Corporate Law’s Duty of Data Loyalty

Andy Serwin, Neil Richards, Woodrow Hartzog and Ryan Durrie
28 Yale J.L. & Tech. 499

Privacy law used to be a relatively tidy field, involving a few interesting but discrete topics like press disclosures of private facts, wiretapping, and the processing of personal data by internet companies. But as the digital revolution continues to disrupt area after area of human activity and software “is eating the world,”  the core concerns of privacy law such as “when is it appropriate to process personal data?” have similarly entered field after field. Today, most fields of law, including discrimination law, antitrust, and international law, have found it necessary to reckon with the questions of informational harm and power with which privacy law has been concerned in recent decades. Although personal data and privacy law have become areas of core concern in these disparate areas of law, the United States has been slow to address these issues. The United States remains the only advanced economy without a comprehensive, national data protection law providing rights to its citizens regarding how their data is processed and placing general obligations on the private entities that process that data. There have been no shortage of proposals for a federal statute, and over a dozen states have passed their own “comprehensive” privacy laws.  Yet as we have explored in prior work, the national debate has lacked both a consensus on what needs to be done and a set of proposals that meaningfully push the debate beyond the existing frameworks of notice (where that “notice” can be buried in a privacy policy no one reads) and choice (where the choice can be little more than the choice not to use the internet).  Given the current push towards deregulation at the federal level, it appears unlikely that any national level regulation will move forward in the near term. Recent scholarship searching for frameworks superior to the failed notice and choice model has proposed a variety of approaches, including trust-building relational approaches centered around duties of data loyalty. A significant literature has developed by scholars including Balkin, Hartzog & Richards, I. Kerr, Nissenbaum, Scholz, and Waldman.  Loyalty approaches have certainly had their critics, including Cohen, Grimmelman, and others, including critiques that relational models will not scale to the platform economy, that loyalty proposals are vague, and that they are contrary to existing principles of corporate law.  This last critique by Khan & Pozen has been partly addressed on the merits by Andrew Tuch, but the relationships between privacy and corporate law necessary to fully examine loyalty proposals remain under-studied.  Moreover, Tuch’s work presents yet another field that privacy has come to influence, namely substantive Delaware corporate law–a body of law that few privacy law scholars have expertise in, just as few corporate law scholars have expertise in privacy law. This is a shame, because there are important insights that privacy law and corporate law can learn from each other. In that spirit, this Essay offers an intervention to this literature at the borders of privacy and corporate law.   It argues that whether or not a privacy-based duty of data loyalty along the lines proposed by Richards & Hartzog (and others) is a good idea, a corporate law-based duty of data loyalty already exists as part of the broader principles of Delaware fiduciary law. This corporate duty of data loyalty needs to be considered as part of the broader debate. Our argument is developed in three steps. First, we explain the ways in which companies are already doing business using human data at virtually every level of their operations, and that this trend is only going to become more pronounced as companies invest further in artificial intelligence technologies. While these business practices justifiably alarm most privacy scholars, from the perspective of businesses—as revealed in their corporate filings, and in germinal work by Cohen and Zuboff—the collection and exploitation of personal data have become indispensable to their operations as a factual matter. Second, looking to Delaware fiduciary law, we argue that there is already a more than colorable claim that existing law mandates a kind of data loyalty: If personal data has become indispensable to businesses, then the existing Delaware duties of care and loyalty imposed on directors and officers and the Caremark duty of oversight apply to the provenance, legality, and sustainability of the continued use of that data. Moreover, this duty requires more than the thin notions of compliance that companies have continued to assert. The critical point here is that legal compliance is one risk, but not the only risk, that the Delaware fiduciary duty requires companies to address. If one accepts the point (advocated by companies themselves) that the vast majority of business processes depend on the use of technology and data, then it becomes clear that the duties that the directors and officers owe (care and loyalty) would inherently cover a company’s use of data and digital technology. Because Delaware law requires companies to be both “compliant” and “resilient,” companies have a duty to make sure that their use of data is done in a manner that is doesn’t place the business at risk from foreseeable legal liability or even foreseeable changes in law. Third, we argue that recognizing this corporate duty of data loyalty has significant advantages for privacy protection. To be sure, this duty of data loyalty is distinct from the one proposed by Richards and Hartzog in that it runs from the directors and officers to the corporation, rather than to the data subjects themselves. But it has the advantage of being (1) an existing data loyalty duty that privacy advocates can point to as precedent; and (2) a constraint on the ability of companies to rewrite privacy in self-interested ways as documented in detail by Waldman.  Moreover, for both corporations seeking to get ahead of resiliency risk and lawmakers seeking substantive data privacy rules, there are real advantages to recognizing this corporate duty of data loyalty right now. We conclude by arguing that a duty of data loyalty from privacy law may well be the ideal way to solve many of the problems of informational and platform capitalism. However, as we search for new solutions to these problems, it’s time for us to recognize that there is already an existing corporate duty of data loyalty that can be used to begin addressing these problems without needing to change the law. Additionally, with a lack of federal action and the recent pushback against agency regulatory extension and interpretation,  state laws have become an increasingly important way of addressing privacy concerns.