05 November 2016

Obscurity, Censorship and Personality Rights

'The Anglo-American / Continental Privacy Divide? How Civilian Personality Rights Can Help Reconceptualize the ‘Right to Be Forgotten’ Towards Greater Transnational Interoperability' by Karen Eltis in (2016) 94 Canadian Bar Review comments
The European Court of Justice’s much maligned decision in Google v Costeja González, appears to compel search engines, to remove links to certain impugned search results at the request of individual Europeans (and potentially by others beyond Europe’s borders). Further complicating an already thorny situation is the court’s failure to impart much-needed practical guidance in Costeja.
What is more, Costeja may inadvertently and ironically have the effect of appointing (chiefly American) ‘data controllers’ as unwitting private censors; arbiters of the European public interest. Indeed, the decision may be deemed a culmination of the growing divergence between Anglo-American and Continental approaches to privacy significantly extending beyond the United States, to the United Kingdom.
It further reflects internal normative contradictions within the continental tradition and emphasizes the urgency of re-conceptualizing digital privacy in a more transystemically viable fashion in Europe and beyond.
In light of the above, informational privacy, the following posits, must ultimately be re-theorized in a manner that would presumably obviate – or at the very least palliate – the need for a stand-alone ill-defined and under-theorized ‘right to be forgotten’, as set out at pains in Costeja. It is in essence a procedural right predicated on the impracticable idea that individuals ‘own’ data, rather than a right to their identity itself and the perception thereof. It therefore fails to accord with the long-established civilian tradition of personality rights, which, unlike its common law counterpart, emphasizes personhood not property. In the end, a more robust construction of privacy predicated on protecting identity would allow for a more nuanced balancing of privacy and freedom of expression.

29 October 2016

Blood Data Breach

The Australian Red Cross, in reporting the large scale breach regarding data about actual and prospective blood donors, states
On 26 October the Blood Service became aware a file containing donor information was placed in an insecure environment by a third party that develops and maintains the Blood Service’s website. This file contained registration information of 550,000 donors made between 2010 and 2016. Included in the file was information such as names, addresses and dates of birth. 
This information was copied by a person scanning for security vulnerabilities who then, through an intermediary, informed the Australian Cyber Emergency Response Team (AusCERT) with whom the Blood Service has membership. 
With assistance of AusCERT, the Blood Service took immediate action to address the problem. The Blood Service has been in communication with the Australian Cyber Security Centre and the Office of the Australian Information Commissioner. 
IDCARE, a national identity and cyber support service, has assessed the information accessed as of low risk of future direct misuse. 
To our knowledge all known copies of the data have been deleted. However, investigations are continuing. 
The online forms do not connect to our secure databases which contain more sensitive medical information. 
The Blood Service continues to take a strong approach to cyber safety so donors and the Australian public can feel confident in using our systems.
In the circumstances the organisations' knowledge of deletion of copies is unlikely to be exhaustive.

Information exposed through the breach (responses to the online blood donor appointment request form) encompasses answers to
  • First and last name 
  • Address, Suburb, Postcode, State 
  • Mobile phone (optional) 
  • Email Donor ID (optional). 
  •  Have you donated in the last 24 months? 
  • Postcode or suburb for donation
  •  Preferred date range request for donation, and preferred time of day 
  • Preferred location for donation 
  • Preferred appointment time 
  • Date of birth 
  • Gender 
  • In the 4 months leading up to your appointment, will you travel outside of Australia? 
  • Between 1980 and 1986, did you live in the UK for a cumulative period of 6 months? 
  • Are you feeling unhealthy or unwell? 
  • Are you taking antibiotics at the moment? 
  • Are you currently pregnant or have you been pregnant in the last 9 months? 
  • Have you had an operation or surgical procedure in the last 6 months? 
  • Are you planning any operations or surgical procedures in the next 3 months? 
  • In the last week, have you had any dental work, cleaning, fillings or extractions? 
  • In the last 4 months: Have you had a tattoo? Have you had a piercing? 
  • Do you weigh less than 50 kilograms?
  •  In the last 12 months, have you engaged in at-risk sexual behaviour?
The Red Cross states
A file containing donor information was placed in an insecure environment by a third party that develops and maintains the Blood Service’s website. This was a human error on the part of the third party service. This information was copied by a person scanning for security vulnerabilities who then, through an intermediary, informed AusCERT. 
What are you doing about this? 
Working with AusCERT, a cyber security organisation who provides information and security advice to us as a member of their service, we have managed to have all known copies of the archive deleted, and have removed the vulnerability from the web developer’s server. We’ve mobilised a team of security experts to conduct a forensic analysis of the incident. We are also establishing a taskforce including independent experts to conduct a thorough investigation of governance and security structures within the Blood Service. 
How long was the data available? 
At this stage we understand the data may have been available from 5 September 2016 to 25 October 2016. Our forensic experts are working to confirm the exact dates. To our knowledge, all known copies of the data have been deleted, however investigations are continuing. 
When was the data accessed? 
We believe the archive was accessed on 24 October 2016, our forensic experts are confirming this. We have managed to have all known copies deleted and have removed the vulnerability from the third party service that develops and maintains the Blood Service’s website. 
Why should I trust you with my information? 
We take the security of information our donors provide extremely seriously and have done everything in our power, since becoming aware of this situation, to address this security issue. 
Is this the Blood Service's fault? 
This was a human error on the part of the third party service that develops and maintains the Blood Service’s website. We take full responsibility for this mistake and apologise unreservedly to all affected. We take cyber security very seriously and we are deeply disappointed this occurred. 
What actions are you taking? 
Working with AusCERT we have managed to delete all known copies of the archive, and have removed the vulnerability from the third party service that develops and maintains the Blood Service’s website. We’ve mobilised a team of security experts to conduct a forensic analysis of the incident. We are also establishing a taskforce including independent experts to conduct a thorough investigation of governance and security structures within the Blood Service. IDCARE, a national identity and cyber support service, has assessed the information accessed as of low risk of future direct misuse. We are reviewing our arrangements with the third party provider.

US broadband privacy rules

The US Federal Communications Commission this week adopted rules requiring broadband internet service providers to protect the privacy of their customers.
The rules ensure broadband customers have meaningful choice, greater transparency and strong security protections for their personal information collected by ISPs. 
 The rules implement privacy requirements of Section 222 of the Communications Act. The FCC states that
To provide consumers more control over the use of their personal information, the rules establish a framework of customer consent required for ISPs to use and share their customers’ personal information that is calibrated to the sensitivity of the information. 
This approach is consistent with other privacy frameworks, including the Federal Trade Commission’s and the Administration’s Consumer Privacy Bill of Rights. 
The rules separate the use and sharing of information into three categories and include clear guidance for both ISPs and customers about the transparency, choice and security requirements for customers’ personal information:
  • Opt-in: ISPs are required to obtain affirmative “opt-in” consent from consumers to use and share sensitive information. The rules specify categories of information that are considered sensitive, which include precise geo-location, financial information, health information, children’s information, social security numbers, web browsing history, app usage history and the content of communications. 
  • Opt-out: ISPs would be allowed to use and share non-sensitive information unless a customer “opts-out.” All other individually identifiable customer information – for example, email address or service tier information – would be considered non-sensitive and the use and sharing of that information would be subject to opt-out consent, consistent with consumer expectations.
  • Exceptions to consent requirements: Customer consent is inferred for certain purposes specified in the statute, including the provision of broadband service or billing and collection. For the use of this information, no additional customer consent is required beyond the creation of the customer-ISP relationship.
Additionally the rules include:
  • Transparency requirements that require ISPs to provide customers with clear, conspicuous and persistent notice about the information they collect, how it may be used and with whom it may be shared, as well as how customers can change their privacy preferences; 
  • A requirement that broadband providers engage in reasonable data security practices and guidelines on steps ISPs should consider taking, such as implementing relevant industry best practices, providing appropriate oversight of security practices, implementing robust customer authentication tools, and proper disposal of data consistent with FTC best practices and the Consumer Privacy Bill of Rights.  
  • Common-sense data breach notification requirements to encourage ISPs to protect the confidentiality of customer data, and to give consumers and law enforcement notice of failures to protect such information. 
The FCC notes that
The scope of the rules is limited to broadband service providers and other telecommunications carriers. 
The rules do not apply to the privacy practices of web sites and other “edge services” over which the Federal Trade Commission has authority. 
The scope of the rules do not include other services of a broadband provider, such as the operation of a social media website, or issues such as government surveillance, encryption or law enforcement.

Speech and relationships

'Two Rights of Free Speech' (Cornell Legal Studies Research Paper No. 6-37) by Andrei Marmor argues that
the right to freedom of expression is not a single right, complex as it may be, but spans two separate rights that I label the right to speak and the right to hear. Roughly, the right to speak stands for the right of a person to express freely whatever they wish to communicate to some other persons or to the public at large. The right to hear stands for the right to have free and unfettered access to any kind of content that has been communicated by others. The right to speak and the right to hear are two separate rights, grounded in different kinds of interests. Choice and control are central aspects of the right to speak and much less central to the right to hear. I try to show that this division of rights and their respective rationales can be utilized to explain how we think about some of the limits of the right to freedom of expression, particularly in the context of conflicts between the right to speak and the right to hear, conflicts that are rather pervasive. I also argue, though perhaps less conclusively, that in thinking about the limits of freedom of expression, an exclusive focus on the harm principle would be misguided. There is no reason to deny that speech is often harmful, sometimes very much so, but the prevention of harm is not sufficient to justify legal prohibition, at least not in this case.
'Just Relationships' by Hanoch Dagan and Avihay Dorfman in (2016) 116(6) Columbia Law Review comments
Scholars traditionally conceptualize private law around a commitment to the values of formal freedom and equality. Critics of the traditional view (including lawyer-economists) dispute the significance of a distinction between public and private law, construing private law as merely one form of public regulation. Both positions are flawed. The traditional position is conceptually misguided and normatively disap­pointing; the critical position confuses a justified rejection of private law libertarianism with a wholesale dismissal of the idea of a private law, thus denying private law’s inherent value. 
This Article seeks to break the impasse between these two positions by offering an innovative account of the values that should, and to some extent already do, underlie the law of interpersonal interactions among private individuals in a liberal state. Rather than succumbing to the unappealing adherence to formal freedom and equality, private law should openly embrace the liberal commitment to self-determination and substantive equality. A liberal private law establishes frameworks of respectful interaction conducive to self-determining individuals. These frameworks are indispensable for a society in which individuals recognize each other as genuinely free and equal agents.

Corporations

'Corporate Entities: Their Ownership, Control, and Purpose' (Cornell Legal Studies Research Paper No. 16-38) by Lynn A. Stout - published as a chapter in the Oxford Handbook of Law and Economics - provides
an introduction to the law and economics of the corporate form. It first distinguishes “the corporation” from “the firm.” It then describes and discusses the characteristics of the corporate form, including legal personality, limited liability, delegated management, transferable equity, and perpetual life. It then reviews the dominant theories of the corporation, including the entity theory, the aggregate theory, the property (principal/agent) theory, the nexus of contracts theory, the team production theory, and the franchise government/concession theory. It concludes by discussing various theories of corporate purpose, including the state interest, managerialist, customer service, shareholder value/primacy, stakeholder welfare, team production, and long-term production approaches to understanding the purpose of corporations.

27 October 2016

Concentration

From the speech by Australian Competition and Consumer Commission Chairman Rod Sims at today’s RBB Economics Conference in Sydney
The rise of large corporations in the Australian economy has been substantial. Indeed it seems we have outpaced the US. 
Analysis prepared by Port Jackson Partners Limited shows the revenue of Australia’s largest 100 listed companies increased from 15% of GDP in 1993 to 47% of GDP in 2015. This compares to the US figures of 33% to 46%. 
In Australia many markets are concentrated or are likely to become concentrated as firms pursue efficiencies from scale. In some markets there may not be room for more than a few efficiently sized firms given the size of demand. 
From a competition perspective, what we need to understand is whether smaller rivals or new entrants can readily contest the position of larger, more established firms. 
We should, therefore, have an eye to how often the identity of large firms change.  Again, drawing on work by Port Jackson Partners Ltd, of the ASX top 100 companies in 1990, only 29 companies remained in the top 100 as at October 2015.
Sims notes
drawing on work by Port Jackson Partners Ltd, of the ASX top 100 companies in 1990, only 29 companies remained in the top 100 as at October 2015. Sixty one had been acquired or merged, five had disappeared due to corporate collapses and five had slipped from the top 100. 
However, the identity of the six largest listed companies has not changed substantially in recent times. For example, in 2005 the top six listed companies by market capitalisation, in order, were BHP, Telstra, and four banks: Commonwealth, NAB, ANZ and Westpac. Today the top six companies in order are four banks: Commonwealth, Westpac, ANZ and NAB, followed by BHP Billiton and Telstra. 
But the top 6 companies have not grown as strongly as the rest of the top 100, as another chart from Port Jackson Partners Ltd shows. Since 1993, the top 6’s revenue as a proportion of GDP has doubled from 7% to 16%. For the rest of the top 100 this percentage has nearly quadrupled from 8% to 31%.
Sims questioned belief that we need not be concerned with heavy concentration and monopolistic behaviour.
It seems to me that, absent a clear and convincing economic and evidence based explanation of how a merger will avoid harming consumers, the standard economic wisdom should prevail. 
This wisdom is that mergers resulting in high levels of concentration in markets with substantial barriers to entry will usually reduce competition and cause harm to consumers and our economy. Circumstances where monopoly pricing has no effect, or only a small effect on economic efficiency, are rare.
Sims identified questions about market concentration and merger analysis, including:

  •  Why is it that economic argument and opinion increasingly down plays conventional economic theory and wisdom on high levels of consolidation and monopolies? 
  • Do we need to consider something similar to the approach adopted by US courts where once markets are defined and the merger is likely to result in a significant increase in concentration, there exists a “rebuttable presumption” that the merger should not proceed absent evidence to the contrary? There will be times when a merger to high concentration is acceptable, due perhaps to low entry barriers, but logic says it will not be the norm. 
  • Why shouldn’t those arguing the unconventional have the burden of producing evidence to support their position? 
  • Are regulators able to analyse and act where large incumbent firms continue to acquire promising start-ups? Is there too much focus on overlap in specific narrow market sectors? 
  • Should we focus more on the wider actual and potential competitive constraints and the extent or strength of those constraints? 
  • How many different forms of remedy should a competition regulator need to assess before saying “enough”?

24 October 2016

Punitive Damages and ISDS empiricism

'Punitive Damages Revisited: A Statistical Analysis of How Federal Circuit Courts Decide the Constitutionality of Such Awards' by Hironari Momioka in 2014 uses the data of punitive damages decisions of U.S. federal circuit courts from 2004 to 2012 in an attempt to establish empirically that.
(1) There is no apparent statistical difference between the levels of jury and judge awards.
(2) U.S. Supreme Court decisions such as Philip Morris (2007) or Exxon (2008) do not actually or substantially affect the level of punitive damage awards.
(3) With regard to the cases involving remittitur or reduction of awards, the Exxon decision did not radically affect the decreasing ratio of punitive to compensatory damage awards.
(4) As the levels of compensatory awards go up, the ratio becomes strikingly low and stable.
(5) Finally, the proportionality between punitive and compensatory awards is not the key factor that influences upper court judges when they consider the constitutionality of punitive damages. Unexplained portions of the relationship between the amount of punitive damages and the wealth of a defendant remain to be examined further.
'The Impact of Investment Treaties and ISDS Provisions on Foreign Direct Investment: A Baseline Econometric Analysis' (Sydney Law School Research Paper No. 16/74) by Shiro Patrick Armstrong and Luke R. Nottage considers Investor-State Dispute Settlement.

The authors comment 
Based on an interdisciplinary and cross-institutional research project (2014-7) assessing international investment treaty dispute management more broadly, this paper (abridged from a related project) introduces part of our joint project examining key questions around the effect of investment treaties and some of their provisions on direct investment flows. It focuses on the vexed question of whether offering treaty-based Investor-State Dispute Settlement (‘ISDS’) leads to significant increases in inbound foreign direct investment (FDI), in light of the persistent public debate about the merits of this procedural option for enforcing substantive commitments made by host states.
Overall, our econometric analysis generates complex implications for policy-makers reassessing the historical impact of ISDS in order to decide whether and how to include different forms of such procedural provisions in future investment treaties. Skeptics can point to counter-intuitive results indicating that weaker-form ISDS and/or substantive provisions seem to have stronger and more robust impact, especially since the turn of this century. Proponents can point to results indicating that there has still been a positive and significant impact from stronger provisions, including from full-scale ISDS provisions in promptly ratified treaties concluded between OECD and non-OECD countries.
Although our baseline model specification has generally dealt effectively with the endogeneity problem characteristic of this field, further variables impacting on FDI may be investigated (notably, double tax treaties) and data limitations remain (notably, FDI outflows from non-OECD countries and sectoral-level data). This econometric analysis can therefore be usefully complemented by the qualitative research component of our ongoing project.