Volume 28 - Symposium Issue

Corporate Law’s Duty of Data Loyalty

Authors: 
Andy Serwin, Neil Richards, Woodrow Hartzog and Ryan Durrie
Volume: 
Issue: 
Spring
Starting Page Number: 
499
Year: 
2026
Preview: 
Privacy law used to be a relatively tidy field, involving a few interesting but discrete topics like press disclosures of private facts, wiretapping, and the processing of personal data by internet companies. But as the digital revolution continues to disrupt area after area of human activity and software “is eating the world,” the core concerns of privacy law such as “when is it appropriate to process personal data?” have similarly entered field after field. Today, most fields of law, including discrimination law, antitrust, and international law, have found it necessary to reckon with the questions of informational harm and power with which privacy law has been concerned in recent decades. Although personal data and privacy law have become areas of core concern in these disparate areas of law, the United States has been slow to address these issues. The United States remains the only advanced economy without a comprehensive, national data protection law providing rights to its citizens regarding how their data is processed and placing general obligations on the private entities that process that data. There have been no shortage of proposals for a federal statute, and over a dozen states have passed their own “comprehensive” privacy laws. Yet as we have explored in prior work, the national debate has lacked both a consensus on what needs to be done and a set of proposals that meaningfully push the debate beyond the existing frameworks of notice (where that “notice” can be buried in a privacy policy no one reads) and choice (where the choice can be little more than the choice not to use the internet). Given the current push towards deregulation at the federal level, it appears unlikely that any national level regulation will move forward in the near term. Recent scholarship searching for frameworks superior to the failed notice and choice model has proposed a variety of approaches, including trust-building relational approaches centered around duties of data loyalty. A significant literature has developed by scholars including Balkin, Hartzog & Richards, I. Kerr, Nissenbaum, Scholz, and Waldman. Loyalty approaches have certainly had their critics, including Cohen, Grimmelman, and others, including critiques that relational models will not scale to the platform economy, that loyalty proposals are vague, and that they are contrary to existing principles of corporate law. This last critique by Khan & Pozen has been partly addressed on the merits by Andrew Tuch, but the relationships between privacy and corporate law necessary to fully examine loyalty proposals remain under-studied. Moreover, Tuch’s work presents yet another field that privacy has come to influence, namely substantive Delaware corporate law–a body of law that few privacy law scholars have expertise in, just as few corporate law scholars have expertise in privacy law. This is a shame, because there are important insights that privacy law and corporate law can learn from each other. In that spirit, this Essay offers an intervention to this literature at the borders of privacy and corporate law. It argues that whether or not a privacy-based duty of data loyalty along the lines proposed by Richards & Hartzog (and others) is a good idea, a corporate law-based duty of data loyalty already exists as part of the broader principles of Delaware fiduciary law. This corporate duty of data loyalty needs to be considered as part of the broader debate. Our argument is developed in three steps. First, we explain the ways in which companies are already doing business using human data at virtually every level of their operations, and that this trend is only going to become more pronounced as companies invest further in artificial intelligence technologies. While these business practices justifiably alarm most privacy scholars, from the perspective of businesses—as revealed in their corporate filings, and in germinal work by Cohen and Zuboff—the collection and exploitation of personal data have become indispensable to their operations as a factual matter. Second, looking to Delaware fiduciary law, we argue that there is already a more than colorable claim that existing law mandates a kind of data loyalty: If personal data has become indispensable to businesses, then the existing Delaware duties of care and loyalty imposed on directors and officers and the Caremark duty of oversight apply to the provenance, legality, and sustainability of the continued use of that data. Moreover, this duty requires more than the thin notions of compliance that companies have continued to assert. The critical point here is that legal compliance is one risk, but not the only risk, that the Delaware fiduciary duty requires companies to address. If one accepts the point (advocated by companies themselves) that the vast majority of business processes depend on the use of technology and data, then it becomes clear that the duties that the directors and officers owe (care and loyalty) would inherently cover a company’s use of data and digital technology. Because Delaware law requires companies to be both “compliant” and “resilient,” companies have a duty to make sure that their use of data is done in a manner that is doesn’t place the business at risk from foreseeable legal liability or even foreseeable changes in law. Third, we argue that recognizing this corporate duty of data loyalty has significant advantages for privacy protection. To be sure, this duty of data loyalty is distinct from the one proposed by Richards and Hartzog in that it runs from the directors and officers to the corporation, rather than to the data subjects themselves. But it has the advantage of being (1) an existing data loyalty duty that privacy advocates can point to as precedent; and (2) a constraint on the ability of companies to rewrite privacy in self-interested ways as documented in detail by Waldman. Moreover, for both corporations seeking to get ahead of resiliency risk and lawmakers seeking substantive data privacy rules, there are real advantages to recognizing this corporate duty of data loyalty right now. We conclude by arguing that a duty of data loyalty from privacy law may well be the ideal way to solve many of the problems of informational and platform capitalism. However, as we search for new solutions to these problems, it’s time for us to recognize that there is already an existing corporate duty of data loyalty that can be used to begin addressing these problems without needing to change the law. Additionally, with a lack of federal action and the recent pushback against agency regulatory extension and interpretation, state laws have become an increasingly important way of addressing privacy concerns.
Abstract: 

Privacy law used to be a relatively tidy field, involving a few interesting but discrete topics like press disclosures of private facts, wiretapping, and the processing of personal data by internet companies. But as the digital revolution continues to disrupt area after area of human activity and software “is eating the world,”  the core concerns of privacy law such as “when is it appropriate to process personal data?” have similarly entered field after field.

Anonymity, Consent, And Other Noble Lies: An Empirical Study of The Data Economy

Authors: 
Joel Reardon, Serge Egelman, Kenneth A. Bamberger & Laurel E. McGrane
Volume: 
Issue: 
Spring
Starting Page Number: 
432
Year: 
2026
Preview: 
While legal scholars have cited decades of computer science research that demonstrates why anonymity is hard (and that datasets should not be labelled as “anonymous” cavalierly), industry and legal practitioners have not heeded those warnings: many organizations trafficking in consumer data continue to assert to customers, courts, and regulators, that their data is anonymous or “deidentified.” We acquired datasets from multiple data brokers to demonstrate empirically why this is false. Using publicly available email addresses found in data breaches posted on the Internet, we trivially reidentified 88% of the hashed email addresses that we obtained; using modern password-cracking techniques, we were able to reidentify 97% of the 6 million email addresses that we collected. Reidentifying hashed email addresses need not rely on illicit data or specialized hardware: by constructing rainbow tables with synthetic data representative of typical email addresses, we reidentified most of the hashed email addresses. In all cases, the hashed email addresses were linked to other device-based identifiers (e.g., mobile device advertising IDs, IPs, etc.), demonstrating why device-based identifiers have long been considered personally identifiable information. Relatedly, organizations trafficking in this data make another assertion, that this data was collected from consumers with their consent. To evaluate this claim, we performed a survey (n=369), in which we emailed a subset of the reidentified individuals in our datasets to recruit them to participate. This survey asked participants about their recollections of having provided consent (99% had no recollection) and their feelings about the sale of their information (94% were opposed, while 77% said they planned to submit deletion requests). Overall, our study shows that hashed email addresses and device identifiers do not come close to meeting commonly understood definitions of “anonymous” or “deidentified” data, and that any notion of “consent” must also involve a similarly tortured definition. We argue that this industry and its defenders are not simply misinformed or indifferent to the veracity of their statements, but that this is an example of Plato’s “noble lie”: their entire social order relies on these demonstrably untrue statements being believed by courts, regulators, policymakers, and the public.
Abstract: 

While legal scholars have cited decades of computer science research that demonstrates why anonymity is hard (and that datasets should not be labelled as “anonymous” cavalierly), industry and legal practitioners have not heeded those warnings: many organizations trafficking in consumer data continue to assert to customers, courts, and regulators, that their data is anonymous or “deidentified.” We acquired datasets from multiple data brokers to demonstrate empirically why this is false.

The Hypocrisy of Data Governance

Authors: 
Zubair Shafiq, Olivia Figueira, Athina Markopoulou, Woodrow Hartzog & Michael Lavine
Volume: 
Issue: 
Spring
Starting Page Number: 
393
Year: 
2026
Preview: 
“Data governance” is an empty term, like a Rorschach inkblot just waiting to be filled with meaning. Tech companies take advantage of this ambiguity to craft narratives about their data-governance capabilities to fit their audience and purpose. On one hand, tech companies brag about their data-governance capabilities when it fits their business model (for example, to advertisers) and public image (for example, to their customers). On the other hand, tech companies claim that meaningful data governance is challenging or impossible when accountability is demanded. In this Article, we argue that tech companies systematically misrepresent or selectively ignore their data-governance capabilities. To demonstrate our point, we present two case studies showing how tech companies adopt inconsistent and self- serving positions when it comes to the treatment of consumers’ personal information. First, we show examples where tech companies actively identify children to deliver personalized advertising and content recommendations but disclaim the knowledge or ability to identify children when legal obligations attach. Second, we show how tech companies commonly claim they do not know whether the information collected by their tracking tools is protected health information (PHI) under HIPAA, even though standard techniques enable such classification. We conclude this article by arguing for a more sustained critique and skepticism of the concept and implementation of data governance. Lawmakers could better scrutinize what constitutes reasonable efforts under existing data protection rules, they could better tailor new rules to the data governance capabilities of tech companies, and finally, lawmakers could better scrutinize the use of the term “data governance” as an efficacy claim within the law of consumer protection.
Abstract: 

“Data governance” is an empty term, like a Rorschach inkblot just waiting to be filled with meaning. Tech companies take advantage of this ambiguity to craft narratives about their data-governance capabilities to fit their audience and purpose. On one hand, tech companies brag about their data-governance capabilities when it fits their business model (for example, to advertisers) and public image (for example, to their customers). On the other hand, tech companies claim that meaningful data governance is challenging or impossible when accountability is demanded.

Economic Rationales for Regulating Behavioral Ads

Authors: 
Pegah Moradi, Cristobal Cheyre, Alessandro Acquisti
Volume: 
Issue: 
Spring
Starting Page Number: 
336
Year: 
2026
Preview: 
Advocates for regulating behaviorally targeted advertisements tend to focus on ethical and legal justifications for regulation. Meanwhile, the advertising technology industry has staunchly opposed regulation by drawing on economic arguments, contending that such regulation would be harmful to advertisers, consumers, publishers, and data intermediaries alike—ultimately undermining innovation and accessibility of free products across the Internet. In this Article, we analyze the theoretical and empirical economic literature on the costs and benefits of privacy regulation in the context of behavioral advertising in order to evaluate the strength of economic arguments for and against regulation. Our analysis suggests that recent enforcement actions against ad-technology firms and movements across the world for online privacy regulations may be justifiable not merely on ethical or moral grounds, but on economic grounds. We show that current economic arguments used by the ad industry to oppose privacy regulation are poorly substantiated, and therefore, do not outweigh valid legal and ethical justifications for privacy regulation. Furthermore, there are valid theoretical and empirical economic justifications for regulating behavioral ads. Rather than resulting in a loss of welfare for consumers, regulation may produce a reduction of harms and a more balanced allocation of the costs and benefits of data accumulation. Still, future economic work must move from analyzing narrow micro-level effects to research designs that are both rigorous and encompassing, allowing for a fuller understanding of impacts across stakeholders to more effectively inform privacy regulation.
Abstract: 

Advocates for regulating behaviorally targeted advertisements tend to focus on ethical and legal justifications for regulation. Meanwhile, the advertising technology industry has staunchly opposed regulation by drawing on economic arguments, contending that such regulation would be harmful to advertisers, consumers, publishers, and data intermediaries alike—ultimately undermining innovation and accessibility of free products across the Internet.

Privacy Paradox in Digital Service Taxation

Authors: 
Zhaoyi Li
Volume: 
Issue: 
Spring
Starting Page Number: 
181
Year: 
2026
Preview: 
As the digital economy expands, tax jurisdictions face increasingly large challenges, as taxable activities like online shopping and advertising frequently extend beyond national borders. This shift has led to the emergence of the European Union’s Digital Services Tax (“DST”). While current discussions on this topic focus on the optimal methods and equitable distribution of taxing rights among countries, they overlook user privacy issues inherent in taxes like the DST. In light of the ongoing debate over whether the U.S. should tax digital transactions, this Article examines the legal framework of the DST and explores its implications from a data privacy perspective. By analyzing the implications of taxing the collection, use, and security of consumer data in the digital economy, this Article illustrates the broader effects of digital taxes on privacy rights and compliance. While the DST offers fiscal benefits, it simultaneously raises significant privacy concerns that must be addressed to safeguard consumer interests in an increasingly data-driven marketplace. To resolve this tension, this Article advances a privacy-centric model for the DST, integrating privacy protection measures directly into the DST’s structure and objectives. This comprehensive approach underscores the need for a harmonized framework that balances the economic goals of taxation with the protection of individual privacy, fostering a fairer and more equitable digital ecosystem for all stakeholders.
Abstract: 

As the digital economy expands, tax jurisdictions face increasingly large challenges, as taxable activities like online shopping and advertising frequently extend beyond national borders. This shift has led to the emergence of the European Union’s Digital Services Tax (“DST”). While current discussions on this topic focus on the optimal methods and equitable distribution of taxing rights among countries, they overlook user privacy issues inherent in taxes like the DST. In light of the ongoing debate over whether the U.S.

Disciplining Mechanisms: Governing Data Markets with Competition and Regulation

Authors: 
Peter Ormerod
Volume: 
Issue: 
Spring
Starting Page Number: 
308
Year: 
2026
Preview: 
The past decade has witnessed conceptual renewals in both competition law and information privacy law. These regulatory movements—Neo-Brandeis antitrust and structural data governance—share the objective of recalibrating the balance of power between individuals and the massive data-processing firms that now dominate modern life. Despite their common ends, policy interventions drawn from these schools of thought can work at cross purposes: competitive pressure can induce data exploitation, and privacy rules tend to benefit the largest firms. This Essay exposes the friction in their relationship and offers guidance on how to mediate their tension. Competition policy alone will prove ineffective at indirectly disciplining most data activities, so policymakers should largely favor the structural data-governance approach to address the information economy’s pathologies. But pro-competition policies will nevertheless be essential to reining in firms that are too big to meaningfully regulate and may also prove helpful in solving certain discrete data-processing problems. Policymakers today have two distinct mechanisms for disciplining firms’ data-driven activities. This Essay describes them, exposes their contours, and offers those policymakers guidance on how best to deploy them.
Abstract: 

The past decade has witnessed conceptual renewals in both competition law and information privacy law. These regulatory movements—Neo-Brandeis antitrust and structural data governance—share the objective of recalibrating the balance of power between individuals and the massive data-processing firms that now dominate modern life. Despite their common ends, policy interventions drawn from these schools of thought can work at cross purposes: competitive pressure can induce data exploitation, and privacy rules tend to benefit the largest firms.

Governing Toxic Data

Authors: 
Diane Lourdes Dick, Joseph W. Yockey
Volume: 
Issue: 
Spring
Starting Page Number: 
279
Year: 
2026
Preview: 
Companies increasingly boast to the public markets about their massive digital transformations and the value of their extraordinary customer insights. In this way, data is emerging as a crown jewel asset with unique corporate-governance implications under state and federal laws. For those firms touting data and other digital resources as among their most valuable assets, compliance with evolving cybersecurity and privacy laws, regulations, customer expectations, digital norms, and best practices will be the key to unlocking this value. By the same token, when compliance and policy gaps become pronounced, data and other digital assets can become toxic; not only will they fail to serve as drivers of corporate value, but they may generate significant liabilities. This category of “toxic” data can cause firms to incur massive litigation costs and regulatory fines and penalties, as well as major reputational damage that can destroy brand equity and erode market share. In light of recent signals by the U.S. Securities and Exchange Commission that it intends to focus on these risks, companies and their advisors must now anticipate that well-funded teams of regulators will aggressively monitor corporate disclosures and investigate compliance in an effort to carry out their mission to protect investors and maintain fair, orderly, and efficient markets. In response to this evolutionary enforcement moment, this Article provides the first comprehensive review of the corporate governance of data and other digital assets under state business-entities laws and the federal securities laws, paying special attention to evolving fiduciary responsibilities to monitor, oversee, and report on the risks associated with what we call toxic data.
Abstract: 

Companies increasingly boast to the public markets about their massive digital transformations and the value of their extraordinary customer insights. In this way, data is emerging as a crown jewel asset with unique corporate-governance implications under state and federal laws. For those firms touting data and other digital resources as among their most valuable assets, compliance with evolving cybersecurity and privacy laws, regulations, customer expectations, digital norms, and best practices will be the key to unlocking this value.

Information About Data

Authors: 
Mihailis E. Diamantis, Chen Sun, Rishab Nithyanand
Volume: 
Issue: 
Spring
Starting Page Number: 
238
Year: 
2026
Preview: 
Deterrence-based approaches to privacy enforcement rely on an overlooked and often false premise—that firms know what their own data practices are. There is good reason for skepticism because operational information tends to become siloed within firm subunits. Information about data management is no different. Firms may neglect to memorialize relevant information in reports for internal distribution. And even if such reports are generated, they may not be presented in a manner that is intelligible across firm constituencies. This paper looks outside of privacy law for a solution. Recent scholarship on securities disclosures has highlighted the variety of goals that disclosures serve. While the traditional purpose of financial disclosures is to inform outside investors, the process of preparing disclosures has beneficial internal effects too. It forces firms to study their own financial health and ensures that relevant corporate units are apprised of the results. Mandatory disclosures about corporate data practices could have similarly beneficial effects. While some states already require firms to publish generic information about data practices to consumers, these disclosures lack basic attributes that make financial disclosures effective—they lack detail, no human signs them, and they are not filed with any state authority. Securities- style disclosures hold more promise. By carefully tailoring the content, format, and required signatories of data practice disclosures, authorities could force firms to generate, translate, and internally propagate important information about data. Firms that actually know what they are doing with data are more susceptible to efforts aimed to deter data misuse.
Abstract: 

Deterrence-based approaches to privacy enforcement rely on an overlooked and often false premise—that firms know what their own data practices are. There is good reason for skepticism because operational information tends to become siloed within firm subunits. Information about data management is no different. Firms may neglect to memorialize relevant information in reports for internal distribution. And even if such reports are generated, they may not be presented in a manner that is intelligible across firm constituencies. This paper looks outside of privacy law for a solution.

The Physicist and The Sheep Farmer

Authors: 
Ari Ezra Waldman
Volume: 
Issue: 
Spring
Starting Page Number: 
213
Year: 
2026
Preview: 
This Essay explores two historical events—the exposure of the Daigo Fukuryū Maru (Lucky Dragon #5) to nuclear fallout from a U.S. thermonuclear bomb test in the Pacific Ocean and the contamination of the Cumbrian Fells in the United Kingdom as a result of the nuclear explosion at the Chernobyl disaster— to better understand what, if anything, can the history of technoscientific advising in policymaking contexts teach scholars about technical expertise in policymaking today? The Essay then teases out three lessons. First, expertise in political contexts is never unmediated, meaning that technical expertise should be understood as filtered through social, political economic, and other kinds of biases. Second, informational technologies are multifaceted sociotechnical systems such that giving one form of expertise a privilege over decision-making is a recipe for skewed policymaking. Third, sociotechnical systems operating in the physical world are subject to acute and irresolvable indeterminacies that make the kind of reduction to numbers preferred by technical expertise inappropriate. Sociolegal scholars working in law and technology should consider these lessons in context.
Abstract: 

This Essay explores two historical events—the exposure of the Daigo Fukuryū Maru (Lucky Dragon #5) to nuclear fallout from a U.S. thermonuclear bomb test in the Pacific Ocean and the contamination of the Cumbrian Fells in the United Kingdom as a result of the nuclear explosion at the Chernobyl disaster— to better understand what, if anything, can the history of technoscientific advising in policymaking contexts teach scholars about technical expertise in policymaking today? The Essay then teases out three lessons.

Public Utility for What? Governing AI Datastructures

Authors: 
Julie E. Cohen
Volume: 
Issue: 
Spring
Starting Page Number: 
135
Preview: 
Both in the U.S. and in Europe, initiatives for AI governance have focused principally on identifying and mitigating the risks created by AI models and their downstream uses rather than on those created by the datasets on which the models are trained. However, some of the most intractable dysfunctions of generative AI systems involve datasets. In particular, the very large datasets amassed by dominant providers of generative AI and related services are rapidly taking on infrastructural characteristics and importance. Effective AI governance therefore requires an infrastructural turn in thinking about data. First, the Article explains the significance of the infrastructure lens and sketches some of the distinctive implications of data infrastructures, in particular, for governance of networked digital processes and the social and economic activities that they facilitate. Next, it explores two interrelated problems manifesting within generative AI systems—simulation and sociopathy—that illustrate the extent to which the project of AI governance is, unavoidably, a data governance project. In brief, generative AI models trained on mass content from the open internet are also trained on data infrastructures that have been developed for behaviorist, extractive purposes and that encourage the production and spread of particular kinds of content and particular styles of communication. Last, the article considers whether the concept of public utility, now the subject of growing interest among legal scholars who study regulated industries, might supply a possible foundation for tackling the data governance problems associated with generative AI systems. The public utility model, however, addresses only some of the considerations that the infrastructure lens highlights. It is highly attuned to questions about access to infrastructures and their outputs but relatively insensitive to questions about infrastructure configuration and input sourcing. The problems of simulation and sociopathy belong in the latter category.
Abstract: 
Both in the U.S. and in Europe, initiatives for AI governance have focused principally on identifying and mitigating the risks created by AI models and their downstream uses rather than on those created by the datasets on which the models are trained. However, some of the most intractable dysfunctions of generative AI systems involve datasets. In particular, the very large datasets amassed by dominant providers of generative AI and related services are rapidly taking on infrastructural characteristics and importance.
Subscribe to RSS - Volume 28 - Symposium Issue