
Every day, personal data is bought, sold, and traded online by companies most people have never heard of, often for purposes they never explicitly agreed to. Consumers typically don’t know it’s happening. And the businesses operating websites are also often in the dark as to how some data-collection technologies work in practice.
Artificial intelligence is helping legal teams pull back the curtain on how companies that buy and sell consumer information online—often called data brokers—access and use that data. That same technology is also helping organizations that operate online understand whether their data privacy policies and practices are actually effective.
Data privacy litigation has historically focused on website owners that collect personal digital data, such as health information, financial details, browsing activity, location, and communications, without consent. This can happen when operators add third-party tracking technologies, such as cookies and pixels, to their websites.
Pixels collect and transmit user data so websites can better understand who a user is and what actions they might take. Cookies store data on a user’s computer, allowing websites to identify the user and provide a targeted experience based on past online behavior.
Courts increasingly view the practice of intercepting and disclosing this type of consumer behavior data without proper consent as a potential wiretap violation. Wiretap claims against medical websites, in particular, have historically dominated this area of plaintiff litigation.
A new kind of case is emerging for firms seeking to protect consumer data through the courts. Instead of focusing on consumer-facing companies, plaintiffs are bringing claims against organizations whose trackers collect consumer information in the background of those websites and profit from it (often without explicit consent and in violation of data privacy statutes) using the Electronic Communications Privacy Act (“ECPA”).
These more recent cases go beyond the tech giants that have historically faced class action lawsuits (e.g., Google and Facebook) and look at other players in the adtech pipeline. These entities are typically registered data brokers that operate within the real-time bidding (“RTB”) infrastructure, which precisely targets ads to individual users based on the information collected about them.
Key developments driving potential claims against data brokers include the emergence of positive case law on the privacy harm of profiling users.
While data broker and adtech vendor privacy claims are growing in number, there are several hurdles to bringing forward these claims, from clearly defining the class to proving harm on technology platforms that are constantly changing. Understanding which companies introduce the risk and identifying class members can be challenging.
Related: New Rules For Regulated Industries Released
Proving harm or consent is also a challenge, with different legal theories existing about what counts as a privacy harm and what level of consent is required when being tracked online. The concept of broad consent versus narrow consent is being debated in courts, with some arguing that users must be informed of the specific ways in which their information is tracked and shared.
As litigation in this sector continues to grow, AI can be used to scan cases and identify potential patterns that could help legal teams more efficiently identify, and therefore mitigate, other areas of potential harm. Public marketing materials from data brokers and other adtech vendors can be analyzed to flag inconsistencies between actual practices and consumer harm policies.
With the emergence of AI, identification of data privacy violations is shifting from reactive methods to proactive ones. Litigation will likely continue to rise, but companies and consumers can take steps to better understand how data brokers access data and how that access is reflected in the privacy policies they ask customers to accept.
Privacy advocates will likely continue to unearth privacy violations caused by data brokers at scale. With this new depth of insight, legal teams have the clarity and foresight needed to flag and address signals of data privacy risk to not only protect consumer data today but also shape how consumer data is tracked and shared online for decades to come.
In practice, this means that consumers will have more control over their personal data, and companies will be held accountable for their data collection and use practices. As AI technology continues to evolve, it will play an increasingly important role in helping legal teams and organizations understand the affordability crisis in consumer data privacy.
They will also be able to analyze public marketing materials to identify inconsistencies between actual practices and privacy policies, and flag potential areas of harm. This will enable them to take proactive steps to mitigate these risks and ensure that consumer data is protected.
Legal teams and organizations are working to handle this complex issue.
Consumers are becoming more aware of the importance of protecting their personal data. Companies are being held accountable for their data collection and use practices.
Leave a Reply