Advertisement
Promo

Compliance Toolkit

Online privacy case thrown out

Paul Festa CNET News.com

Published: 16 Jun 2004 15:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The dismissal of lawsuits brought against Northwest Airlines has online privacy advocates renewing calls for federal privacy legislation.

In a decision dated 6 June, US District Court Judge Paul Magnuson ruled that seven consolidated class action lawsuits against Northwest had no merit -- in part because the privacy policy posted on the airline's Web site was unenforceable unless plaintiffs claimed to have read it. The plaintiffs had contended that the airline, in giving passenger information to the government in the wake of the 11 September, 2001, terrorist attacks, violated laws and its own privacy policy.

"Although Northwest had a privacy policy for information included on the Web site, plaintiffs do not contend that they actually read the privacy policy prior to providing Northwest with their personal information," Magnuson noted. "Thus, plaintiffs' expectation of privacy was low."

Privacy advocates assailed that part of the decision, saying it rendered Web site privacy policies all but unenforceable.

"I don't think it's relevant whether or not they actually read the privacy policy first," said Lee Tien, senior staff attorney for the Electronic Frontier Foundation (EFF) in San Francisco. "Think of all the 'fine print' we run into every day -- warranties and the like. Rather than focus on what the plaintiffs actually read, we should focus on what Northwest said it would do."

"The rationale the court uses calls into question the assurances of any policy posted on any Web site," said David Sobel, general counsel for the Electronic Privacy Information Centre (EPIC) in Washington, D.C.

Northwest shared passenger information with the National Aeronautical and Space Administration (NASA) for its research into improving airline security following the terrorist attacks of 11 September, 2001.

According to the plaintiffs, Northwest violated its privacy policy, the Electronic Communications Privacy Act, the Fair Credit Reporting Act and Minnesota's Deceptive Trade Practices Act by giving NASA passenger name records, which include not only passengers' name but also their flight numbers, credit card information, hotel and car rental reservations, and names of travelling companions.

The EFF's Tien and other privacy advocates said the decision illustrated the inadequacy of US privacy law.

"This decision is precisely why so many advocates call for consumers to be given a right to sue for privacy breaches," said Ray Everett-Church, chief privacy officer for the ePrivacy Group. "This decision tells companies that promises they make in privacy policies can be ignored because the people who are harmed have little legal basis for complaining."

EPIC's Sobel agreed, saying the decision undermined marketers' claims that industry is capable of regulating itself when it comes to consumers' privacy.

"The online industry has always made the argument that there's no need for legislation protecting online privacy, that through privacy policies and self-regulation they're able to give people the protections they need," Sobel said. "This decision really underscores the fact that there appears to be no enforceable protection in place."

Church said the decision would not prevent the Federal Trade Commission from acting against the airline or a Web site vendor that violated its posted privacy policy. Last week, the FTC promised that at least one such action was in progress.

Attorneys for the plaintiffs, asked whether they planned to appeal, did not return calls.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
40 out of 95 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Cloud Watch Special Report

Five cloud computing myths exploded

Five cloud computing myths exploded

Analysis The cloud is providing a fertile habitat for the marketeers and their exaggerated claims. We examine the hokum and debunk the five most frequently peddled misconceptions about the cloud

More Special Reports

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters