the Law, the Universe, and Everything 

Search

Concurring Opinions is a
general-interest legal blog
operated by Concurring
Opinions LLC, a Pennsylvania
Limited Liability Corporation.

Yale University Press

ad-logo5.jpg

Our Podcast

Subscribe to Law Talk

Law-Rev-Forum-2.jpg

law-rev-contents2.jpg

Law-Prof-Blog-Census.jpg

Categories

Administrative Announcements
Administrative Law
Admiralty
Advertising
Agricultural Law
Anonymity
Antitrust
Architecture
Articles and Books
Bankruptcy
Behavioral Law and Economics
Bioethics
Blogging
Book Reviews
Capital Punishment
Civil Procedure
Civil Rights
Conferences
Constitutional Law
Consumer Protection Law
Contract Law & Beyond
Corporate Law
Criminal Law
Criminal Procedure
Culture
Current Events
Cyberlaw
DRM
Economic Analysis of Law
Education
Empirical Analysis of Law
Employment Law
Environmental Law
Family Law
Feminism and Gender
First Amendment
Food
Google & Search Engines
Health Law
History of Law
Humor
Immigration
Insurance Law
Intellectual Property
International & Comparative Law
Interviews
Jurisprudence
Law and Humanities
Law and Inequality
Law and Psychology
Law Practice
Law Professor Blogger Census
Law Rev (Boston College)
Law Rev (Boston University)
Law Rev (California)
Law Rev (Chicago)
Law Rev (Columbia)
Law Rev (Cornell)
Law Rev (Duke)
Law Rev (Emory)
Law Rev (Fordham)
Law Rev (Georgetown)
Law Rev (GW)
Law Rev (Harvard)
Law Rev (Illinois)
Law Rev (Indiana)
Law Rev (Michigan)
Law Rev (Minnesota)
Law Rev (Northwestern)
Law Rev (Notre Dame)
Law Rev (NYU)
Law Rev (Penn)
Law Rev (S Cal)
Law Rev (Stanford)
Law Rev (Texas)
Law Rev (UCLA)
Law Rev (Vanderbilt)
Law Rev (Virginia)
Law Rev (Wash U)
Law Rev (Yale)
Law Rev Contents
Law Rev Forum
Law School
Law School (Hiring & Laterals)
Law School (Law Reviews)
Law School (Rankings)
Law School (Scholarship)
Law School (Teaching)
Law Student Discussions
Law Talk
Legal Ethics
Legal Theory
Media Law
Movies & Television
Philosophy of Social Science
Politics
Privacy
Privacy (Consumer Privacy)
Privacy (Electronic Surveillance)
Privacy (Gossip & Shaming)
Privacy (ID Theft)
Privacy (Law Enforcement)
Privacy (Medical)
Privacy (National Security)
Property Law
Race
Religion
Reparations
Science Fiction
Securities
Social Network Websites
Sociology of Law
Supreme Court
Tax
Teaching
Technology
Tort Law
Web 2.0
Weird
Wiki
Wills, Trusts, and Estates

Recent Comments

Archives

May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
January 2007
December 2006
November 2006
October 2006
September 2006
August 2006
July 2006
June 2006
May 2006
April 2006
March 2006
February 2006
January 2006
December 2005
November 2005
October 2005
August 2005
July 2005
June 2005

 

« Slapping Down Lower Courts | Main | "I'm not crazy, I'm just a little unwell" -- a DSM for bloggers »

April 11, 2006

The Datran Media Case: Information Privacy Due Diligence

posted by Daniel J. Solove

datran.jpgRecently, New York AG Eliot Spitzer settled a case against Datran Media that could have some wide-ranging implications for information privacy law. Datran Media styles itself "a leading performance-based marketing company with Enabling Technology that connects marketers to consumers through a comprehensive set of email marketing and digital media services." This is basically a verbose way of saying that it sends unsolicited email, which is perhaps a kind way of describing spam.

Datran obtained personal information from other companies which violated their privacy policies in selling the data to Datran. According to the AP:

The Internet "customer acquisition" companies proclaimed on their websites that they wouldn't lend or sell the information provided. Consumers were often enticed to reveal their names, addresses and financial data in exchange for free iPods and DVD movies.

Spitzer accused Datran of knowing of the companies' pledges but nevertheless spamming those consumers with unsolicited e-mails advertising discount drugs, diet pills and other products. Spitzer's staff said it believed this was the largest deliberate breach of Internet privacy discovered by U.S. authorities.

In other words, the theory of the case was that Datran engaged in "unfair and deceptive trade practices" when it acquired and used information which it knew was being improperly supplied. Datran settled with Spitzer for $1.1 million. The settlement agreement is here.

Obviously, the database industry is up in arms. In an article critical of the case, Kirk Nahra, a partner at the law firm of Wiley Rein & Fielding, LLP, describes it as an "Alice-in-Wonderland result." He observes that "Spitzer is holding Datran liable for the list seller's violation of its own policies." He goes on to write:

How far will this go? Does the vendor have to review underlying consents? Does the vendor have to engage in an audit of the list supplier's privacy practices? How does this new vendor-to-vendor due diligence obligation affect the already growing client-to-vendor oversight obligations?

Obviously, it is too soon to know the full implications of this case—including whether there are any real implications beyond this specific set of facts and companies. It is clear, however, that the Datran settlement adds a new and difficult dimension to vendor contracting, making it even more time consuming and burdensome to retain vendors for any activity that involves personal information. Is that really a result that protects people's privacy?

I don't think that the Datran theory is so outlandish. Under fiduciary duty law, a person can be liable for knowingly accepting the benefit of a breach. The law restricts knowingly receiving stolen property. And the federal Wiretap Act of ECPA penalizes any person "who intentionally discloses, or endeavors to disclose, to any other person the contents of any wire, oral, or electronic communication, knowing or having reason to know that the information was obtained through the interception of a wire, oral, or electronic communication in violation of this subsection." 18 U.S.C. § 2511(1)(c). Therefore, many other areas of the law recognize the concept of liability for knowingly benefiting when another party has violated the law or breached a duty to another.

Chris Hoofnagle has an excellent discussion of the implications of this case:

As a result of the case, it's clear that it is unfair and deceptive to acquire personal information knowing that the data come from a site that promises not to sell it. But does it also mean that Datran violated the law in cases where it didn't know or should have known about the sellers' privacy policies?

Guidance may be found later in the settlement agreement, where Datran agreed to independently review the provenance of all personal information it buys, to confirm that the seller explicitly stated to consumers that the data could be transferred to third parties, and to keep copies of these privacy policies.

In order to limit exposure to further lawsuits, all purchasers of personal information are going to have to exercise more due diligence in how they select lists.

Indeed, maybe a little due diligence isn't so bad or unjustified. Read more at Chris's posts here and here.

Posted by Daniel J. Solove at April 11, 2006 01:45 AM

Trackback Pings

TrackBack URL for this entry:
http://www.concurringopinions.com/movabletype/mt-tb.cgi/722.

Comments

Post a comment




Remember Me?

(you may use HTML tags for style)

Authors

Daniel J. Solove

Website
Understanding Privacy

Kaimipono Wenger

Website
SSRN Page

Dave Hoffman

Website
SSRN Page

Nate Oman

Website
SSRN Page

Frank Pasquale

Website
SSRN Page

Deven Desai

Website
SSRN Page


Guests

William Birdthistle
Elaine Chiu
David Fontana
James Grimmelmann
Dan Kahan
Sam Kamin
Anita S. Krishnakumar
William McGeveran
Michael O'Shea






ad-logo3.jpg

blawg100_winner2.jpg

Previous Guests

Michael Abramowicz
Michelle Adams
Robert Ahdieh
Michelle Anderson
Laura Appleman
Francesca Bignami
Jeremy Blumenthal
Bruce Boyden
Donald Braman
Al Brophy
Bill Burke-White
Scott Burris
Anupam Chander
Miriam Cherry
Jack Chin
Jennifer Collins
Allison Danner
Brannon Denning
Deven Desai
Mike Dimino
Christine Haight Farley
Kim Ferzan
Dan Filler
Amanda Frost
Timothy Glynn
Rachel Godsil
Eric Goldman
Craig Green
Jeffrey Harrison
Erica Hashimoto
Laura Heymann
Christine Hurt
Heidi Kitrosser
Adam Kolber
Russell Korobkin
Anita S. Krishnakumar
Greg Lastowka
Joseph Liu
Solangel Maldonado
Jason Mazzone
William McGeveran
Salil Mehra
Carrie Menkel-Meadow
Scott Moss
Eric Muller
Jaya Ramji-Nogales
Elizabeth Nowicki
Paul Ohm
Michael O'Shea
Rafael Pardo
Marcy Peek
Eduardo Peñalver
Neil RIchards
Lori Ringhand
Alice Ristroph
Paul Secunda
Peter Smith
Charles Sullivan
Rick Swedloff
Steph Tai
Robert Tsai
Steve Vladeck
Sarah Waldeck
Melissa Waters
Alfred Yen
David Zaring
Timothy Zick
Jonathan Zittrain

Blogroll

Above the Law
ACS Blog
Althouse
Balkinization
Becker-Posner Blog
Beltway Blogroll
BlackProf
BoingBoing
Chicago Law Faculty Blog
Conglomerate
Convictions
CrimLaw
Crime & Federalism
CrimProf Blog
Crooked Timber
Discourse.net
Dorf on Law
Election Law
Emergent Chaos
Feminist Law Profs
43(B)log
Freakonomics Blog
Freedom to Tinker
Google Blogoscoped
How Appealing
Ideoblog
Info/Law
Instapundit.com
JD2B.com
Juris Novus
Jurisdynamics
Law and Letters
Legal Profession Blog
Legal Theory Blog
Legal Times Blog
Leiter Reports
Brian Leiter's Law School Reports
Lessig Blog
Madisonian
Mirror of Justice
National Security Advisors
Opinio Juris
Point of Law
Political Theory Daily Review
PrawfsBlawg
ProfessorBainbridge.com
Property Prof
Red Tape Chronicles
The Right Coast
Schneier on Security
SCOTUSBlog
Security Dilemmas
Sentencing Law and Policy
Simple Justice
Sivacracy.net
The Situationist
Susan Crawford
TalkLeft
Talking Points Memo
TaxProf Blog
Tech & Marketing Law
Truth on the Market
Volokh Conspiracy
WorkPlace Prof Blog
WSJ Law Blog
Wonkette
The Yin Blog

Pajamas Media BlogRoll Member