Google Spain, the Right to Be Forgotten, and the Construction of the Public Sphere
Total Page:16
File Type:pdf, Size:1020Kb
POST IN PRINTER FINAL (DO NOT DELETE) 2/6/2018 10:44 AM DATA PRIVACY AND DIGNITARY PRIVACY: GOOGLE SPAIN, THE RIGHT TO BE FORGOTTEN, AND THE CONSTRUCTION OF THE PUBLIC SPHERE ROBERT C. POST† ABSTRACT The 2014 decision of the European Court of Justice in Google Spain controversially held that the fair information practices set forth in European Union (EU) Directive 95/46/EC (Directive) require that Google remove from search results links to websites that contain true information. Google Spain held that the Directive gives persons a “right to be forgotten.” At stake in Google Spain are values that involve both privacy and freedom of expression. Google Spain badly analyzes both. With regard to the latter, Google Spain fails to recognize that the circulation of texts of common interest among strangers makes possible the emergence of a “public” capable of forming the “public opinion” that is essential for democratic self-governance. As the rise of American newspapers in the nineteenth and twentieth centuries demonstrates, the press underwrites the public sphere by creating a structure of communication both responsive to public curiosity and independent of the content of any particular news story. Google, even though it is not itself an author, sustains the contemporary virtual public sphere by creating an analogous structure of communication. With regard to privacy values, EU law, like the laws of many nations, recognizes two distinct forms of privacy. The first is data privacy, which is protected by the fair information practices contained Copyright © 2018 Robert C. Post. † Sterling Professor of Law, Yale Law School. I am deeply grateful for the research assistance of Jeremy Buotte, Conor Clark, Nina Cohen, Samir Doshi, Jean-Philippe Foegle, Jesse Hogin, Bryn Lese, Bernat Torok, and Andrew Udelsman. I am fortunate indeed to have received helpful and constructive advice from Jack Balkin, Eduardo Bertoni, R. Howard Bloch, Frederik Zuiderveen Borgesius, Pablo Salvador Coderch, Jennifer Daskal, Anuj Desai, David Erdos, Krzysztof Garstka, Dieter Grimm, Amy Kapczynski, Daphne Keller, Leslie Kendrick, Antoni Rubi Puig, Artemi Rallo, Jeffrey Rosen, Timo Ruikka, Reva Siegel, Daniel Solove, Alexander Tsesis, Eugene Volokh, and Patrick Weil. Thanks also to my friend and guide, Paul Schwartz, without whom this never would have been written. POST IN PRINTER FINAL (DO NOT DELETE) 2/6/2018 10:44 AM 982 DUKE LAW JOURNAL [Vol. 67:981 in the Directive. These practices regulate the processing of personal information to ensure (among other things) that such information is used only for the specified purposes for which it has been legally gathered. Data privacy operates according to an instrumental logic, and it seeks to endow persons with “control” over their personal data. Data subjects need not demonstrate harm in order to establish violations of data privacy. The second form of privacy recognized by EU law is dignitary privacy. Article 7 of the Charter of Fundamental Rights of the European Union protects the dignity of persons by regulating inappropriate communications that threaten to degrade, humiliate, or mortify them. Dignitary privacy follows a normative logic designed to prevent harm to personality caused by the violation of civility rules. There are the same privacy values as those safeguarded by the American tort of public disclosure of private facts. Throughout the world, courts protect dignitary privacy by balancing the harm that a communication may cause to personality against legitimate public interests in the communication. The instrumental logic of data privacy is inapplicable to public discourse, which is why the Directive contains derogations for journalistic activities. The communicative action characteristic of the public sphere is made up of intersubjective dialogue, which is antithetical both to the instrumental rationality of data privacy and to its aspiration to ensure individual control of personal information. Because the Google search engine underwrites the public sphere in which public discourse takes place, Google Spain should not have applied fair information practices to Google searches. But the Google Spain opinion also invokes Article 7, and in the end the decision creates doctrinal rules that are roughly approximate to those used to protect dignitary privacy. The Google Spain opinion is thus deeply confused about the kind of privacy it wishes to protect. It is impossible to ascertain whether the decision seeks to protect data privacy or dignitary privacy. Google Spain is ultimately pushed in the direction of dignitary privacy because data privacy is incompatible with public discourse, whereas dignitary privacy may be reconciled with the requirements of public discourse. Insofar as freedom of expression is valued because it fosters democratic self-government, public discourse cannot serve as an effective instrument of self-determination without a modicum of civility. Yet the Google Spain decision recognizes dignitary privacy only in a rudimentary and unsatisfactory way. If it had more clearly focused on the requirements of dignitary privacy, Google Spain would not so sharply have distinguished Google links from the underlying POST IN PRINTER FINAL (DO NOT DELETE) 2/6/2018 10:44 AM 2018] RIGHT TO BE FORGOTTEN 983 websites to which they refer. Google Spain would not have blithely outsourced the enforcement of the right to be forgotten to a private corporation like Google. TABLE OF CONTENTS Introduction ............................................................................................ 983 I. A Critical Analysis of Google Spain ................................................ 995 A. Data Privacy and Ordinary Life ......................................... 995 B. Data Privacy, Dignitary Privacy, and the Public Sphere ...................................................................... 1002 C. Ambiguities in the Google Spain Opinion ...................... 1010 II. The Rise of a “Newspaperized World” ....................................... 1017 III. Google and the Public Sphere ..................................................... 1039 IV. Google, the RTBF, and the Right To Be Forgotten ................ 1046 A. Google and the RTBF ....................................................... 1047 B. Google Spain and the Right To Be Forgotten ................ 1054 V. Conclusion ....................................................................................... 1070 Appendix ............................................................................................... 1072 INTRODUCTION Lying at the intersection of big data and mass communication, the Internet has become the site of furious tension between data privacy and freedom of expression. The conflict is especially acute in the European Union (EU), which highly prizes the protection of personal information. Data privacy is typically secured by “fair information practices” that seek to ensure the accuracy, transparency, and instrumental rationality of data processing.1 Article 40 of the 1978 French Privacy 1. David H. Flaherty, Governmental Surveillance and Bureaucratic Accountability: Data Protection Agencies in Western Societies, 11 SCI. TECH. & HUM. VALUES 7, 8 (1986). “The West German state of Hesse passed the first general data protection law in 1970,” followed by “Sweden (1973); United States (1974); Federal Republic of Germany (1977); Canada (1977); France (1978); and the United Kingdom (1984).” Id. at 7–8. “The influential [1981] OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data summarize the basic principles for national application in the following terms: collection limitation, data quality, purpose specification, use limitation, security safeguards, openness, individual participation, and accountability.” Id. at 8. POST IN PRINTER FINAL (DO NOT DELETE) 2/6/2018 10:44 AM 984 DUKE LAW JOURNAL [Vol. 67:981 Law2 established “the central principle of the right to be forgotten,”3 providing that “[e]very data subject can . require the data controller to rectify, complete, update, lock out or erase personal data relating to him or her, where the data is inaccurate, incomplete, ambiguous, expired, or whose collection, use, communication or storage is forbidden.”4 Fair information practices were consolidated in the EU in 1995 with the adoption of Directive 95/46/EC5 (Directive), which “is probably the most influential data privacy text in the world.”6 The Directive requires Member States to protect the privacy of “data subjects” by enacting laws that require personal data be “collected [only] for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes”; that the processing of data be “adequate, relevant and not excessive in relation to the purposes for which they are collected”; that personal data be maintained accurately and “kept up to date”; and that personal data be “kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data were 2. Loi No. 78-17 du 6 janvier 1978 relative à l’informatique, aux fichiers et aux libertés [Law 78-17 of January 6, 1978 on Information Technology, Data Files and Civil Liberties], JOURNAL OFFICIEL DE LA REPUBLIQUE FRANÇAISE [J.O.] [OFFICIAL GAZETTE OF FRANCE], Jan. 7, 1978, art. 40. 3. DAVID H. FLAHERTY, PROTECTING PRIVACY IN SURVEILLANCE SOCIETIES: THE FEDERAL REPUBLIC OF GERMANY, SWEDEN, FRANCE, CANADA, AND THE UNITED STATES 180 (1989). Writing in 1989, Flaherty