Stanford Law Review
May, 2000; 52 Stan. L. Rev. 1125

Privacy As Intellectual Property?

Pamela Samuelson
Professor of Information Management and of Law, University of California, Berkeley.

Information privacy is a scarce commodity in cyberspace.  n1 The technical infrastructure of cyberspace makes it remarkably simple and inexpensive to collect substantial amounts of information identifiable to particular individuals.  n2 Once these data have been collected, information technologies make it very easy and cheap to process the data in any number of ways (for example, to make profiles of particular users' interests).  n3 Although some privacy-enhancing technologies (PETs) are being developed and deployed, these technologies have thus far done little to make cyberspace more privacy-friendly.  n4 The market incentives for firms to collect and process personal data are very high. Data about users is not only useful in assessing how a firm might improve service for its customers,  n5 but it also has become a key commercial asset which firms use both for internal marketing purposes and for licensing to third parties.  n6 Although the Clinton Administration has worked very hard to persuade Internet economy firms to adopt privacy policies and practices to make users more comfortable about engaging in e-commerce transactions in cyberspace,  n7 these efforts have done little to overcome the inertia of the current technical and economic environment  n8 that is  [*1127]  generally hostile to privacy interests.  n9 This symposium has been convened to consider whether the law should play a greater role in promoting greater information privacy in cyberspace.

A recent book succinctly stated the principal utilitarian argument for providing greater protection to personal data in cyberspace and elsewhere:

Consider the incentives of a company that acquires private information. The company gains the full benefit of using the information in its own marketing efforts or in the fee it receives when it sells the information to third parties. The company, however, does not suffer losses from the disclosure of private information. Because customers often will not learn of the overdisclosure, they may not be able to discipline the company effectively. In economic terms, the company internalizes the gains from using the information but can externalize some of the losses and so has a systematic incentive to overuse it.
This market failure is made worse by the costs of bargaining for the desired level of privacy. It can be daunting for an individual consumer to bargain with a distant Internet merchant ... about the desired level of privacy. To be successful, bargaining might take time, effort, and considerable expertise in privacy issues.  n10

To overcome this market failure, some American commentators have proposed that the law should grant individuals a property right in their personal data which would enable individuals to bargain over which personal data to reveal to which firms for what purposes.  n11 Other American commentators have recommended a contractual approach to protecting personal data in cyberspace (or more generally).  n12 Some suggest that the law should try to facilitate, and perhaps to approximate, the "privacy agreement the two sides would reach if they were both well informed and it was not expensive to reach an agreement."  n13 American commentators generally prefer market-  [*1128]  based solutions to personal data protection over the strict comprehensive regulatory regime adopted some years ago in Europe.  n14
While utilitarian considerations weigh heavily in the minds of many Americans who have written on information privacy issues, noneconomic considerations provide an equally or more compelling rationale for legal protection of personal data in cyberspace, according to other commentators. Those who conceive of personal data protection as a fundamental civil liberty interest, essential to individual autonomy, dignity, and freedom in a democratic civil society, often view information privacy legislation as necessary to ensure protection of this interest.  n15 Others regard cognitive limitations on the ability of individuals to comprehend and accurately assess the risks of revealing personal data to others as a reason for the law to provide corrective measures.  n16 Still others argue for information privacy protection to guard against identity theft, harassment, and other wrongful uses of personal information.  n17 Achieving consensus on the rationale for information privacy protection, however, may be unnecessary if both economic and noneconomic considerations favor greater protection for personal data in cyberspace.  n18
Part I considers both the appeal and limitations of the property rights model for protecting personal data. A property rights model offers two principal benefits: First, it would establish a right in individuals to sell their personal  [*1129]  data and thereby capture some of the value their data have in the marketplace. Second, a property rights model would force companies to internalize certain social costs of the widespread collection and use of personal data now borne by others. By internalizing these costs, firms may make better investment decisions about what data to collect and what uses to make of the data. A property rights model for protecting personal data nevertheless presents many problems. This approach to personal data protection would, in essence, establish a new form of intellectual property right in information. But it would be an intellectual property right of a very different sort than existing regimes provide. Deep differences in the purposes and mechanisms of traditional intellectual property rights regimes and the proposed property rights regime in personal data raise serious doubts about the viability of a property rights approach and about its prospects of achieving information privacy goals.
Part II explores an alternative market-oriented legal regime for protecting personal information. Such a regime need not ground itself in property law. The law can establish a default rule providing individuals with certain rights to control the collection or processing of personal information about them while also providing individuals with the power to contract away this right (e.g., when they receive compensation for doing so). Because market imperfections may impede fair and effective licensing of personal data in cyberspace, the law can supply some default terms for the licensing of personal data. Certain trade secrecy licensing default rules may be adaptable to the licensing of personal data. The Uniform Computer Information Transactions Act (UCITA) may supply additional default rules for the licensing of personal data in cyberspace.  n19 Adoption of online privacy policies could facilitate a market-based licensing approach to personal data protection. When Web sites post notices saying personal data will not be collected, disclosed, or used except for named purposes, users who supply data in reliance on those restrictions may be able to enforce the restrictions. A market-based licensing approach may also arise if technology evolves to allow "negotiated" agreements on the collection, use, or disclosures of personal data.
Although this article endorses a licensing approach to the protection of personal data, it recognizes that the law alone cannot solve information privacy problems in cyberspace. Work must continue on evolving norms about appropriate and inappropriate uses of personal data, on persuading firms that the trust necessary for electronic commerce to flourish requires the interests of individuals in information privacy to be given appropriate deference, and on adapting the technological infrastructure of cyberspace so that information privacy becomes easier to achieve. The principal challenge of these  [*1130]  multifaceted endeavors is not to recreate in cyberspace some preexisting zone of privacy from the physical world,  n20 but to articulate values inhering in information privacy that should constrain and structure social, economic, technological, and legal relations.  n21
I. The Appeal and Limitations of a Property Rights Approach To Protecting Personal Information
A. The Appeal of a Property Rights Approach

It may seem natural for individuals to assume that they do or should own data about themselves.  n22 It is surely true that the law will enforce the expectations of individuals that certain private information (for example, a diary or journal) should remain secret.  n23 Because individuals generally have a legal right to exclude other people from access to their private data, they may have a sense that they have a property right in the data as well as a legal right to restrict access to it. Even when data about individuals are in the hands of others (such as banks, doctors, and insurance companies), individuals may perceive themselves to have a protectable interest in records of their financial transactions or medical histories.  n24 Because the law will sometimes protect these and other types of data from unauthorized uses and disclosures,  n25 this too may reinforce a sense of ownership in personal data.
Although the law often protects the interests of individuals against wrongful uses or disclosures of personal data,  n26 the rationale for these legal protections has not historically been grounded on a perception that people  [*1131]  have property rights in personal data as such.  n27 Indeed, the traditional view in American law has been that information as such cannot be owned by any person.  n28 The Fourth Amendment and real property law may provide protection against certain unauthorized intrusions into one's real or personal property for purposes of getting access to information that might be stashed there, and the Fifth Amendment may provide protection against compulsion to reveal certain information about oneself. But these results are not grounded on a belief that people have property rights in information about themselves, but on the recognition of legally protectable interests of other sorts.  n29 An individual, for example, may be able to obtain relief if a doctor releases details of her medical history to a prospective employer, but the individual's rights would arise under contract or privacy law, not from the existence of any property rights in this information.  n30
Many examples illustrate that the law does not generally recognize the legal right of individuals to control uses or disclosures of personal data.  n31 Individuals, for example, have no legal right to stop firms from marketing  [*1132]  their personal data to other firms based on information that the individuals disclosed on a product warranty card sent to manufacturers of that product.  n32 Nor can they stop state governments from selling drivers' license data about themselves.  n33 Thus, however intuitively powerful the notion of property rights in one's data may be, it is clear that in the United States the existence of some legally protectable interests in personal data in certain circumstances is not equivalent to a legal rule that a person has a property interest in one's personal data.  n34
In recent years, a number of economists and legal commentators have argued that the law ought now to grant individuals property rights in their personal data.  n35 Some favor propertizing personal data as a way to allow individuals to make appropriate deals for selling their personal data and to receive compensation for uses of their personal data so that markets in personal information will work more fairly.  n36 Others favor propertizing personal data as a way of forcing companies to internalize more fully the costs associated with the collection and processing of personal data, in the hope that this will lead to greater privacy.  n37
There is at the moment a "lively market" in personal data, but it is a market in which individuals play at most a very small role.  n38 Many firms collect and process personal data because of its value and because information technology makes the collection and use of such data so much easier and cheaper.  n39 They also do so because they are not forced to internalize the societal  [*1133]  costs of private sector processing of personal data.  n40 Because they may have invested time, money and energy in compiling, organizing, or processing the data, they may well think of themselves as owning the data they have gathered or otherwise acquired.  n41 Perhaps firms would collect or process less personal data than they currently do if they had to pay individuals for rights to do so.  n42 If so, this would simultaneously achieve information privacy goals and allow individuals who wish to sell their data to receive some benefits from this market. In addition, a property rights regime might enable firms to make fewer wasteful investments in personal data and to develop higher quality databases, since individuals would presumably agree to release personal data to firms from whom they would be willing to receive information, and would have less incentive to lie as a way to protect their privacy.  n43
[*1134]  Governments clearly have power to create property rights when appropriate to cure or ameliorate market failure problems.  n44 Creating property rights in informational assets is, in fact, remarkably common. Intellectual property law grants exclusive rights in information-based creations in order to promote development of a thriving marketplace for them.  n45 A number of commentators have observed that, in an information economy, an increasing commodification of information and a creation of new property rights seems almost inevitable.  n46 Granting individuals property rights in their data would seem consistent with this general trend and with the emergence of an "attention economy."  n47
A property rights approach to solving the information privacy problem may also be consistent with survey evidence suggesting that most Americans are willing to disclose personal data to businesses and allow them to use these data as long as the individuals obtain a discernible benefit from this disclosure and use (for example, a discounted price for certain goods or services).  n48 If what upsets Americans most about the loss of control over their personal data is that they are not receiving any benefits arising from private sector reuses of the data, a property rights approach would arguably provide individuals with a way to exercise meaningful control over the market in personal data which they do not currently enjoy. This would arguably cure a market failure, as well as halt the unjust enrichment that compilers of personal information now enjoy.
A property rights approach may be especially useful to accommodate the varying preferences of individuals about private sector uses of personal data.  n49 Although some individuals may value privacy so highly that they will choose not to engage in market transactions about their personal data, others may be quite willing to sell their personal data to firms A, B, and C (even if  [*1135]  not to X, Y, or Z). Or they may be willing to sell personal data about their recreational interests, but not about the associations to which they belong. The market arguably provides an efficient device - namely the price mechanism - with which individuals can express their preferences about who should be able to use which of their personal data and to what degree.  n50 Private sector buyers would, of course, dicker on price and other terms, but economists generally assume that the market is a good way to achieve an efficient outcome satisfactory to both buyer and seller.  n51 If the market works well in enabling transactions in other commodities, it would presumably work for transactions in personal data as well.
A property rights approach to the information privacy problem would involve substantial transaction costs for individuals if they have to separately negotiate with each prospective buyer of their personal data.  n52 To overcome such problems, some commentators have predicted the emergence of new businesses to serve as intermediaries on behalf of individuals to represent their interests and negotiate with buyers of these data ("infomediaries").  n53 Others anticipate the development of electronic agents to perform negotiations and make deals to sell personal data in cyberspace.  n54 Still others expect individuals to be able eventually to program their browser software to incorporate their privacy preferences.  n55 Well-programmed browsers might then avoid Web sites that do not conform to their masters' preferences and only make automated deals with Web sites whose privacy terms are within an acceptable range.
A property rights approach offers a further potential advantage over other legal approaches to protecting privacy in that it could protect personal data without requiring the establishment of a substantial government bureaucracy, as some nations have done, to oversee regulation of personal data protection.  n56 Americans generally disfavor the substantial costs associated  [*1136]  with direct government oversight of industry practices. They also tend to bristle if the government requires firms to establish internal oversight procedures and structures, as the European Directive requires.  n57 To the extent that a property rights approach would avoid such costs, this would seem to be another factor in its favor.
B. Limitations of a Property Rights Approach

Despite these appealing features, there are some reasons to doubt that a property rights approach to protecting personal data would actually achieve the desired effect of achieving more information privacy. A property rights approach may have some unintended consequences that proponents of this approach have not recognized.
To understand some possible disadvantages of the property rights approach, it is necessary to think beyond the initial creation of a property right in an individual's personal data. Proponents implicitly assume that the creation of the property right is the only significant act necessary to enable the growth of a functioning market in which individuals could engage in personal data transactions.  n58 Kenneth Laudon is one of the few commentators to consider the infrastructure required to make a property rights system work.  n59
Laudon proposes the establishment of a regulated National Information Market (NIM) to allow "personal information to be bought and sold, conferring on the seller the right to determine how much information is divulged."  n60 Individuals would first "establish information accounts and deposit their information assets and informational rights in a local information bank, which could be any local financial institution interested in moving into the information business."  n61 The banks would then pool these information assets and sell "baskets" of them in a National Information Exchange.  n62 Buyers would receive the right to make commercial uses of personal information in those baskets for stated periods of time, in exchange for compensation  [*1137]  paid to the seller-banks. The banks would then equitably allocate this compensation among the individuals whose information was pooled in a particular basket (less a service fee).  n63 Laudon foresees assigning every participant in the NIM a unique identifier and barcode symbol (to be known as a National Information Account number) which "would help individuals keep track of who is using their information by informing the account whenever the individual's name is sold as part of a basket of information."  n64 Laudon proposes to make it a crime to use personal information without permission.  n65 He also foresees a substantial role for government oversight of this market.  n66
One need not agree with all the particulars of Laudon's vision in order to agree with his basic insight that an institutional infrastructure would be needed to make a new property rights market in personal information work. Even if one "grandfathered" in private sector "rights" to continue using personal data collected before the effective date of legislation establishing a property right in personal data, the new property system would introduce significant "friction" to a market that currently operates without it. This friction may be justifiable as a way to force data compilers to internalize certain costs they currently impose on others,  n67 but it is fair to say that the costs of establishing new procedures and implementing them would be far from trivial for both companies and for individuals.  n68 Collectors of personal data would presumably have to pay individuals for rights to process the data; this cost would unquestionably have to be passed on to others in the form of higher prices for the firms' own products or services, and establishing an enforcement system would also be costly. Property rights systems are not costless.  n69 Too little thought has been given as yet to how to move from where we are today to a thriving market in personal data under a property rights regime in which individuals would have a right to control market transactions in data about themselves.
Achieving information privacy goals through a property rights system may be difficult for reasons other than market complexities. Chief among  [*1138]  them is the difficulty with alienability of personal information.  n70 It is a common, if not ubiquitous, characteristic of property rights systems that when the owner of a property right sells her interest to another person, that buyer can freely transfer to third parties whatever interest the buyer acquired from her initial seller.  n71 Free alienability works very well in the market for automobiles and land, but it is far from clear that it will work well for information privacy. An individual may be willing to sell his data to company N for purpose S, but he may not wish to give N rights to sell these data to M or P, or even to let N use the data for purposes T or U. The individual may be able to make a reasonable estimate of the value they should receive from N for a grant for S purpose, but may at the time of transacting with N be unable to assess what value he should receive for any transfer of the same data to M, P, or any other licensee of N. Collectors of data may prefer a default rule allowing them to freely transfer personal data to whomever they wish on whatever terms they can negotiate with their future buyers. However, individuals concerned with information privacy will generally want a default rule prohibiting retransfer of the data unless separate permission is negotiated. They will also want any future recipient to bind itself to the same constraints that the initial purchaser of the data may have agreed to as a condition of sale. Information privacy goals may not be achievable unless the default rule of the new property rights regime limits transferability.
Consider also that the most common justification for granting property rights - to enable market allocations of scarce resources - does not seem to apply to personal data.  n72 What is scarce is information privacy, not personal data. If anything, personal data are being too plentifully distributed in the marketplace right now. Indeed, a reason many people argue in favor of granting individuals property rights in these data is, in essence, to make the distribution of them scarcer. While there are other instances in which property rights have been created in order to make a too plentiful a resource more scarce - for example, the creation of property rights to allow emissions of  [*1139]  pollutants up to certain levels as a way to achieve environmental goals  n73 - such a property rights system works because of the free transferability of the property rights. The right to pollute to a certain level is, by virtue of the property right grant, made into a scarce resource that the market can then allocate efficiently.  n74 The alienability of this property right is an essential part of what enables the property regime to accomplish its objective of controlling pollution levels. Yet, as noted above, the free alienability of property rights in personal data may prove troublesome.
Consider also differences between the rationale for the proposed property rights in personal information and the rationale for existing property rights regimes that regulate markets for information-based products, namely, intellectual property law.  n75 The economic rationale for intellectual property law arises from a public goods problem with information products that this law strives to overcome.  n76 In the absence of intellectual property rights, there may be too little incentive to induce an optimal level of private investments in the production and dissemination of intellectual products. Everyone benefits if such investments are made, regardless of whether they are in technological,  [*1140]  artistic or literary fields.  n77 However, without a legal protection system, creators will find it difficult to exclude free-riders from appropriating the fruits of their labor and selling identical or very similar products in the marketplace at a cheaper price.  n78 The prospect of being unable to recoup research and development costs may deter such investments from being made in the first place.  n79 A limited grant of property rights in intellectual productions gives creators assurance that they can control the commercialization of their work and enjoy some fruits of their labor, assuming the market finds the product attractive.  n80
The standard rationale for granting property rights in personal data is, of course, quite different.  n81 The personal data most likely to become the subject matter of such a property right, for the most part, already exist. Property rights are not needed to bring them into being, nor to achieve widespread distribution of them. There are, in addition, no research and development costs to recoup. It is, of course, possible that people might invest more time, money and energy in the creation of additional personal data about themselves (for example, hobbies the person would like to have or famous people the person would want to meet) if they could assert property rights in this new data, but there is some reason to think that people may be willing to do this even without a grant of property rights in the data.  n82
A further cause for concern about a property rights approach to protecting personal data is the potential that such grant of intangible rights in intangible information will lead to greater incoherence in intellectual property law. A fundamental principle for Congressional grants of intellectual property rights is that such legislation should "promote the Progress of Science and [the] useful Arts ...."  n83 It is difficult enough these days for Congress to adhere to this principle: Expanding intellectual property law to protect personal  [*1141]  data would only strain the coherence of this body of law further.  n84 This constitutional principle does apply to personal data. The creation and dissemination of personal data does not generally promote "science" in the constitutional sense (i.e., knowledge),  n85 nor does it promote technological innovation.  n86 Indeed, the purpose of the proposed new personal data property right is almost the inverse of traditional intellectual property law, for it would grant a property right in order to restrict the flow of personal data to achieve privacy goals.  n87
It is also far from clear what constitutional authority Congress would have to enact legislation creating a property right in personal data. Given the mismatch between the purposes of personal data protection and of traditional intellectual property rules, it would be difficult to justify such legislation under the enabling clause for copyright and patent legislation.  n88 Because of the interstate character of the Internet and web, it might be possible to justify congressional legislation granting property rights to personal data in cyberspace under the Commerce Clause.  n89 However, a more general grant of property rights in personal data might be constitutionally troublesome.  n90  [*1142]  Grants of property rights are generally the province of state law.  n91 Indeed, the state law doctrine out of which a property right regime in personal data would seem the most natural extension is right of publicity law which gives individuals some rights to control commercial exploitation of their names, likenesses, and other indicia of the commercial value of their person.  n92 Although the right of publicity has often been characterized as a property interest,  n93 it is an interest that law has allowed celebrities, not ordinary folk.  n94
Creating a property right in personal data may, moreover, be objectionable to those who consider information privacy to be a fundamental civil right.  n95 While the civil right conception of personal data protection is predominant in Europe,  n96 sometimes this conception is evident in U.S. decisions  [*1143]  on privacy,  n97 even in cases involving uses or disclosures of personal data.  n98 Other cases have been less deferential to information privacy as a protectable civil liberty interest,  n99 but this conception of information privacy unquestionably has adherents in the United States.  n100 From a civil liberties perspective, propertizing personal information as a way of achieving information privacy goals may seem an anathema.  n101 Not only might it be viewed as an unnecessary and possibly dangerous way to achieve information privacy goals, it might be considered morally obnoxious. If information privacy is a civil liberty, it may make no more sense to propertize personal data than to commodify voting rights.  n102
Europeans have more of a civil libertarian perspective on personal data protection in part because of certain historical experiences they have had.  n103 One factor that enabled the Nazis to efficiently round up, transport, and seize assets of Jews (and others they viewed as "undesirables") was the extensive repositories of personal data available not only from public sector but also from private sector sources.  n104 Europeans may realize more than most  [*1144]  Americans the abusive potential for reuses of personal data that may initially have been provided to a particular entity for a specific, limited purpose. If more Americans had an appreciation of the negative consequences that might arise from commercial distributions of their personal data, they might perceive personal data protection differently.  n105
Congress has sometimes legislated information privacy protections out of concern about cognitive difficulties in appreciating the risks of supplying personal data to private sector firms, for example, in respect of gathering information from children under the age of thirteen.  n106 On occasion, Congress has also recognized that adults, too, may not appreciate certain risks in supplying personal data to private sector firms and has decided that in those instances even the adults should be protected. When renting certain video cassettes from a corner rental store, Robert Bork, for example, surely did not anticipate that he was running the risk that the owner of the video store might disclose his rental choices to the press while he was a nominee to the U.S. Supreme Court.  n107 The disclosure of his viewing choices was not, under then existing law, illegal. It is illegal now. And the Video Privacy Protection Act  [*1145]  is far from the only law of this kind.  n108 Congress has also acted to protect individuals against public sector commercialization of drivers' license data in part because of the involuntary nature of this particular kind of data collection and in part because of negative consequences arising from the widespread market availability of such data.  n109
As difficult as it may be for the average person to judge the risks of personal data misuse as a general matter, it may be even more difficult for the average person to judge the risks of selling her property rights in personal data.  n110 Data collectors may well insist on broad transfers of all of a person's right, title and interest in her personal data.  n111 While such a broad transfer works very well in a sale of a used car or a house, it may be troublesome in the context of personal data. As a result of such a transfer, an individual could potentially be foreclosed from any control over these data in the hands of the transferee or in the hands of other firms to whom the data might have been transferred. The individual could even be precluded from engaging in further transactions to sell the same data to other firms because her rights in the data now belong to a personal data aggregator. Other firms wanting to access or use these data would have no choice but to go to the data aggregator and license the data from that firm - on terms that would likely reflect the interests of the aggregator rather than those of the individual whose data has been licensed.
This cluster of problems could be mitigated if the individual makes a more limited grant of rights to a data aggregator,  n112 but this may suggest that a different approach to protecting information privacy may be more satisfactory than a property rights approach. It is unusual for a property rights regime to establish a rule or strong presumption against alienability.  n113 A  [*1146]  property approach may also thwart information privacy goals unless the law makes it clear that a person does not abandon property rights in personal data when visiting Web sites that collect personal data.  n114 The rhetoric of property law may also be unsuited to further elucidation of normative understandings about acceptable and unacceptable uses of personal data that is sorely needed in this era of rapid technological, economic, and social change.
C.A Moral Right in Personal Data?

As vigorously as this subsection has argued against a property rights model for protecting personal data, it has done so because the standard models of property rights seem unsuitable to achieving information privacy goals. There is, however, one rather unusual class of property right that protects personhood interests of individuals, melding economic, reputational, and autonomy interests at its core. In the spirit of providing exemplars from the existing tool kit of property law, it may be worth mentioning "moral rights" of authors as a model for a nontraditional property right that might be adaptable to protecting personal data.  n115
In Europe and many other nations, authors have "moral rights" in the works they have created.  n116 These rights are distinct from the purely economic rights that European law, like American copyright law, grants to authors. The moral rights regime derives from a conception of artistic and literary creations as emanations of the author's personality in which he can  [*1147]  and should retain an interest even after copies of the work have entered the stream of commerce.  n117 Among the commonly recognized moral rights are the rights of attribution (i.e., the right to be identified as the author of the work) and of integrity (i.e., the right to protect the work from alterations that would be harmful to the author's reputation).  n118 In some jurisdictions, authors also have moral rights of "divulgation" (i.e., the right to decide when and under what circumstances to divulge the work) and sometimes even of withdrawal (i.e., the right to withdraw all published copies of the work if the work no longer represents the author's views or otherwise would be detrimental to the author's reputation).  n119
Moral rights are generally waivable by contract, although some countries - notably France - regard such rights as sufficiently important and vulnerable to unfair contractual overrides that they have made them inalienable rights.  n120 An advantage of moral rights is that these rights can be exercised long after the author has sold copies of her work to the public and can be exercised against remote purchasers. If the owner of a sculpture, for example, alters it in a way that the sculptor deems detrimental to his interests (for example, by tying red ribbons around its neck), the sculptor can assert his moral right of integrity in the work and can obtain injunctive relief requiring restoration of the original.  n121 While moral rights generally focus on the personal, reputational interests of authors, an economic consideration may partly  [*1148]  underlie moral rights. "Mutilation" of an author's work can tarnish the author's reputation in ways that may be difficult to measure, akin to the harm to goodwill when trademarks are disparaged or tarnished.  n122
A moral rights-like approach might be worth considering as to personal data. As with the moral right of authors, the granting of a moral right to individuals in their personal data might protect personality based interests that individuals have in their own data. The admixture of personal and economic interests could be reflected in the right. The integrity and divulgation interests may be the closest analogous moral rights that might be adaptable to protect personal data. An individual has an integrity interest in the accuracy and other qualitative aspects of personal data, even when the data are in the hands of third parties.  n123 An individual also has an interest in deciding what information to divulge, to whom and under what circumstances.  n124 An advantage of a moral rights-like approach is that this right can be asserted against persons beyond those with whom one has contracted. Contract law, in general, provides relief for breach as between the parties to a contract, not rights against third parties.  n125 Firms that collect and process personal data are often not in privity with the individual whose data is being used.  n126
[*1149]  A moral right-like approach would overcome a second important limitation of a purely contractual approach which generally aims to compensate the non-breaching party through an award of damages, not by granting injunctive relief.  n127 Property law, in contrast, generally allows the owner of the right to exclude other people from engaging in certain activities, and injunctive relief is consequently generally available.  n128 A person who has licensed a particular use of her personal data, but not another use, would almost certainly want injunctive relief upon learning that her licensee is using the data for more than the authorized purpose.  n129 A property right in her personal data could provide grounds for injunctive remedy.
[*1150]  However, the idea of creating a moral right-like interest in personal data presents many difficulties. For one thing, U.S. law has generally been inhospitable to the idea of moral rights of authors,  n130 even though it has ratified a treaty that requires such protection.  n131 This augurs poorly for adaptation of the concept to protection of personal data. It is also unclear what constitutional authority Congress would have for enacting legislation of this sort. Moreover, even the Europeans might balk at the idea of generalizing the moral right concept for personal data because it undermines the special status of authorship that provides the theoretical justification for existing moral rights law.  n132
Two state law doctrines out of which a moral right-like interest might emerge are right of publicity law and the appropriation branch of privacy law. Right of publicity law, like moral rights law, has generally protected the interests of special status individuals (in the case of publicity rights, the interests of "celebrities"),  n133 and like intellectual property laws, publicity law largely concerns itself with providing appropriate incentives to induce investments in creative efforts, not to protect personality based interests.  n134 The appropriation tort could be extended to provide individuals with a protectable interest in personal data.  n135 Even though the right created would not be a "property right,"  n136 it could still allow individuals to contract for allowable  [*1151]  uses of personal data  n137 and to police third party uses of personal data insofar as these uses were unreasonable.  n138 This tort protects dignity-, integrity-, and autonomy-based interests of individuals by setting bounds on acceptable behavior.  n139 However, the appropriation privacy tort seems an unsuitable way to establish a market-based system for enabling transactions in personal data in which the individual participates, even though this is what many Americans seem quite willing to do with personal data.  n140 The next section will explain why a licensing system built on modified trade secrecy default principles might offer a useful model for licensing of personal data, and will offer some suggestions about how such a system might be implemented to facilitate greater protection for personal data in cyberspace.
II. Modified Trade Secrecy Default Rules for Promoting Information Privacy

The law can grant individuals a protectable interest in their personal data without grounding that interest in property law.  n141 It can do so by setting a default rule forbidding certain activities with respect to these data, such as unauthorized collection or uses of them unless the individual has agreed to these activities.  n142 Because market imperfections make it difficult to negotiate effectively about terms of use as to personal data,  n143 it may make sense to establish some default terms for such agreements which the parties could override if they so choose. Although trade secrecy and information privacy  [*1152]  laws obviously differ in many significant respects, these laws nonetheless have at least three important interests in common: first, an interest in protecting the interest of the claimant to restrict access to and unauthorized uses of secret/private information; second, an interest in giving firms/individuals control over commercial exploitations of secret/private information; and third, an interest in setting and enforcing minimum standards of commercial morality. To achieve policy goals embodied in these interests, trade secrecy law has evolved a set of default licensing rules. Some of these default rules may be adaptable to the licensing of personal information.
A. Rationale for Adapting Trade Secrecy Default Rules to Licensing of Personal Data

Like the information privacy law contemplated in this article, trade secrecy law facilitates license transactions in information, while at the same time providing default rules to govern uses and disclosures of protected information, and setting minimum standards of acceptable commercial practice. Information privacy rights, like trade secrecy rights, can be based on three types of interaction: first, on contractual agreements; second, on conduct between the parties from which it is reasonable to infer that information was disclosed in confidence, and use and disclosure beyond those purposes is wrongful; and third, on the use of improper means to get the information.  n144
Agreement-based trade secrecy typically occurs when A has nonpublic information to which B wants access. A agrees to give B access to the information in exchange for B's agreement to respect certain restrictions on its use, and abide by other terms and conditions (for example, payment of a stated sum or royalty). Because of the exchange value of such information, trade secret information can be a highly valuable asset of the firm and provide it with a substantial revenue stream.  n145 The information, however, does not become "public" simply because a number of firms possess it - as long as each is under an implicit or explicit pledge to maintain the nonpublic status of the information.  n146
Confidential relationship-based trade secrecy may arise when A reveals certain nonpublic information to B under circumstances in which B would have reason to understand the limited purpose of the disclosure, and that use  [*1153]  and disclosure for other purposes would be wrongful.  n147 For example, if a firm discloses certain nonpublic information about the firm's operations to a consultant, the consultant will understand that he is entitled to use this data only for purposes of analysis in order to advise the company about how to improve its operations. The revealed information may have a commercial value beyond its utility to aid the consultant in doing his job, but the consultant understands that it would be inappropriate to sell or release the information to another firm or to reveal it to stockbrokers so they could make better decisions on whether to trade in that firm's securities. Both the consultant and the firm would understand, even if they did not specifically agree, that rights to control uses of the information reside in the firm, not the consultant.
For similar reasons, individuals often regard the data that they reveal to others - their accountants, doctors, and banks, to name a few examples - as having been provided to those firms for limited purposes. Uses and disclosures of the data, whether internally or to third parties, may be inappropriate unless undertaken for purposes consistent with the initial disclosure. Just as the consultant could not justify revealing information to a third party on a theory that this disclosure would enable the other firm to provide new or better service to the company, individuals may be skeptical of those who argue that disclosure of their personal data to a third party is justifiable because it enables that firm to offer service to them.
In trade secrecy law, as in the information privacy law contemplated in this article, there is no need to say that a property right exists in the protected information.  n148 Although courts have sometimes loosely referred to trade  [*1154]  secrets as the "property" of the firm that licensed them and have on occasion held trade secrets to be property for certain purposes,  n149 the more appropriate way to characterize the firm's interest in a trade secret is to say that the law protects the firm against breaches of contracts and confidential understandings,  n150  [*1155]  as well as against the use of improper means to obtain the secret.  n151 Despite its frequent presence in texts of intellectual property law,  n152 trade secrecy law remains firmly rooted in unfair competition law.  n153 A true intellectual property right provides the owner with rights to exclude that are good against the world at large as to innovations that are generally widely distributed to the public.  n154 Trade secrecy law, by contrast, remains a tort law that enforces minimum standards of commercial morality.  n155 Going through trash bins outside a firm's office may, for example, be an acceptable way for the government to obtain information when investigating a crime,  n156 but the law of trade secrecy regards this means of obtaining trade secrets to be improper and the trash searcher as a misappropriator of trade secret information.  n157
Trade secrecy law has a number of default rules that might be useful for information privacy protection. The general rule of trade secrecy licensing law is that if the licensor has provided data to another for a particular purpose, the data cannot be used for other purposes without obtaining permission for the new uses.  n158 Licensing law generally accommodates the  [*1156]  reasonable expectations of the parties.  n159 If a licensor has failed to specify a limitation on use, the limitation may still be enforced so long as circumstances surrounding the agreement reasonably support an implicit understanding about limitations on use.  n160 Moreover, licensing law generally permits revocation of the license for breach of material terms.  n161 Contract law, far more than property law, takes into account cognitive difficulties individuals may have in assessing the risks of certain transactions and provides protections to overcome these cognitive problems.  n162 Some of these doctrines may be adaptable to licensing of personal data, particularly in view of the cognitive difficulties people often have in assessing the risks of permitting certain uses of personal data.  n163
One of the most significant advantages of the licensing regime is that it avoids the problems of a property rights approach deriving from its preference for free alienation. The general default rule of trade secret licensing law is that license rights are nontransferable unless the licensor grants a right to sublicense.  n164 Sublicenses, if permitted, generally oblige the sublicensee  [*1157]  to abide by the same terms as the license imposes on the now sublicensor.  n165 Licenses are also nonexclusive unless expressly provided otherwise.  n166
Trade secrecy law also provides some rights against third party uses of protected information.  n167 If a third party has obtained the protected information from one whom the party knows or has reason to know got the information by improper means, or in breach of confidence, the trade secret can be enforced against the third party.  n168 If the third party got the information innocently, the firm seeking to protect the information may nevertheless be able to stop unauthorized use of the information after giving notice to the third party about its rightful claim to control uses of the information.  n169
Adopting modified trade secrecy licensing default rules for protecting personal data may also be less likely to interfere with or contribute to confusion in the law in respect of intellectual property rights and the First Amendment because it would focus on enforcing agreements and confidential relationships and monitoring acceptable commercial practices.  n170 In addition, such an approach makes it unnecessary to engage in a quasi-religious  [*1158]  war to resolve whether the nature of a person's interest in her personal data is a fundamental civil liberty or commodity interest.  n171 A licensing approach to protecting personal data is consistent with the widespread use of licenses in the digital networked environment.  n172 If software and Internet companies have devised licenses to cover virtually every Internet transaction between them and their customers, it may seem only fair for the customers to start insisting on contractual terms that serve their interests as well.
It is also noteworthy that virtually all of the advantages offered in support of the property rights approach for the legal protection of personal data would be achievable through a licensing regime.  n173 A licensing model would allow a market to exist in personal information insofar as individuals wished to participate in that market. New infomediary businesses could also arise under a licensing regime. Licensing also avoids the need for a government bureaucracy to regulate information privacy practices. Like the property model, the licensing model assumes that the marketplace can generally achieve workable outcomes.
There are obviously significant differences between trade secrets and personal information which may require each law to have different rules.  n174 However, borrowing trade secrecy licensing default rules makes sense insofar as a person and a firm have agreed that the person will reveal nonpublic information to the firm in exchange for a stated sum and a willingness to restrict uses of the information to stated purposes. It also makes sense when a person reveals information to a firm in circumstances in which it is fair to infer that the information has been disclosed in confidence and for limited purposes. Borrowing from trade secrecy law's default rules may even make sense if one can articulate some means of obtaining personal data that the law should be considered improper. Consider, for example, the impropriety in getting personal data by engaging in unauthorized surveillance, by fraud, trickery, misrepresentation, or by hacking into a cryptographic envelope in which the data are being stored.  n175 The law of information privacy, like the law of trade secrecy, could monitor commercial morality, adapt to changing  [*1159]  circumstances, and at the same time accommodate the interests of individuals who are quite willing to reveal or allow uses of their personal information as long as they derive a benefit from it.
B. Developments That Might Cause Licensing To Emerge As a Viable Solution to Cyberspace Information Privacy Problems

Societal consensus about appropriate and inappropriate uses of personal information in cyberspace is forming in the United States, shaped in part by news coverage about information privacy issues. Several times a week, major news stories about information privacy issues appear. One day the story may be about legislation forbidding states to sell drivers' license data as a commercial product.  n176 Another day someone will have discovered that widely used software is sending surreptitious messages back to the firm when a user is playing a sound recording.  n177 Yet another day will bring news that Congress has passed legislation to deregulate the financial services industry will enable subsidiaries to share information about customers (which the industry claims will promote better service to customers and which privacy advocates say will bring harmful consequences, for example, the denial of a person's application for a mortgage on the ground that the insurance data about him suggests he will not live long).  n178 In view of the negative publicity that occurs when information privacy is not respected, major Web sites now worry about whether the information sharing they do is, in fact, fair or unfair.  n179 This publicity has caused firms to back down very publicly when they have acted in a privacy-unfriendly way.  n180 Internet companies know  [*1160]  that an installed base of millions of users can quickly evaporate if customers do not trust the provider.
While fears of negative publicity is one inducement to attend to information privacy concerns, companies have realized that the news can be favorable as well, as when it publicizes private sector initiatives to further information privacy goals. The Online Privacy Alliance has been particularly active in taking a proactive stance on information privacy policy issues and getting the word out about its initiatives.  n181 Industry commentators also frequently point out that information privacy is key to building trust among consumers and trust is essential for the promise of e-commerce to be realized.  n182 In addition, American firms with substantial international market presence are becoming more attentive to information privacy practices and policies because of the need to comply with data protection rules in other jurisdictions.  n183
1. From self-regulation norms to licensing.

For e-commerce Web sites, having a privacy policy is no longer optional. Federal legislation, Federal Trade Commission (FTC) enforcement, the European Union Privacy Directive, economic coercion, and consumer demand have all recently converged to create a new environment in which implementing a privacy policy is a business necessity for most, and legally advisable for all.  n184
To give content to "self-regulation," the Clinton Administration has endorsed privacy principles that it strongly recommends private sector firms should adopt as part of a self-regulatory strategy.  n185 The FTC announced the following five pairs of principles as critical components of a true self-regulatory regime:

. Notice/Awareness
. Choice/Consent
. Access/Participation
[*1161]  . Integrity/Security
. Enforcement/Redress.  n186

In 1998, the FTC conducted a survey of more than 1400 commercial Web sites on privacy policy practices. The agency reported to Congress that a high proportion of such sites (92%) collected personal information from visitors to their sites, although nearly as substantial a proportion (86%) provided no notice about their information privacy policies. A year later, the FTC reported a substantial increase in the proportion of commercial Web sites that provided some notice about their sites' privacy policies.  n187 Based on this progress, the FTC indicated that self-regulation should be given additional time to succeed.  n188
While it is true that more online firms have privacy policies today, it is also true that if the FTC had judged the adequacy of privacy policies based on the criteria it set forth defining meaningful notice, the agency might have perceived less progress than it reported.  n189 And if it judged progress based on private sector adherence to all five privacy principles, it might well have concluded that self-regulation had a very long way to go. Nevertheless, there is some evidence that American-based commercial Web sites provide more notice about privacy policies now than they did a year ago.  n190 Some progress also continues in implementation of the other principles, in part because of the well-publicized actions of major firms, such as IBM Corp., that have announced they will not place advertising with Web sites that do not meet certain privacy standards.  n191
Providing users with meaningful notice about what information a site is collecting about an individual, and what the site intends to do with this data, is definitely a step in the right direction. Notice alone, particularly one that is vague in content, may provide little basis for inferring that the site owner has bound itself to collect only these data and use the data only for stated purposes. However, misrepresentations in Web site privacy notices about  [*1162]  the collection or use of personal data might be actionable.  n192 In addition, the FTC has authority to monitor sites to ensure that they are not engaging in deceptive or other unfair trade practices with respect to personal data they collect.  n193 And the FTC, among other agencies and groups, can be expected to press for greater adherence to the privacy principles over time.
As firms adhere more fully to the FTC privacy principles, it may enable the emergence of a contractual basis for holding firms to privacy representations. The more notice a Web site gives about what data will be collected and for what purposes, and the more the site seeks consent for collection and use of personal data, the more robust the firm's representations about the integrity of its data and the security with which it maintains the data. Also, the more explicit a firm is about remedies available for failure to adhere to stated privacy policies, the more reasonable is an inference that firms have contracted with users about personal data practices. As one legal commentator has observed:

As between the Web site and the user, a privacy policy bears all the earmarks of a contract, but perhaps one enforceable only at the option of the user. It is no stretch to regard the policy as an offer to treat information in specified ways, inviting the user's acceptance by using the site or submitting the information.  [*1163]  The Web site's promise is sufficient consideration to support a contractual obligation, as is the user's use of the site and submission of personal data.  n194

The modified trade secrecy licensing default rule approach discussed above might supply some terms for such contracts.
The evolution of a licensing approach to personal data protection may be necessary because, unlike other fields in which self-regulation has been accepted,  n195 there is no Internet e-commerce industry organization to serve as the overseer of self-regulatory practices to ensure that members of the organization are abiding by self-regulatory norms. Private sector firms are likely to prefer a licensing approach to having the government establish a new privacy bureaucracy. The more enlightened among private sector firms are coming to realize that fuller adherence to privacy principles will promote consumer trust which will, in turn, promote commerce. But providing consumer protection through implied or explicit licenses may ensure that self-regulation will work.
2. Promulgation of Uniform Computer Information Transactions Act.

A recent development that might have implications for the licensing of personal data is the promulgation of a model law, once known as Article 2B of the Uniform Commercial Code and now known as the Uniform Computer Information Transactions Act (UCITA).  n196 The paradigmatic transaction of the Information Age is, in its view, that of licensing.  n197 In July 1999, the  [*1164]  National Conference of Commissioners of Uniform State Laws (NCCUSL) approved this model law for submission to state legislatures,  n198 and it is already being considered for enactment by some states.  n199 For a variety of reasons, this model law has been highly controversial.  n200 UCITA could pave the way for a licensing regime for protecting personal information.  n201
In considering the possible implications of UCITA for personal data protection, it is appropriate to begin with the recognition that the personal data gathered in cyberspace falls within UCITA's rather open-ended definition of "computer information."  n202 Interactive communications between an individual and a commercial Web site, moreover, would seem to constitute a "transaction."  n203 Since the paradigmatic transaction of UCITA is a license, transactions between an individual and a commercial Web site may be among the transactions which UCITA could govern.  n204
[*1165]  For a license in computer information to be enforceable under UCITA, a prospective licensee of personal data (in this case, the Web site owner) must manifest assent, through conduct or otherwise, to the terms of the license after an opportunity to review the terms and conditions of the license.  n205 A potential problem with using UCITA to protect personal information in cyberspace is that individuals today do not generally articulate terms and conditions to which the site must agree before the individuals will supply the site with personal data; nor do they present such a license to site owners for their review before using the site.  n206 Site owners could conclude from the absence of proffered terms that whatever information individuals might provide to the site, wittingly or unwittingly, is being provided without license restrictions.  n207
However, it may be possible to establish restrictive licensing terms for personal data by looking to the prospective licensee's privacy policy as a statement of that party's willingness to restrict its uses of personal data. After all, UCITA does not require restrictive license terms to be set by the licensor; all it requires is a manifestation of assent to restrictive terms. If users assent to the licensee's privacy policy restrictions by supplying information to the site or using it otherwise in accordance with the site's terms, a license agreement subject to these restrictions might be formed.  n208 This license might then be supplemented with the modified trade secrecy licensing default rules proposed above to which site owners and the individuals would agree unless expressly agreed otherwise.  n209
[*1166]  Future developments may also aid in the development of restrictive personal data licenses for cyberspace transactions. Consumer protection organizations could, for example, draft standard form restrictive licensing agreements for individuals to use to protect their privacy interests when dealing with Web sites.  n210 Given the current technical infrastructure of the web, individual users may not be in a position to present their standard form contracts to the site owner in a meaningful way. However, the technical infrastructure of the web may in time allow automated negotiations of privacy licenses that will restrict uses that can be made of personal data (a matter to be considered in the next subsection).  n211
While much more could be said about the pros and cons of utilizing UCITA for personal data protection, there is some reason to question whether UCITA will be useful in achieving information privacy goals. UCITA was, after all, drafted with very different kinds of licensing transactions in mind. From the outset, the core subject matter of the UCITA/Article 2B project has been computer programs.  n212 Some years ago, the subject matter of this model law was expanded to cover virtually all transactions in information.  n213 After several major information industries objected to this scope for the law, in large part because the assumptions and default rules of UCITA/Article 2B did not match well with the licensing practices of those industries,  n214 the drafters eventually contracted the scope of the model law to computer information.  n215 Even with this contracted scope, major information  [*1167]  industries continue to oppose UCITA in part because of the "software-centric" nature of its rules.  n216 If these industries are correct in thinking that UCITA is not suitable for the licensing of such computer information products as computer-processable motion pictures or newspapers, it seems unlikely that UCITA would be suitable for protecting personal data. After all, the commercial goals of the motion picture and news industries would seem to be much closer to those of the software industry than to the licensing of personal data. In view of this, it may be na<um i>ve to think UCITA would provide a workable framework for achieving information privacy goals.
Still, some believe that UCITA provides a licensing regime capable of providing individuals with somewhat greater protection in transactions involving their personal data than they might otherwise have.  n217 To counteract concerns about potential disparities in bargaining power of commercial Web site owners and individuals about personal data matters, it might be worth considering an adaptation of proposals made by Reichman and Franklin for public-interest unconscionability default rules to achieve a better balance in non-negotiated UCITA transactions.  n218 Although Reichman and Franklin may have had other public interests in mind, the concept of public interest unconscionability default rules for licensing of personal data may provide a way to achieve information privacy goals.
3. Privacy-enhancing technologies.

A number of privacy-enhancing technologies (PETs) have been developed in recent years which are capable of masking personal identity in cyberspace in order to achieve information privacy goals.  n219 There is substantial appeal in the idea of a technological solution to a problem that technology itself seems to have created, in part because such technologies  [*1168]  are self-enforcing and appear to reduce the need for regulatory interventions.  n220
One commentator has differentiated among four types of PETs: (1) subject-oriented PETs (those aiming to limit the ability of others to discern the identity of a particular person, for example, an anonymizing browser); (2) object-oriented PETs (those aiming to protect identity through the use of a particular technology, for example, anonymous e-cash); (3) transaction-oriented PETs (those aiming to protect transactional data, for example, automated systems for destroying transactional data); and (4) system-oriented PETs (those aiming to create "zones of interaction where the identity of the subjects is ... hidden, where the objects bear no traces of those handling them, and where no record of the interaction is created or maintained,"  n221 for example, anonymous remailer systems).  n222
A fifth category of PETs capable of being programmed to interact with Web sites about the privacy preferences of individuals potentially interested in visiting the sites might be added as well. One well-publicized example is the Platform for Privacy Preferences (P3P) effort underway at the World Wide Web Consortium.  n223 Some expect electronic agents to be programmed to negotiate privacy and other user-preferred terms of contracts in cyberspace.  n224
If P3P's designers achieve the project's objectives, P3P would enable individuals to program their browsers to identify classes of information that they are willing and unwilling to disclose (for example, yes to zip code, but no to street address) to Web site owners.  n225 Individuals would then not have  [*1169]  to haggle over terms and conditions with every site they visit. Instead, their browsers could be set to avoid sites that do not comport with the individuals' privacy preferences.  n226 The prospect of having fewer people visiting one's site if one's privacy policy does not comport with common user preferences may create significant commercial pressure for firms to offer more consumer-friendly privacy policies.
As promising as P3P and other PETs technologies may be,  n227 it is fair to say that they have yet to prove their worth in achieving information privacy goals except in limited circumstances.  n228 Other presenters at this symposium are better able than I to assess the likelihood that such technologies will provide greater privacy protection over time.  n229 However, it is unlikely that technology alone can solve the problem.
As Professor Burkert has observed, the "main task ... [of] social scientists, lawyers, regulators, and privacy practitioners ... [is] to accept the challenge of information and communication technology as a challenge for social innovation."  n230 Information privacy is a social goal, not a technological one. To achieve information privacy goals will require social innovations, including the formation of new norms and perhaps new legal rules to establish boundary lines between acceptable and unacceptable uses of personal data. It may be easier for information technologists to embody such norms and legal rules in code after society has configured what those rules should be, and they will surely have greater incentives to do so if the law requires it.  n231

Europeans have realized that it is not just an information infrastructure we are in the process of constructing, but an information society.  n232 They have identified information privacy as a fundamental value that should be a keystone of the architecture for achieving an information society in which people will want to live.  n233 In addition, they have demonstrated that political will can be found to utilize the law to ward off Scott McNealy's vision for the information society ("you've got zero privacy now. Get over it"  n234). In these insights may lie some useful lessons for Americans who also value information privacy.  n235
Myriad reasons explain why the U.S. response to the challenges of information privacy for an information society has been so much slower, more erratic, and less comprehensive than in the E.U.  n236 Among them are certainly considerable differences in the regulatory cultures of the U.S. and the E.U., as well as dissimilar attitudes toward the private sector and toward technology.  n237 However, a serious impediment to a comprehensive approach in the U.S. is the lack of clarity in this country about the nature of the interest that individuals have in information about themselves: Is it a commodity interest, a consumer protection interest, a personal dignity interest, a civil  [*1171]  right interest, all of the above, or no interest at all?  n238 One of the strengths of the EU Directive is that the regulatory regime it embodies is consistent with its underlying conception of information privacy as a fundamental human right. Without a coherent conception about the nature of a person's interest in personal data, it is difficult to design a legal regime to protect this interest appropriately.
One of the virtues of the property rights approach to protecting personal data discussed in Part I is that it would seem to solve the nature-of-the-interest problem which, in turn, should simplify the task of constructing a legal regime to protect the interest. However, as Part I has shown, a serious mismatch exists between the traditional rationale for granting property protection to an information resource and the rationale for granting individuals property rights in personal data.  n239 Also mismatched are traditional policies of property law favoring free alienability and information privacy policy preferences for restrictions on alienation.  n240 If the goals and mechanisms of property law are misaligned with information privacy policy objectives, protecting privacy as intellectual property simply may not work.
Even though a one-dimensional conception of a person's interest in her information makes crafting a legal regime easier, in truth, individuals may not have just one interest in personal information, but many interests. Sometimes a person's interest in personal data is a civil liberties interest (for example, not being forced to disclose whether I am a member of the NAACP),  n241 and sometimes it is not (for example, sending me an email to let me know that an author whose books I have bought before has just released a new novel). Sometimes it is a commodity interest (for example, I can get a discount if I disclose my zip code) and sometimes it is not (for example, I do not want software on my hard drive to scan what other software I have installed there and report on this to its home base). Sometimes it is a dignity interest (for example, whether I sweat profusely) and sometimes it is not (for example, whether my eyes are blue).
The task of devising a workable legal framework for regulating private sector uses of personal data is obviously more difficult if one takes a multi-dimensional perspective on the nature of a person's interest in personal data. Yet it is an advance to recognize that a person has more than one kind of interest  [*1172]  in personal information. It is also an advance to realize that the propriety of collecting or processing personal data depends in part on context.  n242 For my doctor to send information about my medical condition to an insurance company so that it will cover the costs of treatment is appropriate, but for the doctor to give the same information to a prospective employer is inappropriate. It further advances understanding to realize that a major factor in a contextual analysis about uses of personal information is whether the person whose data is being collected or processed knows or has reason to know that the data are being collected and what uses will be made of them.  n243 In addition, it may be important to realize that our concept of information privacy, and in particular, our understanding of what is appropriate and inappropriate to do with personal information, is evolving over time.  n244
One of the virtues of a contractual approach to protecting information privacy is that it can accommodate the multiple interests people have in personal information, the contextual nature of determinations about the appropriateness of collection or use of personal data, the significance of consent as a factor in determining appropriate uses, and the evolutionary nature of social understanding about information privacy. It is a flexible, adaptable, market-oriented way to allow individuals to control uses of personal data. Oddly enough, it may more easily be achieved in cyberspace than in the physical world because a Web site's privacy policy can become the basis of a contractual understanding between the user and the Web site.  n245 Although individuals and Web site owners may sometimes reach express agreement on all relevant issues pertaining to allowable uses of personal data, a set of default licensing rules adapted from trade secrecy law might "fill in the gaps" of such agreement (for example, restricting rights to sublicense the data to others if the privacy policy is silent on this issue). Despite obvious differences between trade secrecy and information privacy, there are some significant parallels in the objectives of trade secret law and the information privacy law envisioned in this article: protecting commodity and non-commodity interests of persons in restricting others' uses of certain information; protecting information disclosed in confidence; protecting information against the use of improper means to obtain it; facilitating commercial transactions allowing the holder of the interest to negotiate compensation for allowing uses of information; enforcing agreements about nondisclosure or  [*1173]  limited use; and establishing minimum standards of commercial morality that can evolve over time.
Americans may want information privacy, but they also want a strong information economy. They appear to be willing to balance their interests in keeping certain information about themselves private with their interests in getting access to customized information and services that disclosure of their personal data may enable firms to provide.  n246 If information privacy goals can be achieved without establishing a new government bureaucracy, as a modified licensing regime should allow, Americans objectives for an information society may more fully be realized. 

