The Right to Quantitative Privacy David Gray
Total Page:16
File Type:pdf, Size:1020Kb
University of Minnesota Law School Scholarship Repository Minnesota Law Review 2013 The Right to Quantitative Privacy David Gray Danielle Citron Follow this and additional works at: https://scholarship.law.umn.edu/mlr Part of the Law Commons Recommended Citation Gray, David and Citron, Danielle, "The Right to Quantitative Privacy" (2013). Minnesota Law Review. 285. https://scholarship.law.umn.edu/mlr/285 This Article is brought to you for free and open access by the University of Minnesota Law School. It has been accepted for inclusion in Minnesota Law Review collection by an authorized administrator of the Scholarship Repository. For more information, please contact [email protected]. Article The Right to Quantitative Privacy David Gray† & Danielle Citron†† Introduction ................................................................................. 63 I. Quantitative Privacy: The Perils of Broad and Indiscriminate Surveillance .................................................. 73 II. Quantitative Privacy and the Fourth Amendment ............ 83 A. Qualitative Privacy: The Fourth Amendment Before United States v. Jones ................................... 83 B. A Fourth Amendment Foothold for Quantitative Privacy in United States v. Jones ............................. 87 C. The Fourth Amendment Foundations of † Professor of Law, University of Maryland Francis King Carey School of Law. †† Lois K. Macht Research Professor & Professor of Law, University of Maryland Francis King Carey School of Law, Affiliate Scholar, Stanford Cen- ter on Internet and Society, Affiliate Fellow, Yale Information Society Project. The authors thank everyone who generously commented on this work during presentations at Yale’s Information Society Project, the Annual Meeting of the ABA/AALS Criminal Law Section, the University of North Carolina, North- western, Yale’s Conference on Locational Privacy and Biometrics, Law and So- ciety, the Privacy Law Scholars Conference, and the Computers, Freedom, and Privacy Conference, and during conversations at the American Law Institute Meeting on Information Privacy Law and Harvard Law Review’s Symposium on Informational Privacy. Particular thanks go to Ronald Allen, Julia Angwin, Jack Balkin, Kevin Bankston, Steve Bellovin, Marc Blitz, Richard Boldt, Becky Bolin, Mary Bowman, Al Brophy, Andrew Chin, Bryan Choi, Thomas Clancy, Julie Cohen, Thomas Crocker, Nick Doty, LisaMarie Freitas, Susan Freiwald, Barry Friedman, Brandon Garrett, Bob Gellman, Don Gifford, Mark Graber, John Grant, James Grimmelmann, Deborah Hellman, Leslie Meltzer Henry, Lance Hoffman, Renée Hutchins, Camilla Hrdy, Orin Kerr, Joseph Kennedy, Catherine Kim, Anne Klinefelter, Avner Levin, Michael Mannheimer, Dan Markel, Christina Mulligan, Richard Myers, Neil Richards, Catherine Sabbeth, Laurent Sacharoff, Paul Schwartz, Christopher Slobogin, Robert Smith, Dan Solove, Max Stearns, David Super, Harry Surden, Peter Swire, Peter Quint, Jason Weinstein, Arthur Weisburd, and Jonathan Witmer-Rich. We also thank Liz Clark Rinehart for her research assistance and Max Siegel for his insightful editing. Finally, we are grateful to Frank Lancaster for holding us together. Copyright © by David Gray and Danielle Citron. 62 2013] QUANTITATIVE PRIVACY 63 Quantitative Privacy ................................................. 92 III. The Technology-Centered Approach to Quantitative Privacy ......................................................... 101 A. Fourth Amendment Precedents for a Technology-Centered Approach .............................. 103 B. The Technology-Centered Approach and Aerial Surveillance Drones ................................................. 105 C. The Technology-Centered Approach and Data Aggregation .............................................................. 112 D. The Technology-Centered Approach and Human Surveillance .............................................................. 124 IV. Some Concerns About Quantitative Privacy in Practice . 125 A. The Technology-Centered Approach Resolves Practical Challenges ................................................ 126 B. The Technology-Centered Approach and the Public Observation Doctrine ................................... 131 C. The Technology-Centered Approach and the State Agency Requirement ..................................... 133 D. The Technology-Centered Approach and the Third-Party Doctrine ............................................... 137 Conclusion .................................................................................. 144 INTRODUCTION In June and July 2013, documents leaked by a government contractor revealed details of three expansive surveillance pro- grams operated by the Federal Bureau of Investigation (FBI) and the Department of Defense on behalf of the National Secu- rity Agency (NSA).1 The first requires that Verizon and other telecommunication companies provide to the NSA on a daily basis “all call detail records or ‘telephony metadata’ created by Verizon for communications (i) between the United States and abroad; or (ii) wholly within the United States, including local 1. See Barton Gellman & Laura Poitras, U.S., British Intelligence Min- ing Data from Nine U.S. Internet Companies in Broad Secret Program, WASH. POST, June 6, 2013, http://www.washingtonpost.com/investigations/us -intelligence-mining-data-from-nine-us-internet-companies-in-broad-secret -program/2013/06/06/3a0c0da8-cebf-11e2-8845-d970ccb04497_story.html; Glenn Greenwald, NSA Collecting Phone Records of Millions of Verizon Cus- tomers Daily, GUARDIAN, June 5, 2013, http://www.theguardian.com/world/ 2013/jun/06/nsa-phone-records-verizon-court-order [hereinafter Greenwald, Phone Records]; Glenn Greenwald, XKeyscore: NSA Tool Collects ‘Nearly Eve- rything a User Does on the Internet,’ GUARDIAN, July 31, 2013, http://www .theguardian.com/world/2013/jul/31/nsa-top-secret-program-online-data [here- inafter Greenwald, XKeyscore]. 64 MINNESOTA LAW REVIEW [98:62 telephone calls.”2 Although this program does not allow for the collection of content, including customers’ conversations, te- lephony metadata is a rich source of information, giving au- thorities vast knowledge about callers’ identity, location, and social networks.3 A second program, referred to in leaked doc- uments as “PRISM,” reportedly allows the NSA and the FBI to access “audio and video chats, photographs, e-mails, docu- ments, and connection logs” collected by nine leading U.S. in- ternet companies, including Google and Facebook.4 The third program, called XKeyscore, provides analysts with the capacity to mine content and metadata generated by e-mail, chat, and browsing activities through a global network of servers and in- ternet access points.5 These revelations confirm previous re- ports about a comprehensive domestic surveillance program that seeks to provide government agents with contemporary and perpetual access to details about everywhere we go and everything we do, say, or write, particularly when using or in the company of networked technologies.6 2. Verizon Forced to Hand Over Telephone Data‒Full Court Ruling, GUARDIAN, June 5, 2013, http://www.theguardian.com/world/interactive/2013/ jun/06/verizon-telephone-data-court-order [hereinafter FISA]. The NSA subse- quently released a declassified version of the order. See Declassified Govern- ment Documents Related to NSA Collection of Telephone Metadata Records, WASH. POST, http://apps.washingtonpost.com/g/page/politics/government -documents-related-to-nsa-collection-of-telephone-metadata-records/351/ (last visited Oct. 15, 2013). 3. Dan Roberts & Spencer Ackerman, Anger Swells After NSA Phone Records Court Order Revelations, GUARDIAN, June 6, 2013, http://www .theguardian.com/world/2013/jun/06/obama-administration-nsa-verizon -records (“[Telephony] metadata . can provide authorities with vast knowledge about a caller’s identity. [C]ross-checked against other public records, the metadata can reveal someone’s name, address, driver’s license, credit history, social security number and more.”). 4. Gellman & Poitras, supra note 1. The companies identified as partici- pants in PRISM have denied granting government agents open access to their servers. Id. As of this writing, the full truth of the program remains hidden behind a veil of alleged national security necessity. 5. Greenwald, XKeyscore, supra note 1. 6. See JAMES BAMFORD, THE SHADOW FACTORY 177–96 (2008) [hereinaf- ter BAMFORD, SHADDOW]; James Bamford, The NSA Is Building the Country’s Biggest Spy Center, WIRED MAG., Mar. 15, 2012, available at http://www.wired .com/threatlevel/2012/03/ff_nsadatacenter/all/1 [hereinafter Bamford, The NSA is Building]; Michael Isikoff, The Fed Who Blew the Whistle, NEWSWEEK (Dec. 12, 2008), http://www.thedailybeast.com/newsweek/2008/12/12/the-fed -who-blew-the-whistle.html; James Risen & Eric Lichtblau, Bush Lets U.S. Spy on Callers Without Courts, N.Y. TIMES, Dec. 15, 2005, http://www.nytimes .com/2005/12/16/politics/16program.html?pagewanted=all. 2013] QUANTITATIVE PRIVACY 65 The domestic surveillance infrastructure is not confined to our networked communications, however. Consider aerial drones. No longer just a feature of modern warfare, unmanned aerial drones now populate domestic airspace.7 Military-style drones operate along the United States border with Mexico.8 Farther inland, law enforcement agencies are starting to use a variety of drones during their routine police operations.9 Many of these drones are hardly visible, and some are as small as in- sects.10 Among the primary