News, Developments, and Insights

high-tech technology background with eyes on computer display

Data Is What Data Does: Regulating Based on Harm and Risk Instead of Sensitive Data

Article - Solove - Data Is What Data Does - Sensitive Data 02

I’m delighted to share the final published version of my article, Data Is What Data Does: Regulating Based on Harm and Risk Instead of Sensitive Data, 118 Nw. U. L. Rev. 1081 (2024).

This article was selected for the Future of Privacy Forum’s Privacy Papers for Policymakers Award. The Award aims to “recognize leading U.S. and international privacy scholarship that is relevant to policymakers in the U.S. Congress, federal agencies, and international data protection authorities.”

You can download my article for free here:

Here’s the abstract:

Heightened protection for sensitive data is becoming quite trendy in privacy laws around the world. Originating in European Union (EU) data protection law and included in the EU’s General Data Protection Regulation, sensitive data singles out certain categories of personal data for extra protection. Commonly recognized special categories of sensitive data include racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sexual orientation and sex life, and biometric and genetic data.

Although heightened protection for sensitive data appropriately recognizes that not all situations involving personal data should be protected uniformly, the sensitive data approach is a dead end. The sensitive data categories are arbitrary and lack any coherent theory for identifying them. The borderlines of many categories are so blurry that they are useless. Moreover, it is easy to use nonsensitive data as a proxy for certain types of sensitive data.

Personal data is akin to a grand tapestry, with different types of data interwoven to a degree that makes it impossible to separate out the strands. With Big Data and powerful machine learning algorithms, most nonsensitive data give rise to inferences about sensitive data. In many privacy laws, data giving rise to inferences about sensitive data is also protected as sensitive data. Arguably, then, nearly all personal data can be sensitive, and the sensitive data categories can swallow up everything. As a result, most organizations are currently processing a vast amount of data in violation of the laws.

This Article argues that the problems with the sensitive data approach make it unworkable and counterproductive as well as expose a deeper flaw at the root of many privacy laws. These laws make a fundamental conceptual mistake—they embrace the idea that the nature of personal data is a sufficiently useful focal point for the law. But nothing meaningful for regulation can be determined solely by looking at the data itself. Data is what data does.

To be effective, privacy law must focus on harm and risk rather than on the nature of personal data. The implications of this point extend far beyond sensitive data provisions. In many elements of privacy laws, protections should be proportionate to the harm and risk involved with the data collection, use, and transfer.


Continue Reading

Cartoon: Internet Wolves

Cartoon Internet Wolves - TeachPrivacy Training 03

My new cartoon — a play on the famous New Yorker cartoon: “On the Internet, nobody knows you’re a dog.”

* * *

Professor Daniel J. Solove is a law professor at George Washington University Law School. Through his company, TeachPrivacy, he has created the largest library of computer-based privacy and data security training, with more than 150 courses. 

Professor Solove’s Privacy Cartoon Collection

More than 100 cartoons!

Cartoons - Privacy - Solove 01

PSA Courses Button 01

Artificial Intelligence Training Course

A basic introduction about AI for the workforce, ethical principles, and general guidance for following developing legal regulation

PSA Courses Button 01

Webinar – Privacy Law and the First Amendment Blog

In case you missed my webinar on Privacy Law and the First Amendment, you can watch the replay here.  I had a great discussion with Gautam Hans (Cornell Law) about several recent First Amendment cases that intersect with privacy law — the NetChoice cases.

Button Watch Webinar 02

Also, if you’re interested, I wrote a blog post about the CAADC case., NetChoice v. Bonta.

First Amendment Expansionism and California’s Age-Appropriate Design Code

Continue Reading

Kafka in the Age of AI and the Futility of Privacy as Control

Kafka in the Age of AI - an essay by Professors Daniel Solove and Woodrow Hartzog

I’m very pleased to post a draft of my forthcoming essay with Professor Woodrow Hartzog (BU Law), Kafka in the Age of AI and the Futility of Privacy as Control, 104 B.U. L. Rev. (forthcoming 2024). It’s a short engaging read – just 20 pages!  We argue that although Kafka shows us the plight of the disempowered individual, his work also paradoxically suggests that empowering the individual isn’t the answer to protecting privacy, especially in the age of artificial intelligence.

You can download the article for free on SSRN. We welcome feedback.

Download Button 02 small

Scroll down for some excerpts from our PowerPoint presentation for this essay – images created by AI!

Continue Reading

2023 Highlights: Training and Whiteboards

2023 Highlights - Training

Here’s a roundup of my privacy training and whiteboard in 2023. I created short courses for AI and for technology and data ethics. These courses are partially created with AI. The narrator is AI, and some of the images in the AI course are created by AI. The Technology and Data Ethics course has both the narrator and images created by AI. I used a claymation style, and I think that the AI really did a great job (though it took countless attempts in prompting and many tries to get things right).

I created regional whiteboards and courses (Latin America and Asia). These whiteboards and courses summarize general themes and trends in privacy laws in these world regions.

Plus, I created more courses in a series on privacy and data management topics: Secondary Use and Data Minimization. My goal with this series is to cover the basic concepts and practices in a privacy program. Previous courses include Data Mapping, Vendor Management, Data Protection Impact Assessments, Data Subject Rights, Data Retention, and other topics.

Artificial Intelligence and Data Ethics Training

Artificial Intelligence (AI) Training Course

AI Training Course

Technology and Data Ethics Training Course  

Continue Reading

2023 Highlights: Scholarship

2023 Highlights - Scholarship 02

Here’s a roundup of my scholarship for 2023. With Professor Paul Schwartz, I published a new edition of my casebook, Information Privacy Law as well as new editions of the topical paperbacks (will be in print by the end of December).  One article came out in print, and I have several paper drafts in various stages of the publication process.  See below for details.


New Edition of Information Privacy Law Casebook

(Aspen 2024) (with Professor Paul Schwartz)Privacy Casebook

New Editions of Information Privacy Law
Topical Paperback Casebooks

(Aspen 2024) (with Professor Paul Schwartz)

Cover Information Privacy Law Paperbacks 02

Continue Reading

Webinar – Privacy Law in the 21st Century: Past, Present, Future Blog

In case you missed my webinar on Privacy Law in the 21st Century, you can watch the replay here.  I had a great discussion with Salomé  Viljoen (Michigan Law), Ari Waldman (U.C. Irvine Law), and Margot Kaminski (Colorado Law) about how privacy law has been evolving.

Button Watch Webinar 02Continue Reading