Privacy in the USA
Total Page:16
File Type:pdf, Size:1020Kb
Privacy in the USA Background Report in Draft Form Prepared by Emily Smith, Researcher For the Globalization of Personal Data Project Queen’s University August 2005 c/o Department of Sociology Queen’s University Kingston, ON K7L 3N6 (613) 533-6000, ext. 78867 (613) 533-6499 FAX [email protected] http://www.queensu.ca/sociology/Surveillance © Globalization of Personal Data Project, Queen’s University Not to be cited or quoted without permission of the Surveillance Project USA Table of Contents Privacy Policies and Laws……………………….…………………………………………….....3 Government Regulation of Privacy…………………………………………………….....3 Privacy Laws and the Private Sector……………………………………………………...5 Debate over Government Regulation of the Private Sector…………………………….....8 Introduction of New State Laws…………………………………………………………..9 International Privacy Law Affecting the US…………………………………………….10 Legal Changes after September 11th, 2001………………………………………………11 Cultural Values, Attitudes and Public Opinion on Privacy……………………………………...14 Hofstede’s Cultural Values Index………………………………………………………..14 Public Opinion Polling on Privacy in the US……………………………………………16 High Concern…………………………………………………………………………….18 Alan Westin and the Privacy Dynamic…………………………………………………..20 Factors Influencing Opinions…………………………………………………………….24 Consumer Concerns and Reporting of Changed Behaviour……………………………..26 September 11th, 2001 and Changes in Public Opinion…………………………………..27 Public Opinion on Privacy and the Law…………………………………………………30 E-Commerce and Trust………………………………………………………......………………33 E-Commerce……………………………………………………………………………..33 Privacy Concerns………………………………………………………………………...34 Privacy and Trust………………………………………………………………………...35 Give up Privacy for Benefits……………………………………………………………..37 Public Opinion of Privacy Regulation Online…………………………………………...38 Conclusions………………………………………………………………………………………41 References………………………………………………………………………………………..43 2 USA Privacy in the USA – Draft Report Privacy Policies and Laws Government Regulation of Privacy The United States has very limited legislation regarding privacy. Privacy is not a guaranteed right under the Constitution, there is no independent or federal privacy oversight body and no comprehensive federal or commercial privacy legislation exists. Instead, the US favours a self-regulatory model, relying on the free market economy to balance the privacy needs of individuals with that of organizations. A patchwork of federal and state privacy legislation does exist with regard to the protection of information held certain public and private sectors, in the areas considered the most sensitive. Individual states are currently expanding privacy legislation, as a response to growing data abuses and privacy concerns. Despite popular belief1, privacy is not explicitly addressed as a right in the US Constitution. Limited constitutional rights of privacy are granted under the Bill of Rights, including the right to privacy from government surveillance into areas where a person has a “reasonable expectation of privacy” and in matters of marriage, procreation, contraception, family relationships, child rearing and education (Privacy International 2003). The Fourth Amendment gives Americans the right to security of the person, against unreasonable search and seizure, as well as against the issue of warrants without probable cause. Some states also give explicit privacy protection in their Constitutions, such as Alaska, Arizona, California, Florida, Hawaii, Illinois, Louisiana, Montana, New York, Pennsylvania, South Carolina, and Washington (Weston 2005). Individuals can also challenge their personal right to privacy in the legal system. 1 For example, a Gallup Poll conducted in February of 1999 surveying 1,054 adults found that 70 percent of respondents believed that the Constitution guaranteed citizens the right to privacy. 3 USA Many cases involving privacy have been heard in the courts, from drivers licence information to grading in schools, mostly with regard to Fourth Amendment Rights. The Privacy Act was passed in 1974, which defines privacy as a fundamental right and sets provisions for the protection of records held by the US government and companies that they conduct business with (Privacy International 2003). This Act requires that agencies holding this information use basic Fair Information Principals (FIPs), such as the collection of necessary information only, collecting information directly from the individual, the use of data only for routine purposes, obtaining consent from individuals for information disclosure, providing access to an individuals personal records, rights for individuals to correct information about themselves, use of information only for the purposes originally collected unless authorized by the individual and prohibiting the use of secret databases (Lyon and Bonikowski 2002). However, these laws are subject to interpretation by administrative bodies and certain records are exempt, such as the National Crime Information Center. An investigation by the General Accounting Office found uneven compliance with the Privacy Act in 2003, with lack of leadership and guidance of the Act, low priority of implementation, insufficient training, and the absence of consistency in compliance. Thus, the provisions of the Privacy Act are not adequately protected (Privacy International 2003). There is no independent agency in the U.S. dedicated to privacy oversight for the government. The Office of Management and Budget have a limited role in setting policy for federal agencies under the Privacy Act and appointed a Chief Counsellor for Privacy to coordinate these efforts in 1999. However, this oversight position was deemed ineffective and was eliminated by the Bush administration (Privacy International 2003). 4 USA The Freedom of Information Act (FOIA) was enacted in 1966, with amendments in 1974 and 1976, to reduce government secrecy and give citizens access to information held by the federal government (Privacy International 2003). Many exemptions apply to this Act, including protection for issues of national security, trade secrets, medical files, investment records, and financial information (Lyon and Bonikowski 2002). Access to government records are also permitted by some state laws (Privacy International 2003). The Federal Trade Commission (FTC) has some oversight and enforcement powers for laws protecting children online, consumer credit information and fair trade practices, but not privacy rights in particular. Their use of the federal law on “unfair and deceptive” practices has been important for bringing privacy suits against companies that affect the entire industry where the law is ruled (ibid). The FTC conducts extensive research on internet privacy and despite a belief in industry self-regulation, has recommended to the US Congress that legislation is necessary to protect consumer privacy online (ibid). Legal efforts of the FTC are focussed on telemarketing laws, spam, pretexting and children’s privacy. Of greatest media attention was their changes to the Telemarketing Sales Rule to create a do-not-call list of individuals wishing to opt-out of telemarketing. The FTC proposed Fair Information Principles (FIPs) for handling personal data, including notice, choice, access, integrity, and enforcement, based on principles defined by the U.S. Department of Health, Education, and Welfare (Bellman et al 2003). Privacy Laws and the Private Sector The United States does hot have comprehensive federal legislation to govern privacy and information collection practices in the private sector. Various federal laws cover certain categories of privacy and personal information collection in the private sector that are perceived 5 USA to be the most sensitive, such as financial records, health information, and children’s privacy (Cockfield 2004). The US federal government relies on the rationale that the market will be more effective in balancing and regulating the commercial needs of business and privacy interests of consumers (ibid). Some examples of the most significant federal privacy regulation include: the Gramm-Leah-Bliley Act, the Children’s On-Line Privacy Protection Act, the Health Insurance Portability and Accountability Act, the Fair Credit Reporting Act, and the Videotape Privacy Protection Act (ibid). The Gramm-Leah-Bliley Act (GLBA) was passed in 1999, also called the Financial Modernization Act, under administration by the FTC, and is designed to regulate privacy practices in the financial sector (Cockfield 2004). The Act came at a time of increased scrutiny of financial privacy, after the Michigan Attorney General sued several banks for revealing they were selling information about customers to marketers; other banks around the country also admitted to this (Privacy International 2003). The Act sets weak protections on financial information that is shared among merged institutions and provides individuals with limited opt- out abilities for information shared with non-affiliated institutions (ibid). The Act enforces an ‘opt-out’ standard, where onus is placed on customers to contact their financial institution to request that constraints be placed on sharing their personal information with unrelated third parties. This law also requires financial institutions to have a privacy policy that is brought to the customers’ attention, but does not set out what principals these privacy policies must include (Cockfield 2004). Also administered by the FTC is the Children’s On-Line Privacy Protection Act (COPPA), which was passed by Congress 1998