Privacy on the Books and on the Ground

70 Pages Posted: 11 Mar 2010 Last revised: 6 Aug 2014

Kenneth A. Bamberger

University of California, Berkeley - School of Law

Deirdre K. Mulligan

University of California, Berkeley - School of Information

Date Written: November 18, 2011

Abstract

U.S. privacy law is under attack. Scholars and advocates criticize it as weak, incomplete, and confusing, and argue that it fails to empower individuals to control the use of their personal information. These critiques present a largely accurate description of the law “on the books.” But the debate has strangely ignored privacy “on the ground” - since 1994, no one has conducted a sustained inquiry into how corporations actually manage privacy, and what motivates them.

This Article presents findings from the first study of corporate privacy management in fifteen years, involving qualitative interviews with Chief Privacy Officers identified by their peers as industry leaders. Spurred by these findings, we present a descriptive account of privacy “on the ground” that upends the terms of the prevailing policy debate. This alternative account identifies elements neglected by the traditional story - the emergence of the Federal Trade Commission as a privacy regulator, the increasing influence of privacy advocates, market and media pressures for privacy-protection, and the rise of privacy professionals - and traces the ways in which these players supplemented a privacy debate largely focused on processes (such as notice and consent mechanisms) with a growing emphasis on substance: preventing violations of consumers’ expectations of privacy.

This “grounded” account should inform privacy reforms. While widespread efforts to expand consent mechanisms to empower individuals to control their personal information may offer some promise, those efforts should not proceed in a way that eclipses robust substantive definitions of privacy and the protections they are beginning to produce, or that constrains the regulatory flexibility that permits their evolution. This would destroy important tools for limiting corporate over-reaching, curbing consumer manipulation, and protecting shared expectations about the personal sphere on the Internet, and in the marketplace.

Keywords: privacy, regulation, consumer protection, chief privacy officers, Federal Trade Commission, data protection, new governance, organizational fields, professionalization

JEL Classification: D73, D81, K20, K23, O38

Suggested Citation

Bamberger, Kenneth A. and Mulligan, Deirdre K., Privacy on the Books and on the Ground (November 18, 2011). Stanford Law Review, Vol. 63, January 2011; UC Berkeley Public Law Research Paper No. 1568385. Available at SSRN: https://ssrn.com/abstract=1568385

Kenneth A. Bamberger (Contact Author)

University of California, Berkeley - School of Law ( email )

Boalt Hall NA446
Berkeley, CA 94720-7200
United States
(510) 643-6218 (Phone)

HOME PAGE: http://www.law.berkeley.edu/faculty/profiles/facultyProfile.php?facID=5701

Deirdre K. Mulligan

University of California, Berkeley - School of Information ( email )

102 South Hall
Berkeley, CA 94720-4600
United States

Paper statistics

Downloads
1,945
Rank
5,643
Abstract Views
13,381