the Law, the Universe, and Everything 

Search

Concurring Opinions is a
general-interest legal blog
operated by Concurring
Opinions LLC, a Pennsylvania
Limited Liability Corporation.

lr_jkr9_15_08constific.jpg

ad-logo5.jpg

Our Podcast

Subscribe to Law Talk

Law-Rev-Forum-2.jpg

law-rev-contents2.jpg

Law-Prof-Blog-Census.jpg

Categories

Accounting
Administrative Announcements
Administrative Law
Admiralty
Advertising
Agricultural Law
Anonymity
Antitrust
Architecture
Articles and Books
Bankruptcy
Behavioral Law and Economics
Bioethics
Blogging
Book Reviews
Capital Punishment
Civil Procedure
Civil Rights
Conferences
Constitutional Law
Consumer Protection Law
Contract Law & Beyond
Corporate Finance
Corporate Law
Criminal Law
Criminal Procedure
Culture
Current Events
Cyberlaw
DRM
Economic Analysis of Law
Education
Empirical Analysis of Law
Employment Law
Environmental Law
Estates and Trusts
Evidence Law
Family Law
Feminism and Gender
First Amendment
Food
Google & Search Engines
Health Law
History of Law
Humor
Immigration
Insurance Law
Intellectual Property
International & Comparative Law
Interviews
Jurisprudence
Law and Humanities
Law and Inequality
Law and Psychology
Law Practice
Law Professor Blogger Census
Law Rev (Boston College)
Law Rev (Boston University)
Law Rev (California)
Law Rev (Chicago)
Law Rev (Columbia)
Law Rev (Cornell)
Law Rev (Duke)
Law Rev (Emory)
Law Rev (Fordham)
Law Rev (Georgetown)
Law Rev (GW)
Law Rev (Harvard)
Law Rev (Illinois)
Law Rev (Indiana)
Law Rev (Iowa)
Law Rev (Michigan)
Law Rev (Minnesota)
Law Rev (Northwestern)
Law Rev (Notre Dame)
Law Rev (NYU)
Law Rev (Penn)
Law Rev (S Cal)
Law Rev (Stanford)
Law Rev (Texas)
Law Rev (UCLA)
Law Rev (Vanderbilt)
Law Rev (Virginia)
Law Rev (Wash U)
Law Rev (Wm & Mary)
Law Rev (Yale)
Law Rev Contents
Law Rev Forum
Law School
Law School (Hiring & Laterals)
Law School (Law Reviews)
Law School (Rankings)
Law School (Scholarship)
Law School (Teaching)
Law Student Discussions
Law Talk
Legal Ethics
Legal Theory
Media Law
Movies & Television
Philosophy of Social Science
Politics
Privacy
Privacy (Consumer Privacy)
Privacy (Electronic Surveillance)
Privacy (Gossip & Shaming)
Privacy (ID Theft)
Privacy (Law Enforcement)
Privacy (Medical)
Privacy (National Security)
Property Law
Race
Religion
Reparations
Science Fiction
Second Amendment
Securities
Securities Regulation
Social Network Websites
Sociology of Law
Supreme Court
Tax
Teaching
Technology
Tort Law
Web 2.0
Weird
Wiki
Wills, Trusts, and Estates

Archives

November 2008
October 2008
September 2008
August 2008
July 2008
June 2008
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
January 2007
December 2006
November 2006
October 2006
September 2006
August 2006
July 2006
June 2006
May 2006
April 2006
March 2006
February 2006
January 2006
December 2005
November 2005
October 2005
August 2005
July 2005
June 2005
May 2005

 

« 1950s and 2000s Conservatism | Main | A Modest Defense of Law Reviews »

November 09, 2005

ChoicePoint: More Than 145,000 Victims?

posted by Daniel J. Solove

choicepoint2.jpgChoicePoint just won't be outdone. They were, after all, the company that started all the extensive attention on data security breaches. Back in February 2005, ChoicePoint announced that it had improperly sold personal data on about 145,000 people to identity thieves. Pursuant to a California data security breach notice law, ChoicePoint notified the affected individuals in California. Soon afterwards, many states started thinking: Geez, we'd like our citizens to be informed too. They put up a fuss, and ChoicePoint voluntarily agreed to notify all of the 145,000 people it said were affected. Many states subsequently passed data security breach notification laws similar to California's.

After ChoicePoint's announcement came a barrage of announcements of security breaches by numerous companies and institutions. According to a very useful listing and tally by the Privacy Rights Clearinghouse, data security breaches have affected over 50 million Americans (there may surely be some double-counting here, as some unlucky folks may have been affected multiple times).

Now ChoicePoint has announced that it has notified another 17,000 people that their personal data was compromised in the breach announced in February. According to the AP:

ChoicePoint Inc., the company that disclosed earlier this year that thieves had accessed its massive database of consumer information, said Tuesday in a regulatory filing it has sent out another 17,000 notices to people telling them they may be victims of fraud.
The Alpharetta-based company had said in February, after announcing the breach, that it had notified roughly 145,000 consumers that they may have had their personal information improperly accessed.

That number has now increased to 162,000, ChoicePoint said in its quarterly report to the Securities and Exchange Commission. The filing did not detail reasons for the increase, though the company had previously said the number could ultimately be higher.

Related Posts:
1. Solove, Free Credit Reports: My Exciting Adventure (Concurring Opinions) (October 2005)
2. Solove, Notice Much Delayed: The FDIC Security Breach (PrawfsBlawg) (June 2005)
3. Solove, Data Security Breach Supersized: 40 Million People Affected (PrawfsBlawg) (June 2005)
4. Solove, Data Leaks: Déjà Vu All Over Again (PrawfsBlawg) (June 2005)
5. Solove, Tallying Up Data Security Breaches (PrawfsBlawg) (May 2005)

Posts on Identity Theft:
1. Solove, Youngest ID Theft Victim? (PrawfsBlawg) (July 2005)
2. Solove, Why Identity Theft Isn’t Pretty (PrawfsBlawg) (July 2005)
3. Solove, Identity Theft Fears and Online Shopping (PrawfsBlawg) (June 2005)
4. Solove, Identity Thief Professors (PrawfsBlawg) (June 2005)

Posted by Daniel J. Solove at November 9, 2005 12:35 PM

Trackback Pings

TrackBack URL for this entry:
http://www.concurringopinions.com/movabletype/mt-tb.cgi/181.

Comments

Isn't the relevant datum how many people have suffered some harm or loss? I find the Privacy Rights Clearinghouse collection interesting, but not particularly useful.

Shortly after the orignial ChoicePoint revelation, I heard that something like 700 or 1,000 people were victimized by identity fraud as a reault. That makes 144,000 people - now 161,000 - who were not, or about whom we don't know.

I would resist calling people to whom nothing has happened "victims".

Posted by: Jim Harper at November 10, 2005 11:01 AM


original

result

Honest, I know how to spell . . . .

Posted by: Jim Harper at November 10, 2005 11:03 AM


Jim,

Isn't there a harm in being exposed to a greater risk of future harm? So if a person is exposed to radiation, increasing his risk of cancer by a non-trivial amount, do we say that he is not harmed at all? The people whose information was leaked are indeed worse off. There is a harm here even though the people are not victimized by identity theft.

Posted by: Daniel J. Solove at November 11, 2005 12:16 AM


Having gone back to the law books, I have to admit having been slightly imprecise with language. I used "harm" to denote injury or damage. The word "harm" does appear to include metaphysical detriments like being placed at greater risk of some adverse event.

The question I'm trying to get at (and I've assumed we're working on because this is a law blog, not a philosophy blog) is when liability should accrue.

I would be very careful about equating (I would argue conflating) risk and harm (in the injury/damages sense). Try applying elsewhere the general principle that creation of 'non-trivial' risk is a legally cognizable harm: I would have a cause of action against hundreds of drivers every week, and they against me.

I reacted to your characterization of the people about whom data has been lost or leaked as "victims." I think the barriers around the meaning of the word have fallen away if each person exposed to a risk is a victim.

[I spell-checked this before posting in hopes of avoiding the humiliation of finding errors after posting again. ;-]

Posted by: Jim Harper at November 14, 2005 11:13 AM


Jim,

Based on things you've said here and elsewhere, here's how I understand your basic view as to how to address privacy and security issues:

1. You'd eliminate regulation and move to a common law tort model to address data security and privacy harms.

2. You'd only recognize liability when there's a "harm," which consists of an actual identity theft or fraud, not being exposed to a greater risk.

Here are the problems I see with your view:

1. Your common law tort model would be hard to work because harm often doesn't materialize immediately after an information leak. Information gets out there and it could be years before an identity theft occurs.

2. People are certainly worse off after their information is leaked. They may also feel anxiety about the increased risk of identity theft and fraud. Is there anything in your solution to make them whole again or to address their being worse off? If the system doesn't deter behavior that causes leaks (but ones that don't clearly result in "harm" as you define it), then how will it deter companies from making people worse off in this way?

3. Even in the event of an identity theft, it is very hard to prove causation. There are many sources of personal data -- how do we know an identity theft was caused by info leaked by a particular company? Does the identity thief's actions break the chain of causation? With such difficulty in establishing causation, can a tort regime be effective?

4. The damages from each identity theft victim are not likely to be gigantic. They will often be relatively insignificant for companies like ChoicePoint. The difficulty in proving causation might make tort cases relatively rare, and with small damages for each one. Thus, there's little of an incentive for companies to exercise better care. How do you address this issue?

5. What is the duty owed to particular people when companies maintain their data? There must be a duty before there's tort liability.

6. Quite frankly, I fear that your tort solution, definition of harm, and call for curtailing regulation is really a big boon for the companies that faciliate identity theft. My guess is that companies would just love your position -- it seems like it is tailor made for companies that want to avoid liability. You're basically attacking regulation and move toward a tort solution -- and it remains very dubious whether your tort solution will be more effective if not much much worse in protecting the consumer. I'm not adverse to using torts, but I'd very much like to see you develop your tort solution into something more meaningful -- to demonstrate how it might work, how it will have teeth, how it will more effectively address the problems. It's easy to say "less regulation; let's stick with common law torts," but I'm unconvinced unless you develop this more. I know that you're advancing your tort solution in good faith, but without elaboration on these issues, it appears as little more than a clever strategy to help out the companies.

Posted by: Daniel J. Solove at November 14, 2005 12:51 PM


These are great questions, and they do need more thorough answers. Hopefully, I can turn to that for my next project. (Currently finishing a book, out mid-next year, on identification - which you're gonna love!)

I will respond to the tweak in your last sentence: If someone really wanted to help companies, they would promote administrative regulation. Enforcement in that arena results in costs to wrongdoers as low as one one-thousandth of the ill-gotten gain. [Follow link to notable blog.]

Now that's a clever strategy!

Posted by: Jim Harper at November 14, 2005 01:24 PM


Post a comment




Remember Me?

(you may use HTML tags for style)

Authors

Daniel J. Solove

Website
Understanding Privacy

Kaimipono Wenger

Website
SSRN Page

Dave Hoffman

Website
SSRN Page

Nate Oman

Website
SSRN Page

Frank Pasquale

Website
SSRN Page

Deven Desai

Website
SSRN Page

Michael O'Shea

Website
SSRN Page

Sarah Waldeck

Website
SSRN Page

Lawrence Cunningham

Website
SSRN Page

Danielle Citron

Website
SSRN Page

Jaya Ramji-Nogales

Website
SSRN Page


Guests

Robert Ahdieh
Miriam Cherry
Mark Edwards
Susan Kuo
Jonathan Lipson
Scott Moss
David Opderback
Kristen Osenga
Geoffrey Rapp
Susan Scafidi
Howard Wasserman






ad-logo3.jpg

blawg100_winner2.jpg

Previous Guests

Michael Abramowicz
Michelle Adams
Robert Ahdieh
Michelle Anderson
Laura Appleman
Francesca Bignami
Jeremy Blumenthal
Bruce Boyden
Donald Braman
Al Brophy
Neil H. Buchanan
Bill Burke-White
Scott Burris
Anupam Chander
Miriam Cherry
Jack Chin
Jennifer Collins
Allison Danner
Brannon Denning
Deven Desai
Mike Dimino
Christine Haight Farley
Kim Ferzan
Dan Filler
Amanda Frost
Timothy Glynn
Rachel Godsil
Eric Goldman
Craig Green
Jeffrey Harrison
Erica Hashimoto
Carissa Hessick
Laura Heymann
Christine Hurt
Darian Ibrahim
Dan Kahan
Sam Kamin
Heidi Kitrosser
Adam Kolber
Russell Korobkin
Anita S. Krishnakumar
Greg Lastowka
Sarah Lawsky
Erik Lillquist
Jeff Lipshaw
Joseph Liu
Solangel Maldonado
Jason Mazzone
William McGeveran
Salil Mehra
Carrie Menkel-Meadow
Max Minzner
Scott Moss
Eric Muller
Jaya Ramji-Nogales
Elizabeth Nowicki
Paul Ohm
Michael O'Shea
Rafael Pardo
Marcy Peek
Eduardo Peñalver
Neil RIchards
Lori Ringhand
Alice Ristroph
Paul Secunda
Jessica Silbey
Peter Smith
Charles Sullivan
Rick Swedloff
Steph Tai
Robert Tsai
Steve Vladeck
Sarah Waldeck
Melissa Waters
Alfred Yen
David Zaring
Timothy Zick
Jonathan Zittrain

Blogroll

Above the Law
ACS Blog
Althouse
Balkinization
Becker-Posner Blog
Beltway Blogroll
BlackProf
BoingBoing
Chicago Law Faculty Blog
Conglomerate
Convictions
CrimLaw
Crime & Federalism
CrimProf Blog
Crooked Timber
Discourse.net
Dorf on Law
Election Law
Emergent Chaos
Feminist Law Profs
43(B)log
Freakonomics Blog
Freedom to Tinker
Google Blogoscoped
How Appealing
Ideoblog
Info/Law
Instapundit.com
JD2B.com
Juris Novus
Jurisdynamics
Law and Letters
Legal Profession Blog
Legal Theory Blog
Legal Times Blog
Leiter Reports
Brian Leiter's Law School Reports
Lessig Blog
Madisonian
Mirror of Justice
National Security Advisors
Opinio Juris
Point of Law
Political Theory Daily Review
PrawfsBlawg
ProfessorBainbridge.com
Property Prof
Red Tape Chronicles
The Right Coast
Schneier on Security
SCOTUSBlog
Security Dilemmas
Sentencing Law and Policy
Simple Justice
Sivacracy.net
The Situationist
Susan Crawford
TalkLeft
Talking Points Memo
TaxProf Blog
Tech & Marketing Law
Truth on the Market
Volokh Conspiracy
WorkPlace Prof Blog
WSJ Law Blog
Wonkette
The Yin Blog

Pajamas Media BlogRoll Member