Sometimes the premise is the point. “When did your mother get out of prison?” says, indirectly but clearly, that your mother was in prison. Same with the question “How much should the government rummage people’s things?” In tech policy today, two highly aligned policy proposals sit on different sides of an interesting premise: that people’s communications and private information are theirs.
The bipartisan NDO Fairness Act is a salutary proposal to update the terms on which government can compel online service providers to disclose customers’ personal information. The Stored Communications Act allows government agents to seize customers’ communications from service providers without a warrant when those communications have been stored for more than 180 days. Another provision of the law allows for delayed notification if government agents allege any one of five ways that providing notice threatens people or prosecutions.
There are paltry limits on seeking delayed notification, and incentives work. Investigator demands for delayed notification are now boilerplate, and each year thousands of Americans who probably should learn in a timely manner that their data have been seized do not. A few of those thousands have been members of Congress, which sets the stage for felicitous reform sought by a fairly united online services industry. Congress may revisit the rules by which the government can rummage people’s digital things.
Just there, I put your mother in prison. I called private data “people’s things.” That implies an important premise, customer ownership. But nondisclosure order (NDO) reform relies on the same premise as the Stored Communications Act: These are not people’s things. They are companies’ things, and they are available to the government on terms set by the government.
The SCA and NDO reform further assume that communications and other generally private information are owned by service providers. (Surely, it’s not in the commons or public domain.) Your Gmails are Google’s, your texts are Verizon’s, and so on. That is counterintuitive.
Legislation recently introduced in New Hampshire points in the same reformist direction, but it starts from an entirely different premise.
New Hampshire’s House Bill 1436 is the Common Law Privacy and Consumer Protection Act. The findings say:
- Advances in technology and business practices involving the transfer of personal information to third-party platforms and cloud service providers have put consumers and citizens at considerable risk of being divested of rights in their information that they actually retain.
- Common law recognition of people’s retained rights in information so transferred has not been sufficiently recognized.
- Recognition of the rights people retain in information they share with others in controlled contexts, such as providing services or sharing in confidential relationships, will help protect privacy without hindering information flows or the development of new business models and services.
- Individuals retain property rights in information they share subject to appropriate controls, so that it is legally and constitutionally their information.
The bill creates a presumption in New Hampshire law that transferring private information to a service provider creates a bailment of that information.
“Bailment”? What is that?
Ever hand a private document to a friend to be returned? Toss your keys to a valet at a restaurant? Ask your neighbor to look after your dog while you travel? You would not expect the friend to share the document with others; the valet to lend your car to his buddy; or the neighbor to put Fido up for adoption. Entrusting your stuff to others is a bailment.
That’s Justice Neil Gorsuch in Carpenter v. United States, which dealt with cell site location information. He argued that others’ “access to or possession of your papers and effects does not necessarily eliminate your interest in them.”
Almost 100 years ago, another Supreme Court justice wrote about solving privacy problems using common law tools. It was Justice Pierce Butler in Olmstead v. United States:
The contracts between telephone companies and users contemplate the private use of the facilities employed in the service. The communications belong to the parties between whom they pass.
But transfixed by Justice Louis Brandeis’ grandiloquence, and his “right to be let alone,” courts for the past century have been trying to administer legal protections for privacy, including the Fourth Amendment, using feelings, not basic legal tools like property and contract.
The Common Law Privacy and Consumer Protection Act would start to remedy that. Were it the law nationwide, NDO reform would already be done. People would have a due process right to contest seizures of their data when government agents do not use a warrant. Whether people get such rights ultimately depends on whether the law supports the premise that private information lodged with service providers under promises of privacy and security are “people’s things.”