{"id":52771,"date":"2016-09-30T11:27:00","date_gmt":"2016-09-30T16:27:00","guid":{"rendered":"https:\/\/content.findlaw-admin.com\/ability-legal\/supreme\/legal-commentary\/privacy-and-search-engine-data-a-recent-aol-research-project-has-perilous-consequences-for-subscribers.html"},"modified":"2016-09-30T11:27:00","modified_gmt":"2016-09-30T16:27:00","slug":"privacy-and-search-engine-data-a-recent-aol-research-project-has-perilous-consequences-for-subscribers","status":"publish","type":"supreme","link":"https:\/\/supreme.findlaw.com\/legal-commentary\/privacy-and-search-engine-data-a-recent-aol-research-project-has-perilous-consequences-for-subscribers.html","title":{"rendered":"Privacy and Search Engine Data A Recent AOL Research Project Has Perilous Consequences for Subscribers"},"content":{"rendered":"\n<div class=\"wp-container-core-columns-is-layout-9d6595d7  fl-block-columns fl-sectionWithSidebar fl-container fl-flex fl-flex-wrap fl-gap30\">\n    \n    <div class=\"fl-page-articles   fl-block-column fl-section-main fl-section-main-full-width\">\n        <div class=\"yui-g\" id=\"leftcol-module\">\n      <!-- Right Line of Links Section -->\n      <!-- BEGIN PICTURE INSERTION -->\n      <!-- BEGIN TITLE AND AUTHOR INSERTION -->\n      <table>\n        <tr>\n\n          <td width=\"100\" rowspan=\"3\" class=\"wiauthor\"><a href=\"\/legal-commentary\/anita-ramasastry-archive\"><img decoding=\"async\" src=\"https://supreme.findlaw.com/static/f/images\/writ\/anita.ramasastry.jpg\" border=\"0\"><\/a><\/td>\n          <td class=\"wititle\"><h1>Privacy and Search Engine Data: A Recent AOL Research Project Has Perilous Consequences for Subscribers<\/h1><\/td>\n        <\/tr>\n        <tr>\n          <td class=\"wiauthor\"><a href=\"\/legal-commentary\/anita-ramasastry-archive\" class=\"graybold\"><h2>By ANITA RAMASASTRY<\/h2><\/a><\/td>\n        <\/tr>\n        <tr>\n          <td class=\"widate\">Monday, Aug. 21, 2006<\/td>\n\n        <\/tr>\n      <\/table>\n      <span class=\"smalltext\"><p>Some America Online (AOL) Internet service subscribers may be in for a nasty shock. Approximately 658,000 subscribers had their search queries &#8211; numbering a reported 20 million &#8211; made public for 10 days in early August, when the data, meant to be shared only with search engine researchers, was mistakenly released. And records of the data still remain accessible on the Internet; while AOL removed the data, it had already been mirrored and cached elsewhere. <\/p>  <p>This is far from an isolated incident: Reportedly, Excite and AltaVista released smaller amounts of their users&#8217; search results approximately five or six years ago. Both used anonymous identifiers, as AOL did. <\/p>  <!-- 300x250 AD -->\n\n<p>An AOL spokesperson has been quoted as saying, &#8220;there was no personally-identifiable data linked to these accounts.&#8221; And it&#8217;s true that AOL did not post names in combination with the searches &#8211; just numerical IDs. But based on various news reports and blog commentaries, it has become readily apparent that the search data is enough to identify quite a few individuals. <\/p>  <p>The upshot: If an individual did searches based on, for instance, their own names, neighborhoods, street addresses, and so on, others may be able to find out what <u>other<\/u> searches the individual did &#8211; even if the information revealed is legally private (a search for information related to a confidential medical condition such as AIDS), intensely embarrassing (for example, a search for porn sites), or even evidence of crime (a reported search for tips on how to commit murder). <\/p>  <p>Accurate inferences from these searches may damage the searcher; so might false inferences (for instance, suppose the &#8220;AIDS&#8221; searcher did not suffer from AIDS herself). <\/p>  <p>Two privacy groups, the Electronic Frontier Foundation (EFF) and <a href=\"http:\/\/www.worldprivacyforum.org\/pdf\/WPF_FTCcomplaint8162006fswp.pdf\" class=\"left-link\" target=\"blank\" rel=\"noopener\">the World Privacy Forum (WPF)<\/a> have filed complaints with the Federal Trade Commission (FTC) calling AOL&#8217;s actions unfair and deceptive trade practices. It is still too early to tell if they will ultimately prevail, but it&#8217;s very important that an investigation be conducted. As EFF notes, among the other serious injuries the now-public data may wreak, is the possibility of identity theft. And there&#8217;s no question that the searches can be connected to individuals: In support of <a href=\"http:\/\/www.eff.org\/Privacy\/AOL\/aol_ftc_complaint_final.pdf\" class=\"left-link\" target=\"blank\" rel=\"noopener\">its complaint<\/a>, EFF confidentially submitted a sampling of AOL search queries containing personally identifiable information and search histories that could likely be tied to particular AOL subscribers.<\/p>  <p>Congress also should examine this recent customer data leak, because once again, consumer data is making the rounds, without a subscriber&#8217;s consent. There are still no uniform federal standards, under our laws, for dealing with disclosures of individuals&#8217; search records &#8211; whether solely by a private company, or in response to a government request or subpoena. That situation ought to change. We need to have clear rules as to what is permitted, and what is forbidden. <\/p>   <p><b>What AOL Did: Why Anonymous Identifiers Didn&#8217;t Prevent Matching Searches to Individuals<\/b><\/p>  <p>AOL had posted the data on its recently launched AOL Research site, aimed at database and search engine researchers.  The problem: Anyone could access the site, which was apparently not password-protected. (Since then, a lot of dot-connecting has gone on. The <i>New York Times<\/i> figured out that user &#8220;4417749&#8221; &#8212; who searched &#8220;homes sold in shadow lake subdivision gwinnett county Georgia,&#8221; and searched the names of several people with the surname &#8220;Arnold&#8221; &#8211; was 62-year-old Georgia resident Thelma Arnold. <\/p>  <!-- MIDDLE AD PLACEHOLDER -->\n<p>Others poring over the data claim to have discovered over 100 Social Security numbers; dozens &#8211; perhaps hundreds &#8212; of credit card numbers; and the full names, addresses and birthdates of various subscribers who entered these terms as part of search queries.<\/p>    <p><b>The FTC Complaints Filed by the Electronic Frontier Foundation and the World Privacy Forum<\/b><\/p>  <p>Both the EFF and the WPF have asked the FTC to investigate, and possibly sanction, AOL for its unauthorized release of customer search queries. . <\/p>  <p>The FTC complaints allege that AOL engaged in unfair or deceptive business practices by exposing its subscribers&#8217; information without warning them previously that it might do so. Indeed, according to the EFF complaint. AOL claimed in its privacy statement that it took &#8220;reasonable and appropriate&#8221; measures to protect personal consumer information from public disclosure. Surely such measures ought to have prevented the public posting of private search data! <\/p>   <p>AOL should be required to notify every customer whose privacy has been jeopardized by the company&#8217;s handling of this private information. AOL also should adopt policies for the future by which it either does not cache such data, or quickly purges its caches. EFF and WPF have asked the FTC to require changes in AOL&#8217;s privacy practices, and these requests, too, are a good idea.<\/p>    <p>Granted, researchers involved with database and search engine research may have valid reasons to seek such data. But, as EFF has noted, that there may be ways such research can be done without making individuals&#8217; search terms public.  University researchers, too, could be asked to abide by AOL&#8217;s privacy policy and other state privacy laws. And AOL could also seek user consent before sharing such data with researchers or others; of AOL&#8217;s millions of users, enough might have consented to the research to allow a substantial database to be created. <\/p>  <p><b>Consequences: It&#8217;s Time for Clear Laws, with Strong Remedies, Regarding Search Disclosures, Whether or Not at the Government&#8217;s Behest <\/b><\/p>  <p>While AOL released data to the public of its own accord, there has also been concern, in recent months, about ISPs&#8217; turning over search data to government officials in response to subpoenas. <\/p>  <p>In March, <a href=\"http:\/\/www.epic.org\/privacy\/gmail\/doj_court_order.pdf\" class=\"left-link\" target=\"blank\" rel=\"noopener\">a federal judge rejected<\/a> efforts by the Department of Justice to use subpoenas to Google to gain access to Google users&#8217; search logs. The court, however, held that the Justice Department could have limited access, instead, to Google&#8217;s index of Web site URLs. (Google was the only search engine to fight the Justice Department on this issue, with Yahoo, Microsoft&#8217;s MSN and AOL handing over their users&#8217; search data, rather than litigating the point.) <\/p>  <p>Hopefully, AOL&#8217;s violation of its users&#8217; privacy will spur Congress to clarify when and how search log information should be protected. As EFF notes, a few states require that consumers be notified in the event of a security breach. In this case, it is unclear whether such laws would apply to the AOL search data scenario &#8211; but if they don&#8217;t, they ought to. And in any case, federal-law protection is needed so that all Americans can use the Internet with confidence, and without fear their privacy will be invaded.<\/p> \n\n\n<\/span>\n\n\n\n<hr size=\"1\">\n<p class=\"authorfoot\">\n\n<!-- BEGIN AUTHORS FOOTNOTE -->\n<a name=\"bio\"><\/a>\nAnita Ramasastry is an Associate Professor of Law at the University of Washington School of Law in Seattle and a Director of the Shidler Center for Law, Commerce &amp; Technology. She has previously written on business law, cyberlaw, computer data security issues, and other legal issues for this site, which contains an archive of her columns. \n<br><br>\n\n<\/p>\n    <\/div><div class=\"was-this-helpful\">\n    <div\n            class=\"was-this-helpful__question-container\"\n            aria-labelledby=\"was-this-helpful__question\"\n            role=\"group\"\n    >\n        <span\n                id=\"was-this-helpful__question\"\n                class=\"was-this-helpful__question fl-text-lg-bold\"\n        >Was this helpful?<\/span>\n        <button\n                class=\"was-this-helpful__button fl-text-sm\"\n                aria-label=\"Yes\"\n                value=\"yes\"\n        >\n            <span class=\"was-this-helpful__button-text fl-text-bold\">Yes<\/span>\n            <i class=\"was-this-helpful__button-icon\">\n                <svg width=\"22\" height=\"22\" viewBox=\"0 0 22 22\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                    <g id=\"thumbs-up\" clip-path=\"url(#clip0_604_3418)\">\n                        <path id=\"Vector\"\n                              d=\"M6 21H3C2.46957 21 1.96086 20.7893 1.58579 20.4142C1.21071 20.0391 1 19.5304 1 19V12C1 11.4696 1.21071 10.9609 1.58579 10.5858C1.96086 10.2107 2.46957 10 3 10H6M13 8V4C13 3.20435 12.6839 2.44129 12.1213 1.87868C11.5587 1.31607 10.7956 1 10 1L6 10V21H17.28C17.7623 21.0055 18.2304 20.8364 18.5979 20.524C18.9654 20.2116 19.2077 19.7769 19.28 19.3L20.66 10.3C20.7035 10.0134 20.6842 9.72068 20.6033 9.44225C20.5225 9.16382 20.3821 8.90629 20.1919 8.68751C20.0016 8.46873 19.7661 8.29393 19.5016 8.17522C19.2371 8.0565 18.9499 7.99672 18.66 8H13Z\"\n                              stroke=\"#666666\" stroke-width=\"2\" stroke-linecap=\"round\"\n                              stroke-linejoin=\"round\"><\/path>\n                    <\/g>\n                    <defs>\n                        <clipPath id=\"clip0_604_3418\">\n                            <rect width=\"22\" height=\"22\" fill=\"white\"><\/rect>\n                        <\/clipPath>\n                    <\/defs>\n                <\/svg>\n            <\/i>\n        <\/button>\n        <button\n                class=\"was-this-helpful__button fl-text-sm\"\n                aria-label=\"No\"\n                value=\"no\"\n        >\n            <span class=\"was-this-helpful__button-text fl-text-bold\">No<\/span>\n            <i class=\"was-this-helpful__button-icon\">\n                <svg width=\"22\" height=\"22\" viewBox=\"0 0 22 22\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                    <g id=\"thumbs-down\" clip-path=\"url(#clip0_604_3423)\">\n                        <path id=\"Vector\"\n                              d=\"M16 0.999995H18.67C19.236 0.989986 19.7859 1.18813 20.2154 1.55681C20.645 1.9255 20.9242 2.43905 21 3V10C20.9242 10.5609 20.645 11.0745 20.2154 11.4432C19.7859 11.8119 19.236 12.01 18.67 12H16M9.00003 14V18C9.00003 18.7956 9.3161 19.5587 9.87871 20.1213C10.4413 20.6839 11.2044 21 12 21L16 12V0.999995H4.72003C4.2377 0.994543 3.76965 1.16359 3.40212 1.47599C3.0346 1.78839 2.79235 2.22309 2.72003 2.7L1.34003 11.7C1.29652 11.9866 1.31586 12.2793 1.39669 12.5577C1.47753 12.8362 1.61793 13.0937 1.80817 13.3125C1.99842 13.5313 2.23395 13.7061 2.49846 13.8248C2.76297 13.9435 3.05012 14.0033 3.34003 14H9.00003Z\"\n                              stroke=\"#666666\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\n                    <\/g>\n                    <defs>\n                        <clipPath id=\"clip0_604_3423\">\n                            <rect width=\"22\" height=\"22\" fill=\"white\"\/>\n                        <\/clipPath>\n                    <\/defs>\n                <\/svg>\n            <\/i>\n        <\/button>\n    <\/div>\n    <span class=\"was-this-helpful__taken-action fl-text-sm-bold\"><\/span>\n    <div class=\"was-this-helpful__feedback-container\">\n        <div class=\"was-this-helpful__choose-option-message\" role=\"status\">\n            <p class=\"was-this-helpful__choose-option-message-text\"><\/p>\n        <\/div>\n        <form class=\"was-this-helpful__feedback-form\">\n            <div class=\"was-this-helpful__feedback was-this-helpful__feedback--positive\">\n                <fieldset>\n                    <legend class=\"was-this-helpful__feedback-form-title\" tabindex=\"0\">Why was this helpful?<\/legend>\n                    <div class=\"fl-radio-button-field fl-flex was-this-helpful__feedback-form-title\">\n                        <input\n                                id=\"was-this-helpful__radio-button--understandable\"\n                                class=\"fl-radio-button-field-input\"\n                                type=\"radio\"\n                                name=\"positive-feedback\"\n                                value=\"Easy to understand\"\n                        >\n                        <label\n                                class=\"fl-radio-button-field-label fl-text-sm was-this-helpful__radio-label\"\n                                for=\"was-this-helpful__radio-button--understandable\"\n                        >Easy to understand<\/label>\n                    <\/div>\n                    <div class=\"fl-radio-button-field fl-flex was-this-helpful__feedback-form-title\">\n                        <input\n                                id=\"was-this-helpful__radio-button--solved-problem\"\n                                class=\"fl-radio-button-field-input\"\n                                type=\"radio\"\n                                name=\"positive-feedback\"\n                                value=\"Solved my problem\"\n                        >\n                        <label\n                                class=\"fl-radio-button-field-label fl-text-sm was-this-helpful__radio-label\"\n                                for=\"was-this-helpful__radio-button--solved-problem\"\n                        >Solved my problem<\/label>\n                    <\/div>\n                    <div class=\"fl-radio-button-field fl-flex was-this-helpful__feedback-form-title\">\n                        <input\n                                id=\"was-this-helpful__radio-button--other\"\n                                class=\"fl-radio-button-field-input\"\n                                type=\"radio\"\n                                name=\"positive-feedback\"\n                                value=\"Other\"\n                        >\n                        <label\n                                class=\"fl-radio-button-field-label fl-text-sm was-this-helpful__radio-label\"\n                                for=\"was-this-helpful__radio-button--other\"\n                        >Other<\/label>\n                    <\/div>\n                <\/fieldset>\n            <\/div>\n            <div class=\"was-this-helpful__feedback was-this-helpful__feedback--negative\">\n                <fieldset>\n                    <legend class=\"was-this-helpful__feedback-form-title\" tabindex=\"0\">Why was this not helpful?<\/legend>\n                    <div class=\"was-this-helpful__choose-option-message\" role=\"status\">\n                        <p class=\"was-this-helpful__choose-option-message-text\"><\/p>\n                    <\/div>\n                    <div class=\"fl-radio-button-field fl-flex was-this-helpful__feedback-form-title\">\n                        <input\n                                id=\"was-this-helpful__radio-button--missing-info\"\n                                class=\"fl-radio-button-field-input\"\n                                type=\"radio\"\n                                name=\"negative-feedback\"\n                                value=\"Missing Information\"\n                        >\n                        <label\n                                class=\"fl-radio-button-field-label fl-text-sm was-this-helpful__radio-label\"\n                                for=\"was-this-helpful__radio-button--missing-info\"\n                        >Missing the information I need<\/label>\n                    <\/div>\n                    <div class=\"fl-radio-button-field fl-flex was-this-helpful__feedback-form-title\">\n                        <input\n                                id=\"was-this-helpful__radio-button--complicated\"\n                                class=\"fl-radio-button-field-input\"\n                                type=\"radio\"\n                                name=\"negative-feedback\"\n                                value=\"Too complicated\"\n                        >\n                        <label\n                                class=\"fl-radio-button-field-label fl-text-sm was-this-helpful__radio-label\"\n                                for=\"was-this-helpful__radio-button--complicated\"\n                        >Too complicated \/ too many steps<\/label>\n                    <\/div>\n                    <div class=\"fl-radio-button-field fl-flex was-this-helpful__feedback-form-title\">\n                        <input\n                                id=\"was-this-helpful__radio-button--dated\"\n                                class=\"fl-radio-button-field-input\"\n                                type=\"radio\"\n                                name=\"negative-feedback\"\n                                value=\"Out of date\"\n                        >\n                        <label\n                                class=\"fl-radio-button-field-label fl-text-sm was-this-helpful__radio-label\"\n                                for=\"was-this-helpful__radio-button--dated\"\n                        >Out of date<\/label>\n                    <\/div>\n                    <div class=\"fl-radio-button-field fl-flex was-this-helpful__feedback-form-title\">\n                        <input\n                                id=\"was-this-helpful__radio-button--negative-other\"\n                                class=\"fl-radio-button-field-input\"\n                                type=\"radio\"\n                                name=\"negative-feedback\"\n                                value=\"Other\"\n                        >\n                        <label\n                                class=\"fl-radio-button-field-label fl-text-sm was-this-helpful__radio-label\"\n                                for=\"was-this-helpful__radio-button--negative-other\"\n                        >Other<\/label>\n                    <\/div>\n                <\/fieldset>\n            <\/div>\n            <div class=\"was-this-helpful__form-buttons-container\">\n                <button\n                    class=\"was-this-helpful__feedback-button was-this-helpful__feedback-button--positive at-feedback-submit fl-button secondary\"\n                    type=\"submit\"\n                >\n                    <span class=\"fl-button-content\">Submit<\/span>\n                    <i\n                        class=\"fa fa-angle-right medium\"\n                        aria-hidden=\"true\"\n                    ><\/i>\n                <\/button>\n                <button\n                    class=\"was-this-helpful__feedback-button was-this-helpful__feedback-button--cancel fl-button primary disabled\"\n                    type=\"reset\"\n                >\n                    <span class=\"fl-button-content\">Cancel<\/span>\n                    <i\n                        class=\"fa fa-times-circle medium\"\n                        aria-hidden=\"true\"\n                    ><\/i>\n                <\/button>\n            <\/div>\n        <\/form>\n    <\/div>\n    <div class=\"was-this-helpful__thank-you-message\" role=\"status\">\n        <i class=\"was-this-helpful__thank-you-message-icon fa fa-check\"><\/i>\n        <p class=\"was-this-helpful__thank-you-message-text\" aria-live=\"polite\"><\/p>\n    <\/div>\n<\/div>\n\n\n    <\/div>\n    \n    <div class=\"fl-block-column fl-section-sidebar\">\n        \n    <\/div>\n<\/div>","protected":false},"parent":49876,"menu_order":0,"template":"app\/Http\/Controllers\/Templates\/ArticlePageController.php","meta":{"_acf_changed":false,"_stopmodifiedupdate":false,"_modified_date":"","_cloudinary_featured_overwrite":false},"class_list":["post-52771","supreme","type-supreme","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/supreme.findlaw.com\/legal-api\/wp-json\/wp\/v2\/supreme\/52771","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/supreme.findlaw.com\/legal-api\/wp-json\/wp\/v2\/supreme"}],"about":[{"href":"https:\/\/supreme.findlaw.com\/legal-api\/wp-json\/wp\/v2\/types\/supreme"}],"up":[{"embeddable":true,"href":"https:\/\/supreme.findlaw.com\/legal-api\/wp-json\/wp\/v2\/supreme\/49876"}],"wp:attachment":[{"href":"https:\/\/supreme.findlaw.com\/legal-api\/wp-json\/wp\/v2\/media?parent=52771"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}