Home | About | RSS Feed | Contact and Publicity Guidelines | Comment Policy the Law, the Universe, and Everything 

Search


Concurring Opinions is a
general-interest legal blog
operated by Concurring
Opinions LLC, a Pennsylvania
Limited Liability Corporation.

jr_114_9780195367195_bnr

jr_114_9780195383768_bnr

advertise-here4


FC-CO(SS)

Our Podcast

Subscribe to Law Talk

law-rev-contents2.jpg


  • Posts by Author

  • Categories

  • Archives


  • Recent Comments

    • Mike Zimmer on From the other side at AALS . . .

    • Mike Zimmer on The Employer’s Strategy in Gross v. FBL Financials

    • Mike Zimmer on Drafting the 28th Amendment

    • M.G.M on Drafting the 28th Amendment

    • A.J. Sutter on Lawyers: Don’t Trade on Inside Information!

    • No Load Funds on Consumer Financial Product Safety?

    • grad student on Princeton and the Behavioral Revolution

    • Anon321 on The Passive Voice in Statutory Interpretation

    • Steven Kaminshine on The Employer’s Strategy in Gross v. FBL Financials

    • Alex Kreit on Politicians: Have you talked to your constituents about drug policy?

    • Alex Kreit on Election Night 2009

    • mikeb302000 on Election Night 2009

    • Neal Goldfarb on The Passive Voice in Statutory Interpretation

    • Orin Kerr on Politicians: Have you talked to your constituents about drug policy?

    • MYarnell on Curricular Reform Revisited

  •  

    Site Meter

The Facebook-Fandango Connection: Invasion of Privacy?

posted by Daniel Solove

facebook3.jpgfandango.jpg

Facebook recently rolled out a new advertising program called Social Ads, where Facebook users’ images, names, and words are used to help advertise products and services. I blogged about Facebook’s Social Ads here and here, contending that they are likely a violation of the tort of appropriation of name or likeness as well as the right to publicity tort.

Peter Lattman at the WSJ Blog has a great new post about Facebook that throws in another even more troubling wrinkle:

Last Sunday the Law Blog purchased three tickets to “Bee Movie” on Fandango, the movie site. After we did this, Facebook automatically updated our profile to say, “Peter bought ‘Bee Movie’ on Fandango.”

Huh? Did we want everyone on Facebook to know our movie-buying habits? Not really. But it seems we agreed to this. According to Fandango’s privacy policy, which we agreed to by using the site, “If you are a member of a social network service (such as Facebook, MySpace, etc.) or you use other Internet sites where you have authorized them to gather information about your online behavior on Fandango . . . Fandango may share information regarding your activities . . . with those third parties pursuant to your authorization.”

Then we checked out our privacy settings on Facebook. Under “Privacy Settings for External Websites,” there’s a Fandango icon, indicating that we’ve agreed to have our actions on Fandango sent to our Facebook profile. We changed our profile, mandating that they never — never! — do this again.

This case illustrates why the current legal regime regulating personal information at most websites is so deeply flawed. The default settings are set to allow information sharing and disclosure, with users often completely unaware of how their information is going to be used. Businesses frequently tout how they are protecting privacy by providing users with “notice and choice” about how their information will be collected, used, and disseminated. Yet the system rarely results in informed consumers or meaningful choices.

So imagine: You go to Fandango and buy tickets to see a movie — and then all of a sudden your purchase is being revealed publicly to everybody you know on Facebook. You probably didn’t even know that Facebook had this deal with Fandango. What if more websites like Fandango start to collude with Facebook? Does this mean that every time we visit a website, every time we make a purchase, the information starts showing up in our Facebook profiles and on our friends’ Facebook profiles?

At least Social Ads, as I understood it, involved people publicly stating they liked or used a product. This is still problematic, for the reasons I discussed in my posts — being used in an ad unwittingly is a harm even if one has publicly praised the things being advertised in the past. But now Facebook is taking things one step beyond by exposing people’s personal information to the public. Perhaps Peter Lattman doesn’t want the world to know that he saw Bee Movie. Perhaps he does. But this is something he should decide, not the corporate officials at Facebook or Fandango.

“Poor Peter,” Fandango and Facebook will say, “But you should have read our privacy policies! It’s all your fault Peter.” Fandango’s privacy policy states:

If you are a member of a social network service (such as Facebook, MySpace, etc.) or you use other Internet sites where you have authorized them to gather information about your online behavior on Fandango (for instance, to notify your friends that you have viewed a video or bought movie tickets), including participation in any behavioral reporting program that they may operate on or off of their own site (i.e., Facebook Beacon, etc.), Fandango may share information regarding your activities on our Site or other Service with those third parties pursuant to your authorization, and they may associate that information with Personally Identifiable Information they already have about you (such as your Facebook Profile) and use it to improve their site or services or for other purposes. Fandango does not control the privacy policies of such third parties, and their privacy policies will govern their use of your information once it has been transmitted by Fandango. Fandango assumes no responsibility or liability for the actions of such third parties with respect to their use of your information or otherwise. Accordingly, make sure you are aware of and comfortable with the privacy policies of any third parties that you authorize to gather information from Fandango.

Get that? If you don’t like it, Fandango is saying you should take it up with Facebook. This paragraph is buried in a very lengthy policy of 2474 words. But if you’ve used Fandango, you’ve agreed to it, whether you read it or not. According to the policy:

When you use the Site or other Service, you are accepting the terms and conditions of this Privacy Policy, and Fandango will have the right to use your Personally Identifiable Information or other information about you as described in this Privacy Policy.

So Fandango passes the buck to Facebook. On to Facebook then. Facebook’s privacy policy clocks in at 3514 words. Plus, you can’t just read that. You also need to read the Terms of Use (a mere 6445 words). And then check your default settings, which are preset to maximize the exposure of your information. And of course, the privacy policies of Facebook, Fandango, and any other website that might later share information with Facebook are subject to change at moment’s notice, all without notifying you of the change!

So read up! Read often! Does this really make sense as a meaningful way to protect consumer privacy?

There’s another way to protect people’s privacy — opt-in. If Fandango wants to share your information with Facebook, it should ask for your consent first before doing so. Simply providing a privacy policy, a verbose and lengthy document that nobody reads and that is subject to change at any moment isn’t sufficient. You don’t consent just because they assume you do. If Facebook wants to disclose what you’re doing and buying on other websites, or use your name or image in an ad, then it should ask you. Instead, these companies hide behind thousands of words of legalese, claiming that by merely providing a little link to these policies at the bottom of their websites, you’ve consented to them the second you start using the site. This isn’t meaningful consent. And it isn’t a meaningful way to protect consumer privacy.


 November 16, 2007 at 1:57 pm   Posted in: Privacy, Privacy (Consumer Privacy), Social Network Websites, Technology, Tort Law, Web 2.0   Print This Post Print This Post

Responses (3)

  1. 2L - November 16, 2007 at 8:16 pm

    It’s not just Fandango, seems to be at least a few different retailers. I just bought a pair of moccasins on Zappos.com and the same thing happened to me. The fact that I’d bought the shoes, and a link to them, was on my main profile page. Now there’s a Zappos icon in my privacy settings. Facebook users will have to actively change the privacy setting for every online store where they shop that has this kind of relationship with Facebook each time they make a purchase, and don’t want the purchase broadcast on their profile. That doesn’t seem right…. even if I “should have” read the privacy policy.

  2. unc 2L - November 17, 2007 at 9:38 am

    It gets worse than that at facebook. Facebook gives you no chance to opt-out of sharing that information from 3rd party sites until after they have already received something and posted it.

    If you go to the external websites tab in your privacy settings on Facebook, you don’t see any websites listed unless they have already received some information from one.

    So the harm to your privacy is already done before you get a chance to stop it from happening.

  3. carrollstraus - February 15, 2008 at 1:07 pm

    Yep, i just checked and i got dinged because i logged on to “Swap Anything.”

    I am not part of the age demographic that lives and dies by Facebook, and i find the public face of that demographic disheartenig to say the least, but I refuse to become a dinosaur. So i checked it out.

    But all the on line and software user agreements we all sign are 1) onerous 2) usually unintellible 3) without a doubt contracts of adhesion and 4) almost certainly incapable of standing up in court.

    But they are so ubiquitous and so seldom an issue that no one will do anything about it until, and unless there is a really big scandal. Ivolving blood. Mayhem.

    Or some DEEP pockets.

    Good luck, to those of you who would ask for decency, fairness, common sense. These are crrently out of vogue, as the meanspirited among the comments above show all to well.

Leave a Reply

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word


  • « Previous post
  • Next post »

Authors

Daniel J. Solove

Website
Understanding Privacy

Kaimipono Wenger

Website
SSRN Page

Dave Hoffman

Website
SSRN Page

Nate Oman

Website
SSRN Page

Frank Pasquale

Website
SSRN Page

Deven Desai

Website
SSRN Page

Danielle Citron

Website
SSRN Page

Lawrence Cunningham

Website
SSRN Page

Sarah Waldeck

Website
SSRN Page

Jaya Ramji-Nogales

Website
SSRN Page

Solangel Maldonado

Website
SSRN Page

Gerard Magliocca

Website
SSRN Page


Guests

Rachel Godsil
Alex Kreit
Anita Krishnakumar
Matthew Sag
Michael Zimmer






Previous Guests

Michael Abramowicz
Michelle Adams
Robert Ahdieh
Michelle Anderson
Laura Appleman
Ann Bartow
Francesca Bignami
Jeremy Blumenthal
Kathleen Boozang
Bruce Boyden
Donald Braman
Al Brophy
Neil H. Buchanan
Bill Burke-White
Scott Burris
Paul Butler
Naomi Cahn
Anupam Chander
Miriam Cherry
Jack Chin
Jennifer Collins
Allison Danner
Brannon Denning
Deven Desai
Mike Dimino
Mark Edwards
David Fagundes
Christine Haight Farley
Kim Ferzan
Dan Filler
Michael Froomkin
Amanda Frost
Timothy Glynn
Rachel Godsil
Eric Goldman
David Gray
Craig Green
Tristin Green
Jeffrey Harrison
Erica Hashimoto
Carissa Hessick
Laura Heymann
Robert Hillman
Christine Hurt
Darian Ibrahim
John Ip
Kevin Johnson
Dan Kahan
Brian Kalt
Sam Kamin
Michael Kang
Chimène Keitner
Orin Kerr
Nancy Kim
Heidi Kitrosser
Adam Kolber
Russell Korobkin
Anita S. Krishnakumar
Susan Kuo
Greg Lastowka
Sarah Lawsky
Erik Lillquist
Jeff Lipshaw
Jonathan Lipson
Jacqueline Lipton
Joseph Liu
Michael Madison
Solangel Maldonado
Jason Mazzone
Linda McClain
William McGeveran
Salil Mehra
Carrie Menkel-Meadow
Max Minzner
Scott Moss
Eric Muller
Jaya Ramji-Nogales
Helen Norton
Elizabeth Nowicki
Paul Ohm
Michael O'Shea
David Opderback
Kristen Osenga
Rafael Pardo
Marcy Peek
Eduardo Peñalver
Robert Percival
David Post
Shruti Rana
Geoffrey Rapp
Neil Richards
Lori Ringhand
Alice Ristroph
Susan Scafidi
Paul Secunda
Jonathan Siegel
Jessica Silbey
Peter Smith
Charles Sullivan
Rick Swedloff
Steph Tai
Andrew Taslitz
Robert Tsai
Jenia Turner
Steve Vladeck
Sarah Waldeck
Melissa Waters
Alfred Yen
David Zaring
Timothy Zick
Spencer Weber Waller
Howard Wasserman
Frank Wu
Corey Yung
Jonathan Zittrain

Blogroll

Above the Law
ACS Blog
Althouse
Balkinization
Becker-Posner Blog
BlackProf
BoingBoing
Chicago Law Faculty Blog
Conglomerate
CrimLaw
Crime & Federalism
CrimProf Blog
Crooked Timber
Discourse.net
Dorf on Law
Election Law
Emergent Chaos
The Faculty Lounge
Feminist Law Profs
43(B)log
Freakonomics Blog
Freedom to Tinker
Google Blogoscoped
How Appealing
Ideoblog
Info/Law
Instapundit.com
Juris Novus
Jurisdynamics
Law and Humanities Blog
Law and Letters
Law Librarian Blog
Legal Profession Blog
Legal Theory Blog
Legal Times Blog
Leiter Reports
Brian Leiter's Law School Reports
Lessig Blog
Madisonian Theory
Media Law Blog
Mirror of Justice
The Moderate Voice
National Security Advisors
Opinio Juris
Point of Law
PrawfsBlawg
ProfessorBainbridge.com
Property Prof Blog
Red Tape Chronicles
The Right Coast
Schneier on Security
SCOTUSBlog
Security Dilemmas
Sentencing Law and Policy
Simple Justice
Sivacracy.net
The Situationist
Susan Crawford
TalkLeft
Talking Points Memo
TaxProf Blog
Tech & Marketing Law
Truth on the Market
Volokh Conspiracy
WorkPlace Prof Blog
WSJ Law Blog
Wonkette
The Yin Blog


© Concurring Opinions

Powered by WordPress