Document Type
Article
Abstract
This Article identifies and categorizes the most dangerous contemporary e-threats—based on their ability to compromise PII—through a model entitled the Privacy Matrix. The Matrix demonstrates how each e-threat impacts consumer privacy during the primary stages of the PII Processing Cycle and explains how businesses, guided by an updated and balanced regulatory privacy regime, can create a safer e-commerce environment. I argue that e-threats targeting PII when businesses first attempt to collect such information from visitors—through a company’s “front door”—are less invasive and less dangerous than e-threats targeting PII after its dissemination into cyberspace—through a company’s “back door.” Accordingly, what is needed is a comprehensive federal statute that is narrowly tailored to protect privacy against front door e-threats, but drafted to morph into a more comprehensive privacy protection regime as PII is shuttled towards a company’s back door.
More specifically, the Privacy Matrix is introduced and interpreted in Part II. Part III focuses on the major front door e-threats and argues that a federal statute requiring the posing of a multilayered electronic privacy policy is sufficient to protect consumers at this stage because the decision to provide PII primarily rests with consumers. Part IV moves forward to the prominent e-treats targeting PII stored and processed in the company and argues that the privacy policy statute must be supplemented with a provision—structured as a regulatory ceiling prohibiting more restrictive state laws—requiring companies to adequately protect stored and processed PII and to notify all PII providers of major security breaches. This additional regulation is necessary to protect against the more serious e-threats lurking at this stage—an environment where the initial provider of the PII has less, but still some, control over the information. Part V introduces the e-threats targeting PII at the company’s back door and argues that privacy policy and security breach regulations must now be supplemented by stricter provisions that are specifically passed as regulatory floors allowing individual states room to thoroughly experiment with back door prevention tactics. Comprehensive regulation is necessary at this stage because PII exiting a company’s back door is virtually irretrievable by the person it identifies and can be used to cause serious emotional and financial damage with the perpetrators, who nearly impossible to identify. Part VI concludes by summarizing the argument and suggesting areas for further research.
Recommended Citation
Corey Ciocchetti,
The Privacy Matrix,
12 J. Tech. L. & Pol'y
(2007).
Available at: https://scholarship.law.ufl.edu/jtlp/vol12/iss2/4