Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • EU 5G Report Warns of Vendors From 'Hostile' Nations
    • FTC to Send More than $31M in Refund Checks in LifeLock Case
    • Implementing baseline best practices is key to improving cybersecurity, says PCAOB Member Hamm
    • Merits of Stand-Alone Privacy Watchdog Debated
    • Researchers Support Common Law Approach to Privacy
    • Vestager Pledges to Work on Digital Services Act
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Researchers Support Common Law Approach to Privacy, (Oct 9, 2019)

    Organizations Mentioned:Competitive Enterprise Institute

    By Brian Craig

    In lieu of comprehensive national legislation and a regulatory framework to address data breaches and privacy concerns, two researchers with the Competitive Enterprise Institute say a common law approach combined with the use of emerging technologies ...

    By Brian Craig

    In lieu of comprehensive national legislation and a regulatory framework to address data breaches and privacy concerns, two researchers with the Competitive Enterprise Institute say a common law approach combined with the use of emerging technologies, such as blockchain, offers a better solution.

    Co-authors Sinclair Davidson and Chris Berg argue that the European Union's General Data Protection Regulation (GDPR) helps demonstrate why top-down regulatory approaches toward property rights over data are unlikely to be effective. Instead, the co-authors contend that under a common law approach, privacy questions would be resolved case-by-case, drawing on and building up a stock of precedent that has more fidelity to real-world privacy issues than do planned regulatory frameworks.

    In a press release, Mr. Berg said, "The ideal public policy setting is one in which individuals have property rights over personal information and can control and monetize their own data."

    In the report, Mr. Davidson and Mr. Berg point to the promise of blockchain technology, which vests its users with cryptographically secure control over digital assets, such as cryptocurrency tokens. Blockchain also has the ability to respond faster to new technology than legislation, they said.

    "For our purposes, the key characteristic of blockchain is its provision of a shared infrastructure for the protection and exchange of owned data," they said.

    "Blockchains potentially allow a new mechanism not only for the sharing of data, but also for its ownership and exchange. The latter, in turn, allows for new transactions that were technically or economically unfeasible in environments of centralized data management," they added.

    "Humans have always sought to defend a zone of privacy around themselves in order to protect their personal information, their intimate actions and relationships, and their thoughts and ideas from outside scrutiny. However, thanks to the rapid advance of digital technology, we now have little expectation of privacy," Mr. Davidson said. "Policy-makers should rely on the common law to govern questions of data privacy because its case-by-case, evolutionary nature is more likely to provide a sustainable and adaptive framework to approach these difficult questions."

    Mr. Davidson and Mr. Berg argue in the report that the GDPR helps demonstrate why regulatory approaches toward property rights over data will likely be ineffective. Proposed in 2012 and finalized in 2016, the GDPR reflects the prevailing technologies and concerns of the time in which it was developed.

    Since the adoption of the GDPR, there have been dramatic changes in technology, data use, and the social and political consequences of information disclosure, according to the co-authors. Mr. Davidson and Mr. Berg write that "[t]he rigid regulatory frameworks risk either locking in anachronistic approaches to privacy protections or failing to tackle new and unanticipated problems. As technologies change, so do the norms and attitudes around those technologies. These changes are hard to predict in advance."

    The co-authors state that confusion over the definition and scope of privacy, combined with government hostility toward the notion of privacy in the economic and political spheres, results in poor policy outcomes. "Government intervention that impedes this process of trial and error among actors in the market is likely to undermine individuals' ability to either monetize their personal information or gain from trade in their personal information," they said.

    The co-authors argue that the GDPR has other shortcomings "On the face of it, the GDPR looks like a regulatory implementation of personal data ownership, but in fact the resemblance to property as understood in the classical liberal tradition is only superficial," they write.

    "The EU data protection approach features a cocktail of private rights—such as the right to information about how personal data is used and to object to some automated decision-making processes—and command-and-control mechanisms that are directly enforced by public agencies. Rather than establishing general principles or desired outcomes which are then enforced by regulators and the courts, the GDPR focuses on regulating the process by which data is acquired and managed," they said.

    The co-authors highlight a privacy dilemma: An enormous amount of economic value can be unlocked with the use and analysis of personal data, but the use of that data can expose information about individuals without their consent. Mr. Davidson and Mr. Berg argue that "[w]hile free individuals expose information about themselves in the course of social and economic activity, public policy should strive to ensure they do so only with their own implied or explicit consent."

    Another challenge, according to the co-authors, is defining what is meant by "privacy." It's difficult to devise policies to address concerns across all areas of privacy such as individual autonomy, self-definition, solitude and intimacy, confidentiality, anonymity, security, freedom from intrusion, freedom from annoyance, freedom from crime, freedom from embarrassing disclosure, freedom from discrimination, profit, and trust. Mr. Davidson and Mr. Berg argue that privacy rights have not evolved as economic rights, but rather have emerged as legal rights.

    According to Mr. Davidson and Mr. Berg, the subjectivity of the experience of privacy and its violation suggests that, rather than search for silver bullet solutions, policy-makers should seek to open a space in which the appropriate legal bounds of privacy protection are discovered through learning and experimentation.

    News: Privacy

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use