having
public interest;
(iii) it is an expressive work; …
“Expressive work.”
A literary, dramatic, fictional, historical, audiovisual or musical work
regardless of the communications medium by which it is exhibited,
displayed, performed or transmitted, other than when used or employed for a commercial or advertising purpose.
0
3
2
d
e
h
s
i
l
b
a
t
s
o
i
t
c
s
a
n
o
f
i
o
e
t
i
e
s
n
s
o
i
f
1
u
p
2
a
e
e
6
2
1
5
3
6
e
QUESTIONS
The Freedom of Eavesdropping? What does the intrusion on seclusion tort
have to do with speech? Is there a First Amendment right to observe as well
as to speak? To speak about what one has observed? If so, what work are the
concepts of “public place” and “private place” doing in defining the contours
of the tort?
.
n
§
8
1
238
239
. Privacy vs. Publicity: What is the difference between “publicity given to private
life” and the “right of publicity?”
. Photography Hypotheticals: Which of the following are legal when the subject
is not aware that they are being observed? What about when they are? Does
it matter whether and how the photograph is then sold?
• Taking an upskirt photograph of a woman seated on the subway?
• Taking an aerial photograph of a celebrity’s house?
• Photographing the police as they attempt to subdue and arrest a
suspect?
• Photographing the face of a person on a public sidewalk?
• Photographing people lounging about in the living room of a groundoor apartment that faces directly onto a public park?
The following cases include discussion of harassment.
PEOPLE V. GOLB [GOLB I]
23 N.Y.3d 455 (2014)
n
g
i
a
p
m
a
t
e
n
r
e
t
n
s
t
n
a
d
n
e
f
e
d
n
a
s
l
l
o
r
c
a
e
d
a
8
e
0
0
2
8
e
4
9
h
Abdus-Salaam, Justice:
University of Chicago Professor Norman Golb is a scholar of the Dead Sea
Scrolls. This case involves an Internet campaign by Golb’s son, Raphael Golb, to
attack the integrity and harm the reputation of other Dead Sea Scrolls academics
and scholars, while promoting the views of his father.
To accomplish his goal of discrediting and harming these individuals, defendant, using pseudonyms and impersonating real academics and scholars, sent
emails to museum administrators, academics and reporters. …
I. T D
S S
D
' I
C
…
[T]he Dead Sea Scrolls are a collection of ancient religious writings dating from
the second and third century B.C.E. to the first century C.E. They were discovered
in
in caves near Qumran, in the West Bank. Norman Golb, defendant's father, is a professor at the University of Chicago, and a scholar on the subject of the
Scrolls. There is disagreement among scholars and experts about who wrote the
Scrolls. …
The Scrolls were put on exhibit at the Jewish Museum in New York City in the
fall of
, and NYU Professor Lawrence Schiffman was scheduled as a lecturer.
Defendant used the pseudonym “Peter Kaufman” to publish an article about
Schiffman on the social news website NowPublic entitled “Plagiarism and the
Dead Sea Scrolls: Did NYU department chairman pilfer from Chicago historian's
work?” Defendant as “Kaufman” wrote of a “little-known case of apparent academic quackery.” He complained of Schiffman's failure to credit Professor Golb for
ideas expressed in Schiffman's articles about the Scrolls, and Schiffman's repeated
plagiarisms of Golb's work.
Using NYU computers, defendant sent emails from another account he created
– “larry.schiffman@gmail.com” – to four of Schiffman's students and multiple
NYU addresses of Schiffman's colleagues that included a link to the article. The
emails stated, among other things, that “someone is intent on exposing a minor
failing of mine that dates back almost fifteen years ago” and that “[t]his is my career at stake.” He signed those emails “Lawrence Schiffman.” Additionally, defendant sent identical emails from the Schiffman email address to the Provost of NYU
1
fl
3
2
Chapter 4: Privacy
Internet Law
2
3
4
8
4
1
1
8
1
4
0
0
8
3
7
0
9
9
2
1
1
2
3
1
1
5
7
4
6
2
2
1
3
e
5
e
r
0
7
2
g
9
9
7
e
9
8
1
1
1
d
5
6
n
2
7
o
0
c
e
9
1
4
4
7
e
9
1
h
7
t
5
8
2
n
8
8
i
7
5
4
0
5
n
1
9
2
2
1
o
0
i
2
9
t
1
a
n
3
o
6
s
1
r
8
e
7
p
m
l
a
n
0
i
4
1
9
0
m
9
i
1
2
r
0
and the Dean of NYU Graduate School of Arts and Science. Defendant, as Schiffman, asked what action he could take “to counter charges of plagiarism that have
been raised against me” and stated:
Apparently, someone is intent on exposing a failing of mine that dates
back almost fifteen years ago. It is true that I should have cited Dr.
Golb's articles when using his arguments, and it is true that I misrepresented his ideas. But this is simply the politics of Dead Sea Scrolls
studies. If I had given credit to this man I would have been banned
from conferences around the world.
He signed those emails “Lawrence Schiffman, professor.”
NYU's Senior Vice Provost responded to this email, stating that he had assigned the matter to a dean for further investigation. Defendant, as “Schiffman,”
forwarded that email from the Vice Provost (including defendant's email to the
Provost) to five NYU school newspaper email addresses, asking that they not mention this matter and stating that his “career is at stake.” He signed those emails
“Lawrence Schiffman.” …
[Golb engaged in similar conduct toward UCLA Ph.D. student Robert Cargill,
Duke library clerk Stephen Goranson, retired Harvard professor Frank Cross, and
rabbi and University of Oregon professor Jonathan Seidel.]
II. C
I
S
D
Defendant was convicted of
counts of criminal impersonation in the second
degree. A person is guilty of this crime when he or she “[i]mpersonates another
and does an act in such assumed character with intent to obtain a benefit or to
injure or defraud another” Penal Law §
. [ ] . … Although requested to do so
by defendant, the trial court did not limit the statutory terms “benefit” or “injure”
in its charge to the jury. … Defendant maintains that the trial court's failure to
properly limit and define the terms “injure” and “benefit” constituted reversible
error because the jury could have interpreted the statute as capturing any benefit
or harm. Thus, argues defendant, when literally anything can be a legally cognizable benefit or harm, one can be found guilty of violating this law if one, for example, simply causes hurt feelings, mocks or criticizes. Similarly, says defendant, a
benefit could be any gain or advantage, no matter how slight.
Cases applying Penal Law §
. have traditionally involved monetary fraud
or interference with government operations see e.g. People v. Sanchez,
N.Y. d
(
) (impersonation of an FBI agent); People v. Hooks, A.D. d
,( d
Dept.
) (after damaging victim's vehicle, defendant called police station, identifying herself as victim, informing them that she did not want to press charges);
People v. Nawrocki,
A.D. d
( th Dept.
) (defendant used his brother's name, Social Security number and employment status to apply for and receive
a loan from a finance company); People v. Chive,
Misc. d
,(
) (conviction for falsely identifying oneself to police and possession of an altered passport);
People v. Bentley,
Misc. d
(
) (woman signed a false name to a supermarket cash register receipt); People v. Diamond,
Misc. d
,(
) (conviction for seeking to avoid an arrest by impersonating a transit authority conductor).
The Appellate Division cited People v. Kase,
A.D. d
( st Dept.
), in support of its holding that “injure” and “defraud” are not limited to tangible harms
such as financial harms involved in the filing of a false instrument. There, Kase
argued that Penal Law §
. did not apply where the People had not demonstrated that there had been a pecuniary loss to the State, and the court disagreed,
4
4
240
241
finding that it is sufficient if the fraud impacts the State's power to fulfill its governmental responsibilities.
Here, defendant did not cause any pecuniary loss or interfere with governmental operations. While we agree with defendant that the statutory terms “injure”
and “benefit” cannot be construed to apply to any injury or benefit, no matter how
slight, we conclude that injury to reputation is within the “injury” contemplated by
Penal Law §
. . Many people, particularly with a career in academia, as relevant to this case, value their reputations at least as much as their property, and we
believe the legislature intended that the scope of the statute be broad enough to
capture acts intended to cause injury to reputation. …
Accordingly, a person may be found guilty of criminal impersonation in the
second degree if he or she impersonates another with the intent to cause a tangible, pecuniary injury to another, or the intent to interfere with governmental operations. In addition, a person who impersonates someone with the intent to harm
the reputation of another may be found guilty of this crime. Here, there was sufficient evidence to support the jury's finding that defendant's emails impersonating
Schiffman, Seidel and Cross were more than a prank intended to cause temporary
embarrassment or discomfiture, and that he acted with intent to do real harm. …
GOLB V. ATTORNEY GENERAL OF THE STATE OF NEW YORK [GOLB II]
870 F.3d 89 (2d. Cir. 2017)
5
6
9
1
7
8
2
8
3
5
2
0
9
[Golb brought a habeas corpus action in federal court seeking relief from his state
conviction.] Golb makes three arguments as to why his surviving convictions must
be vacated. …
U.S. ,(
), ar• Golb invokes Shuttlesworth v. City of Birmingham,
guing that his impersonation convictions must be vacated if the jury might
have relied on the impermissibly overbroad literal terms of the statute that
the Court of Appeals subsequently narrowed. …
• Second, Golb argues that the criminal impersonation statute is facially unconstitutional. …
A. The Shuttlesworth Claim …
. Five counts are based on emails sent under the name Lawrence Schiffman. In
these emails, Golb-as-Schiffman confessed to plagiarism and misrepresentation,
and asked recipients, including a student newspaper, to supress the facts of his
misdeeds in order to protect him. These emails were clearly sent with the intent to
damage Schiffman's reputation. Indeed, Golb sent the Schiffman emails at the
same time that he emailed NYU administrators from a separate pseudonymous
account requesting that they investigate the possible plagiarism—with the result
that those administrators pursued the allegations of misconduct. As Golb acknowledged during his trial, plagiarism “is one of the more serious forms of unethical conduct anybody can engage in in the academic world.” The only alternate
theory Golb puts forward is that the jury might have convicted on the theory that
he simply intended to embarrass Schiffman; but that is too implausible to require
a grant of habeas relief. …
. Two counts are based on emails sent under the name Jonathan Seidel, disparaging Golb's father. (The emails refer to Norman Golb and his views as “filth.”)
The defendant's intent in sending these emails is obscure: Golb–as–Seidel sent
other emails seemingly relying on Seidel's good repute. We therefore lack sufficient confidence that the jury convicted based on the narrower meaning of
1
2
1
Chapter 4: Privacy
Internet Law
“injure,” as opposed to a mere desire to antagonize. The district court granted the
habeas petition as to these convictions, and we affirm its judgment.
. A single count is based on an email that Golb sent under the name Jonathan
Seidel to the Royal Ontario Museum's Board of Trustees. The email asked whether
the Museum intended to have Golb's father lecture at an exhibit about the Scrolls.
The district court upheld this conviction on the theory that Golb intended to get a
benefit – a speaking role for his father – rather than that Golb intended to injure.
That is possible, but the email also attacks various individuals in a way likely to
cause consternation, rather than any tangible, pecuniary, or reputational impact.
The jury may well have impermissibly convicted Golb on this count under the theory that he intended to cause annoyance rather than a culpable injury. We therefore reverse the judgment of the district court and grant the habeas petition as to
this conviction. …
. A single count is based on an email Golb sent under the name “Frank Cross”
which said that “Bart has gone and put his foot in his mouth again.” The district
court upheld this conviction on the theory that it was intended to hurt Professor
Bart Ehrman's reputation. But the email is so mild and puerile that it might have
been intended to embarrass Ehrman without actual injury to his reputation, and
at no point in the trial did the prosecutors argue that it was intended to hurt
Ehrman. In light of our substantial concern that the jury impermissibly convicted
Golb on this count based on the overbroad interpretation of injure, we therefore
reverse the judgment of the district court and grant the habeas petition as to this
conviction.
B. Golb’s Facial Challenge to the Criminal Impersonation Statute …
Golb implicitly concedes that the criminal impersonation statute constitutionally
criminalizes some core conduct; there is no doubt that the state may properly forbid (for example) impersonating a pawnshop customer in order to redeem an object of value. But he argues that there are categories that the statute improperly
criminalizes: in particular, some types of satire and parody. …
The First Amendment protects parody, see Hustler Magazine, Inc. v. Falwell,
U.S.
(
), but Golb misunderstands the genre. While it is true that a
parody enjoys First Amendment protection notwithstanding that not everybody
will get the joke, it is also true that parody depends on somebody getting the joke;
parody succeeds only by its recognition as parody. An author who intends to fool
everyone may be pulling a prank or perpetrating a hoax, but the result is not a
parody. Parody thus differs from “impersonat[ion]” as the term is used in the
criminal impersonation statute. …
8
8
9
1
6
4
5
QUESTIONS
. Identity Theft Online: Is it easier to commit identity theft online or offline?
. Overbreadth: The First Amendment creates drafting challenges for legislatures? A narrow statute will miss some unprotected speech, but a broad
statute will sweep in some protected speech. Have the courts here done a
good job of ensuring that Golb and others like him are punished when – and
only when – the First Amendment allows?
. Platform Policies: Twitter’s parody, newsfeed, commentary, and fan account
policy requires that such an account’s bio must “clearly indicate that the user
is not affiliated with the subject of the account” and its name “should not be
the exact name as the subject of the account without some other distinguish-
8
4
4
3
3
2
1
242
243
ing word such as (but not limited to) ‘not,’ ‘fake,’ or ‘fan.’” Does this go further
than New York’s impersonation law? Not as far?
. Deepfakes: A deepfake is a computer-generated image, audio, or video of an
actual person saying or doing something they did not actually do. (The name
comes from the “deep neural networks” usually used to create them.) Some
deepfakes are uncannily convincing. What kinds of havoc could deepfakes
cause? Are they primarily an impersonation issue, or something else?
The following case includes discussion of nonconsensual pornography.
STATE V. AUSTIN
2019 IL 123910
5
3
2
1
1
5
3
2
1
1
5
0
2
7
2
1
0
2
d
n
u
o
r
g
k
c
Neville, Justice:
Defendant Bethany Austin was charged with violating section - . (b) of the
Criminal Code of
(
ILCS / - . (b)), which criminalizes the nonconsensual dissemination of private sexual images. …
I. B
Defendant was engaged to be married to Matthew, after the two had dated for
more than seven years. Defendant and Matthew lived together along with her
three children. Defendant shared an iCloud account with Matthew, and all data
sent to or from Matthew’s iPhone went to their shared iCloud account, which was
connected to defendant’s iPad. As a result, all text messages sent by or to
Matthew’s iPhone automatically were received on defendant’s iPad. Matthew was
aware of this data sharing arrangement but took no action to disable it.
While Matthew and defendant were engaged and living together, text messages
between Matthew and the victim, who was a neighbor, appeared on defendant’s
iPad. Some of the text messages included nude photographs of the victim. Both
Matthew and the victim were aware that defendant had received the pictures and
text messages on her iPad. Three days later, Matthew and the victim again exchanged several text messages. The victim inquired, “Is this where you don’t want
to message [because] of her?” Matthew responded, “no, I’m fine. [S]omeone
wants to sit and just keep watching want [sic] I’m doing I really do not care. I
don’t know why someone would wanna put themselves through that.” The victim
replied by texting, “I don’t either. Soooooo baby ….”
Defendant and Matthew cancelled their wedding plans and subsequently broke
up. Thereafter, Matthew began telling family and friends that their relationship
had ended because defendant was crazy and no longer cooked or did household
chores.
In response, defendant wrote a letter detailing her version of events. As support, she attached to the letter four of the naked pictures of the victim and copies
of the text messages between the victim and Matthew. When Matthew’s cousin
received the letter along with the text messages and pictures, he informed
Matthew.
Upon learning of the letter and its enclosures, Matthew contacted the police.
The victim was interviewed during the ensuing investigation and stated that the
pictures were private and only intended for Matthew to see. The victim acknowledged that she was aware that Matthew had shared an iCloud account with defendant, but she thought it had been deactivated when she sent him the nude photographs.
a
4
Chapter 4: Privacy
Internet Law
5
0
9
4
3
0
0
0
0
1
9
4
7
8
1
1
0
0
2
5
2
1
1
0
7
6
2
3
3
0
8
6
3
2
4
3
1
7
3
4
1
5
2
2
7
1
4
2
5
s
3
i
2
s
1
y
4
l
1
1
9
0
6
a
0
n
2
5
6
Defendant was charged by indictment with one count of nonconsensual dissemination of private sexual images. …
II. A
…
A. The Necessity for the Law
Section - . addresses the problem of nonconsensual dissemination of private
sexual images, which is colloquially referred to as "revenge porn." Generally, the
crime involves images originally obtained without consent, such as by use of hidden cameras or victim coercion, and images originally obtained with consent, usually within the context of a private or confidential relationship. Once obtained,
these images are subsequently distributed without consent. Danielle Keats Citron
& Mary Anne Franks, Criminalizing Revenge Porn,
Wake Forest L. Rev.
,
(
); see Adrienne N. Kitchen, The Need to Criminalize Revenge Porn: How
a Law Protecting Victims Can Avoid Running Afoul of the First Amendment,
Chi.-Kent L. Rev.
,
- (
).
The colloquial term “revenge porn” obscures the gist of the crime:
“In essence, the crux of the definition of revenge porn lies in the fact
that the victim did not consent to its distribution—though the victim
may have consented to its recording or may have taken the photo or
video themselves. As a result, the rise of revenge porn has (unsurprisingly) gone hand-in-hand with the increasing use of social media and
the Internet, on which people constantly exchange ideas and images
without asking permission from the originator.” Christian Nisttáhuz,
Fifty States of Gray: A Comparative Analysis of ‘Revenge-Porn’’Legislation Throughout the United States and Texas’s Relationship Privacy
Act,
Tex. Tech. L. Rev.
,
(
).
Indeed, the term “revenge porn,” though commonly used, is misleading in two respects. First, “revenge” connotes personal vengeance. However, perpetrators may
be motivated by a desire for profit, notoriety, entertainment, or for no specific reason at all. The only common factor is that they act without the consent of the person depicted. Second, “porn” misleadingly suggests that visual depictions of nudity
or sexual activity are inherently pornographic. …
This is a unique crime fueled by technology:
“We do not live in a world where thousands of websites are devoted to
revealing private medical records, credit card numbers, or even love
letters. By contrast, ‘revenge porn’ is featured in as many as ,
websites, in addition to being distributed without consent through
social media, blogs, emails, and texts. There is a demand for private
nude photos that is unlike the demand for any other form of private
information. While nonconsensual pornography is not a new phenomenon, its prevalence, reach, and impact have increased in recent
years in part because technology and social media make it possible to
‘crowdsource’ abuse, as well as make it possible for unscrupulous individuals to profit from it. Dedicated ‘revenge porn’ sites and other forums openly solicit private intimate images and expose them to millions of viewers, while allowing the posters themselves to hide in the
shadows.” Franks, “Revenge Porn” Reform: A View from the Front
Lines,
Fla. L. Rev.
,
- (
).
Consent is contextual. “The consent to create and send a photo or the consent to
be photographed by another is one act of consent that cannot be equated with
4
3
244
245
0
4
5
6
1
3
0
2
2
1
1
0
1
9
0
1
1
0
3
1
4
9
1
5
0
5
9
2
8
3
1
6
2
5
0
1
8
6
1
1
5
5
2
0
1
2
9
1
3
5
9
1
5
3
3
2
2
1
1
5
1
3
2
0
consenting to distribute that photo to others outside of the private relationship… .”
Erica Souza, “For His Eyes Only”: Why Federal Legislation Is Needed to Combat
Revenge Porn,
UCLA Women’s L.J.
,
- (
). Accordingly, criminal
liability here does not depend on “whether the image was initially obtained with
the subject’s consent; rather, it is the absence of consent to the image’s distribution
that renders the perpetrator in violation of the law.” Ava Schein, Note, When Sharing Is Not Caring: Creating an Effective Criminal Framework Free From Specific
Intent Provisions to Better Achieve Justice for Victims of Revenge Pornography,
Cardozo L. Rev.
,
- (
). The nonconsensual dissemination of private sexual images “is not wrong because nudity is shameful or because the act of
recording sexual activity is inherently immoral. It is wrong because exposing a
person’s body against her will fundamentally deprives that person of her right to
privacy.” Franks, supra, at
.…
The overwhelming majority of state legislatures have enacted laws criminalizing the nonconsensual dissemination of private sexual images. …
B. The General Assembly’s Solution
Against this historical and societal backdrop, we consider the terms of the statutory provision at issue. Section - . (b) provides as follows:
(b) A person commits non-consensual dissemination of private sexual images
when he or she:
( ) intentionally disseminates an image of another person:
(A) who is at least years of age; and
(B) who is identifiable from the image itself or information displayed in connection with the image; and
(C) who is engaged in a sexual act or whose intimate parts are exposed, in whole or in part; and
( ) obtains the image under circumstances in which a reasonable person
would know or understand that the image was to remain private; and
( ) knows or should have known that the person in the image has not
consented to the dissemination.
ILCS / - . (b). …
D. First Amendment …
. No Categorical Exception …
We acknowledge, as did the Vermont Supreme Court, that the nonconsensual dissemination of private sexual images “seems to be a strong candidate for categorical
exclusion from full First Amendment protections” based on “[t]he broad development across the country of invasion of privacy torts, and the longstanding historical pedigree of laws protecting the privacy of nonpublic figures with respect to
matters of only private interest without any established First Amendment limitations.” State v. VanBuren,
VT , ¶ . However, we decline to identify a new
categorical first amendment exception when the United States Supreme Court has
not yet addressed the question. …
. Degree of Scrutiny …
In contrast to content-based speech restrictions, regulations that are unrelated to
the content of speech are subject to an intermediate level of scrutiny because in
most cases they pose a less substantial risk of excising certain ideas or viewpoints
from the public dialogue. We conclude that section - . (b) is subject to an in-
2
7
1
2
Chapter 4: Privacy
Internet Law
termediate level of scrutiny for two independent reasons. First, the statute is a
content-neutral time, place, and manner restriction. Second, the statute regulates
a purely private matter.
a. Time, Place, and Manner …
We recognize that section - . (b) on its face targets the dissemination of a specific category of speech—sexual images. However, the statute is content neutral. A
regulation that serves purposes unrelated to the content of expression is deemed
neutral, even if it has an incidental effect on some speakers or messages but not
others. …
In the case at bar, section - . (b) is justified on the grounds of protecting
privacy. Section - . (b) distinguishes the dissemination of a sexual image not
based on the content of the image itself but, rather, based on whether the disseminator obtained the image under circumstances in which a reasonable person
would know that the image was to remain private and knows or should have
known that the person in the image has not consented to the dissemination. There
is no criminal liability for the dissemination of the very same image obtained and
distributed with consent. The manner of the image’s acquisition and publication,
and not its content, is thus crucial to the illegality of its dissemination. …
Viewed as a privacy regulation, section - . is similar to laws prohibiting the
unauthorized disclosure of other forms of private information, such as medical
records (
ILCS
/ (d) (West
)), biometric data (
ILCS / (West
)), or Social Security numbers ( ILCS
/ (West
)). The entire field
of privacy law is based on the recognition that some types of information are more
sensitive than others, the disclosure of which can and should be regulated. To invalidate section - . would cast doubt on the constitutionality of these and other statutes that protect the privacy rights of Illinois residents. …
b. Purely Private Matter …
5
1
4
1
6
0
1
4
7
0
2
0
1
9
5
7
1
3
2
1
1
1
1
6
1
0
5
2
0
2
3
5
5
5
3
4
3
2
2
3
1
4
1
1
4
1
3
5
5
3
0
3
2
5
2
2
6
1
5
1
1
1
0
1
4
6
1
Speech on matters of public concern lies at the heart of first amendment protection. However, first amendment protections are less rigorous where matters of
purely private significance are at issue …
The Supreme Court has articulated some guiding factors:
“Speech deals with matters of public concern when it can be fairly
considered as relating to any matter of political, social, or other concern to the community, or when it is a subject of legitimate news interest; that is, a subject of general interest and of value and concern to
the public. The arguably inappropriate or controversial character of a
statement is irrelevant to the question whether it deals with a matter
of public concern.”
Snyder v. Phelps,
U.S.
,
(
). …
Applying these principles to the instant case, we have no difficulty in concluding that the nonconsensual dissemination of the victim’s private sexual images was
not an issue of public concern. Matthew was telling his and defendant’s families
and friends that it was defendant’s fault that their relationship ended. Defendant
responded with a letter, in which she explained her version of events. To this letter
defendant attached the victim’s private sexual images along with text messages
between the victim and Matthew. The victim’s private sexual images, in context
with her and Matthew’s text messages, were never in the public domain. They do
not relate to any broad issue of interest to society at large. The message they con-
0
2
246
247
5
3
2
1
1
5
3
2
1
1
%
0
vey is not a matter of public import. Cf. id. (holding that messages on protest signs
at a private funeral related to broad issues of interest to society at large and were
matters of public import). Rather, the public has no legitimate interest in the private sexual activities of the victim or in the embarrassing facts revealed about her
life. …
. Applying Intermediate Scrutiny …
Generally, to survive intermediate scrutiny, the law must serve an important or
substantial governmental interest unrelated to the suppression of free speech and
must not burden substantially more speech than necessary to further that interest
or, in other words, must be narrowly tailored to serve that interest without unnecessarily interfering with first amendment freedoms, which include allowing reasonable alternative avenues of communication. …
[Governmental interest] In the case at bar, we conclude that section - .
serves a substantial government interest. [The court summarized the development
of privacy laws, especially the tort of public disclosure of private facts.] …
Specifically, the nonconsensual dissemination of private sexual images causes
unique and significant harm to victims in several respects. Initially, this crime can
engender domestic violence. Perpetrators threaten disclosure to prevent victims
from ending relationships, reporting abuse, or obtaining custody of children. Sex
traffickers and pimps threaten disclosure to trap unwilling individuals in the sex
trade. Rapists record their sexual assaults to humiliate victims and deter them
from reporting the attacks.
Also, the victims’ private sexual images are disseminated with or in the context
of identifying information. Victims are frequently harassed, solicited for sex, and
even threatened with sexual assault and are fired from their jobs and lose future
employment opportunities. Victims additionally suffer profound psychological
harm. Victims often experience feelings of low self-esteem or worthlessness, anger,
paranoia, depression, isolation, and thoughts of suicide.
Additionally, the nonconsensual dissemination of sexual images disproportionately affects women, who constitute
of the victims, while men are most commonly the perpetrators and consumers ….
[Least restrictive means] In contending that the statute fails strict scrutiny,
defendant argues that a penal statute is not the least restrictive means to accomplish the alleged compelling government interest. …
We conclude that the substantial government interest of protecting Illinois residents from nonconsensual dissemination of private sexual images would be
achieved less effectively absent section - . . …
Civil actions are inadequate. …
“Civil suits based on privacy violations are problematic. Most victims
want the offensive material removed and civil suits almost never succeed in removing the images due to the sheer magnitude of dissemination. Highly publicized trials often end in re-victimization. Civil
litigation is expensive and time-consuming, and many victims simply
cannot afford it. It is difficult to identify and prove who the perpetrator is for legal proceedings because it is so easy to anonymously post
and distribute revenge porn. Even when victims can prove who the
perpetrator is in court and win money damages, many defendants are
judgment-proof so victims cannot collect. …
Further, a court order requiring a defendant or website to remove
the images would fail to remove the images from the web entirely,
9
3
Chapter 4: Privacy
Internet Law
8
1
6
1
1
0
2
5
6
1
3
3
0
2
2
1
1
5
1
5
3
3
2
2
5
1
1
1
1
3
2
5
1
1
3
1
5
5
3
2
0
1
2
5
1
7
2
5
1
3
2
1
5
1
3
5
2
2
1
1
1
5
5
3
3
2
2
0
1
2
particularly as they appear on numerous sites. Because most
perpetrators are judgment-proof, and injunctive relief may be difficult
to obtain and would ultimately fail to remove the images, civil suits
are poor remedies. As perpetrators frequently have nothing to lose,
which is why they engage in this behavior in the first place, civil suits
do not deter revenge porn.”
Kitchen, supra, at
- .…
[Burdening more speech than necessary] We next consider whether section
- . burdens substantially more speech than necessary. …
Subsection (b) is narrowly tailored in several respects so as not to burden more
speech than necessary. First, the images must be “private sexual images” that portray any of several specific features, including the depiction of a person whose intimate parts are exposed or visible, in whole or in part, or who is engaged in a sexual act as defined in the statute. Id. § - . (a), (b)( )(C). Therefore, the scope of
the statute is restricted to images that can fairly be characterized as being of a discreet and personal nature. …
Second, the person portrayed in the image must be over the age of
and identifiable from the image or information displayed in connection with the image.
ILCS / - . (b)( )(A)-(B) (West
). The statute is inapplicable if the
image does not contain sufficient information to identify the person depicted.
Therefore, section - . (b) burdens only speech that targets a specific person.
Third, the image must have been obtained under circumstances in which a reasonable person would know or understand that it was to remain private. Id. §
- . (b)( ). We construe this provision as requiring a reasonable awareness that
privacy is intended by the person depicted. This requirement limits the statute’s
application to the types of personal, direct interactions or communications that
are typically involved in a close or intimate relationship. Thus, this provision ensures that the statute is inapplicable if the image was obtained under circumstances where disclosure to another is a natural and expected outcome.
Fourth, the person who disseminates such an image must have known or
should have known that the person portrayed in the image has not consented to
the dissemination.
ILCS / - . (b)( ) (West
). The lack of consent to
dissemination forms the core of the statute and its protective purpose. As with the
expectation of privacy discussed above, we construe this provision to incorporate a
reasonable awareness of the lack of consent to dissemination. Where the person
portrayed in the image has consented to its disclosure, the statute simply does not
apply and poses no restriction on the distribution of the image to others.
Fifth, the statute specifically requires that the dissemination of private sexual
images be intentional. Id. § - . (b)( ). Therefore, the probability that a person
will inadvertently violate section - . (b) while engaging in otherwise protected
speech is minimal.
Section - . also includes several specific exemptions. Subsection (c) provides as follows:
(c) The following activities are exempt from the provisions of this Section:
( ) The intentional dissemination of an image of another identifiable person who is engaged in a sexual act or whose intimate parts are exposed when the dissemination is for the purpose of a criminal investigation that is otherwise lawful.
1
1
7
1
248
Chapter 4: Privacy
249
3
5
5
3
2
3
2
1
5
1
1
1
3
2
1
1
6
2
3
1
5
3
5
2
5
3
1
2
1
3
1
2
1
5
1
3
1
5
2
3
4
3
2
1
2
1
1
1
( ) The intentional dissemination of an image of another identifiable person who is engaged in a sexual act or whose intimate parts are exposed when the dissemination is made for the purpose of, or in connection with, the reporting of unlawful conduct.
( ) The intentional dissemination of an image of another identifiable person who is engaged in a sexual act or whose intimate parts are exposed when the images involve voluntary exposure in public or commercial settings.
( ) The intentional dissemination of an image of another identifiable person who is engaged in a sexual act or whose intimate parts are exposed when the dissemination serves a lawful public purpose.
Id. § - . (c).
These exemptions shield from criminal liability any dissemination of a private
sexual image that advances the collective goals of ensuring a well-ordered system
of justice and protecting society as a whole. In addition, subsection (c)( ) recognizes that public disclosure has been sanctioned based on the very nature of such
an image. Finally, the statute does not apply to electronic communication companies that provide access to the Internet, public mobile services, or private radio
services. Id. § - . (d).
Based on the statutory terms set forth above, section - . is narrowly tailored to further the important governmental interest identified by the legislature.
Accordingly, we conclude the statute does not burden substantially more speech
than necessary.
Also, we observe that reasonable avenues of communication remain. Under
section - . , “[p]eople remain free to produce, distribute, and consume a vast
array of consensually disclosed sexually explicit images. Moreover, they remain
free to criticize or complain about fellow citizens in ways that do not violate the
privacy rights of others.” Franks, supra, at
. …
In this case, defendant makes no argument that her speech would have been in
any way stifled by not attaching the victim’s private sexual images to her letter. We
hold that section - . satisfies intermediate scrutiny.
E. First Amendment Overbreadth …
As support of its overbreadth determination, the circuit court posited several hypothetical scenarios as examples of circumstances in which the statute would impermissibly restrict protected speech. …
We … reject the circuit court’s suggestion that section - . (b) would impose
criminal liability on a person who discovers and shares with other family members
nude sketches of his or her grandmother that were created by his or her grandfather but were discovered in an attic after her death. … Obviously, the statute is intended to protect living victims from the invasion of privacy and the potential
threat to health and safety that is intrinsic in the disclosure of a private sexual image. … In light of the fact that a deceased person cannot suffer the types of injuries
that section - . (b) is intended to safeguard against, the statute does not apply
to the hypothetical situation suggested by the circuit court.
The circuit court also questioned whether section - . (b) would criminalize
the sharing of nude sketches of a person’s grandmother if his or her grandfather
had been an artist such as Andrew Wyeth, who created the “Helga Pictures” that
remained secret for many years, or Pablo Picasso. … Given that a model who poses
for an artist is aware of that person’s profession, it will generally be understood
Internet Law
that the sketch or painting may be displayed to others at some point in time. In
such a circumstance, the statute would not apply because a reasonable person
would not know or understand that the image was to remain private. The same is
true of the circuit court’s reference to images published in Playboy Magazine and
in movies or programs depicting nudity. The people portrayed in such images have
clearly consented to public disclosure and dissemination. Indeed, that is the whole
point of appearing in such a photograph or film. …
The circuit court further observed that section - . (b) does not expressly
require a showing of any specific harm to the victim. … [W]e believe that the
unauthorized dissemination of a private sexual image, which by definition must
depict a person while nude, seminude, or engaged in sexually explicit activity, is
presumptively harmful.
In evaluating the competing social costs at stake, we have held that Illinois has
a substantial governmental interest in protecting the privacy of persons who have
not consented to the dissemination of their private sexual images. Although defendant claims that section - . (b) will deter the free speech of persons who
have legally and unconditionally obtained the private sexual images of others, her
assertion is unpersuasive given the limited application of the statute and the fact
that any possible overbreadth is minor when considered in light of the statute’s
legitimate sweep. Defendant also contends that section - . “criminalizes an
adult complainant’s own stupidity at the expense of the [f]irst [a]mendent.” Yet
this argument entirely disregards the victim’s first amendment right to engage in a
personal and private communication that includes a private sexual image. Defendant’s crude attempt to “blame the victim” is not well received and reinforces the
need for criminalization. Accordingly, defendant has not established that, on balance, the social costs weigh in her favor or that the marginal restraint on constitutionally protected speech is greater than necessary to advance the governmental
interest at stake. …
QUESTIONS
. Special-Purpose Laws: Do you agree that there is a need for criminal statutes
specifically directed at nonconsensual distribution of intimate images?
Could Austin or Matthew have been prosecuted or sued for copyright infringement? For intentional infliction of emotional distress? Wiretapping?
Public disclosure of private facts?
. Doctrinal Inflexibility: Count the number of different First Amendment doctrines discussed by the court. Why is it so challenging to analyze the Illinois
statute in terms of established caselaw?
E. Consumer Privacy
Our next topic is the personal privacy issues that arise out of ordinary web use.
What do websites know about you, what can they do with that information, and
what information do you expose about yourself to the world?
5
3
2
1
1
5
3
2
1
1
5
3
2
1
NOTE ON COOKIES
HTTP, the protocol on which the web runs, is stateless. Every request to a server
for a web page is independent of every other request. This property makes it easier
to implement simple web servers and create basic web pages, because the web
1
2
1
250
Chapter 4: Privacy
251
3
3
0
1
5
3
0
1
server’s job is just to find the HTML document the client asked for, and transmit it
back to the client. And this is fine for simple static pages that don’t change much,
like a restaurant’s menu.
But a purely stateless protocol doesn’t work for dynamic websites that need to
be heavily customized for different users. Imagine an outdoor-gear store called
Great Outdoors, at greatoutdoors.com. If you add a rain jacket to your Great Outdoors shopping cart, the site needs to remember that the jacket is still in your cart
as you browse for boots. But with a stateless protocol, every request looks like
every other request to the Great Outdoors server. It has no way of telling that the
GET /section/boots request at
: came from the same user that made the
POST /addtocart?item=31568 request at
: . To connect them up, it needs a
way to associate multiple requests with a single user’s browser.
The technology that does this connecting is the cookie. When the Great Outdoors server sends a webpage to your browser, it also sends along a small chunk of
data called a cookie. In its simplest form, the cookie is simply a random string of
numbers and letters, like O4AkSCJ8xLW45. Your browser stores the cookie and associates it with greatoutdoors.com. From now on, whenever the browser visits
greatoutdoors.com, it also sends along the cookie, in effect saying “It’s me! I’m user
O4AkSCJ8xLW45, and I’m back.” When it sees this cookie, the Great Outdoors
server looks up user O4AkSCJ8xLW45 and sees that you already have the rain jacket
in your shopping cart. Thus, it customizes the contents of the page it sends back to
show that the jacket is in your cart.
Cookies are typically unique for each user. My Great Outdoors cookie is
AJi4QfG9lWhbB, which means that my shopping cart won’t show your jacket, and
yours won’t show my backpack. Cookies are also unique for each website. The
server at greatoutdoors.com can only see the cookies it itself set; it cannot see the
cookies set by sportsball.com or by todaystopnews.com. This is an important feature
of web security; it prevents malicious sites from spying on users’ activity on other
sites.
Cookies play an essential role in giving users a dynamic and personalized web
experience. E-commerce sites use them to store shopping carts and wishlists; social-media sites use them to give each user a personalized feed of content from
their friends. Web sites use cookies invisibly to generate site analytics: what pages
do users click on from the home page, and how many jackets do they look at before adding one to their carts? The cookie allows the site to organize the vast
haystack of GET requests for pages into individual activity trails for particular
users.
These detailed transcripts of user activity help designers create better interfaces
and promote content that users care more about. They are also used for behavioral profiling: identifying particular users’ interests by observing what they click
on. This is how Facebook decides what stories to put in your News Feed, and how
YouTube decides what video to play next. Based on your history of interactions
with the site, they know that you like first-person shooter games but not real-time
strategy games, and Beyoncé but not Rihanna. The cookie is the essential link tying all of a user’s activity together.
In addition to content recommendation, behavioral profiling is also used extensively for targeted advertising. Some of the targeting is done by advertisers. Facebook has tools that let advertisers select highly specific groups of users like “People
in New Jersey who have expressed an interest in historical romance novels,” and
Facebook then shows their ads to users whose behavioral profiles match the adver-
2
1
252
Internet Law
tiser’s selections. And some of the targeting is done by websites themselves. Based
on your on-site activity, their algorithms pick the ads you are most likely to click
on.
From an advertiser’s perspective, the best behavioral profiles would be all-encompassing: they would learn about your interests from everything you do online,
on every website. But this is where the cookie security model creates difficulties.
Because websites cannot see each others’ cookies, the kinds of “first-party” cookies
set by greatoutdoors.com. cannot be linked to your activity on other sites like sportsball.com. But the demand from advertisers for these comprehensive profiles is so
great, that they have found ways around this obstacle.
One technique is to “link” a user’s activity on different sites by determining that
the user with cookie JCPi1nrJY33ig on greatoutdoors.com is the same person as
the user with cookie BQp54ioZ0tZ on sportsball.com. Great Outdoors might contract with a data broker: a company that maintains profiles of user data. Great
Outdoors shares some of the information it has on its users with UserXChange, a
(hypothetical) data broker. UserXChange correlates that data with its own profiles
and realizes that JCPi1nrJY33ig is Jane Q. User, who follows women’s soccer
scores on SportsBall. It passes this fact back to Great Outdoors, which can then
suggest exercise gear to her in its “Recommended for You” section. This kind of
linking requires collaboration by the websites which have agreed to share data
with a data broker (and indirectly with each other). Because it happens on the
back end, in exchanges between servers, it is invisible to users.
Another technique is to use third-party cookies, which can effectively follow a
user from site to site. Great Outdoors adds to the HTML for each of the pages on
its site instructions to insert a tiny, effectively invisible, one-pixel by one-pixel image. Crucially, this image does not come from the greatoutdoors.com server. Instead,
the user’s browser requests the image from a third-party server, say bigadtracker.com. When this server sends back the image, it also sets a cookie. Because this
cookie is associated with bigadtracker.com rather than with greatoutdoors.com, it can
be read on any other requests to bigadtracker.com – like on the tracking pixel on
every other Great Oudoors page, and on SportsBall, and Today’s Top News. Thus,
the server at bigadtracker.com knows that it is the same user visiting all three sites,
because it sees the same cookie.
Why would a website do this? One reason is that it can receive valuable analytics data, precisely because BigAdTracker observes users’ activity all over the web.
Another is that it enables targeted advertising. Instead of a tiny invisible tracking
pixel, BigAdTracker could show a big and very visible ad — and that ad could be
chosen to match what BigAdTracker knows about the user’s interests based on
their behavioral profile. Large advertising networks have massive databases of
user profiles and even conduct real-time auctions, in which advertisers automatically bid against each other to show their ad in a given slot.
QUESTIONS
. Harms: For years, behavioral advertising networks have maintained that they
offer consumers a useful service. What service is that? How useful do you
find it? How would the Web change if third-party tracking cookies were
banned tomorrow? Which forms of web advertising do you find most annoying? Creepiest? Which, if any, would you prohibit?
. Opt-Outs: Advertising networks typically offer users an opt-out from their
cookie tracking. For example, The Digital Advertising Alliance provides an
253
opt-out-form for its member companies at https://optout.aboutads.info/. The
fraction of Internet users who have opted out it is infinitesimal. Why might
that be? Does the fact that most users haven’t opted out indicate that they
don’t care about privacy? Would an opt-in system be better?
. Wiretapping? The first wave of anti-tracking lawsuits claimed that the use of
third-party cookies by itself violated communications privacy laws like
Wiretap Act and the Stored Communication Act. These lawsuits almost uniformly failed. Why might that be? Are the harms to users from tracking
cookies harms of the sort these laws were intended to prevent?
EICHENBERGER V. ESPN, INC.
876 F.3d 979 (9th Cir. 2017)
1
1
0
1
7
2
8
8
1
y
8
r
9
1
o
t
2
s
i
l
a
r
u
d
e
c
o
r
d
n
n
a
o
i
l
s
a
s
u
u
t
c
c
s
i
Graber, Circuit Judge:
Plaintiff Chad Eichenberger alleges that Defendant ESPN, Inc. violated the
Video Privacy Protection Act of
(“VPPA”), which bars a “video tape service
provider” from knowingly disclosing “personally identifiable information concerning any consumer of such provider.” U.S.C. §
(b)( ). …
F
P
H
…
Defendant produces sports-related news and entertainment programming.
Though best known for its television channel, Defendant also offers access to video
content through an application called the “WatchESPN Channel,” which is available on the Roku digital streaming device. Roku allows users to view videos and
other content on their televisions by means of Internet streaming.
Plaintiff downloaded the WatchESPN Channel on his Roku device and used it
to watch sports-related news and events. He did not consent to Defendant's sharing his information with a third party. But every time Plaintiff watched a video,
Defendant knowingly disclosed to a third party, Adobe Analytics: ( ) Plaintiff 's
Roku device serial number and ( ) the identity of the video that he watched.
Adobe uses the information obtained from Defendant to identify specific consumers by connecting that information “with existing data already in Adobe's profile of th[ose] individual[s].” Adobe obtains the additional information—such as
“email addresses, account information, or Facebook profile information, including
photos and usernames”—from sources other than Defendant. Adobe gives the resulting data back to Defendant in an aggregated form; Defendant in turn provides
advertisers with aggregated information about its users’ demographics.
In this action, Plaintiff alleges that Adobe used the foregoing process to identify
him as having watched specific videos. He argues that Defendant disclosed his
“personally identifiable information” by giving Adobe his Roku device serial number and identifying the videos that he watched, because Defendant knew that
Adobe could and would use that information to identify him. The district court
dismissed the action on the ground that the information that Defendant disclosed
did not constitute “personally identifiable information” within the meaning of the
VPPA. …
D
…
B. “Personally Identifiable Information”
The district court dismissed Plaintiff 's claim on the ground that the allegedly disclosed information did not constitute “personally identifiable information” within
the meaning of the VPPA. The VPPA defines “personally identifiable information”
to “include[ ] information which identifies a person as having requested or ob-
a
3
Chapter 4: Privacy
Internet Law
8
1
1
0
1
7
6
8
3
2
4
4
2
8
8
2
4
2
6
3
2
8
1
0
3
2
8
7
2
6
8
8
4
8
8
9
1
3
0
2
8
0
1
3
9
2
3
0
0
1
1
3
7
7
2
2
0
1
7
7
2
2
8
6
1
0
2
6
1
0
8
tained specific video materials or services from a video tape service provider.”
U.S.C. §
(a)( ). We agree with the district court's conclusion.
As an initial matter, “personally identifiable information” must include more
information than that which, by itself, identifies an individual as having watched
certain videos. Instead, “personally identifiable information” covers some information that can be used to identify an individual.
Two reasons support that conclusion, and both flow directly from the VPPA's
text. First, §
(a)( ) uses the open-ended word “includes,” which suggests that
the proffered definition describes only one example of “personally identifiable information.” … Second, Congress used the word “identifiable.”
U.S.C. §
(a)
( ) (emphasis added). …
The question remains, though: Under the VPPA, what information did Congress intend to cover as “capable of ” identifying an individual? Two circuits have
considered that question in similar cases, and each has articulated a different
standard. Yershov v. Gannett Satellite Info. Network, Inc.,
F. d
,
( st
Cir.
); In re Nickelodeon Consumer Privacy Litig.,
F. d
,
( d Cir.
).
In Yershov, the First Circuit held that the term “personally identifiable information” encompasses “information reasonably and foreseeably likely to reveal
which ... videos [a person] has obtained.”
F. d at
(emphasis added). The
court concluded that an iPhone user's GPS coordinates and device identifier fell
within that definition. In a similar case, though, the Third Circuit held that a
unique IP address did not qualify as “personally identifiable information,” because
the term includes only information that “readily permit[s] an ordinary person to
identify a [particular individual as having watched certain videos].” In re Nickelodeon,
F. d at
(emphasis added). We adopt the Third Circuit's “ordinary
person” standard.
The “ordinary person” test better informs video service providers of their obligations under the VPPA. The VPPA protects consumer privacy by directing video
service providers not to do certain things with consumer information. To that end,
U.S.C. §
(b)( ) focuses on what information a video service provider
“knowingly discloses.” In other words, the statute views disclosure from the perspective of the disclosing party. It looks to what information a video service
provider discloses, not to what the recipient of that information decides to do with
it. As a result, “personally identifiable information” must have the same meaning
without regard to its recipient's capabilities. Holding otherwise would make the
lawfulness of a disclosure depend on circumstances outside of a video service
provider’s control. The Third Circuit's “ordinary person” test, by contrast, provides
video service providers with enough guidance to comply with the VPPA's requirements.
The interpretation that we adopt fits most neatly with the regime that the
VPPA's enacting Congress likely had in mind. In
, the Internet had not yet
transformed the way that individuals and companies use consumer data—at least
not to the extent that it has today. Then, the VPPA's instructions were clear. The
manager of a video rental store in Los Angeles understood that if he or she disclosed the name and address of a customer—along with a list of the videos that the
customer had viewed—the recipient of that information could identify the customer. By contrast, it was clear that, if the disclosure were that “a local high school
teacher” had rented a particular movie, the manager would not have violated the
statute. That was so even if one recipient of the information happened to be a re-
3
2
1
254
Chapter 4: Privacy
255
sourceful private investigator who could, with great effort, figure out which of the
hundreds of teachers had rented the video. Plaintiff 's Roku device serial number is
like the information in the latter scenario. It creates a sizable “pool” of possible
viewers—here, Roku users—just as the information in the latter example does—
there, high school teachers.
It is true that today's technology may allow Adobe to identify an individual
from the large pool by using other information—as Plaintiff alleges. But the advent
of the Internet did not change the disclosing-party focus of the statute. And we are
not persuaded that the
Congress intended for the VPPA to cover circumstances so different from the ones that motivated its passage. Therefore, drawing
on the Third Circuit's reasoning, we hold that “personally identifiable information”
means only that information that would readily permit an ordinary person to
identify a specific individual's video-watching behavior.
Applying that definition here, the operative complaint is deficient. Plaintiff
alleges that Defendant disclosed to Adobe: ( ) his Roku device serial number and
( ) the names of the videos that he watched. As Plaintiff concedes, that information cannot identify an individual unless it is combined with other data in Adobe's
possession—data that ESPN never disclosed and apparently never even possessed.
Indeed, according to Plaintiff, Adobe can identify individuals only because it uses a
complex “Visitor Stitching technique” to link an individual's Roku device number
with other identifying information derived from “an enormous amount of information” collected “from a variety of sources.” We conclude that an ordinary person
could not use the information that Defendant allegedly disclosed to identify an
individual. Plaintiff has therefore failed to state a claim under Rule (b)( ). …
QUESTION
Did ESPN realize that Adobe could and would reidentify users? Should it have?
TRANSUNION LLC V. RAMIREZ
594 U.S. 413 (2021)
6
3
2
1
5
8
1
2
3
3
6
1
6
1
0
2
3
1
5
8
4
8
5
8
3
8
1
9
1
1
0
8
4
3
0
3
3
2
3
3
6
8
7
5
2
Justice Kavanaugh delivered the opinion of the Court.
To have Article III standing to sue in federal court, plaintiffs must demonstrate,
among other things, that they suffered a concrete harm. No concrete harm, no
standing. Central to assessing concreteness is whether the asserted harm has a
“close relationship” to a harm traditionally recognized as providing a basis for a
lawsuit in American courts — such as physical harm, monetary harm, or various
intangible harms including (as relevant here) reputational harm. Spokeo, Inc. v.
Robins,
U.S.
,
–
(
).
In this case, a class of ,
individuals sued TransUnion, a credit reporting
agency, in federal court under the Fair Credit Reporting Act. The plaintiffs claimed
that TransUnion failed to use reasonable procedures to ensure the accuracy of
their credit files, as maintained internally by TransUnion. For ,
of the class
members, TransUnion provided misleading credit reports to third-party businesses. We conclude that those ,
class members have demonstrated concrete reputational harm and thus have Article III standing to sue on the reasonable-procedures claim. The internal credit files of the other ,
class members were not
provided to third-party businesses during the relevant time period. We conclude
that those ,
class members have not demonstrated concrete harm and thus
lack Article III standing to sue on the reasonable-procedures claim. …
Internet Law
1
8
6
1
0
2
0
2
1
8
6
1
1
5
0
3
5
3
1
5
1
0
8
0
7
1
0
1
8
3
5
1
6
1
$
2
1
2
7
8
0
6
2
1
0
1
2
1
1
1
1
0
8
1
6
2
8
1
6
7
0
1
4
2
7
8
9
0
1
0
I
In
, Congress passed and President Nixon signed the Fair Credit Reporting
Act.
Stat.
, as amended,
U.S.C. §
et seq. The Act seeks to promote
“fair and accurate credit reporting” and to protect consumer privacy. §
(a). To
achieve those goals, the Act regulates the consumer reporting agencies that compile and disseminate personal information about consumers.
The Act “imposes a host of requirements concerning the creation and use of
consumer reports.” Spokeo,
U.S. at
. Three of the Act's requirements are
relevant to this case. First, the Act requires consumer reporting agencies to “follow
reasonable procedures to assure maximum possible accuracy” in consumer reports. §
e(b). Second, the Act provides that consumer reporting agencies must,
upon request, disclose to the consumer “[a]ll information in the consumer's file at
the time of the request.” §
g(a)( ). Third, the Act compels consumer reporting
agencies to “provide to a consumer, with each written disclosure by the agency to
the consumer,” a “summary of rights” prepared by the Consumer Financial Protection Bureau. §
g(c)( ).
The Act creates a cause of action for consumers to sue and recover damages for
certain violations. The Act provides: “Any person who willfully fails to comply with
any requirement imposed under this subchapter with respect to any consumer is
liable to that consumer” for actual damages or for statutory damages not less than
and not more than ,
, as well as for punitive damages and attorney’s
fees. §
n(a).
TransUnion is one of the “Big Three” credit reporting agencies, along with
Equifax and Experian. As a credit reporting agency, TransUnion compiles personal
and financial information about individual consumers to create consumer reports.
TransUnion then sells those consumer reports for use by entities such as banks,
landlords, and car dealerships that request information about the creditworthiness
of individual consumers.
Beginning in
, TransUnion introduced an add-on product called OFAC
Name Screen Alert. OFAC is the U.S. Treasury Department’s Office of Foreign Assets Control. OFAC maintains a list of “specially designated nationals” who threaten America's national security. Individuals on the OFAC list are terrorists, drug
traffickers, or other serious criminals. It is generally unlawful to transact business
with any person on the list.
C.F.R. pt.
, App. A (
). TransUnion created
the OFAC Name Screen Alert to help businesses avoid transacting with individuals
on OFAC’s list.
When this litigation arose, Name Screen worked in the following way: When a
business opted into the Name Screen service, TransUnion would conduct its ordinary credit check of the consumer, and it would also use third-party software to
compare the consumer's name against the OFAC list. If the consumer's first and
last name matched the first and last name of an individual on OFAC's list, then
TransUnion would place an alert on the credit report indicating that the consumer's name was a “potential match” to a name on the OFAC list. TransUnion did
not compare any data other than first and last names. Unsurprisingly, TransUnion's Name Screen product generated many false positives. Thousands of lawabiding Americans happen to share a first and last name with one of the terrorists,
drug traffickers, or serious criminals on OFAC’s list of specially designated nationals.
Sergio Ramirez learned the hard way that he is one such individual. On February ,
, Ramirez visited a Nissan dealership in Dublin, California, seeking
1
$
256
Chapter 4: Privacy
257
3
0
8
1
7
3
1
8
0
0
2
5
4
7
2
9
6
2
5
8
1
1
8
8
4
6
5
1
2
5
9
9
1
1
6
5
6
1
0
0
6
2
5
0
5
4
5
3
5
0
3
3
2
1
0
4
0
2
5
8
7
5
to buy a Nissan Maxima. Ramirez was accompanied by his wife and his father-inlaw. After Ramirez and his wife selected a color and negotiated a price, the dealership ran a credit check on both Ramirez and his wife. Ramirez’s credit report, produced by TransUnion, contained the following alert: “***OFAC ADVISOR ALERT
- INPUT NAME MATCHES NAME ON THE OFAC DATABASE.” A Nissan
salesman told Ramirez that Nissan would not sell the car to him because his name
was on a “‘terrorist list.’” Ramirez's wife had to purchase the car in her own name.
…
In February
, Ramirez sued TransUnion [on behalf of a class of similarly
situated consumers and, as relevant here] alleged that TransUnion, by using the
Name Screen product, failed to follow reasonable procedures to ensure the accuracy of information in his credit file. See §
e(b). … Ramirez requested statutory
and punitive damages. …
II
The question in this case is whether the ,
class members have Article III
standing as to their three claims. …
A…
Article III confines the federal judicial power to the resolution of “Cases” and
“Controversies.” For there to be a case or controversy under Article III, the plaintiff
must have a personal stake in the case — in other words, standing. To demonstrate
their personal stake, plaintiffs must be able to sufficiently answer the question:
“What's it to you?”
To answer that question in a way sufficient to establish standing, a plaintiff
must show (i) that he suffered an injury in fact that is concrete, particularized, and
actual or imminent; (ii) that the injury was likely caused by the defendant; and
(iii) that the injury would likely be redressed by judicial relief. Lujan v. Defenders
of Wildlife,
U.S.
,
–
(
). If the plaintiff does not claim to have
suffered an injury that the defendant caused and the court can remedy, there is no
case or controversy for the federal court to resolve.
Requiring a plaintiff to demonstrate a concrete and particularized injury
caused by the defendant and redressable by the court ensures that federal courts
decide only “the rights of individuals,” Marbury v. Madison, U.S.
(
), and
that federal courts exercise their proper function in a limited and separated government. Under Article III, federal courts do not adjudicate hypothetical or abstract disputes. Federal courts do not possess a roving commission to publicly
opine on every legal question. Federal courts do not exercise general legal oversight of the Legislative and Executive Branches, or of private entities. And federal
courts do not issue advisory opinions. …
B
The question in this case focuses on the Article III requirement that the plaintiff ’s
injury in fact be “concrete” — that is, “real, and not abstract.” Spokeo, Inc. v.
Robins,
U.S.
,
(
)
What makes a harm concrete for purposes of Article III? As a general matter,
the Court has explained that “history and tradition offer a meaningful guide to the
types of cases that Article III empowers federal courts to consider.” Sprint Communications Co. v. APCC Services, Inc.,
U.S.
,
(
). And with respect to the concrete-harm requirement in particular, this Court's opinion in
Spokeo v. Robins indicated that courts should assess whether the alleged injury to
the plaintiff has a “close relationship” to a harm “traditionally” recognized as pro-
258
Internet Law
6
8
2
7
2
5
6
1
6
4
1
3
6
3
1
2
4
8
3
8
8
7
5
2
3
3
1
4
3
3
5
8
1
6
8
2
9
8
7
5
8
1
1
0
4
2
3
viding a basis for a lawsuit in American courts.
U.S. at
. That inquiry asks
whether plaintiffs have identified a close historical or common-law analogue for
their asserted injury. Spokeo does not require an exact duplicate in American history and tradition. But Spokeo is not an open-ended invitation for federal courts to
loosen Article III based on contemporary, evolving beliefs about what kinds of
suits should be heard in federal courts.
As Spokeo explained, certain harms readily qualify as concrete injuries under
Article III. The most obvious are traditional tangible harms, such as physical
harms and monetary harms. If a defendant has caused physical or monetary injury
to the plaintiff, the plaintiff has suffered a concrete injury in fact under Article III.
Various intangible harms can also be concrete. Chief among them are injuries
with a close relationship to harms traditionally recognized as providing a basis for
lawsuits in American courts. Those include, for example, reputational harms, disclosure of private information, and intrusion upon seclusion. And those traditional
harms may also include harms specified by the Constitution itself [such as
abridgment of free speech or infringement of free exercise of religion].
In determining whether a harm is sufficiently concrete to qualify as an injury in
fact, the Court in Spokeo said that Congress’s views may be “instructive.”
U.S.
at
. Courts must afford due respect to Congress’s decision to impose a statutory
prohibition or obligation on a defendant, and to grant a plaintiff a cause of action
to sue over the defendant's violation of that statutory prohibition or obligation. In
that way, Congress may “elevate to the status of legally cognizable injuries concrete, de facto injuries that were previously inadequate in law.” Id. at
. But even
though “Congress may ‘elevate’ harms that ‘exist’ in the real world before Congress
recognized them to actionable legal status, it may not simply enact an injury into
existence, using its lawmaking power to transform something that is not remotely
harmful into something that is.” Hagy v. Demers & Adams,
F. d
,
( th
Cir.
).
Importantly, this Court has rejected the proposition that “a plaintiff automatically satisfies the injury-in-fact requirement whenever a statute grants a person a
statutory right and purports to authorize that person to sue to vindicate that
right.” Spokeo,
U.S. at
. As the Court emphasized in Spokeo, “Article III
standing requires a concrete injury even in the context of a statutory violation.” Id.
…
For standing purposes, therefore, an important difference exists between (i) a
plaintiff ’s statutory cause of action to sue a defendant over the defendant's violation of federal law, and (ii) a plaintiff ’s suffering concrete harm because of the defendant's violation of federal law. Congress may enact legal prohibitions and obligations. And Congress may create causes of action for plaintiffs to sue defendants
who violate those legal prohibitions or obligations. But under Article III, an injury
in law is not an injury in fact. Only those plaintiffs who have been concretely
harmed by a defendant's statutory violation may sue that private defendant over
that violation in federal court. As then-Judge Barrett succinctly summarized, “Article III grants federal courts the power to redress harms that defendants cause
plaintiffs, not a freewheeling power to hold defendants accountable for legal infractions.” Casillas,
F. d at
.…
III
We now apply those fundamental standing principles to this lawsuit. We must determine whether the ,
class members have standing to sue TransUnion for its
alleged violations of the Fair Credit Reporting Act. The plaintiffs argue that Trans-
259
Union failed to comply with statutory obligations (i) to follow reasonable procedures to ensure the accuracy of credit files so that the files would not include
OFAC alerts labeling the plaintiffs as potential terrorists; and (ii) to provide a consumer, upon request, with his or her complete credit file, including a summary of
rights. …
A…
Assuming that the plaintiffs are correct that TransUnion violated its obligations
under the Fair Credit Reporting Act to use reasonable procedures in internally
maintaining the credit files, we must determine whether the ,
class members
suffered concrete harm from TransUnion’s failure to employ reasonable procedures.
Start with the ,
class members (including the named plaintiff Ramirez) whose
reports were disseminated to third-party businesses. The plaintiffs argue that the
publication to a third party of a credit report bearing a misleading OFAC alert injures the subject of the report. The plaintiffs contend that this injury bears a “close
relationship” to a harm traditionally recognized as providing a basis for a lawsuit
in American courts — namely, the reputational harm associated with the tort of
defamation. Spokeo, Inc. v. Robins,
U.S.
,
(
).
We agree with the plaintiffs. Under longstanding American law, a person is injured when a defamatory statement “that would subject him to hatred, contempt,
or ridicule” is published to a third party. Milkovich v. Lorain Journal Co.,
U.S.
,
(
); see also Restatement of Torts §
(
). TransUnion provided
third parties with credit reports containing OFAC alerts that labeled the class
members as potential terrorists, drug traffickers, or serious criminals. The ,
class members therefore suffered a harm with a “close relationship” to the harm
associated with the tort of defamation. We have no trouble concluding that the
,
class members suffered a concrete harm that qualifies as an injury in fact.
TransUnion counters that those ,
class members did not suffer a harm
with a “close relationship” to defamation because the OFAC alerts on the disseminated credit reports were only misleading and not literally false. See id. §
.
TransUnion points out that the reports merely identified a consumer as a “potential match” to an individual on the OFAC list — a fact that TransUnion says is not
technically false.
In looking to whether a plaintiff ’s asserted harm has a “close relationship” to a
harm traditionally recognized as providing a basis for a lawsuit in American
courts, we do not require an exact duplicate. The harm from being labeled a “potential terrorist” bears a close relationship to the harm from being labeled a “terrorist.” In other words, the harm from a misleading statement of this kind bears a
sufficiently close relationship to the harm from a false and defamatory statement.
…
3
1
5
8
1
5
0
8
5
1
2
7
9
4
5
8
1
8
6
1
8
0
3
2
9
1
1
4
9
3
5
5
0
3
3
8
3
5
7
5
8
1
2
3
3
3
5
8
6
1
1
0
1
9
0
9
2
1
3
2
3
5
3
1
3
The remaining ,
class members are a different story. To be sure, their credit
files, which were maintained by TransUnion, contained misleading OFAC alerts.
But the parties stipulated that TransUnion did not provide those plaintiffs’ credit
information to any potential creditors during the class period from January
to July
. Given the absence of dissemination, we must determine whether the
,
class members suffered some other concrete harm for purposes of Article
III.
8
1
1
1
2
6
Chapter 4: Privacy
Internet Law
8
1
0
6
2
1
5
0
2
4
3
4
4
7
3
1
8
0
4
4
2
3
0
3
9
3
9
3
3
5
9
2
7
7
3
9
8
2
1
3
9
9
7
9
8
1
6
9
0
0
3
9
2
8
3
2
9
6
1
4
5
8
4
7
4
2
3
4
1
0
3
2
1
4
8
3
9
3
7
7
5
8
8
7
6
5
5
2
3
The initial question is whether the mere existence of a misleading OFAC alert
in a consumer's internal credit file at TransUnion constitutes a concrete injury. As
Judge Tatel phrased it in a similar context, “if inaccurate information falls into” a
consumer's credit file, “does it make a sound?” Owner-Operator Independent Drivers Assn., Inc. v. United States Dept. of Transp.,
F. d
,
(D.C. Cir.
).
Writing the opinion for the D.C. Circuit in Owner-Operator, Judge Tatel answered no. Publication is “essential to liability” in a suit for defamation. Restatement of Torts §
, Comment a, at
. And there is “no historical or commonlaw analog where the mere existence of inaccurate information, absent dissemination, amounts to concrete injury.” Owner-Operator,
F. d at
–
. “Since
the basis of the action for words was the loss of credit or fame, and not the insult,
it was always necessary to show a publication of the words.” J. Baker, An Introduction to English Legal History
( th ed.
). Other Courts of Appeals have
similarly recognized that, as Judge Colloton summarized, the “retention of information lawfully obtained, without further disclosure, traditionally has not provided the basis for a lawsuit in American courts,” meaning that the mere existence of
inaccurate information in a database is insufficient to confer Article III standing.
Braitberg v. Charter Communications, Inc.,
F. d
,
( th Cir.
); see
Gubala v. Time Warner Cable, Inc.,
F. d
,
( th Cir.
).
The standing inquiry in this case thus distinguishes between (i) credit files that
consumer reporting agencies maintain internally and (ii) the consumer credit reports that consumer reporting agencies disseminate to third-party creditors. The
mere presence of an inaccuracy in an internal credit file, if it is not disclosed to a
third party, causes no concrete harm. In cases such as these where allegedly inaccurate or misleading information sits in a company database, the plaintiffs’ harm
is roughly the same, legally speaking, as if someone wrote a defamatory letter and
then stored it in her desk drawer. A letter that is not sent does not harm anyone,
no matter how insulting the letter is. So too here.
Because the plaintiffs cannot demonstrate that the misleading information in
the internal credit files itself constitutes a concrete harm, the plaintiffs advance a
separate argument based on an asserted risk of future harm. They say that the
,
class members suffered a concrete injury for Article III purposes because
the existence of misleading OFAC alerts in their internal credit files exposed them
to a material risk that the information would be disseminated in the future to
third parties and thereby cause them harm. The plaintiffs rely on language from
Spokeo where the Court said that “the risk of real harm” (or as the Court otherwise
stated, a “material risk of harm”) can sometimes “satisfy the requirement of concreteness.”
U.S. at
–
.
To support its statement that a material risk of future harm can satisfy the concrete-harm requirement, Spokeo cited this Court’s decision in Clapper v. Amnesty
Int’l USA,
U.S.
(
). But importantly, Clapper involved a suit for injunctive relief. As this Court has recognized, a person exposed to a risk of future
harm may pursue forward-looking, injunctive relief to prevent the harm from occurring, at least so long as the risk of harm is sufficiently imminent and substantial.
But a plaintiff must demonstrate standing separately for each form of relief
sought. Therefore, a plaintiff ’s standing to seek injunctive relief does not necessarily mean that the plaintiff has standing to seek retrospective damages.
TransUnion advances a persuasive argument that in a suit for damages, the
mere risk of future harm, standing alone, cannot qualify as a concrete harm — at
3
6
260
Chapter 4: Privacy
261
least unless the exposure to the risk of future harm itself causes a separate concrete harm. TransUnion contends that if an individual is exposed to a risk of future
harm, time will eventually reveal whether the risk materializes in the form of actual harm. If the risk of future harm materializes and the individual suffers a concrete harm, then the harm itself, and not the pre-existing risk, will constitute a
basis for the person's injury and for damages. If the risk of future harm does not
materialize, then the individual cannot establish a concrete harm sufficient for
standing, according to TransUnion.
Consider an example. Suppose that a woman drives home from work a quarter
mile ahead of a reckless driver who is dangerously swerving across lanes. The reckless driver has exposed the woman to a risk of future harm, but the risk does not
materialize and the woman makes it home safely. As counsel for TransUnion stated, that would ordinarily be cause for celebration, not a lawsuit. But if the reckless
driver crashes into the woman's car, the situation would be different, and (assuming a cause of action) the woman could sue the driver for damages.
The plaintiffs note that Spokeo cited libel and slander per se as examples of cases where, as the plaintiffs see it, a mere risk of harm suffices for a damages claim.
But as Judge Tatel explained for the D.C. Circuit, libel and slander per se “require
evidence of publication.” Owner-Operator,
F. d at
. And for those torts,
publication is generally presumed to cause a harm, albeit not a readily quantifiable
harm. As Spokeo noted, “the law has long permitted recovery by certain tort victims even if their harms may be difficult to prove or measure.”
U.S. at
(emphasis added). But there is a significant difference between (i) an actual harm
that has occurred but is not readily quantifiable, as in cases of libel and slander per
se, and (ii) a mere risk of future harm. By citing libel and slander per se, Spokeo did
not hold that the mere risk of future harm, without more, suffices to demonstrate
Article III standing in a suit for damages.
Here, the ,
plaintiffs did not demonstrate that the risk of future harm materialized — that is, that the inaccurate OFAC alerts in their internal TransUnion
credit files were ever provided to third parties or caused a denial of credit. Nor did
those plaintiffs present evidence that the class members were independently
harmed by their exposure to the risk itself — that is, that they suffered some other
injury (such as an emotional injury) from the mere risk that their credit reports
would be provided to third-party businesses. Therefore, the ,
plaintiffs’ argument for standing for their damages claims based on an asserted risk of future
harm is unavailing. …
Moreover, the plaintiffs did not present any evidence that the ,
class members even knew that there were OFAC alerts in their internal TransUnion credit
files. If those plaintiffs prevailed in this case, many of them would first learn that
they were “injured” when they received a check compensating them for their supposed “injury.” It is difficult to see how a risk of future harm could supply the basis
for a plaintiff ’s standing when the plaintiff did not even know that there was a risk
of future harm. …
1
4
3
8
7
5
2
2
3
3
3
3
6
6
5
4
3
3
9
7
8
2
3
3
6
Justice Thomas, dissenting: …
Key to the scope of the judicial power, then, is whether an individual asserts his
or her own rights. At the time of the founding, whether a court possessed judicial
power over an action with no showing of actual damages depended on whether the
plaintiff sought to enforce a right held privately by an individual or a duty owed
broadly to the community. Where an individual sought to sue someone for a violation of his private rights, such as trespass on his land, the plaintiff needed only to
Internet Law
allege the violation. Courts typically did not require any showing of actual damage.
But where an individual sued based on the violation of a duty owed broadly to the
whole community, such as the overgrazing of public lands, courts required “not
only injuria [legal injury] but also damnum [damage].” Spokeo,
U.S. at
(Thomas, J., concurring).
This distinction mattered not only for traditional common-law rights, but also
for newly created statutory ones. The First Congress enacted a law defining copyrights and gave copyright holders the right to sue infringing persons in order to
recover statutory damages, even if the holder could not show monetary loss. In the
patent context, a defendant challenged an infringement suit brought under a similar law. Along the lines of what TransUnion argues here, the infringer contended
that “the making of a machine cannot be an offence, because no action lies, except
for actual damage, and there can be no actual damages, or even a rule for damages, for an infringement by making a machine.” Whittemore v. Cutter,
F.Cas.
,
(No. ,
) (CC Mass.
). Riding circuit, Justice Story rejected that
theory, noting that the plaintiff could sue in federal court merely by alleging a violation of a private right: “[W]here the law gives an action for a particular act, the
doing of that act imports of itself a damage to the party” because “[e]very violation
of a right imports some damage.” Id. …
Here, each class member established a violation of his or her private rights. …
Take §
e(b), which requires a consumer reporting agency to “follow reasonable
procedures to assure maximum possible accuracy of the information concerning
the individual about whom the report relates.” This statute creates a duty: to use
reasonable procedures to assure maximum possible accuracy. And that duty is particularized to an individual: the subject of the report. …
Were there any doubt that consumer reporting agencies owe these duties to
specific individuals—and not to the larger community—Congress created a cause
of action providing that “[a]ny person who willfully fails to comply” with an FCRA
requirement “with respect to any consumer is liable to that consumer.” §
n(a)
(emphasis added). If a consumer reporting agency breaches any FCRA duty owed
to a specific consumer, then that individual (not all consumers) may sue the
agency. No one disputes that each class member possesses this cause of action.
And no one disputes that the jury found that TransUnion violated each class
member’s individual rights. The plaintiffs thus have a sufficient injury to sue in
federal court.
6
4
3
1
8
9
6
1
2
8
7
5
3
1
8
1
0
0
6
7
1
1
8
1
2
6
1
1
1
0
2
QUESTIONS
. Privacy Harms: Do you agree with the Court that falsely flagging a person as a
potential terrorist in a database causes that person no harm, regardless of
how carelessly the database is maintained? And that passing along that notice to a third party does, regardless of whether the third party reads the notice or does anything based on it?
. Whither the VPPA? Did the plaintiffs in Eichenberger have standing?
. Data Breaches: Suppose that TransUnion suffers a data breach that exposes
plaintiffs’ names, addresses, phone numbers, email addresses, and dates of
birth. Plaintiffs sue, alleging increased likelihood of identity theft. Do they
have standing? What if their credit card numbers have also been exposed?
Does it matter whether they have suffered any unauthorized charges,
whether they can trace those charges to the data breach, or whether they are
financially responsible for those charges under their credit card agreements?
1
1
3
2
1
262
263
. Privacy vs. Speech: In Sorrell v. IMS Health Inc.,
U.S.
(
), the
Supreme Court held unconstitutional a Vermont law prohibiting pharmacies
from selling data to drug companies about which doctors prescribed what
medications. This data, held the Court, was First Amendment-covered
speech, and Vermont’s rationale—to protect doctors from targeted marketing
trying to convince them to prescribe expensive brand-name drugs—was
viewpoint discrimination. Does Sorrell mean that the VPPA and FCRA are
also unconstitutional?
IN RE GOOGLE, INC. PRIVACY POLICY LITIG.
No. C-12-01382-PSG12/03/2013, 2013 WL 6248499 (N.D. Cal. Dec. 2, 2013)
Grewal, Magistrate Judge: …
After this court’s order dismissing their consolidated complaint on standing
grounds with leave to amend, Plaintiffs … filed an amended complaint. In their
amended complaint, Plaintiffs again challenge the introduction of a new, unified
privacy policy by Defendant Google, Inc. permitting the commingling of user data
across different Google products. Plaintiffs also challenge Google’s disclosure of
this data to third parties, including developers of applications for the Google Play
market and advertising partners. … As detailed below, the court agrees with
Google that the amended complaint is defective and therefore must be dismissed,
but … with further leave to amend.
I. B
By now, most people know who Google is and what Google does. Google serves
billions of online users in this country and around the world. What started as simply a search engine has expanded to many other products such as YouTube and
Gmail. Google offers these products and most others without charge. With little or
no revenue from its users, Google still manages to turn a healthy profit by selling
advertisements within its products that rely in substantial part on users’ personal
identification information (“PII”). As some before have observed, in this model,
the users are the real product.
Before March ,
, Google maintained separate privacy policies for each of
its products, each of which confirmed that Google used a user’s PII to provide that
particular product. These policies also confirmed that Google would not use the
PII for any other purpose without the user’s explicit consent. As Google put it,
“[w]hen you sign up for a particular service that requires registration, we ask you
to provide personal information. If we use this information in a manner different
than the purpose for which it was collected, then we will ask for your consent prior
to such use.”
On March ,
, Google announced a new policy. The majority of its separate
privacy policies were eliminated in favor of a single, universal privacy policy that
spells out that Google may combine a user’s PII across multiple Google products.
Google explained the basis for the change in policy as follows:
1
1
0
2
2
5
5
1
1
0
2
4
6
5
2
1
0
2
2
1
d
1
0
n
2
u
o
1
r
g
k
c
For example, in a legal notice issued to Gmail users in
, Google stated, “We will
not use any of your content [defined to include ‘text, data, information, images, photographs, music, sound, video, or other material’] for any purpose except to provide
you with the service.” Google has also pledged that “Gmail stores processes, and
maintains your messages, contact lists, and other data related to your account in
order to provide the service to you.”
a
4
3
3
Chapter 4: Privacy
Internet Law
1
1
2
1
0
2
9
2
2
1
0
2
1
+
4
0
0
2
9
1
1
2
1
Our new Privacy Policy makes clear that, if you’re signed in, we may
combine information that you’ve provided from one service with information from other services. In short, we’ll treat you as a single user
across all our products, which will mean simpler, more intuitive
Google experience.
In other words, through the new policy, Google is explicit that it may combine PII
collected from a user’s Gmail or YouTube account, including the content of that
account, with PII collected from that user’s Google search queries, along with the
user’s activities on other Google products, such as Picasa, Maps, Docs, and Reader.
This PII includes:
• first and last name;
• home or other physical address (including street name and city);
• current, physical location, a user’s email address, and other online contact
information (such as the identifier or screen name);
• IP address;
• telephone number (both home and mobile numbers);
• list of contacts;
• search history from Google’s search engine;
• web surfing history from cookies placed on the computer; and
• posts on Google .
Plaintiffs contend that Google’s new policy violates its prior policies because the
new policy no longer allows users to keep information gathered from one Google
product separate from information gathered from other Google products. Plaintiffs further contend that Google’s new policy violates users’ privacy rights by allowing Google to take information from a user’s Gmail account, for which users
may have one expectation of privacy, for use in a different context, such as to personalize Google search engine results, or to personalize advertisements shown
while a user is surfing the internet, products for which a user may have an entirely
different expectation of privacy. In addition to commingling Plaintiffs’ PII across
the various Google products, Plaintiff contend Google has shared Plaintiffs’ PII
with third-party entities who have partnered with Google in order to develop applications for the Google Play app store to help it place targeted advertisements.
Plaintiffs bring this nationwide class action against Google on behalf of all persons and entities in the United States who acquired a Google account between
August ,
, and February ,
, and maintained such an account until,
on, or after March ,
. Plaintiffs also bring this action on behalf of [two subclasses of purchasers of Android phones].
Plaintiffs allege that they each acquired a Gmail account before the March ,
announcement of the new policy and continued to use it after the new policy
took effect. They each further allege they purchased an Android phone before
March and that after implementing the new policy Google aggregated their personal information without consent or compensation. Mr. Marti further alleges
Google used his likeness in display advertisements without authorization. Mr.
Nisenbaum further alleges that after March , for privacy reasons, he replaced his
Android phone for privacy reasons with an iPhone. The other plaintiffs allege use
of various Android-powered phones and that they downloaded various Android
Applications (“apps”) from the Google Play store. Based on these allegations,
Plaintiffs bring claims against Google for statutory and common law misappropri-
0
2
264
265
4
9
1
0
1
5
0
2
1
0
5
2
1
5
4
5
2
2
4
0
1
1
5
2
3
9
2
0
7
9
5
5
0
3
1
1
5
5
6
2
1
3
1
1
5
2
1
1
0
2
8
1
7
4
0
2
0
1
n
o
i
s
s
u
c
s
i
5
2
1
0
1
1
1
0
0
ation of likeness, violation of California’s Unfair Competition Law (“UCL”), breach
of contract, common law intrusion upon seclusion, violation of California’s User
Legal Remedies Act (“CLRA”), violation of the Wiretap Act, and violation of the
Stored Communications Act (“SCA”). …
III. D
…
B. [Wiretap Act] …
The Wiretap Act, as amended by the Electronic Communication Privacy Act
(“ECPA”), generally prohibits the intentional interception of “wire, oral, or electronic communications.”
U.S.C. §
( ). The purpose of the Wiretap Act is to
protect the privacy of communications. … The Act defines “intercept” as “the aural
or other acquisition of the contents of any wire, electronic, or oral communication
through the use of any electronic, mechanical, or other device.” Id. §
( ).
However, the definition of “electronic, mechanical, or other device” excludes [any
instrument “being used by a provider of wire or electronic communication service
in the ordinary course of its business.” Id. §
( )(a)(ii)].
The amended complaint fails to allege any interception by Google that falls
outside the scope of this broad immunity. While Plaintiffs point to their allegations that Google’s use of the accused devices to intercept Gmail communications
and co-mingle the contents and distribute those contents without consent was not
necessary to the delivery of Gmail, this narrow read of the exemption, as being
limited to only action taken to deliver the electronic communication, does not
square with the plain meaning of the statutory text at issue. The text exempts from
the definition of “intercept” any use of a device by a provider “in the ordinary
course of its business.” Rather than narrowing the exemption to only the provision
of electronic communications services itself, or some such narrower scope, Congress specifically chose the broader term “business” that covers more far-ranging
activity. For good measure, Congress also teamed the term “business” with the
terms “ordinary course,” suggesting an interest in protecting a provider’s customary and routine business practices. …
Although the Ninth Circuit has yet to rule on the subject, other appellate courts
that have agreed that the “ordinary course of business” exception is not limited to
actions necessary to providing the electronic communication services (“ECS”) at
issue. … In Kirch v. Embarq Management Co.,
F. d
,
( th Cir.
), the Tenth Circuit held that the defendant was protected by the exception
when it conducted a test using third-party advertising technology and its customers’ communications, because the defendant had “no more of its users’ electronic communications than it had in the ordinary course of its business as an
ISP.” The trial court’s decision affirmed by Kirch noted that the “ordinary course of
its business” defense “appears to have merit, as plaintiffs have admitted that Embarq conducted the NebuAd test to further legitimate business purposes and that
behavioral advertising is a widespread business and is commonplace on the Internet.” Kirch, No. –
–JAR,
WL
, at * n.
(D. Kan. Aug. ,
). Kirch thus supports the application of Section
( )(a)(ii) where the
provider is furthering its “legitimate business purposes” – including advertising –
and is not limited to only those acts that are technically necessary to processing
email.
The more fundamental problem with Plaintiffs’ narrow construction of Section
( )(a)(ii) is that in defining “ordinary course of business” as “necessary” it
begs the question of what exactly its means for a given action to be “necessary” to
the delivery of Gmail. For example, in delivering Gmail is it really “necessary” do
5
2
2
2
Chapter 4: Privacy
1
+
1
+
1
0
7
2
1
+
1
0
4
7
4
2
3
3
1
8
+
1
1
+
1
+
1
+
3
3
For example, Plaintiffs might have a claim if they could allege that the feature did
not work as Google explained, that Google did not adequately disclose how the feature worked, a theory of how clicking on the “ ” feature did not demonstrate consent, or an allegation that his name or likeness was associated with brands, products,
or websites he did not “ .”
1
1
Internet Law
more than just the comply with email protocols such as POP, IMAP and MAPI?
What about spam-filtering or indexing? None of these activities have anything
specifically to do with transmitting email. And yet not even Plaintiffs suggest that
these activities are unnecessary and thus lie outside of the “ordinary course business.” …
C. Stored Communications Act
The SCA was enacted because the advent of the Internet presented a host of potential privacy breaches that the Fourth Amendment does not address. Despite
this purpose, the SCA has a narrow scope: the SCA is not a catch-all statute designed to protect the privacy of stored Internet communications.
Plaintiffs claim that … in aggregating users’ information between Google services without their consent, Google exceeded the scope of Google’s authorized access in violation of
U.S.C. §
(a). This claim borders on frivolous, considering the plain language of subsection (c) of Section
(a) that exempts conduct
authorized “by the person or entity providing a wire or electronic communications
service.” Whatever the propriety of Google’s actions, it plainly authorized actions
that it took itself. …
D. Misappropriation of Likeness
California Civil Code Section
prohibits the use of another’s name or likeness
[“to defendant’s advantage, commercially or otherwise”] without the person’s consent. … Here, Plaintiffs fail to adequately allege lack of consent. …
Plaintiffs in this case only make a threadbare allegation that Google did not
obtain their consent to use their name or likeness in advertisements associated
with its “ ” feature, and the claim is not supported by other allegations. To the
contrary, the complaint alleges that Ms. Marti voluntarily clicked on the “ ” feature, that Google clearly disclosed how the feature worked as part of the feature’s
launch, and that the feature worked as Google said it would when Marti used it. In
particular, the amended complaint quotes Google as: describing the “ ” feature as
“the digital shorthand for ‘this is pretty cool’ ” and a way “to share recommendations with the world;” explaining that to “[t]o recommend something, all you have
to do is click
on a webpage or ad you find useful;” and giving the example of a
person planning a winter trip to Tahoe, California who, when doing a search, “may
now see a
from [his] slalom-skiing aunt next to the result for a lodge in the
area.”
Without some contradictory allegations, this is a clear disclosure of how the
feature worked such that the voluntary use of it constituted consent. Plaintiffs
therefore have not stated any claim for statutory or common law misappropriation
of likeness.
E. Breach of Contract …
Google argues that it has not breached its contact with Plaintiffs because the original contract included provisions for it to make the types of very changes that
Plaintiffs allege breached the contract. …
1
1
266
Chapter 4: Privacy
267
2
1
0
2
1
1
2
1
0
2
1
2
The policy plainly includes a provision for the commingling of PII across
Google products. That provision states: “We may combine the information you
submit under your account with information from other services.” In light of this
express provision, it is not plausible to say that Google could be considered to have
breached the contract. Plaintiffs again have failed to state a claim.
F. California’s Unfair Competition Law (“UCL”)
California’s UCL provides a private cause of action for users who are harmed by
unfair, unlawful, or fraudulent business practices. Plaintiffs here plead their UCL
claim under all three prongs. To sustain a claim under the unlawful prong, Plaintiffs must allege facts that, if proven, would demonstrate that Defendant’s conduct
violated another, underlying law. … Under the fraudulent prong, Plaintiffs must
allege specific facts to show that the members of the public are likely to be deceived by the actions of the defendant. …
To support their claim under the UCL’s unlawful prong, Plaintiffs allege that
Google’s conduct violates [the laws discussed above]. As discussed in other sections, Plaintiffs have failed to set forth sufficient factual allegations to support
these underlying charges, and without having plead any underlying unlawful conduct, Plaintiffs unlawful conduct claim under the UCL must be dismissed.
With respect to their claim under the fraudulent prong, Plaintiffs allege that
when Google collected their PII before March ,
, it assured them that it
would not use the information for any purpose other than delivering the service
for which the users provided it. [But] the documents submitted for judicial notice
undermine any notion that Google failed to disclose its data commingling practices before March ,
.
Finally, Plaintiffs seek to support their claim of unfair conduct by alleging that
Google lead them to believe that they could opt out of endorsements, profiting
from the use of the plaintiff ’s information, and “encouraging Plaintiffs and the
Class to make Google products indispensable to their lives,” before making it incredibly difficult for them to effectively “opt out” of programs making use of their
data. These facts, as alleged, do not rise to the level of “unscrupulous” or “unethical.” Even if its earlier policies were not transparent, Google provided notice to its
users when it changed its privacy policy, which undercuts any unethical or immoral allegations; this was not a change made in the dark, but rather one broadcast to all those affected. In addition, the overall benefit to users in receiving free,
“indispensable” services offsets much of the harm they may suffer through the
change. As it stands, Plaintiffs have not set forth sufficient allegations to support
an unfairness prong claim.
G. Common Law Intrusion Upon Seclusion
In order to put forth a claim for intrusion upon seclusion, a plaintiff must plead
facts to support two elements: ) intrusion into a private place, conversation or
matter, and ) in a manner highly offensive to a reasonable person. … Courts have
recognized facts sufficient to support these elements in the context of repeated
phone calls, eavesdropping on workplace conversations, and unauthorized review
of email.
Plaintiffs here allege that Google’s PII commingling intruded upon their email,
contact lists, web histories, and other secluded and private spaces. According to
Plaintiffs, this expectation was reasonable in light of the previous privacy policies,
which assured Plaintiffs of the isolated use of their data. But once again, the court
does not find any expectation to be plausible in light of Google’s earlier disclosure
Internet Law
that it would commingle PII across products to support its advertising model.
Without a plausible expectation, Plaintiffs seclusion on intrusion claim cannot
stand.
H. California’s User Legal Remedies Act (“CLRA”)
Plaintiffs’ sixth cause of action seeks recovery under Sections (a)( ), ( ), and ( )
of the CLRA, which ban advertising goods with intent not to sell them in the
manner advertised, representing that a transaction conveys rights which it does
not, and representing that the subject of a transaction has been conveyed in accordance with terms of a previous transaction, when it has not. In order to recover,
Plaintiffs must also allege facts to establish that they relied on the misrepresentations in question, and that in so relying, they suffered damage. …
Plaintiffs’ claims are insufficiently plead because they fail to allege that Google
intended to use the PII in a manner other was advertised at the time that the
plaintiffs purchased the goods and registered for the services in question. Under
the CLRA, the intent to deceive or misuse information must be present at the time
of sale in order for a plaintiff to recover. Yet even if its commingling practices were
not disclosed in
, Plaintiffs offer no factual allegations indicating that Google
planned to change its policies as far back as
, such that the existing policies
were aimed to deceive at the time the business relationship began. They have not
put forth any allegations suggesting that Google did not intend to honor its existing privacy policies, at the time they became customers. They certainly do not provide the requisite level of detail under Rule (b) to support allegations of intent to
deceive.
IV. C
Google’s motion to dismiss is GRANTED. Plaintiffs must file any further amended
complaint by January ,
. Having dismissed two complaints already, Plaintiffs are on notice that any further dismissal will likely be with prejudice.
QUESTIONS
. Privacy Policies: Is the court right that Google’s earlier statements put plaintiffs on notice that it might commingle their data? If so, how much are privacy promises really worth?
. Kitchen Sinks: Why is this opinion (which is fairly typical of digital privacy
class-action litigation) so long, so detailed, and so boring?
CHRIS YIU (@CLRY2)
CHRIS YIU (@CLRY2), TWEETSTORM ON AD TRACKING
Twitter (June 7, 2018). https://twitter.com/clry2/status/1004754363745734656
6
1
4
1
9
0
1
0
2
0
9
9
9
1
4
1
0
2
6
1
0
1
0
2
n
o
i
s
u
l
c
n
Ever wondered *how* those adverts manage to keep on finding you - even when
you go incognito, switch devices, or never actually searched for the product in the
first place? Let us count the (many, many) ways [THREAD]
You visit a website and it stores a cookie in your web browser. You return later
on, the cookie identifies you and the site shows you products you were looking at
earlier. Old hat (unless you live in the
s), but important to understand for
what's coming next
You visit a website and it stores a cookie from a third-party ad network. Later
on you visit a different site that carries ads from the same network. They see the
cookie and display ads based on what you were looking at earlier. This is called
"retargeting" or “remarketing”
o
2
1
268
Chapter 4: Privacy
269
0
3
You open Google and search for a product or website, which helps Google build
up a profile of you and your interests. Later on you use your Google account to
sign in somewhere else, and you see ads based on this profile (N.B. you can turn
ads personalisation off if you want to)
You're logged in to Facebook. You visit a website and it has Facebook's tracking
pixel (or Like button) installed, which lets Facebook know you're there. Later on
you visit Facebook, and your newsfeed contains adverts based on what you were
looking at earlier
N.B. Facebook doesn't let website owners single you out for these adverts (nor
does it sell your data to them). Ads are targeted at groups e.g. people who visited a
site in the last
days. These groups are called “audiences”
You visit a website and create an account with them. They upload a list of customer email addresses to Google / Facebook / Twitter etc. to target a campaign.
Later on you visit one of these sites, and you see adverts based on what you were
looking at earlier
You turn on incognito mode (aka "private browsing"), which limits things like
cookies. The ad network records other information about your system instead, e.g.
web browser, IP address, operating system, screen size, time zone etc. This is
called “fingerprinting"...
...Later on you visit a site where this network displays ads. They recognise your
browser fingerprint (albeit with varying degrees of accuracy) and you see adverts
based on what you were looking at earlier, even though you were using incognito
mode
You log into the same online account on more than one browser or device. The
provider of the account associates the different fingerprints with your account.
Adverts targeted at your account can now follow you from one browser / device to
another
You carry more than one device and you never log into the same account on
both, but you do connect them to the same WiFi networks at the same times, and
you use both devices to visit sites that contain trackers from the same ad network.
Boom, your devices are associated
You install an app on your phone. Apps don't use cookies, but your phone sends
a unique device ID to the app creator instead. Later on you open a different app
and see ads based on the app you were using earlier
You install an app on your phone, and then sign in to it using one of your online
accounts. You guessed it: your device ID is now associated with that account. Later
on you see ads based on your apps when you're using the account on your computer
N.B. Apple, Android and Windows mobile devices all let you disable or reset
your device ID. This won't stop you seeing ads, but it will reduce the amount of
personalisation that can follow you from one app to another
You never actually visited a particular site, but other people did. You go on
Facebook and see ads for it, because your profile is similar to those other people,
and the whole group is being targeted. The group you belong to is called a "lookalike audience”
You have a voice assistant (aka "smart speaker") and ask it about something.
Later on you visit a website that uses an ad network provided by the company that
makes your assistant, and you see ads for the thing you asked about
N.B. In some cases your voice assistant can be triggered without you using its
wake word (because its speech recognition system sometimes makes mistakes, and
Internet Law
in unpredictable ways). Extremely rare, but will also add to you voice history if it
happens
You never actually visited a particular site, but you share an IP address with
people who did, e.g. you and your flatmates are all using the same broadband
router. Later on you see ads from that site, because you are all being targeted at
your (shared) IP address
You never actually visited a particular site, but you were in close proximity to
other people who did, and you were all signed in to a service with access to your
location data. Later on you see ads from that site, because the whole group is being
targeted
After all this, it may surprise you to hear that I don't think personalised ads are
anything like the problem they are sometimes made out to be.
This doesn't mean I think the status quo is OK - we could do with a lot more
transparency about how ads are being targeted, and there is still room for improvement on making sure people know and have a choice about when their behaviour is being captured, stored and shared.
But the fact of the matter is, there are real products and services where zero is
the best price point for everyone because it enables the greatest number of people
to participate. And in these cases, carrying ads is often the best way to monetise.
And it turns out targeted advertising is also the best way for lots of new and
niche businesses to find their customers. Ideas that would never have been viable
before the internet can now get in front of a critical mass of potential customers
online.
Nor is targeted advertising a new phenomenon. Buy a particular newspaper or
magazine? Congratulations, you're in a rudimentary lookalike audience. Those
coupons they print for you at the supermarket? Retargeting based on past purchases (linked by your store or credit card).
So even though ads sometimes feel creepy, there are bigger things to worry
about - like political campaigns based on voter suppression, or apps that are
wrecking our attention spans, or big decisions about the online world moving from
elected assemblies to unelected boardrooms.
We'll talk about all of that another time. [ENDS]
QUESTIONS
. Yiu vs. Yiu: Is Yiu persuasive when he says there are more important things to
worry about than the detailed list of ad-tracking techniques he has just run
through?
. Is Law Working? Based on the cases in this section, is privacy law dealing appropriately with the kinds of ad tracking Yiu describes?
IN RE SNAPCHAT, INC.
2015-1 Trade Cas. (CCH) ¶ 17,115, 2014 WL 7495798 (F.T.C. 2014)
t
n
i
a
l
p
m
C
The Federal Trade Commission, having reason to believe that Snapchat, Inc. (“respondent”) has violated the provisions of the Federal Trade Commission Act, and
it appearing to the Commission that this proceeding is in the public interest, alleges: …
Respondent’s Business Practices
3. Snapchat provides a mobile application that allows consumers to send and
receive photo and video messages known as “snaps.” Before sending a snap,
o
2
1
270
Chapter 4: Privacy
271
the application requires the sender to designate a period of time that the
recipient will be allowed to view the snap. Snapchat markets the application
as an “ephemeral” messaging application, having claimed that once the
timer expires, the snap “disappears forever.”
4. Snapchat launched its mobile application on Apple Inc.’s iOS operating system in September 2011 and on Google Inc.’s Android operating system in
October 2012. Snapchat added video messaging to the iOS version of its application in December 2012 and to the Android version of its application in
February 2013.
5. Both the iTunes App Store and the Google Play store list Snapchat among
the top 15 free applications. As of September 2013, users transmit more
than 350 million snaps daily.
Snapchat’s “Disappearing” Messages (Counts 1 and 2)
6. Snapchat marketed its application as a service for sending “disappearing”
photo and video messages, declaring that the message sender “control[s]
how long your friends can view your message.” Before sending a snap, the
application requires the sender to designate a period of time - with the default set to a maximum of 10 seconds - that the recipient will be allowed to
view the snap …
7. Since the application’s launch on iOS until May 2013, and since the application’s launch on Android until June 2013, Snapchat disseminated, or caused
to be disseminated, to consumers the following statements on its product
description page on the iTunes App Store and Google Play:
[You control how long your friends can view your message –
simply set the timer up to ten seconds and send.
They’ll have that long to view your message and then it disappears forever. We’ll let you know if they take a screenshot!]
272
Internet Law
ffi
fi
fl
fi
fi
fi
ffi
fi
fi
fi
fi
fi
fi
From October 2012 to October 2013, Snapchat disseminated, or caused to
be disseminated, to consumers the following statement on the “FAQ” page
on its website:
Is there any way to view an image after the time has expired?
No, snaps disappear after the timer runs out ....
9. Despite these claims, several methods exist by which a recipient can use
tools outside of the application to save both photo and video messages, allowing the recipient to access and view the photos or videos inde nitely.
10. For example, when a recipient receives a video message, the application
stores the video le in a location outside of the application’s “sandbox” (i.e.,
the application’s private storage area on the device that other applications
cannot access). Because the le is stored in this unrestricted area, until October 2013, a recipient could connect his or her mobile device to a computer
and use simple le browsing tools to locate and save the video le. This
method for saving video les sent through the application was widely publicized as early as December 2012. Snapchat did not mitigate this aw until
October 2013, when it began encrypting video les sent through the application.
11. Furthermore, third-party developers have built applications that can connect to Snapchat’s application programming interface (“API”), thereby allowing recipients to log into the Snapchat service without using the o cial
Snapchat application. Because the timer and related “deletion” functionality
is dependent on the recipient’s use of the o cial Snapchat application, recipients can instead simply use a third-party application to download and
save both photo and video messages. As early as June 2012, a security researcher warned Snapchat that it would be “pretty easy to write a tool to
download and save the images a user receives” due to the way the API functions. Indeed, beginning in spring 2013, third-party developers released several applications on the iTunes App Store and Google Play that recipients
can use to save and view photo or video messages inde nitely. On Google
Play alone, ten of these applications have been downloaded as many as 1.7
million times.
12. The le browsing tools and third-party applications described in paragraphs
10 and 11 are free or low cost and publicly available on the Internet. In order
to download, install, and use these tools, a recipient need not make any
modi cations to the iOS or Android operating systems and would need little
technical knowledge.
13. In addition to the methods described in paragraphs 10-12, a recipient can
use the mobile device’s screenshot capability to capture an image of a snap
while it appears on the device screen.
14. Snapchat claimed that if a recipient took a screenshot of a snap, the sender
would be noti ed. On its product description pages, as described in paragraph 7, Snapchat stated: “We’ll let you know if [recipients] take a screenshot!” In addition, from October 2012 to February 2013, Snapchat disseminated, or caused to be disseminated, to consumers the following statement
on the “FAQ” page on its website:
fi
8.
Chapter 4: Privacy
18.
19.
20.
21.
22.
23.
fi
2
1
3
fi
24.
fi
17.
fi
16.
fi
What if I take a screenshot?
Screenshots can be captured if you’re quick. The sender will be
noti ed immediately.
However, recipients can easily circumvent Snapchat’s screenshot detection
mechanism. For example, on versions of iOS prior to iOS 7, the recipient
need only double press the device’s Home button in rapid succession to
evade the detection mechanism and take a screenshot of any snap without
the sender being noti ed. This method was widely publicized.
Count
As described in Paragraphs 6, 7, and 8, Snapchat has represented, expressly
or by implication, that when sending a message through its application, the
message will disappear forever after the user-set time period expires.
In truth and in fact, as described in Paragraph 9-12, when sending a message through its application, the message may not disappear forever after
the user-set time period expires. Therefore, the representation set forth in
Paragraph 16 is false or misleading.
Count
As described in Paragraphs 7 and 14, Snapchat has represented, expressly or
by implication, that the sender will be noti ed if the recipient takes a
screenshot of a snap.
In truth and in fact, as described in Paragraph 15, the sender may not be
noti ed if the recipient takes a screenshot of a snap. Therefore, the representation set forth in Paragraph 18 is false or misleading.
Snapchat’s Collection of Geolocation Information (Count 3)
From June 2011 to February 2013, Snapchat disseminated or caused to be
disseminated to consumers the following statements in its privacy policy:
We do not ask for, track, or access any location-speci c information from your device at any time while you are using the
Snapchat application.
In October 2012, Snapchat integrated an analytics tracking service in the
Android version of its application that acted as its service provider. While
the Android operating system provided notice to consumers that the application may access location information, Snapchat did not disclose that it
would, in fact, access location information, and continued to represent that
Snapchat did “not ask for, track, or access any location-speci c
information ...”
Contrary to the representation in Snapchat’s privacy policy, from October
2012 to February 2013, the Snapchat application on Android transmitted
Wi-Fi-based and cell-based location information from users’ mobile devices
to its analytics tracking service provider.
Count
As described in Paragraph 21, Snapchat has represented, expressly or by
implication, that it does not collect users’ location information.
In truth and in fact, as described in Paragraph 22, Snapchat did collect
users’ location information. Therefore, the representation set forth in Paragraph 23 is false or misleading. …
15.
fi
273
274
Internet Law
fi
fi
ff
fi
fi
fi
Snapchat’s Collection of Contacts Information (Counts 4 and 5) …
25. Snapchat provides its users with a feature to nd friends on the service.
During registration, the application prompts the user to “Enter your mobile
number to nd your friends on Snapchat!,” implying - prior to September
2012 - through its user interface that the mobile phone number was the only
information Snapchat collected to nd the user’s friends, as depicted below:
…
26. However, when the user chooses to Find Friends, Snapchat collects not only
the phone number a user enters, but also, without informing the user, the
names and phone numbers of all the contacts in the user’s mobile device
address book.
[The FTC alleged that the failure to notify users was false or misleading. and that
Snapchat made deceptive statements in its privacy policy about the feature.]
Snapchat’s Failure to Secure Its Find
Friends Feature (Count 6) …
35. From September 2011 to December 2012, Snapchat failed to
verify that the phone number
that an iOS user entered into
the application did, in fact, belong to the mobile device being
used by that individual. Due to
this failure, an individual could
create an account using a phone
number that belonged to another consumer, enabling the individual to send and receive snaps
associated with another consumer’s phone number.
36. Numerous consumers complained to Snapchat that individuals had created Snapchat
accounts with phone numbers
belonging to other consumers,
leading to the misuse and unintentional disclosure of consumers’
personal information. For example, consumers complained that they had
sent snaps to accounts under the belief that they were communicating with
a friend, when in fact they were not, resulting in the unintentional disclosure of photos containing personal information. In addition, consumers
complained that accounts associated with their phone numbers had been
used to send inappropriate or o ensive snaps.
37. Snapchat could have prevented the misuse and unintentional disclosure of
consumers’ personal information by verifying phone numbers using common and readily available methods.
38. Indeed, in December 2012, Snapchat began performing short-message-service (“SMS”) veri cation to con rm that the entered phone number did in
fact belong to the mobile device being used by that individual.
275
fi
ff
fi
r
ff
e
d
r
fi
d
ff
n
a
n
6
o
i
s
4
i
c
1
e
39. In addition, from September 2011 to December 2013, Snapchat failed to
implement e ective restrictions on the number of Find Friend requests that
any one account could make to its API. Furthermore, Snapchat failed to implement any restrictions on serial and automated account creation. As a result of these failures, in December 2013, attackers were able to use multiple
accounts to send millions of Find Friend requests using randomly generated
phone numbers. The attackers were able to compile a database of 4.6 million Snapchat usernames and the associated mobile phone numbers. The
exposure of usernames and mobile phone numbers could lead to costly
spam, phishing, and other unsolicited communications. …
40. … Snapchat disseminated or caused to be disseminated to consumers the
following statement in its privacy policy:
Snapchat takes reasonable steps to help protect your personal
information in an e ort to prevent loss, misuse, and unauthorized access, disclosure, alteration, and destruction. …
Count
43. As described in Paragraphs 40-42, Snapchat has represented, expressly or
by implication, that it employs reasonable security measures to protect personal information from misuse and unauthorized disclosure.
44. In truth and in fact, as described in Paragraphs 34-39, in many instances,
Snapchat did not employ reasonable security measures to protect personal
information from misuse and unauthorized disclosure. Therefore, the representation set forth in Paragraph 43 is false or misleading.
45. The acts and practices of respondent as alleged in this complaint constitute
deceptive acts or practices in or a ecting commerce in violation of Section
5(a) of the Federal Trade Commission Act, 15 U.S.C. § 45(a).
THEREFORE, the Federal Trade Commission this twenty-third day of December,
, has issued this complaint against respondent.
D
O
…
[Snapchat entered into a consent order under which it neither admitted nor denied the allegations in the complaint but agreed to certain changes in its business
practices.]
Definitions
For purposes of this Order, the following definitions shall apply: …
3. “Covered information” shall mean information from or about an individual
consumer, including but not limited to (a) a rst and last name; (b) a home
or other physical address, including street name and name of city or town;
(c) an email address or other online contact information, such as an instant
messaging user identi er or a screen name; (d) a telephone number; (e) a
persistent identi er, such as a customer number held in a “cookie,” a static
Internet Protocol (“IP”) address, a mobile device ID, or processor serial
number; (f ) precise geo-location data of an individual or mobile device, including GPS-based, Wi-Fi-based, or cell-based location information; (g) an
authentication credential, such as a username or password; or (h) any communications or content that is transmitted or stored through respondent’s
products or services.
0
2
Chapter 4: Privacy
Internet Law
I.
IT IS ORDERED that respondent and its officers, agents, representatives, and
employees, directly or indirectly, shall not misrepresent in any manner, expressly
or by implication, in or affecting commerce, the extent to which respondent or its
products or services maintain and protect the privacy, security, or confidentiality
of any covered information, including but not limited to: ( ) the extent to which a
message is deleted after being viewed by the recipient; ( ) the extent to which respondent or its products or services are capable of detecting or notifying the
sender when a recipient has captured a screenshot of, or otherwise saved, a message; ( ) the categories of covered information collected; or ( ) the steps taken to
protect against misuse or unauthorized disclosure of covered information.
II.
IT IS FURTHER ORDERED that respondent, in or affecting commerce, shall, no
later than the date of service of this order, establish and implement, and thereafter
maintain, a comprehensive privacy program that is reasonably designed to: ( )
address privacy risks related to the development and management of new and existing products and services for consumers, and ( ) protect the privacy and confidentiality of covered information, whether collected by respondent or input into,
stored on, captured with, or accessed through a computer using respondent’s
products or services. Such program, the content and implementation of which
must be fully documented in writing, shall contain privacy controls and procedures appropriate to respondent’s size and complexity, the nature and scope of
respondent’s activities, and the sensitivity of the covered information, including
[designation of employees responsible for the privacy program, identification of
forseeable privacy risks, implementation of reasonable privacy controls to address
those risks, appropriate security practices, and ongoing adjustment of the program
in light of changing circumstances].
III.
IT IS FURTHER ORDERED that, in connection with its compliance with Part II
of this order, respondent shall obtain initial and biennial assessments and reports
(“Assessments”) from a qualified, objective, independent third-party professional
…
VIII.
This order will terminate twenty ( ) years from the date of its issuance …
1
4
1
2
2
0
2
QUESTIONS
. FTC Authority: The FTC has the power to investigate and prohibit “unfair or
deceptive acts or practices in or affecting commerce.” Compare the FTC’s
civil enforcement action to the private consumer lawsuits in the previous
cases. Does the FTC have any advantages? Disadvantages?
. Substance vs. Notice: Was there anything wrong with Snapchat’s features, or
just with how they were described?
. Data Security: No statute or regulation specifically tells companies that “reasonable” security measures include “two-factor-authentication” techniques
like sending SMS messages to confirm a user’s phone number. But the FTC
dinged Snapchat anyway for failing to use two-factor-authentication. Did
Snapchat have reasonable notice of its legal obligations? What about future
companies deciding what security measures to employ in light of Snapchat?
3
3
2
1
276
277
. Is Privacy Dead? People send each other all kinds of things on Snapchat, and
post all kinds of things on Facebook and other social media services. Does
this mean that people no longer care about privacy, and the FTC should get
out of the way?
. Consent Decrees: The consent decree’s remedies are all forward-looking: they
are attempts to reform Snapchat’s privacy practices in the future, rather
than to penalize it for its past conduct. How effective will they be? If
Snapchat already has a duty not to commit “unfair or deceptive acts,” is the
consent decree redundant?
. Consumer Understanding: One recent survey found that six out of ten Americans surveyed responded “true” to the question, “If a website has a privacy
policy, it means that the site cannot share information about you with other
companies, unless you give the website your permission.” Are they correct?
After reading In re Snapchat, are you inclined to change your online behavior?
. Data Breach Notification: California has a “data breach law” requiring companies to inform consumers whose personal information (such as social security number, driver’s license number, or credit card number) is acquired by
unauthorized persons. What is the purpose of this kind of notification law?
How effective do you think it will be in limiting security breaches?
CALIFORNIA PRIVACY RIGHTS ACT*
California Civil Code
§
.
– General Duties of Businesses that Collect Personal Information
(a) A business that controls the collection of a consumer’s personal information
shall, at or before the point of collection, inform consumers of the following:
( ) The categories of personal information to be collected and the purposes for which the categories of personal information are collected or
used and whether that information is sold or shared. A business shall
not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information
was collected without providing the consumer with notice consistent
with this section.
( ) If the business collects sensitive personal information, the categories
of sensitive personal information to be collected and the purposes for
which the categories of sensitive personal information are collected or
used, and whether that information is sold or shared. …
( ) The length of time the business intends to retain each category of personal information, including sensitive personal information, or if that
is not possible, the criteria used to determine that period provided
that a business shall not retain a consumer’s personal information or
sensitive personal information for each disclosed purpose for which
8
1
0
2
0
2
0
2
0
1
0
3
2
1
8
9
7
* The California Consumer Privacy Act (CCPA) was enacted in
. The California
Privacy Rights Act (CPRA) was enacted in
by ballot initiative and substantially
amended the CCPA. California’s privacy-law framework is commonly referred to as
the CCPA, the CPRA, or both.
1
7
6
5
4
Chapter 4: Privacy
278
Internet Law
fi
fi
5
fi
6
1
0
6
4
3
2
8
7
0
1
1
8
8
9
9
7
7
1
1
the personal information was collected for longer than is reasonably
necessary for that disclosed purpose. …
(c) A business’ collection, use, retention, and sharing of a consumer’s personal
information shall be reasonably necessary and proportionate to achieve the
purposes for which the personal information was collected or processed, or
for another disclosed purpose that is compatible with the context in which
the personal information was collected, and not further processed in a manner that is incompatible with those purposes. …
(e) A business that collects a consumer’s personal information shall implement
reasonable security procedures and practices appropriate to the nature of
the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modi cation, or disclosure …
§
.
– Consumers’ Right to Delete Personal Information
(a) A consumer shall have the right to request that a business delete any personal information about the consumer which the business has collected
from the consumer. …
(d) A business … shall not be required to comply with a consumer’s request to
delete the consumer’s personal information if it is reasonably necessary for
the business, service provider, or contractor to maintain the consumer’s personal information in order to:
( ) Complete the transaction for which the personal information was collected, ful ll the terms of a written warranty or product recall conducted in accordance with federal law, provide a good or service requested by the consumer, or reasonably anticipated by the consumer
within the context of a business’ ongoing business relationship with
the consumer, or otherwise perform a contract between the business
and the consumer.
( ) Help to ensure security and integrity to the extent the use of the consumer’s personal information is reasonably necessary and proportionate for those purposes.
( ) Debug to identify and repair errors that impair existing intended
functionality.
( ) Exercise free speech, ensure the right of another consumer to exercise
that consumer’s right of free speech, or exercise another right provided for by law. …
( ) Engage in public or peer-reviewed scienti c, historical, or statistical
research that conforms or adheres to all other applicable ethics and
privacy laws, when the business’ deletion of the information is likely
to render impossible or seriously impair the ability to complete such
research, if the consumer has provided informed consent.
( ) To enable solely internal uses that are reasonably aligned with the expectations of the consumer based on the consumer’s relationship with
the business and compatible with the context in which the consumer
provided the information.
( ) Comply with a legal obligation.
§
.
– Consumers’ Right to Correct Inaccurate Personal Information
Chapter 4: Privacy
279
3
1
6
1
6
1
fi
3
1
ffi
1
0
3
1
5
0
1
1
2
5
4
1
3
2
2
2
1
1
1
1
8
8
8
8
9
9
9
9
7
7
7
7
1
1
1
1
(a) A consumer shall have the right to request a business that maintains inaccurate personal information about the consumer to correct that inaccurate
personal information, taking into account the nature of the personal information and the purposes of the processing of the personal information. …
§
.
– Consumers’ Right to Know What Personal Information is Being
Collected. Right to Access Personal Information
(a) A consumer shall have the right to request that a business that collects personal information about the consumer disclose to the consumer the following:
( ) The categories of personal information it has collected about that consumer.
( ) The categories of sources from which the personal information is collected.
( The business or commercial purpose for collecting, selling, or sharing
personal information.
( ) The categories of third parties to whom the business discloses personal information.
( ) The speci c pieces of personal information it has collected about that
consumer. …
§
.
– Consumers’ Right to Know What Personal Information is Sold or
Shared and to Whom
(a) A consumer shall have the right to request that a business that sells or
shares the consumer’s personal information, or that discloses it for a business purpose, disclose to that consumer:
( ) The categories of personal information that the business collected
about the consumer.
( ) The categories of personal information that the business sold or
shared about the consumer and the categories of third parties to
whom the personal information was sold or shared, by category or
categories of personal information for each category of third parties to
whom the personal information was sold or shared.
( ) The categories of personal information that the business disclosed
about the consumer for a business purpose and the categories of persons to whom it was disclosed for a business purpose. …
§
.
– Consumers’ Right to Opt Out of Sale or Sharing of Personal
Information
(a) A consumer shall have the right, at any time, to direct a business that sells or
shares personal information about the consumer to third parties not to sell
or share the consumer’s personal information. …
(c) Notwithstanding subdivision (a), a business shall not sell or share the personal information of consumers if the business has actual knowledge that
the consumer is less than
years of age, unless the consumer, in the case of
consumers at least
years of age and less than
years of age, or the consumer’s parent or guardian, in the case of consumers who are less than
years of age, has a rmatively authorized the sale or sharing of the consumer’s personal information. …
§
.
– Consumers’ Right to Limit Use and Disclosure of Sensitive
Personal Information
Internet Law
0
1
1
8
9
7
1
6
0
ff
1
ff
8
9
7
1
5
0
1
8
9
7
1
0
fi
0
1
8
9
7
1
ff
fi
ff
ff
ff
ff
5
2
1
8
ff
9
7
ff
1
1
5
1
1
2
2
3
1
0
3
5
1
1
8
1
9
7
8
8
9
9
1
7
(a) A consumer shall have the right, at any time, to direct a business that collects sensitive personal information about the consumer to limit its use of
the consumer’s sensitive personal information to that use which is necessary
to perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services …
§
.
– Consumers’ Right of No Retaliation Following Opt Out or
Exercise of Other Rights
(a)
( ) A business shall not discriminate against a consumer because the consumer exercised any of the consumer’s rights under this title, including, but not limited to, by:
(A) Denying goods or services to the consumer.
(B) Charging di erent prices or rates for goods or services, including through the use of discounts or other bene ts or imposing
penalties.
(C) Providing a di erent level or quality of goods or services to the
consumer.
(D) Suggesting that the consumer will receive a di erent price or
rate for goods or services or a di erent level or quality of goods
or services.
(E) Retaliating against an employee, applicant for employment, or
independent contractor …
( ) Nothing in this subdivision prohibits a business, pursuant to subdivision (b), from charging a consumer a di erent price or rate, or from
providing a di erent level or quality of goods or services to the consumer, if that di erence is reasonably related to the value provided to
the business by the consumer’s data.
( ) This subdivision does not prohibit a business from o ering loyalty,
rewards, premium features, discounts, or club card programs consistent with this title.
(b)
( ) A business may o er nancial incentives, including payments to consumers as compensation, for the collection of personal information,
the sale or sharing of personal information, or the retention of personal information. …
.
– Notice, Disclosure, Correction, and Deletion Requirements
(a) In order to comply with Sections
.
,
.
,
.
,
. ,
. , and
.
, a business shall, in a form that is reasonably accessible to consumers:
( )
(A) Make available to consumers two or more designated methods
for submitting requests … including, at a minimum, a toll-free
telephone number. A business that operates exclusively online
and has a direct relationship with a consumer from whom it
collects personal information shall only be required to provide
an email address for submitting requests …
7
1
1
280
281
(B) If the business maintains an internet website, make the internet
website available to consumers to submit requests …
( )
0
2
1
1
1
8
5
9
2
7
1
1
8
9
7
1
1
1
2
fi
1
8
9
5
7
1
1
1
2
8
2
1
1
9
7
1
0
1
1
8
9
7
1
6
0
5
1
4
8
9
7
1
5
1
1
5
0
8
fi
1
9
8
7
1
9
7
1
5
1
2
5
3
2
0
1
0
0
1
1
1
8
9
8
8
7
9
9
7
7
(A) Disclose and deliver the required information to a consumer
free of charge, correct inaccurate personal information, or
delete a consumer’s personal information, based on the consumer’s request, within
days of receiving a veri able consumer request from the consumer. …
( ) Disclose the following information in its online privacy policy or policies if the business has an online privacy policy or policies and in any
California-speci c description of consumers’ privacy rights, or if the
business does not maintain those policies, on its internet website, and
update that information at least once every months:
(A) A description of a consumer’s rights pursuant to Sections
.
,
.
,
.
,
. ,
. , and
.
and two or more designated methods for submitting requests,
except as provided in subparagraph (A) of paragraph ( ) of subdivision (a).
(B) For purposes of subdivision (c) of Section
. :
(i) A list of the categories of personal information it has collected about consumers in the preceding
months by
reference to the enumerated category or categories in
subdivision (c) that most closely describe the personal
information collected.
(ii) The categories of sources from which consumers’ personal information is collected.
(iii) The business or commercial purpose for collecting, selling, or sharing consumers’ personal information.
(iv) The categories of third parties to whom the business discloses consumers’ personal information. …
(b) A business is not obligated to provide the information required by Sections
.
and
.
to the same consumer more than twice in a -month
period.
§
.
– Methods of Limiting Sale, Sharing, and Use of Personal
Information and Use of Sensitive Personal Information
(a) A business that sells or shares consumers’ personal information or uses or
discloses consumers’ sensitive personal information for purposes other than
those authorized by subdivision (a) of Section
.
shall, in a form that
is reasonably accessible to consumers:
( ) Provide a clear and conspicuous link on the business’s internet homepages, titled “Do Not Sell or Share My Personal Information,” to an
internet web page that enables a consumer, or a person authorized by
the consumer, to opt-out of the sale or sharing of the consumer’s personal information.
( ) Provide a clear and conspicuous link on the business’ internet homepages, titled “Limit the Use of My Sensitive Personal Information,”
that enables a consumer, or a person authorized by the consumer, to
1
1
1
Chapter 4: Privacy
Internet Law
ffi
5
0
0
0
0
0
0
fi
5
2
fi
$
5
8
1
1
8
9
0
7
0
1
0
fi
0
5
fi
0
0
1
fi
fi
fi
fi
ff
0
1
4
1
1
fi
2
1
8
9
8
7
9
7
limit the use or disclosure of the consumer’s sensitive personal information to those uses authorized by subdivision (a) of Section
. .…
(d) Nothing in this title shall be construed to require a business to comply with
the title by including the required links and text on the homepage that the
business makes available to the public generally, if the business maintains a
separate and additional homepage that is dedicated to California consumers
and that includes the required links and text, and the business takes reasonable steps to ensure that California consumers are directed to the homepage
for California consumers and not the homepage made available to the public
generally. …
§
.
– De nitions
For purposes of this title: …
(d) “Business” means:
( ) A sole proprietorship, partnership, limited liability company, corporation, association, or other legal entity that is organized or operated for
the pro t or nancial bene t of its shareholders or other owners, that
collects consumers’ personal information … and that … determines
the purposes and means of the processing of consumers’ personal information, that does business in the State of California, and that satises one or more of the following thresholds:
(A) As of January of the calendar year, had annual gross revenues
in excess of twenty- ve million dollars (
,
,
) in the
preceding calendar year, as adjusted pursuant to paragraph ( )
of subdivision (a) of Section
.
.
(B) Alone or in combination, annually buys, sells, or shares the personal information of
,
or more consumers or households.
(C) Derives
percent or more of its annual revenues from selling
or sharing consumers’ personal information. …
(h) “Consent” means any freely given, speci c, informed, and unambiguous indication of the consumer’s wishes by which the consumer, or the consumer’s
legal guardian, a person who has power of attorney, or a person acting as a
conservator for the consumer, including by a statement or by a clear a rmative action, signi es agreement to the processing of personal information
relating to the consumer for a narrowly de ned particular purpose. Acceptance of a general or broad terms of use, or similar document, that contains
descriptions of personal information processing along with other, unrelated
information, does not constitute consent. Hovering over, muting, pausing,
or closing a given piece of content does not constitute consent. Likewise,
agreement obtained through use of dark patterns does not constitute consent.
(i) “Consumer” means a natural person who is a California resident …
(l) “Dark pattern” means a user interface designed or manipulated with the
substantial e ect of subverting or impairing user autonomy, decisionmaking, or choice, as further de ned by regulation.
(n) “Designated methods for submitting requests” means a mailing address,
email address, internet web page, internet web portal, toll-free telephone
1
1
fi
282
Chapter 4: Privacy
283
fi
fi
5
8
fi
1
8
9
7
1
0
1
1
1
5
2
9
3
4
2
9
9
1
1
1
8
8
8
9
9
9
7
7
7
1
1
1
number, or other applicable contact information, whereby consumers may
submit a request or direction under this title, and any new, consumerfriendly means of contacting a business, as approved by the Attorney General pursuant to Section
.
.
(ae) “Sensitive personal information” means:
( ) Personal information that reveals:
(A) A consumer’s social security, driver’s license, state identi cation
card, or passport number.
(B) A consumer’s account log-in, nancial account, debit card, or
credit card number in combination with any required security
or access code, password, or credentials allowing access to an
account.
(C) A consumer’s precise geolocation.
(D) A consumer’s racial or ethnic origin, citizenship or immigration
status, religious or philosophical beliefs, or union membership.
(E) The contents of a consumer’s mail, email, and text messages
unless the business is the intended recipient of the communication.
(F) A consumer’s genetic data. …
( ) Sensitive personal information that is “publicly available” … shall not
be considered sensitive personal information or personal information.
§
.
– Exemptions
(a)
( ) The obligations imposed on businesses by this title shall not restrict a
business’s ability to:
(A) Comply with federal, state, or local laws or comply with a court
order or subpoena to provide information. …
(F) Collect, use, retain, sell, share, or disclose consumers’ personal
information that is deidenti ed or aggregate consumer information.
(G) Collect, sell, or share a consumer’s personal information if every
aspect of that commercial conduct takes place wholly outside of
California. …
( )
(A) This subdivision shall not apply if the consumer’s personal information contains information related to accessing, procuring,
or searching for services regarding contraception, pregnancy
care, and perinatal care, including, but not limited to, abortion
services. …
§
.
– Waiver
Any provision of a contract or agreement of any kind, including a representative
action waiver, that purports to waive or limit in any way rights under this title …
shall be deemed contrary to public policy and shall be void and unenforceable. …
§
.
. .
(a) There is hereby established in state government the California Privacy Protection Agency, which is vested with full administrative power, authority, and
Internet Law
jurisdiction to implement and enforce the California Consumer Privacy Act
of
.…
§
.
. .
(a) When the agency determines there is probable cause for believing this title
has been violated, it shall hold a hearing to determine if a violation has or
violations have occurred. … If the agency determines on the basis of the
hearing conducted pursuant to this subdivision that a violation or violations
have occurred, it shall issue an order that may require the violator to do all
or any of the following:
( ) Cease and desist violation of this title.
( ) Subject to Section
.
, pay an administrative ne of up to two
thousand ve hundred dollars ( ,
) for each violation, or up to
seven thousand ve hundred dollars ( ,
) for each intentional
violation and each violation involving the personal information of minor consumers …
QUESTIONS
. Sectoral Privacy Law: United States privacy law is usually referred to as “sectoral” because it applies to specific types of information. You have already
met the VPPA in Eichenberger. The Children’s Online Privacy Protection Act
(COPPA) prohibits collecting private information from children under
without parental consent. The most rigorous such law is probably the
Health Insurance Portability and Accountability Act, which imposes quite
detailed confidentiality and security obligations on medical professionals
and those working with health records. Does the CPRA change this picture
for the better or for the worse?
. Privacy Federalism: Notice that the CPRA is a state privacy law. How does it
apply to companies and users outside of California. Should the United
States adopt a national privacy law modeled on the CPRA? Should it adopt a
national law that preempts state privacy laws like the CPRA?
3
1
fi
0
0
5
7
$
5
0
5
1
0
5
8
9
2
7
$
1
fi
5
5
fi
9
1
9
2
1
8
1
8
0
9
7
2
COOKIE MONSTER PROBLEM
Cookie Monster is a browser extension that eats cookies. Users install it by downloading it from the Cookie Monster website. After that, every fifteen minutes. it
deletes all third-party cookies of the sort used by DoubleClick and other advertising networks. Consumers can turn off Cookie Monster for a particular website by
clicking a button in the top left corner of the browser window.
Ozalytics is a “website analytics” service used by websites to keep track of how
many visitors they have and what those visitors are doing on the site. It works very
much like advertising networks (and Twitter “tweet this” buttons, for that matter):
by embedding a small image hosted at ozalytics.com into every page on a website
that uses it service. That image can then set a cookie in the user’s browser to track
the user’s engagement with the website.
Unfortunately for Ozalytics, Cookie Monster deletes its cookies, making the
information it returns to websites much less useful. Ozalytics has responded by
asking host websites to include a “Cookie Monster workaround,” consisting of little
bit of Ozalytics JavaScript code on each webpage, in addition to the Ozalyitics image. That code instructs the user’s browser to simulate a mouse click on the corner
1
1
2
284
Chapter 4: Privacy
285
of the window where the button to disable Cookie Monster for that website is located.
You represent SometimeSnack.com, a website devoted to healthy cooking tips
for parents. You have been asked to consider whether to implement Ozalytics’ proposed Cookie Monster workaround, and if so, how to do it. What is your advice?
F. Privacy Law in the European Union
In the European Union (E.U.), privacy is considered a fundamental right; privacy
laws are both stronger and more general than in the United States. Article of the
Charter of Fundamental Rights of the European Union gives all people “the right
to the protection of personal data concerning him or her.” The General Data Protection Regulation puts serious teeth on that principle. This section sets out the
key passages from the GDPR, along with an important recent decision from the
European Court of Justice (ECJ) – a loose European parallel to the United States
Supreme Court – that show some of the recent controversies raised by Europe's
increasingly strong commitments to privacy.
GENERAL DATA PROTECTION REGULATION
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the
Protection of Natural Persons with Regard to the Processing of Personal Data and on the
Free Movement of Such Data, and Repealing Directive 95/46/EC
[2016] OJ L 119/1
8
1
2
3
2
1
2
1
1
art. – Subject-matter and objectives
( ) This Regulation lays down rules relating to the protection of natural persons
with regard to the processing of personal data and rules relating to the free
movement of personal data.
( ) This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data. …
art. – Material scope
( ) This Regulation applies to the processing of personal data wholly or partly
by automated means and to the processing other than by automated means
of personal data which form part of a filing system or are intended to form
part of a filing system.
( ) This Regulation does not apply to the processing of personal data: …
(c) by a natural person in the course of a purely personal or household
activity;
(d) by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution
of criminal penalties, including the safeguarding against and the prevention of threats to public security. …
art. – Territorial scope
( ) This Regulation applies to the processing of personal data in the context of
the activities of an establishment of a controller or a processor in the Union,
regardless of whether the processing takes place in the Union or not.
286
Internet Law
1
9
8
fi
4
5
2
8
7
2
1
1
1
1
( ) This Regulation applies to the processing of personal data of data subjects
who are in the Union by a controller or processor not established in the
Union, where the processing activities are related to:
(a) the offering of goods or services, irrespective of whether a payment of
the data subject is required, to such data subjects in the Union; or
(b) the monitoring of their behaviour as far as their behaviour takes place
within the Union. …
art. –De nitions
For the purposes of this Regulation:
( ) personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one
who can be identified, directly or indirectly, in particular by reference to an
identifier such as a name, an identification number, location data, an online
identifier or to one or more factors specific to the physical, physiological,
genetic, mental, economic, cultural or social identity of that natural person;
( ) ’processing’ means any operation or set of operations which is performed on
personal data or on sets of personal data, whether or not by automated
means, such as collection, recording, organisation, structuring, storage,
adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; …
( ) ‘controller’ means the natural or legal person, public authority, agency or
other body which, alone or jointly with others, determines the purposes and
means of the processing of personal data; where the purposes and means of
such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by
Union or Member State law;
( ) ’processor’ means a natural or legal person, public authority, agency or other
body which processes personal data on behalf of the controller; …
( ) ‘consent’ of the data subject means any freely given, specific, informed and
unambiguous indication of the data subject’s wishes by which he or she, by a
statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her; …
art. – Principles relating to processing of personal data
( ) Personal data shall be:
(a) processed lawfully, fairly and in a transparent manner in relation to
the data subject (‘lawfulness, fairness and transparency’);
(b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes;
further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in
accordance with Article
( ), not be considered to be incompatible
with the initial purposes (‘purpose limitation’);
(c) adequate, relevant and limited to what is necessary in relation to the
purposes for which they are processed (‘data minimisation’);
(d) accurate and, where necessary, kept up to date; every reasonable step
must be taken to ensure that personal data that are inaccurate, having
Chapter 4: Privacy
287
1
9
8
1
6
7
2
1
3
2
1
regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);
(e) kept in a form which permits identification of data subjects for no
longer than is necessary for the purposes for which the personal data
are processed; personal data may be stored for longer periods insofar
as the personal data will be processed solely for archiving purposes in
the public interest, scientific or historical research purposes or statistical purposes in accordance with Article
( ) … (‘storage
limitation’);
(f ) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful
processing and against accidental loss, destruction or damage, using
appropriate technical or organisational measures (‘integrity and confidentiality’).
( ) The controller shall be responsible for, and be able to demonstrate compliance with, paragraph (‘accountability’).
art. – Lawfulness of processing
( ) Processing shall be lawful only if and to the extent that at least one of the
following applies:
(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
(b) processing is necessary for the performance of a contract to which the
data subject is party or in order to take steps at the request of the data
subject prior to entering into a contract;
(c) processing is necessary for compliance with a legal obligation to
which the controller is subject;
(d) processing is necessary in order to protect the vital interests of the
data subject or of another natural person;
(e) processing is necessary for the performance of a task carried out in
the public interest or in the exercise of official authority vested in the
controller;
(f ) processing is necessary for the purposes of the legitimate interests
pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in
particular where the data subject is a child.
art. – Conditions for consent
( ) Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.
( ) If the data subject’s consent is given in the context of a written declaration
which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an
intelligible and easily accessible form, using clear and plain language. …
( ) The data subject shall have the right to withdraw his or her consent at any
time. The withdrawal of consent shall not affect the lawfulness of processing
based on consent before its withdrawal. Prior to giving consent, the data
288
Internet Law
1
6
1
1
2
9
1
3
9
1
2
1
2
1
subject shall be informed thereof. It shall be as easy to withdraw as to give
consent.
art. – Processing of special categories of personal data
( ) Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the
processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural
person’s sex life or sexual orientation shall be prohibited.
( ) Paragraph shall not apply if one of the following applies:
(a) the data subject has given explicit consent to the processing of those
personal data for one or more specified purposes, except where Union
or Member State law provide that the prohibition referred to in paragraph may not be lifted by the data subject; …
(e) processing relates to personal data which are manifestly made public
by the data subject; …
(g) processing is necessary for reasons of substantial public interest, on
the basis of Union or Member State law which shall be proportionate
to the aim pursued, respect the essence of the right to data protection
and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject; …
art. – Information to be provided where personal data are collected from
the data subject
( ) Where personal data relating to a data subject are collected from the data
subject, the controller shall, at the time when personal data are obtained,
provide the data subject with all of the following information:
(a) the identity and the contact details of the controller and, where applicable, of the controller’s representative; …
(c) the purposes of the processing for which the personal data are intended as well as the legal basis for the processing; …
( ) In addition to the information referred to in paragraph , the controller
shall, at the time when personal data are obtained, provide the data subject
with the following further information necessary to ensure fair and transparent processing:
(a) the period for which the personal data will be stored, or if that is not
possible, the criteria used to determine that period;
(b) the existence of the right to request from the controller access to and
rectification or erasure of personal data or restriction of processing
concerning the data subject or to object to processing as well as the
right to data portability;
(c) where the processing is based on point (a) of Article ( ) or point (a)
of Article ( ), the existence of the right to withdraw consent at any
time, without affecting the lawfulness of processing based on consent
before its withdrawal;
(d) the right to lodge a complaint with a supervisory authority;
(e) whether the provision of personal data is a statutory or contractual
requirement, or a requirement necessary to enter into a contract, as
Chapter 4: Privacy
289
1
1
2
3
1
2
2
1
9
2
3
1
6
2
4
fi
1
2
2
fi
5
6
7
1
1
1
3
1
4
3
1
well as whether the data subject is obliged to provide the personal
data and of the possible consequences of failure to provide such data;
(f ) the existence of automated decision-making, including profiling, referred to in Article ( ) and ( ) and, at least in those cases, meaningful information about the logic involved, as well as the significance
and the envisaged consequences of such processing for the data subject.
( ) Where the controller intends to further process the personal data for a purpose other than that for which the personal data were collected, the controller shall provide the data subject prior to that further processing with
information on that other purpose and with any relevant further information as referred to in paragraph .
art. – Right of access by the data subject
( ) The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:
[information analogous to categories quoted above in art. and also]
(c) the recipients or categories of recipient to whom the personal data
have been or will be disclosed, in particular recipients in third countries or international organisations; …
(g) where the personal data are not collected from the data subject, any
available information as to their source; …
( ) The controller shall provide a copy of the personal data undergoing processing. … Where the data subject makes the request by electronic means, and
unless otherwise requested by the data subject, the information shall be
provided in a commonly used electronic form.
( ) The right to obtain a copy referred to in paragraph shall not adversely affect the rights and freedoms of others.
art.
– Right to recti cation
The data subject shall have the right to obtain from the controller without undue
delay the recti cation of inaccurate personal data concerning him or her. …
art. – Right to erasure (‘right to be forgotten’)
( ) The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the
controller shall have the obligation to erase personal data without undue
delay where one of the following grounds applies:
(a) the personal data are no longer necessary in relation to the purposes
for which they were collected or otherwise processed;
(b) the data subject withdraws consent on which the processing is based
according to point (a) of Article ( ), or point (a) of Article ( ), and
where there is no other legal ground for the processing;
(c) the data subject objects to the processing pursuant to Article ( )
and there are no overriding legitimate grounds for the processing, or
the data subject objects to the processing pursuant to Article ( );
(d) the personal data have been unlawfully processed; …
Internet Law
1
6
1
1
6
1
2
2
9
1
1
1
6
0
1
2
2
2
3
1
1
2
1
3
( ) Where the controller has made the personal data public and is obliged pursuant to paragraph to erase the personal data, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are
processing the personal data that the data subject has requested the erasure
by such controllers of any links to, or copy or replication of, those personal
data.
( ) Paragraphs and shall not apply to the extent that processing is necessary:
(a) for exercising the right of freedom of expression and information;
(b) for compliance with a legal obligation which requires processing by
Union or Member State law to which the controller is subject or for
the performance of a task carried out in the public interest or in the
exercise of official authority vested in the controller;
(c) for reasons of public interest in the area of public health …
(d) for archiving purposes in the public interest, scientific or historical
research purposes or statistical purposes in accordance with Article
( ) in so far as the right referred to in paragraph is likely to render
impossible or seriously impair the achievement of the objectives of
that processing; or
(e) for the establishment, exercise or defence of legal claims.
art.
– Right to data portability
( ) The data subject shall have the right to receive the personal data concerning
him or her, which he or she has provided to a controller, in a structured,
commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller
to which the personal data have been provided, where:
(a) the processing is based on consent pursuant to point (a) of Article ( )
or point (a) of Article ( ) or on a contract pursuant to point (b) of
Article ( ); and
(b) the processing is carried out by automated means.
( ) In exercising his or her right to data portability pursuant to paragraph , the
data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible. …s
art.
– Right to object
( ) The data subject shall have the right to object, on grounds relating to his or
her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f ) of Article ( ), including
profiling based on those provisions. The controller shall no longer process
the personal data unless the controller demonstrates compelling legitimate
grounds for the processing which override the interests, rights and freedoms
of the data subject or for the establishment, exercise or defence of legal
claims. …
( ) Where the data subject objects to processing for direct marketing purposes,
the personal data shall no longer be processed for such purposes.
9
8
290
Chapter 4: Privacy
291
fi
2
4
5
8
2
2
2
2
2
3
1
1
3
1
1
2
1
art.
– Automated individual decision-making, including pro ling
( ) The data subject shall have the right not to be subject to a decision based
solely on automated processing, including profiling, which produces legal
effects concerning him or her or similarly significantly affects him or her. …
art.
– Responsibility of the controller
( ) Taking into account the nature, scope, context and purposes of processing as
well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate
that processing is performed in accordance with this Regulation. Those
measures shall be reviewed and updated where necessary. …
art.
– Data protection by design and by default
( )
Taking into account the state of the art, the cost of implementation and the
nature, scope, context and purposes of processing as well as the risks of
varying likelihood and severity for rights and freedoms of natural persons
posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself,
implement appropriate technical and organisational measures, such as
pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate
the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.
( ) The controller shall implement appropriate technical and organisational
measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such
measures shall ensure that by default personal data are not made accessible
without the individual’s intervention to an indefinite number of natural persons. …
art.
– Processor
( ) Where processing is to be carried out on behalf of a controller, the controller
shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject. …
( ) Processing by a processor shall be governed by a contract or other legal act
under Union or Member State law, that is binding on the processor with
regard to the controller and that sets out the subject-matter and duration of
the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of
the controller. …
art.
– Security of processing
( ) Taking into account the state of the art, the costs of implementation and the
nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons,
the controller and the processor shall implement appropriate technical and
organisational measures to ensure a level of security appropriate to the risk,
…
292
Internet Law
1
3
5
4
2
7
fi
3
4
4
5
6
1
7
3
3
4
4
4
5
7
3
1
2
1
1
1
1
1
( ) In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of,
or access to personal data transmitted, stored or otherwise processed. …
art.
– Noti cation of a personal data breach to the supervisory authority
( ) In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than
hours after having become aware
of it, notify the personal data breach to the supervisory authority … unless
the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. …
art.
– Communication of a personal data breach to the data subject
( ) When the personal data breach is likely to result in a high risk to the rights
and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.
( ) The communication to the data subject referred to in paragraph of this
Article shall describe in clear and plain language the nature of the personal
data breach …
art.
– General principle for transfers
Any transfer of personal data which are undergoing processing or are intended for
processing after transfer to a third country or to an international organisation
shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with …
art.
– Transfers on the basis of an adequacy decision
( ) A transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or
the international organisation in question ensures an adequate level of protection. Such a transfer shall not require any specific authorisation. …
art.
– Transfers subject to appropriate safeguards
( ) In the absence of a decision pursuant to Article ( ), a controller or processor may transfer personal data to a third country or an international organisation only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective
legal remedies for data subjects are available.
art. – Supervisory authority
( ) Each Member State shall provide for one or more independent public authorities to be responsible for monitoring the application of this Regulation,
in order to protect the fundamental rights and freedoms of natural persons
in relation to processing and to facilitate the free flow of personal data within the Union (‘supervisory authority’). …
art – Right to lodge a complaint with a supervisory authority
( ) Without prejudice to any other administrative or judicial remedy, every data
subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place
of work or place of the alleged infringement if the data subject considers
that the processing of personal data relating to him or her infringes this
Regulation. …
293
art.
– Right to compensation and liability
( ) Any person who has suffered material or non-material damage as a result of
an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered.
art.
– Processing and freedom of expression and information
( ) Member States shall by law reconcile the right to the protection of personal
data pursuant to this Regulation with the right to freedom of expression and
information, including processing for journalistic purposes and the purposes of academic, artistic or literary expression.
( ) For processing carried out for journalistic purposes or the purpose of academic artistic or literary expression, Member States shall provide for exemptions or derogations from [most of the provisions of the GDPR] if they are
necessary to reconcile the right to the protection of personal data with the
freedom of expression and information.
art.
– Safeguards and derogations relating to processing for archiving
purposes in the public interest, scienti c or historical research purposes or
statistical purposes
( ) Processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, shall be subject to appropriate
safeguards, in accordance with this Regulation, for the rights and freedoms
of the data subject. Those safeguards shall ensure that technical and organisational measures are in place in particular in order to ensure respect for the
principle of data minimisation. Those measures may include pseudonymisation provided that those purposes can be fulfilled in that manner. Where
those purposes can be fulfilled by further processing which does not permit
or no longer permits the identification of data subjects, those purposes shall
be fulfilled in that manner.
( ) Where personal data are processed for scientific or historical research purposes or statistical purposes, Union or Member State law may provide for
derogations from the rights referred to in Articles , ,
and
subject
to the conditions and safeguards referred to in paragraph of this Article in
so far as such rights are likely to render impossible or seriously impair the
achievement of the specific purposes, and such derogations are necessary for
the fulfilment of those purposes. …
8
1
0
2
1
2
8
1
1
6
1
5
5
1
1
fi
5
4
2
5
9
8
8
8
1
2
1
1
QUESTIONS
. E.U. vs. U.S.; How does the European approach to the privacy of personal
data compare with the American approach discussed above? (In June
,
California adopted a Consumer Privacy Act that extensively regulates the
collection and sale of personal data, so the difference may be narrowing …)
. Algorithmic Decisions: What do you make of Article ’s prohibition on decision-making “solely on automated processing of [personal] data?” Credit
checks are ubiquitous in the United States, not just when applying for loans
but also in applying for jobs and leases. How would they fare under the Data
Protection Directive?
. Transfers: Note Article ’s rule allowing transfers to non-E.U. countries on
the basis of a decision that they provide adequate privacy protections. Does
the rule depend on an outdated concept of data having a physical location? Is
United States law adequate? Are U.S. companies most likely to ignore the
GDPR, comply with it, or block E.U. users?
2
1
2
3
Chapter 4: Privacy
Internet Law
. Accept Cookies? The EU “Cookie Directive,”
/
/EC, requires that “the
storing of info mation, or the gaining of access to information already stored,
in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user co cerned has given his or her consent, having been provided with clear and comprehensive information … about the
purposes of the processing.” Have you visited any websites that comply with
this requirement? That fail to comply with it? Has the Cookie Directive improved or impaired the Internet? Does it shed any light on the GDPR?
GOOGLE SPAIN SP V. AGENCIA ESPAÑOLA DE PROTECCIÓN DE DATOS
European Court of Justice
ECLI:EU:C:2014:616
…T
r
o
f
d
e
r
r
e
f
e
r
s
n
o
i
t
s
fi
e
u
q
6
e
3
1
h
t
9
d
0
n
0
a
2
s
g
fi
n
i
d
ff
e
e
n­
c
o
r
p
n
i
a
m
e
g
h
n
i
t
l
n
u
i
r
e
r­
t
y
r
u
p
a
s
n
i
i
d
m
i
e
l
h
e
r
14. On 5 March 2010, Mr Costeja González, a Spanish national resident in
Spain, lodged with the [Agencia Española de Protección de Datos (Spanish
Data Protection Agency) (AEPD)] a complaint against La Vanguardia Ediciones SL, which publishes a daily newspaper with a large circulation, in
particular in Catalonia (Spain) (’La Vanguardia’), and against Google Spain
and Google Inc. The complaint was based on the fact that, when an internet
user entered Mr Costeja González’s name in the search engine of the Google
group (’Google Search’), he would obtain links to two pages of La Vanguardia’s newspaper, of 19 January and 9 March 1998 respectively, on which
an announcement mentioning Mr Costeja González’s name appeared for a
real-estate auction connected with attachment proceedings for the recovery
of social security debts.
15. By that complaint, Mr Costeja González requested, rst, that La Vanguardia
be required either to remove or alter those pages so that the personal data
relating to him no longer appeared or to use certain tools made available by
search engines in order to protect the data. Second, he requested that
Google Spain or Google Inc. be required to remove or conceal the personal
data relating to him so that they ceased to be included in the search results
and no longer appeared in the links to La Vanguardia. Mr Costeja González
stated in this context that the attachment proceedings concerning him had
been fully resolved for a number of years and that reference to them was
now entirely irrelevant.
16. By decision of 30 July 2010, the AEPD rejected the complaint in so far as it
related to La Vanguardia, taking the view that the publication by it of the
information in question was legally justi ed as it took place upon order of
the Ministry of Labour and Social A airs and was intended to give maximum publicity to the auction in order to secure as many bidders as possible.
17. On the other hand, the complaint was upheld in so far as it was directed
against Google Spain and Google Inc. The AEPD considered in this regard
that operators of search engines are subject to data protection legislation
given that they carry out data processing for which they are responsible and
act as intermediaries in the information society. The AEPD took the view
that it has the power to require the withdrawal of data and the prohibition
of access to certain data by the operators of search engines when it considers
that the locating and dissemination of the data are liable to compromise the
fundamental right to data protection and the dignity of persons in the broad
p
4
a
294
Chapter 4: Privacy
295
f
ff
fi
d
e
r
r
e
f
fi
e
fi
r
s
ff
n
o
i
t
s
e
u
fi
fi
q
e
h
t
f
o
n
o
i
t
a
r
e
fi
d
i
s
n
o
sense, and this would also encompass the mere wish of the person concerned that such data not be known to third parties. The AEPD considered
that that obligation may be owed directly by operators of search engines,
without it being necessary to erase the data or information from the website
where they appear, including when retention of the information on that site
is justi ed by a statutory provision.
18. Google Spain and Google Inc. brought separate actions against that decision
…
C
Question 2(a) and (b), concerning the material scope of Directive 95/46 …
22. According to Google Spain and Google Inc., the activity of search engines
cannot be regarded as processing of the data which appear on third parties’
web pages displayed in the list of search results, given that search engines
process all the information available on the internet without e ecting a selection between personal data and other information. Furthermore, even if
that activity must be classi ed as ‘data processing’, the operator of a search
engine cannot be regarded as a ‘controller’ in respect of that processing since
it has no knowledge of those data and does not exercise control over the
data. …
25. Article 2(b) of Directive 95/46 de nes ‘processing of personal data’ as ‘any
operation or set of operations which is performed upon personal data,
whether or not by automatic means, such as collection, recording, organisation, storage, adaptation or alteration, retrieval, consultation, use, disclosure
by transmission, dissemination or otherwise making available, alignment or
combination, blocking, erasure or destruction’. …
27. So far as concerns the activity at issue in the main proceedings, it is not contested that the data found, indexed and stored by search engines and made
available to their users include information relating to identi ed or identi able natural persons and thus ‘personal data’ within the meaning of Article
2(a) of that directive.
28. Therefore, it must be found that, in exploring the internet automatically,
constantly and systematically in search of the information which is published there, the operator of a search engine ‘collects’ such data which it subsequently ‘retrieves’, ‘records’ and ‘organises’ within the framework of its indexing programmes, ‘stores’ on its servers and, as the case may be, ‘discloses’
and ‘makes available’ to its users in the form of lists of search results. As
those operations are referred to expressly and unconditionally in Article 2(b)
of Directive 95/46, they must be classi ed as ‘processing’ within the meaning of that provision, regardless of the fact that the operator of the search
engine also carries out the same operations in respect of other types of information and does not distinguish between the latter and the personal
data.
29. Nor is the foregoing nding a ected by the fact that those data have already
been published on the internet and are not altered by the search engine. …
[The court then found that Google was a controller of the processing of personal
data by its search engine because “the search engine operator which determines
the purposes and means of that activity and thus of the processing of personal data
that it itself carries out.”]
296
Internet Law
ffi
fi
fi
fi
ff
ff
fi
ff
ff
ff
ffi
Question 1(a) to (d), concerning the territorial scope of Directive 95/46 …
60 … Article 4(1)(a) of Directive 95/46 is to be interpreted as meaning that
processing of personal data is carried out in the context of the activities of
an establishment of the controller on the territory of a Member State, within
the meaning of that provision, when the operator of a search engine sets up
in a Member State a branch or subsidiary which is intended to promote and
sell advertising space o ered by that engine and which orientates its activity
towards the inhabitants of that Member State. …
Question 2(c) and (d), concerning the extent of the responsibility of the
operator of a search engine under Directive 95/46 …
63. Google Spain and Google Inc. submit that, by virtue of the principle of proportionality, any request seeking the removal of information must be addressed to the publisher of the website concerned because it is he who takes
the responsibility for making the information public, who is in a position to
appraise the lawfulness of that publication and who has available to him the
most e ective and least restrictive means of making the information inaccessible. Furthermore, to require the operator of a search engine to withdraw information published on the internet from its indexes would take insu cient account of the fundamental rights of publishers of websites, of
other internet users and of that operator itself. …
80. It must be pointed out at the outset that … processing of personal data, such
as that at issue in the main proceedings, carried out by the operator of a
search engine is liable to a ect signi cantly the fundamental rights to privacy and to the protection of personal data when the search by means of that
engine is carried out on the basis of an individual’s name, since that processing enables any internet user to obtain through the list of results a structured overview of the information relating to that individual that can be
found on the internet – information which potentially concerns a vast number of aspects of his private life and which, without the search engine, could
not have been interconnected or could have been only with great di culty –
and thereby to establish a more or less detailed pro le of him. Furthermore,
the e ect of the interference with those rights of the data subject is heightened on account of the important role played by the internet and search engines in modern society, which render the information contained in such a
list of results ubiquitous.
81. In the light of the potential seriousness of that interference, it is clear that it
cannot be justi ed by merely the economic interest which the operator of
such an engine has in that processing. However, inasmuch as the removal of
links from the list of results could, depending on the information at issue,
have e ects upon the legitimate interest of internet users potentially interested in having access to that information, in situations such as that at issue
in the main proceedings a fair balance should be sought in particular between that interest and the data subject’s fundamental rights under Articles
7 and 8 of the Charter. Whilst it is true that the data subject’s rights protected by those articles also override, as a general rule, that interest of internet
users, that balance may however depend, in speci c cases, on the nature of
the information in question and its sensitivity for the data subject’s private
life and on the interest of the public in having that information, an interest
Chapter 4: Privacy
297
ff
fi
ff
fi
which may vary, in particular, according to the role played by the data subject in public life.
82. … when a request such as that at issue in the main proceedings is lodged
with it, the supervisory authority or judicial authority may order the operator of the search engine to remove from the list of results displayed following
a search made on the basis of a person’s name links to web pages published
by third parties containing information relating to that person, without an
order to that e ect presupposing the previous or simultaneous removal of
that name and information – from the web page on which they were published. …
84. Given the ease with which information published on a website can be replicated on other sites and the fact that the persons responsible for its publication are not always subject to European Union legislation, e ective and
complete protection of data users could not be achieved if the latter had to
obtain rst or in parallel the erasure of the information relating to them
from the publishers of websites. …
87. Indeed, since the inclusion in the list of results, displayed following a search
made on the basis of a person’s name, of a web page and of the information
contained on it relating to that person makes access to that information appreciably easier for any internet user making a search in respect of the person concerned and may play a decisive role in the dissemination of that information, it is liable to constitute a more signi cant interference with the
data subject’s fundamental right to privacy than the publication on the web
page.
88. In the light of all the foregoing considerations … the operator of a search
engine is obliged to remove from the list of results displayed following a
search made on the basis of a person’s name links to web pages … even, as
the case may be, when its publication in itself on those pages is lawful.
Question 3, concerning the scope of the data subject’s rights guaranteed by
Directive 95/46
93. … even initially lawful processing of accurate data may, in the course of time,
become incompatible with the directive where those data are no longer necessary in the light of the purposes for which they were collected or processed. That is so in particular where they appear to be inadequate, irrelevant or no longer relevant, or excessive in relation to those purposes and in
the light of the time that has elapsed.
94. Therefore, if it is found, following a request by the data subject pursuant to
Article 12(b) of Directive 95/46, that the inclusion in the list of results displayed following a search made on the basis of his name of the links to web
pages published lawfully by third parties and containing true information
relating to him personally is, at this point in time, incompatible with Article
6(1)(c) to (e) of the directive because that information appears, having regard to all the circumstances of the case, to be inadequate, irrelevant or no
longer relevant, or excessive in relation to the purposes of the processing at
issue carried out by the operator of the search engine, the information and
links concerned in the list of results must be erased. …
97. [The rights of the data subject] override, as a rule, not only the economic
interest of the operator of the search engine but also the interest of the gen-
QUESTIONS
RTBF: Some observers have referred to this decision as creating a “right to be
forgotten” in the European Union. Does it? Does the GDPR?
Removal Process: After Google Spain, what process does someone in the E.U.
need to follow to have unflattering search results removed from search
engines? Who will make the ultimate decision on whether the results will be
removed, and what evidence will they consider?
Compare and Contrast: What result under United States law? Why?
Some Results May Have Been Removed: What can and should Google tell users
when search results have been removed due to a removal request?
Global Removal? Must Google remove these search results for users in Spain?
In the E.U.? Worldwide?
.
.
.
.
.
G. Children’s Privacy
The United States does not have a comprehensive privacy law, a comprehensive
children’s privacy law, or a comprehensive online privacy law. But it does have a
children’s online privacy law — and recently, there has been an explosion of interest in state law-making around children’s use of the Internet.
UNITED STATES OF AMERICA V. EPIC GAMES, INC.
No. 5:22-CV-00518 (W.D.N.C complaint led Dec. 19, 2022)
6
1
3
5
1
3
0
1
5
3
1
1
8
9
9
1
5
fi
1
fi
5
7
5
1
fi
6
5
3
5
0
5
5
6
1
2
0
fi
5
ff
6
5
4
9
1
ff
1
6
1
0
5
3
Plainti , the United States of America, acting upon noti cation and on behalf of
the Federal Trade Commission (“Commission” or “FTC”), for its Complaint alleges:
. Plainti brings this action under Sections (a)( ), (m)( )(A), (b), (a)
( ), and
of the Federal Trade Commission Act (“FTC Act”),
U.S.C. §§
(a)( ),
(m)( )(A),
(b),
(a)( ),
b, and Sections
(c) and
(d) of the Children’s Online Privacy Protection Act of
(“COPPA”),
U.S.C. §§
(c),
(d), to obtain monetary civil penalties, a permanent injunction, and other relief for Defendant’s violations of Section of
5
5
4
3
2
1
Internet Law
eral public in nding that information upon a search relating to the data
subject’s name. However, that would not be the case if it appeared, for particular reasons, such as the role played by the data subject in public life, that
the interference with his fundamental rights is justi ed by the preponderant
interest of the general public in having, on account of inclusion in the list of
results, access to the information in question.
98. As regards [Mr. González], it should be held that, having regard to the sensitivity for the data subject’s private life of the information contained in
those announcements and to the fact that its initial publication had taken
place 16 years earlier, the data subject establishes a right that that information should no longer be linked to his name by means of such a list. Accordingly, since in the case in point there do not appear to be particular reasons
substantiating a preponderant interest of the public in having, in the context
of such a search, access to that information, a matter which is, however, for
the referring court to establish, the data subject may, … require those links
to be removed from the list of results. …
1
4
1
1
298
Chapter 4: Privacy
299
5
1
ff
3
0
3
5
1
2
0
5
3
6
5
5
3
5
1
5
8
1
3
1
0
2
1
8
9
9
1
3
0
0
3
2
1
0
1
0
fi
3
2
2
fi
3
1
ff
0
1
5
ff
5
2
6
4
fi
fi
3
6
1
9
5
9
5
1
1
9
ff
1
3
7
5
5
3
5
3
2
7
8
the FTC Act and the Children’s Online Privacy Protection Rule (“Rule” or
“COPPA Rule”), C.F.R. pt.
.
. Epic Games, Inc. (“Epic,” “Epic Games,” or “Defendant”) is the developer and
distributor of the hit online video game “Fortnite.” Through Fortnite, Epic
matches children and teens with strangers around the world in interactive
gameplay, encourages real-time communications by featuring on-by-default
voice and text chat features, and publicly broadcasts players’ account names.
Even though Fortnite is directed to children, and even when Epic had actual
knowledge that Fortnite users were children, Epic failed to comply with the
COPPA Rule’s parental notice, consent, review, and deletion requirements.
Although Epic has changed its practices over time, those changes have not
cured the violations.
. Ultimately, Epic’s matchmaking children and teens with strangers while
broadcasting players’ account names and imposing live on-by-default voice
and text communications has caused substantial injury that is neither o set
by countervailing bene ts nor reasonably avoidable by consumers. Children
and teens have been bullied, threatened, and harassed within Fortnite, including sexually. Children and teens have also been exposed to dangerous
and psychologically traumatizing issues, such as suicide and self-harm,
through Fortnite. And the few relevant privacy and parental controls Epic
has introduced over time have not meaningfully alleviated these harms or
empowered players to avoid them. …
. Congress enacted COPPA in
to protect the safety and privacy of children online by prohibiting the unauthorized or unnecessary collection of
children’s personal information online by operators of Internet websites and
online services. COPPA directed the Commission to promulgate a rule implementing COPPA. The Commission promulgated the COPPA Rule on November ,
, under Section
(b) of COPPA,
U.S.C. §
(b), and
Section
of the Administrative Procedure Act, U.S.C. §
. The Rule
went into e ect on April ,
. The Commission promulgated revisions
to the Rule that went into e ect on July ,
. Pursuant to Section
(c)
of COPPA,
U.S.C. §
(c), and Section (d)( ) of the FTC Act,
U.S.C. § (a)(d)( ), a violation of the Rule constitutes an unfair or deceptive act or practice in or a ecting commerce, in violation of Section (a) of
the FTC Act, U.S.C. § (a).
. The Rule applies to any operator of a commercial website or online service
directed to children under years of age that collects, uses, and/or discloses
personal information from children, and to any operator of a commercial
website or online service that has actual knowledge that it collects, uses,
and/or discloses personal information from children. The Rule requires an
operator to meet speci c requirements prior to
a) Posting a privacy policy on its website or online service providing
clear, understandable, and complete notice of its information practices, including what information the operator collects from children
online, how it uses such information, its disclosure practices for such
information, and other speci c disclosures set forth in the Rule;
b) Providing clear, understandable, and complete notice of its information practices, including speci c disclosures, directly to parents;
Internet Law
fi
9
1
1
2
0
0
2
2
0
3
9
1
0
2
1
1
3
1
0
s
0
fi
e
i
4
fi
t
i
v
i
7
t
1
ff
0
c
2
s
s
1
e
2
n
0
i
2
s
u
2
s
c
i
2
3
4
5
6
1
1
1
1
1
c) Obtaining veri able parental consent prior to collecting, using, and/or
disclosing personal information from children;
d) Providing a reasonable means for parents to review personal information collected from children online, at a parent’s request; and
e) Deleting personal information collected from children online, at a
parent’s request. …
E ’ B
A
About Epic and Fortnite
. Epic is the developer of Fortnite, a hit online video game available to players
on multiple consoles, including the Sony PlayStation, Microsoft Xbox, and
Nintendo Switch, mobile devices with Android or iOS operating systems,
and personal computers with Windows or MacOS operating systems.
Launched in July
, Fortnite quickly caught the attention of young consumers—teens and children under age —in the United States and abroad
and, today, has more than
million players.
. Available in di erent modes, Fortnite is generally free to download and play
(although one mode, called “Save the World,” costs money). Epic has earned
billions of dollars in revenue through Fortnite, primarily by selling Fortnite
players in- game digital content like costumes (called “cosmetics” or “skins”)
and dance moves (called “emotes”) for their avatars, and through licensing
partnerships with companies selling Fortnite-branded merchandise.
Epic Collects Personal Information From Fortnite Players
. To play Fortnite using a personal computer or mobile device, players must
rst create an Epic Games account. Prior to September
, anyone could
create an Epic Games account by providing Epic Games with their rst
name, last name, and email address, and choosing a name (called a “display
name”) for their account. This remains the process for players located outside the United States and Europe. For players in the United States or Europe, however, Epic began requiring birthdate information as part of the
account creation process on September ,
(for U.S. players), September ,
(for U.K. players), and November
,
(for European
players outside the U.K.).
. To play Fortnite on a PlayStation, Xbox, or Switch console, players can
choose to create an Epic Games account, register their console to an alreadycreated Epic Games account, or access Fortnite using what Epic refers to as
a “nameless” account. If a player chooses this last option to play Fortnite on
their PlayStation, Xbox, or Switch console, Epic creates a “nameless” Epic
Games account for that player on Epic’s backend automatically—generating
a unique account ID for the player, associating that unique account ID to
the player’s PlayStation, Xbox, or Switch console, and collecting the player’s
PlayStation, Xbox, or Switch account name for use as the player’s display
name within Fortnite.
. Regardless of the console or type of account a player uses, several social features are enabled within Fortnite by default that convert the game into a
platform for connecting with other players. Among other things, these social
features allow players to nd and friend each other (by display name), play
matches together, exchange personal information, and converse with each
other in real time by voice and text. On the backend, Epic collects and uses
p
fi
300
301
fi
fl
ffi
7
1
ffi
0
2
fi
ff
4
1
+
0
8
1
7
8
9
0
1
2
1
1
1
2
3
2
various unique device IDs, account IDs, and other persistent identi ers to
keep track of players’ progress, purchases, settings, and friends lists, among
other player-speci c information.
Fortnite Is Directed to Children Under 13
. Considering the factors set forth in the COPPA Rule, including the game’s
subject matter, use of animation, child-oriented activities and language, and
music content, evidence of intended audience, and empirical evidence about
the game’s player demographics, Fortnite is directed to children under age
.
Fortnite’s Gameplay, Visual Content, and Features are Directed to Children
. Revolving around a “shooter-survival” style of gameplay, Fortnite’s various
game modes include “build-and-create” mechanics like those in other games
popular with children, and feature other elements that appeal to children,
like cartoony graphics and colorful animation. For example, in Fortnite’s
popular “Battle Royale” mode, players’ colorful avatars enter the game by
hang gliding to various places in a virtual world (e.g., “Loot Lake,” “Tilted
Towers,” “Retail Row”) after jumping from a whimsical ying blue school
bus, called the “Battle Bus.”
. Akin to digital laser tag, there is no blood or gore in Fortnite, and players are
“eliminated” from the game (not “killed”).
. Prominent in Fortnite gameplay is an emphasis on building “forts” and other creations—o ering children a digital playground to explore. As Epic noted when announcing the game’s release in
, the “soul of Fortnite” derives from the common childhood experience of fort-building—“whether it
was blankets and couch cushions, or building a fort in the woods by your
house, you and your friends could spend Saturday afternoons hiding out, or
repelling hordes of imaginary creatures”—and the game incorporates
“sculpted ‘puzzle pieces’ to create interesting play spaces to explore.”
Fortnite Theming Decisions Ensure Content Appeals to Children
. Epic strives to create a “Living room safe, but barely” environment using
content that appeals to children when making Fortnite theming decisions,
including potential music, celebrity, and brand partnerships. In so doing,
Epic Games employees have explained:
“We want to be living room safe, but barely. We don’t want your
mom to love the game – just accept it compared to alternatives”
“Agree with the idea that, generally, all theming should be relevant to a - y.o., as a litmus test”
“We are NOT adult: experience must allow for parental comfort
for ages
”
Based on these guiding principles, Fortnite has promoted and hosted live ingame concerts featuring celebrities popular with children, such as Marshmello, Travis Scott, Ariana Grande, and BTS.
Epic Has Made Millions in Royalties Selling O cial Fortnite Toys, Halloween
Costumes, and Youth Apparel
. Further evidencing the game’s intended audience, Epic has made millions in
royalties by partnering with companies to sell o cially licensed Fortnite
merchandise for children. Within a year of Fortnite’s public release, Epic
2
1
Chapter 4: Privacy
302
Internet Law
9
7
1
9
1
0
2
2
6
1
2
1
8
fi
0
2
9
fi
0
1
2
ffi
0
1
2
2
3
1
8
ffl
1
ff
0
ffi
2
0
4
2
1
1
fi
1
0
6
2
1
ff
8
ffi
fi
ff
#
ffi
3
3
3
4
5
6
7
2
2
2
2
ff
ff
2
retained a licensing agent and launched a consumer products program to
give players o cial Fortnite-branded merchandise.
. Acknowledging that “Youth and Kids are obsessed with Fortnite” and “want
to show their allegiance to their favorite pastime,” Epic’s agent developed a
licensing plan with a “core” component that targeted “Kids” and “Youth Universes,” and worked closely with Epic to broker partnerships between Epic
and other companies to create Fortnite-branded costumes, toys, books,
youth-sized apparel, and “back to school” merchandise (e.g., backpacks,
pencil cases, etc.). And while Epic’s licensing agent has helped source and
manage these merchandising partnerships, Epic carefully scrutinizes all potential licensees, sets the terms governing each partnership, and approves
every Fortnite-branded product that gets produced—including the product’s
design and packaging, and related advertising and marketing plans.
. In its rst consumer products deal, Epic partnered with Spirit Halloween to
o er o cially licensed Fortnite Halloween costumes. Available in children’s
sizes, these costumes have been very popular with kids and spawned articles
with headlines like “Excited Kids Are Ba ing Adults With Their Fortnite
Halloween Fervor.” Indeed, Spirit Halloween sold hundreds of thousands of
child-sized Fortnite costumes between
and
, which account for
more than half of all Fortnite costumes sold by Spirit Halloween during
those years.
. In another early consumer products deal, Epic partnered with Hasbro to
o er players Fortnite-branded Nerf guns, Super Soaker water guns, and
other popular kids’ toys. Consistent with the core demographic for Hasbro’s
Nerf products, the “Fortnite X Nerf ” product line launched in early
using a “ FortniteIRL [In Real Life]” tagline with paid advertisements in
media channels targeting “ - year old boys.” Today, through its partnership
with Epic, Hasbro o ers more than
di erent o cially licensed Fortnite
toys on its website, including three Super Soaker products for “Kids: - ,”
and
di erent Nerf, Super Soaker, and other toys for “Tweens: - .”
. In addition to Hasbro, Epic has partnered with other companies like
Jazwares and Moose Toys to produce o cial Fortnite action gures, playsets, and other toys. As with the Epic-Hasbro partnership, toys from the
Epic-Jazwares and Epic- Moose Toys partnerships were marketed to and for
kids, including through television commercials targeting those aged that aired on the Cartoon Network, Nickelodeon, and Nicktoons (EpicJazwares), and video advertisements on YouTube and Twitch intended to
reach “Fortnite fans - ” and “Fortnite fans - ” (Epic-Moose Toys). And
toys from all three partnerships were marketed through seasonal toy catalogs from retailers like Amazon, Target, and Walmart.
. Notably, a toy from the Epic-Jazwares partnership—the Fortnite Llama
Loot Pinata—tied with Lego’s Harry Potter products to win the “Toys /
Games / Novelties for Ages - ” category at the
International Licensing Awards. As the head of Epic’s consumer products program explained
internally, Epic won the “Newcomer” award that year after Fortnite or Fortnite-branded products won rst place awards in ve categories—despite
being “up against some heavy hitters like Harry Potter, Jurassic World, and
Lego.”
303
%
0
7
fi
8
5
ffi
fi
%
fi
%
3
0
5
%
8
3
3
3
4
5
0
4
2
8
0
$
8
2
1
0
0
2
5
6
%
0
$
6
3
1
3
1
%
9
0
1
7
0
2
3
0
1
fi
ff
2
0
3
1
2
0
7
1
3
1
3
$
1
fi
%
1
9
$
1
2
ff
1
0
1
7
8
9
1
0
1
2
3
3
2
2
3
3
3
. By the rst half of
, Epic’s consumer products program had generated
more than
billion in gross sales of Fortnite-branded merchandise, bringing more than
million in gross royalties to Epic and its licensing agent.
Most of this success was driven by the popularity of Epic’s o cial Fortnite
toys, which accounted for nearly
(~
million) of all Fortnite-branded merchandise sales, and more than
(~
million) of the royalties
from such sales, through the rst quarter of
.
Many Children Play Fortnite, and Many Fortnite Players Are Children
. Not surprisingly, empirical evidence shows that many children play Fortnite,
which is disproportionately popular with “tweens.” For example, publicly
available survey results from a
report show that
of U.S. children
aged
- played Fortnite weekly, compared to
of U.S. teens aged
- , and
of the U.S. population aged - . And Epic, which had
previously contracted with the company that conducted this survey (to conduct a di erent survey in connection with Fortnite), received pre-publication copies of the survey results along with a private brie ng by the researchers who conducted the survey.
. Results from Epic’s own player surveys are consistent with this data. While
Epic avoided collecting Fortnite players’ precise ages (until it instituted the
limited age gating described below in Paragraphs
through ), Epic has
consistently asked about players’ living situation and occupation through
player surveys—and used the results as a proxy for players’ age demographics. The results show that most Fortnite players (i.e., approximately
)
live at home with their parents or guardians, and, of those who live with
their parents or guardians, most (i.e., approximately
) identify as students. And when soliciting potential brand partnerships for Fortnite, Epic
has used social media data to emphasize Fortnite’s popularity among young
gamers—noting that a third of Fortnite players, based on social media data,
are teens aged - (i.e., the youngest age demographic available in the social media data, which cuts o at age ).
Epic Knows that Children Play Fortnite
. Epic knows that children play Fortnite. Epic employees and player support
agents review and respond to thousands of player-related requests, reports,
and complaints that come in each day, many of which identify speci c Fortnite players as being children under .
. Epic and its employees also regularly monitor, read, and circulate news articles and social media posts chronicling Fortnite’s popularity among children, and sometimes incorporate kids’ ideas directly into the game. For example, the concept behind a popular “cosmetic” (i.e., out t for players’ ingame avatars) in Fortnite, called “Tender Defender,” originated in the mind
of an eight-year-old Fortnite player whose father had shared his son’s idea
on the social media site Reddit.com, where it caught the attention of Epic’s
Fortnite development team.
. Epic, too, has sent Fortnite “swag”—i.e., Fortnite-branded merchandise—
intended for children under , including in response to celebrities’ swag
requests for their “Fortnite obsessed” children. And to help Epic evaluate
potential new features, the former Game Director for Fortnite would bring
his son, who was under
years old, to participate in internal company
playtests of Fortnite.
3
1
Chapter 4: Privacy
304
Internet Law
ff
fi
7
7
1
1
0
0
2
2
fi
8
1
0
2
fi
ff
fi
fl
7
1
0
2
3
1
4
5
6
7
8
9
3
3
3
3
3
3
. Further, when Epic lobbied Microsoft and Sony to support cross-console
gameplay, allowing, e.g., Xbox Fortnite users to play with PlayStation Fortnite users, Epic stressed the feature’s impact on kids, noting for example
that “many Fortnite players are kids” and that cross-console gameplay would
“bring together current and potential gamers in real-world social groups:
college dorms, high school classes, even kids . . .”
. Epic’s records include other acknowledgements, too. In numerous internal
communications, Epic employees have reported being inundated with Fortnite questions and requests during in-person conversations with players
under , watching kids perform Fortnite dances in public, and receiving
notes from teachers about Fortnite’s popularity with their middle and elementary school students. In other ordinary course business communications, Epic employees have noted that “a large portion of our player base”
consists of “underage kids,” acknowledged Fortnite’s “high penetration
among tweens/teens,” agged “that Fortnite is enjoyed by a very young audience at home and abroad,” and described putting on Fortnite “dance cam,”
“makeup booth (for kids),” and other events at public gaming conferences
(where most attendees were “very young”)— including events where “[t]he
idea was that any kid or teenager playing could feel like a pro.”
Fortnite’s Unfair Default Settings Have Harmed Children and Teens
. Predictably, Epic has caused substantial harm by matching children and
teens with strangers in interactive gameplay while publicly broadcasting
players’ display names and imposing real-time communications through onby-default voice and text chat.
. Epic has known about this harm and nevertheless allowed it to persist.
Shortly after Fortnite’s launch, Epic’s then Director of User Experience
(“UX”) emailed Epic leadership in August
seeking “basic toxicity prevention” mechanisms—noting that “surely a lot of kids” were currently playing the game, and imploring Epic to “avoid voice chat or have it opt-in at the
very least.” To no avail. Voice chat remained on by default, including in Fortnite’s Battle Royale mode when Epic enabled voice chat for that mode in
October
. While Epic contemporaneously added a toggle on a settings
page enabling those who happened to nd it to switch voice chat o , the
feature remained on as part of Fortnite’s default con guration for all players.
. Within two weeks of Epic’s October
decision to enable voice chat in
Battle Royale, a high-pro le gamer verbally harassed a young player while
publicly streaming to an audience of thousands of viewers. As an Epic
Games employee acknowledged: “. . . we honestly should have seen this coming or [at least] expected this with an on-by-default voice chat system. Situations like this are bound to happen . . .” But Epic again declined to modify
its on-by-default voice chat system (or implement any other changes) to stop
subjecting kids to such abuse within Fortnite.
Eight months later, in June
, Epic’s UX research team analyzed the
parental and privacy controls o ered by a wide range of other games and
game platforms, and presented the results of their assessment to Epic executives and other employees. Epic’s UX team reiterated their recommendation
to move to an opt-in voice chat con guration for Fortnite, noting that most
players did not use the feature when playing with strangers, which presented “a risk in terms of negative social behavior,” and acknowledging “[f]rom
305
fi
8
1
0
2
ffl
4
5
3
8
8
4
9
ff
fi
ff
8
1
0
2
fl
%
0
1
2
4
0
4
4
social/media stories we have seen both ‘Fortnite is positive’ and ‘child charity
warns parents about predators in Fortnite’ . . .” Epic leadership praised the
“very well-researched and thoughtful” work, but the UX team “got no traction” around opt-in voice chat. Epic continued to reject the UX team’s recommendation.
. All the while, kids have been bullied, threatened, and harassed, including
sexually, through Fortnite. Numerous news stories chronicle reports of
predators blackmailing, extorting, or coercing children and teens they met
through Fortnite into sharing explicit images or meeting o ine for sexual
activity. Such issues are also the subject of numerous player support tickets
submitted to Epic by distressed parents and players.
. In addition, Epic’s Fortnite practices have exposed kids to dangerous and
psychologically traumatizing issues, such as suicide and self-harm. For example, in a May
email to Epic’s customer support leads, one employee
noted that Epic’s player support tickets included “
cases created in the
last year that contain the words ‘kill myself ’ and
containing the word
‘suicide,’” including “cases such as toxicity reports from players who were
told to kill themselves by others.” As one parent explained in an email to
Epic, “[t]his morning, while on Fortnite, my year old son had a ‘friend’
(someone he doesn’t know in real life, but has been playing with for months)
tell him that he was going to kill himself tonight. It shook him to the core.”
. As re ected in internal exchanges between Epic employees, these harms are
not outweighed by countervailing bene ts, nor are they reasonably avoidable by consumers. Shortly before the UX team’s unsuccessful push to convince leadership to change Fortnite’s default settings in June
, an Epic
employee who had helped create Fortnite emailed Epic’s PR manager and
Epic’s Creative Director:
I think you both know this, but our voice and chat controls are
total crap as far as kids and parents go. It’s not a good thing. It
was on my list a year ago, but never bubbled to the surface. This
is one of those things that the company generally has weak will
to pursue, but really impacts our overall system and perception.
I’ve made a coppa [sic] compliant game and we are far from it,
but we don’t need to be that far . . .
To which Epic’s PR manager responded:
agree here. Communication-wise, we are staying out of
the debate, even though Fortnite is right in the middle of it.
We’d come out looking way better if we o ered the proper tools
across the board here. I agree the best response is doing the
right thing, and not debating it . . .
The employee then forwarded the exchange to Epic’s lead UX researcher,
who replied “I would really like to see even the small step of on rst load
asking if people want voice on or o . Even hardcore games like Monster
Hunter have done this.” And when articulating the UX team’s position to
Epic executives a week later, Epic’s lead UX researcher noted a good opt-in
system yielded only upside: it would align with players’ reported preferences
(“when playing with strangers the majority [of Fortnite players] are not typically using it to talk or listen to them”), preserve the feature’s utility
(“[t]here is no doubt that voice is strongly valued by folks when talking to
0
1
Chapter 4: Privacy
Internet Law
4
0
1
ff
8
1
0
2
fi
ff
7
3
ff
fi
3
4
5
6
4
4
4
people they know, and by a signi cant minority who like to use it to talk to
strangers . . . A good opt-in system should maintain this”), and reduce toxicity (“[f]or example when Riot moved to opt-in text chat they saw the same
volume of chat usage, but reduced toxicity as those who want to chat were
able to communicate and those that did not were not exposed”).
. As noted in Paragraph , Epic did introduce a toggle switch allowing Fortnite players to turn voice chat o , but the control was buried on a hard-tond settings page. As one Fortnite programmer lamented:
So when I was at my brothers house, and was watching my
yr old nephew play. I’m like, hey, why is there no sound on the
TV? And he’s like, we turn o the volume because you can hear
people talking. People related to me by blood were no sh[**]
muting the TV instead of looking for a way to disable voice chat.
Not a proud day . . . The settings are not a land most folks venture to, certainly not technophobic parents . . .
When this message was forwarded to Epic’s lead UX researcher, he responded with exasperation: “Sigh. Can we just suggest popping up a dialog asking
people if they want it on or not?”
Epic’s Changes Have Not Cured the Law Violations
. Over time, Epic has introduced a few changes to Fortnite in weak-willed
attempts to provide players and their parents with some privacy and
parental controls, and comply with COPPA’s parental notice, consent, review, and deletion requirements. But these overdue e orts have not cured
the law violations.
Epic Has Consistently Resisted, Deprioritized, and Delayed Privacy and
Parental Controls
. Fortnite launched with no parental controls and minimal privacy settings.
Initially, the only such options consisted of a few settings allowing players to
“mute,” “block,” or “kick” (i.e., remove from shared gameplay activities) individual problematic players they encountered, or narrow the set of players
who could join them in collaborative gameplay (i.e., by changing their “Party
Privacy” setting from “public” to “friends of friends,” “friends,” or “private”).
Neither players nor their parents could prevent a player’s display name from
being publicly broadcast or disable voice and text chat (except by using
parental controls and voice chat settings when playing Fortnite on gaming
consoles that provide such controls and settings).
. Shortly after launch, Epic introduced the toggle switch discussed above, allowing Fortnite players to disable voice chat, but did not inform players of
the setting’s availability and placed the control in the middle of a detailed
settings page. Seven months later, in May
, Epic introduced a setting
called “Streamer Mode” that, when enabled, hid a player’s display name and
the display names of those the player encountered during gameplay. After
surveying players and nding that many who enabled this control were
seeking to avoid harassment—and were not actual “streamers” (i.e., players
who publicly live-streamed their gameplay)—Epic split the feature into an
“Anonymous Mode” setting (which hides a player’s display name during
gameplay, when enabled) and “Hide Other Player Names” setting (which
hides other players’ display names during gameplay, when enabled) in Jan-
4
fi
306
307
9
fi
1
4
0
2
fi
5
fi
7
1
9
0
1
2
0
8
2
1
0
2
9
1
fi
0
fi
2
9
7
8
9
0
1
4
0
4
4
5
uary
. In between, Epic added settings allowing Fortnite players to hide
their display name from appearing in global game statistic leaderboards (in
September
) and disable friend requests from other players (in January
).
. In June
, nearly two years after Fortnite’s launch, Epic nally introduced parental controls to the game. Starting on that date, parents could set
a PIN code that must be entered to adjust various privacy settings—i.e.,
Auto Decline Friend Requests, Hide Other Player Names, Anonymous
Mode, and Voice Chat. Of course, to enable parental controls, parents
would rst need to know they existed, have access to their child’s or teen’s
Fortnite account, and know where to nd the controls.
For More Than Two Years, Epic Took No Steps to Seek Parental Consent Before
Collecting Children’s Personal Information or Explain How the Company
Handled It
. From July
, when Fortnite launched, until September
, Epic took
no steps to (a) provide a direct notice to parents describing Epic’s practices
regarding the collection, use, and disclosure of children’s personal information; (b) explain what information Epic collected from children through
Fortnite; or (c) seek veri able parental consent (“VPC”) from parents before
collecting their children’s personal information through Fortnite.
. Instead, Epic included one paragraph on the second-to-last page of its global privacy policy disavowing that it directed any services to children or intentionally collected any personal information from such players, and asking
parents to contact Epic if they believed Epic had received personal information from their child:
Epic does not direct its websites, games, game engines, or applications to children (usually considered to be under the age of
, depending on the country where you reside). We also do not
intentionally collect personal information from children
through our websites, games, game engines, or applications. If
you are the parent or guardian of a child and you believe that
we have inadvertently received personal information about that
child, please contact us as described in the How to Contact Us
section of this policy and we will delete the information from
our records.
. When parents contacted Epic to review or delete the information Epic collected from their child through Fortnite, or delete their child’s Epic Games
account, and those parents did not have access to their child’s Fortnite account, Epic made those parents jump through extraordinary hoops to “verify” their parental status. For example, Epic required some parents to provide
all IP addresses used by their child to play Fortnite, the date the child’s Epic
Games account was created, an invoice ID for an Epic Games purchase, the
locations (city, state/province) where purchases were made, the last digits
of the rst payment card used on the child’s Epic Games account, the date of
their child’s last Fortnite login, their child’s original Epic Games account
display name, and the names of any PlayStation, Xbox, or Switch consoles
connected to their child’s Epic Games account. Where parents were able to
provide such information, Epic sometimes required them to provide even
more information before Epic would agree to process the parent’s review or
3
2
1
Chapter 4: Privacy
308
Internet Law
fi
fi
3
1
fl
fi
3
3
1
fi
1
3
1
5
1
2
1
ff
fi
3
1
fi
8
3
1
1
9
0
1
2
0
2
0
3
1
1
3
1
1
2
3
4
5
6
5
5
5
5
5
5
deletion request—like the name of a cosmetic item their child purchased
more than
days ago and a copy of the parent’s passport, identi cation
card, or recent rent or mortgage statement.
. Even when Epic obtained actual knowledge that particular Fortnite players
were under , Epic took no steps to comply with COPPA. Indeed, Epic
went to great lengths to pretend it never obtained actual knowledge at all.
. In March
, Microsoft personnel told Epic that Epic would have to block
Xbox accounts belonging to children under
from participating in crossconsole gameplay through Fortnite. In particular, Microsoft wanted Epic to
use an existing Xbox mechanism (an API called the UserAgeGroup) to
check whether a given Xbox player
was using an “Adult,” “Child,” “Teen,” or “Unknown” Xbox account, and block
any Xbox players using “Child” accounts (de ned as accounts belonging to
players under age ) from using Fortnite’s cross-console gameplay feature.
In other words, Microsoft wanted Epic to use Microsoft’s API to determine
which Xbox accounts belonged to children under age
and block those
accounts from participating in Fortnite’s cross- console gameplay feature.
. Although Epic initially resisted, the company ultimately acquiesced and began blocking Xbox accounts identi ed via the UserAgeGroup API as belonging to a player under from participating in cross-console gameplay within
Fortnite. But Epic did not take any other steps to limit those players’ communications with third parties, seek VPC for them, provide their parents
with any notices explaining how Epic handled children’s personal information, or otherwise comply with COPPA. Instead, as re ected in company
records, Epic pretended they had no idea these players were children for any
purpose other than determining whether they could participate in crossconsole gameplay.
Epic’s Dilatory COPPA Measures Fail to Comply With The Law
. Epic eventually began to change its approach to COPPA compliance. On
September ,
—long after Epic obtained empirical evidence pointing
to large numbers of Fortnite players under , received actual knowledge
that many particular players were under , and pro ted from Fortnitebranded merchandise clearly directed to children—Epic introduced an age
gate to the account creation process for prospective Fortnite players attempting to create an Epic Games account on the Epic Games website from
an internet connection with a U.S. IP address. For any such prospective
player who self-identi ed as being
years old or younger, Epic would collect a parent’s email address from the player and send an email to the player’s parent describing how Epic handled children’s personal information and
asking the parent to complete a VPC process—such as using a credit card to
make a small refundable charge.
. But this initiative had no e ect on the default con gurations of Fortnite
players’ privacy controls—which continue to enable the public broadcast of
players’ display names and direct communication between players, regardless of a player’s age.
. Nor did this initiative apply to those seeking to play Fortnite using new
nameless accounts (i.e., accounts generated by Epic for PlayStation, Xbox,
or Switch users, as described in Paragraph ), or those creating Epic Games
accounts from internet connections with an IP address outside the U.S.
Chapter 4: Privacy
309
fl
3
0
1
0
3
5
fi
1
9
1
0
2
9
1
0
fi
2
1
1
0
0
0
3
4
6
1
2
1
3
t
c
6
3
1
fi
2
1
9
fl
fi
1
0
d
2
fi
n
6
1
a
0
1
fi
1
1
e
ff
l
u
fi
0
3
0
1
3
3
1
5
1
3
1
fi
e
4
h
2
t
1
3
f
3
o
1
s
n
fi
o
i
2
1
t
a
l
7
8
9
0
1
2
5
o
6
fi
5
5
6
i
6
. Nor did Epic’s September ,
, changes apply to the hundreds of millions of Fortnite players who already had accounts, with a few limited exceptions. In the weeks before implementation, Epic employees searched Fortnite player support tickets to nd those with indicia that a U.S. player may
be under the age of . These e orts surfaced
,
such tickets, which
Epic associated with
,
identi able Fortnite players. Regardless of
whether a ticket speci cally identi ed a particular player as being under ,
or merely suggested that a player might be under , Epic logged all ,
players out of their accounts and asked them to provide their birthdate the
next time the player attempted to log in—emailing parents a direct notice
and asking them to complete a VPC process only if the player then self-identi ed as being under age .
. Contemporaneously, Epic began instructing player support agents to ag
accounts belonging to U.S. Fortnite players associated with new player support tickets in which players self-identi ed (or were identi ed by others) as
being
years old or younger. Beginning on September ,
, Epic started logging out any accounts with such a ag and requiring the player to pass
Epic’s age gate the next time the player attempted to log in, with Epic requesting a parent’s email address, sending a direct notice, and asking the
parent to complete a VPC process only if the player then self-identi ed as
being under .
. Around the same time, Epic began changing how it handled emails identifying speci c Fortnite players as being age
or younger. Previously, Epic did
not take any steps to ensure the company sought VPC for such players or
provided such players’ parents with any notices describing how Epic handled their children’s personal information. But starting in late
, Epic
began forwarding these types of emails to player support agents, who try to
determine whether the underlying player is based in the U.S. If so, and if the
player has not already been subjected to Epic’s age gate, the player is logged
out and required to provide their birthdate the next time the player attempts
to log in. Only if the player then self-identi es as being twelve or younger
does Epic send their parent a direct notice and seek VPC.
. Based on the facts and violations of law alleged in this Complaint, the FTC
has reason to believe that Defendant is violating or is about to violate laws
enforced by the Commission.
V
COPPA R
FTC A
Count I
Coppa Rule
. As described in Paragraphs
through
above, Defendant is an “operator”
subject to the COPPA Rule.
. In numerous instances, in connection with the acts and practices described
above, Defendant collected, used, and disclosed personal information from
children younger than age in violation of the Rule by:
a) Failing to provide notice on its website or online service of the information it collects online from children, how it uses such information,
and its disclosure practices, among other required content, in violation of Section
. (d) of the Rule, C.F.R. §
. (d);
Internet Law
5
9
1
6
6
1
1
2
5
0
5
2
5
1
6
7
2
3
$
fi
5
4
2
2
1
5
ff
5
4
3
5
4
5
6
1
5
5
3
2
4
3
4
1
3
3
3
6
6
5
1
5
1
2
7
1
1
5
5
3
1
0
6
1
3
1
3
0
3
3
1
1
ffi
5
5
2
6
1
1
1
3
ff
fi
4
2
1
2
3
5
5
6
1
6
2
1
5
3
3
4
3
fi
fi
6
3
7
8
9
0
1
2
6
7
1
6
8
6
6
b) Failing to provide direct notice to parents of the information it collects
online from children, how it uses such information, and its disclosure
practices for such information, among other required content, in violation of Section
. (b) of the Rule, C.F.R. §
. (b);
c) Failing to obtain consent from parents before any collection or use of
personal information from children, in violation of Section
. (a)( )
of the Rule, C.F.R. §
. (a)( );
d) Failing to provide, at the request of parents, a means of reviewing any
personal information collected from children, in violation of Section
. (a)( ) of the Rule, C.F.R. §
. (a)( ); and
e) Failing to delete, at the request of parents, personal information collected from children, in violation of Section
. (a)( ) of the Rule,
C.F.R. §
. (a)( ).
. Pursuant to Section
(c) of COPPA,
U.S.C. §
(c), and Section
(d)( ) of the FTC Act, U.S.C. § a(d)( ), a violation of the Rule constitutes an unfair or deceptive act or practice in or a ecting commerce, in violation of Section (a) of the FTC Act, U.S.C. § (a). …
Count II
Unfair Default Settings
. Section (a) of the FTC Act, U.S.C. § (a), prohibits “unfair or deceptive
acts or practices in or a ecting commerce.”
. Acts or practices are unfair under Section of the FTC Act if they cause or
are likely to cause substantial injury to consumers that consumers cannot
reasonably avoid themselves and that is not outweighed by countervailing
bene ts to consumers or competition. U.S.C. § (n).
. As described in Paragraphs
through
above, Defendant has developed
and operated, and continues to develop and operate, a ubiquitous, freelyavailable, and internet-enabled video game directed at children and teens
that publicly broadcasts players’ display names while putting children and
teens in direct, real-time contact with others through on-by-default lines of
voice and text communication. Even after instituting an age gate on its service, Defendant has continued to broadcast display names and enable such
direct communication by default for all players, including children who
identify themselves as under and young teens.
. As described in Paragraphs
through
above, Defendant’s actions cause
or are likely to cause substantial injury to consumers that consumers cannot
reasonably avoid themselves and that is not outweighed by countervailing
bene ts to consumers or competition.
. Therefore, Defendant’s acts or practices as set forth in Paragraph
constitute unfair acts or practices in violation of Section of the FTC Act,
U.S.C. § (a), (n).
[Simultaneously with ling this complaint, the FTC also led a settlement agreement, under which Epic agreed to pay a civil penalty of
million. Epic also
agreed to comply with the COPPA Rule going forward, to delete previously collected personal information from minors unless it subsequently obtained parental
consent, to require express a rmative consent for disclosure of children’s information, to establish a mandatory privacy program, and to have a third party conduct
independent privacy audits every two years.]
7
3
1
310
311
QUESTIONS
. Compliance: What should Epic have done differently? What will it need to do
differently going forward? Is it better off avoiding COPPA by preventing
children from playing Fortnite, or complying with COPPA by giving parents
better notice, limiting uses of children’s personal information, and restricting
communications with children in Fortnite?
. Wink Wink Nudge Nudge: Your client, Panels, is a service that lets users create
and share online graphic novels. Should Panels ask users their ages when
they sign up? What should it do if they indicate that they are under ?
. Sectoral Privacy, Yet Again: The United States does not have a comprehensive
privacy law, a comprehensive children’s privacy law, or a comprehensive online privacy law. But it does have COPPA — a children’s online privacy law. Is
there something distinctive about children’s experiences online that justifies
a special-purpose privacy law?
CALIFORNIA AGE-APPROPRIATE DESIGN CODE ACT
A.B. 2273 (enacted 2022)
California Civil Code
ff
3
1
fi
ff
fi
fl
9
1
2
3
9
9
9
9
1
8
8
9
9
7
7
1
§
. . .
The Legislature declares that children should be a orded protections not only by
online products and services speci cally directed at them but by all online products and services they are likely to access and makes the following ndings:
(a) Businesses that develop and provide online services, products, or features
that children are likely to access should consider the best interests of children when designing, developing, and providing that online service, product, or feature.
(b) If a con ict arises between commercial interests and the best interests of
children, companies should prioritize the privacy, safety, and well-being of
children over commercial interests. …
§
. . .
(a) A business that provides an online service, product, or feature likely to be
accessed by children shall take all of the following actions:
( )
(A) Before any new online services, products, or features are o ered
to the public, complete a Data Protection Impact Assessment
for any online service, product, or feature likely to be accessed
by children and maintain documentation of this assessment as
long as the online service, product, or feature is likely to be accessed by children. A business shall biennially review all Data
Protection Impact Assessments.
(B) The Data Protection Impact Assessment required by this paragraph shall identify the purpose of the online service, product,
or feature, how it uses children’s personal information, and the
risks of material detriment to children that arise from the data
management practices of the business. The Data Protection
Impact Assessment shall address, to the extent applicable, all of
the following [eight factors].
1
2
1
3
Chapter 4: Privacy
312
Internet Law
ff
1
fi
ff
fi
fi
1
fi
fi
1
2
4
3
5
6
9
8
7
0
2
1
ff
( ) Document any risk of material detriment to children that arises from
the data management practices of the business identi ed in the Data
Protection Impact Assessment required by paragraph ( ) and create a
timed plan to mitigate or eliminate the risk before the online service,
product, or feature is accessed by children.
( ) Within three business days of a written request by the Attorney General, provide to the Attorney General a list of all Data Protection Impact Assessments the business has completed.
( )
(A) For any Data Protection Impact Assessment completed pursuant to paragraph ( ), make the Data Protection Impact Assessment available, within ve business days, to the Attorney
General pursuant to a written request. …
( ) Estimate the age of child users with a reasonable level of certainty
appropriate to the risks that arise from the data management practices of the business or apply the privacy and data protections a orded to children to all consumers.
( ) Con gure all default privacy settings provided to children by the online service, product, or feature to settings that o er a high level of
privacy, unless the business can demonstrate a compelling reason that
a di erent setting is in the best interests of children.
( ) Provide any privacy information, terms of service, policies, and community standards concisely, prominently, and using clear language
suited to the age of children likely to access that online service, product, o
0
You can add this document to your study collection(s)
Sign in Available only to authorized usersYou can add this document to your saved list
Sign in Available only to authorized users(For complaints, use another form )