PRIVACY + SECURITY BLOG

News, Developments, and Insights

high-tech technology background with eyes on computer display

Why Consent Is Broken for Privacy and AI

Originally posted on Substack

The following is an excerpt from my book ON PRIVACY AND TECHNOLOGY where I summarize my thinking on privacy consent:

New technologies pose significant challenges to people’s ability to consent to the collection, use, and disclosure of their personal data. Under most privacy laws, consent makes permissible a wide array of data collection and processing. Websites, devices, and software continually attempt to induce people to consent (or pretend that people have consented) to data practices that are risky, troublesome, and unexpected.

To be meaningful, consent must not be unduly manipulated or coerced. And consent must be informed: people must be able to weigh the costs and benefits of consenting. Unfortunately, most privacy consent falls far short of these goals. In fact, privacy consent could almost be called a complete fiction.

Continue Reading

Bizarre Dystopian Superbowl AI Commercial

Alexa Ad 01

Here’s a bizarre dystopian Superbowl commercial where AIexa+ tries to kill Chris Hemsworth many different ways, then offers him a massage. And this is to try to convince folks that AI is good? I thought it was a promo for a Black Mirror episode.

<iframe width=”560″ height=”315″ src=”https://www.youtube.com/embed/ha92_hfK9Po?si=ka8ErdwxqU_evaIs” title=”YouTube video player” frameborder=”0″ allow=”accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share” referrerpolicy=”strict-origin-when-cross-origin” allowfullscreen></iframe>

 

Continue Reading

My Warning from the Past Remembered

Chronicle of Higher Ed

It’s gratifying to see a Chronicle of Higher Education editor recall a piece I wrote there 15 years ago — though I wish the remembrance was for less ominous reason. He concludes: “It appears that the moment he warned us about has arrived.”

My Chronicle of Higher Ed piece is based on my article, “I’ve Got Nothing to Hide” and Other Misunderstandings of Privacy (free download).

I also wrote a book about the topic, NOTHING TO HIDE: THE FALSE TRADEOFF BETWEEN PRIVACY AND SECURITY – I posted the entire book free online on SSRN.

Nothing to HIde - Solove 01

 

Continue Reading

Cartoon: Cookie Apocalypse

Cartoon Cookie Apocalypse - TeachPrivacy Training 02 JPG

My cartoon about cookies. Privacy law has waged war against the cookie, resulting in endless cookie banners which make a mockery of privacy. Many are dark patterns. Few achieve any purpose other than to annoy users.

For more on my views about how privacy consent is broken, see my article, Murky Consent: An Approach to the Fictions of Consent in Privacy Law, 104 B.U. L. Rev. 593 (2024).

Continue Reading

Privacy in Authoritarian Times: Surveillance Capitalism and Government Surveillance – Final Published Version

Privacy in Authoritarian Times

I’m very excited to share with you the final published version of my article, Privacy in Authoritarian Times: Surveillance Capitalism and Government Surveillance, 67 Boston College Law Review 51 (2026).  You can download the article for free on SSRN.

Continue Reading

Challenging Times Ahead for the Privacy Office

Originally posted on Substack

It’s Data Privacy Day, though it’s now been expanded to data privacy week. Things are quite turbulent for privacy these days, so we need to celebrate less and focus on how to respond to the challenges ahead.

Based on my anecdotal assessment, the CPO and DPO roles seem to have expanded to encompass AI. Unfortunately, despite the growing number of laws and issues CPOs and DPOs face, I don’t see big budget increases, team expansions, or salary increases.

Continue Reading

Privacy and AI Law in 2025

Originally posted on Substack

We’ve now closed the books on 2025, so it’s time to review what happened in privacy law over the past year. At first glance, it seems like a quiet year (no new state consumer privacy laws) but quite a lot happened. Many smaller things, but they really add up.

Here’s a bird’s eye overview:

Continue Reading

Privacy as Contract?

Privacy as Contract

I just posted my new article draft with Professor Woodrow Hartzog (BU Law School) on SSRN (free download): Privacy as Contract?  

Are privacy notices contracts?

Here’s the abstract:

Nearly everything people buy, every service they use, every account they create, and even every website they visit involves the collection, use, and transfer of personal data—a matter that is ostensibly governed by privacy notices (also called “privacy policies”). Privacy notices are the foundation of privacy regulation; most privacy laws rely on the existence of privacy notices as a central pillar. Various statutory rights and obligations are tied or limited by what is specified in privacy notices, including the scope and nature of the collection, use, and transfer of personal data.

On the surface, privacy notices seem like contracts. They feel promissory in nature and are central to the grand bargain between consumers and companies at the heart of surveillance capitalism. When companies break the promises they make in privacy notices, contract law (through regular contract or promissory estoppel) appears to be a tool that could empower consumers to seek redress. But this has rarely been the case. Privacy notices still exist in a weird twilight between a mere description of policy and a binding agreement. They are even strangely still separate documents from companies’ terms of use agreements. Despite nearly forty years after privacy notices emerged to become the dominant mechanism to address privacy issues, the question of how contract law applies to privacy notices has been only thinly addressed by courts.

In this Article, we argue that contract law is unsuitable for governing consumer privacy. The law of consumer contracts is too oblivious to power disparities, too focused on the individual at the expense of groups and society, and too infected with bogus conceptions of consent to serve as a viable foundation to govern privacy in consumer transactions. Applying contract law more robustly and consistently to privacy notices will not better protect consumers—in fact, it will worsen protection and exacerbate the significant power imbalance between companies and consumers.

Even with reforms, applying contract law to privacy notices will not lead to a desirable balance of power between companies and consumers. Current contract law lacks the right tools to address privacy issues; it is rooted far too deeply in an individual control model similar to the one that has failed spectacularly in privacy law.

Instead of being developed to colonize privacy, contract law should be subject to an internal revolution in how it handles transactions in the Digital Age. With the internet and digital technologies, contract doctrine has lost its way and functions mainly to enable companies to wield power unilaterally against consumers. The fundamental goals, scope, and structure of consumer contract law must be rethought to better address problems with consent, fairness, and power.

 

Download ButtonContinue Reading