Module 01 / 14 · Phase 1 — Foundations
1. What privacy is, and why it's contested
This week in the arc
Coming from
Start of the course
Going to
Ethical frameworks as tools, not doctrines
Core
Privacy feels obvious. It is not. Ask ten people what it is and you’ll get answers that quietly contradict each other — a right to be left alone, control over your information, a kind of dignity, a private space no one may enter. This course begins by taking that easy sense of knowing and complicating it, because everything we do afterward depends on privacy being a live, contested question rather than a settled one.
Our subject is the human being — the person on the receiving end — not the compliance checkbox or the policy. Tonight we work with real, current cases and see how quickly ordinary intuitions about privacy come apart when pressed. Come ready to say what you actually think, and to have it tested.
Cases — tagged by category, name the kind before you react
23andMe and the data you can't take backit's not just yours
A genetic-testing company files for bankruptcy, and a court treats the DNA of ~15 million customers as an asset to be sold. Your genome is also your relatives’ — and your children’s.
Clearview AI and the face you made publicpublic for one purpose
A company scrapes billions of public photos into a facial-recognition tool sold to police. Every image was already public — you posted it. Is that a violation?
Reading
Recommended
Hill, “The Secretive Company That Might End Privacy as We Know It” The New York Times, 2020Read in full — the investigation that broke Clearview AI and anchors tonight's in-class Clearview case. Short and narrative, no theory; come with the facts.
Recommended
The Great Scrape: The Clash Between Scraping and Privacy 113 California Law Review 1521 (2025)Read closely: the Introduction and Part I.A (Clearview AI as the paradigm scrape), then Part II.B, “Scraping and Publicly Available Information” (B.1 why “public” is incoherent; B.2 practical obscurity, context, and aggregation) and Part II.C. This is the applied version of Nissenbaum's flow norms on Clearview — lean on her rather than re-deriving. For Part II.A's eight privacy principles, 2–3 exemplars (consent, secondary use, individual control) are enough. Optional depth: Part I.B–D (the CFAA/trespass and regulatory survey) and Part III (remedies). Section labels are exact; page numbers weren't available — go by section.
Recommended
The Right to Privacy 4 Harvard Law Review 193 (1890)Read closely: the opening framing (why a new right is needed as new technology and new business models expose the person — the 1890 analogue to Clearview and 23andMe), the “inviolate personality / right to be let alone” passages, and the six limitations on the right (where privacy becomes contested — the “already public” and consent carve-outs). Optional depth: the long common-law case survey proving privacy is not property or contract, and the remedies section. (Short public-domain essay; page refs approximate.)
Recommended
Privacy as Contextual Integrity 79 Washington Law Review 119 (2004)Read closely: the Introduction (pp. 119–125, the public-surveillance cases) and Part III.A–B (pp. 136–143), which define contextual integrity and its two norms — appropriateness and flow/distribution. Part III.D (pp. 151–155) applies the framework and is recommended. Optional depth: Part II's critique of prior theories (pp. 125–136) and Part III.C's justice grounding (pp. 143–151). This is the theory behind “public, but not for this use.”
Recommended
What Privacy Is For 126 Harvard Law Review (2013)Read closely: Parts I–III (pp. 1904–1918) — why privacy keeps “losing” the balancing frame, privacy reconceived as breathing room for self-development and critical subjectivity, and the “modulation” of the citizen-consumer — plus Part IV's opening (pp. 1918–1920), the privacy-vs-innovation critique. Optional depth: the Big Data analysis (rest of IV), the regulatory Part V, and the conclusion. pp. 1906–1908 (privacy has no single definition) echoes Solove — read lightly if you read Solove first.
Recommended
A Taxonomy of Privacy 154 University of Pennsylvania Law Review 477 (2006)Read closely: the Introduction (why privacy resists a single definition, and the move to a taxonomy of harms centered on the person) and the opening framing of each of the four groups — Collection, Processing, Dissemination, Invasion — plus one subtype per group as an exemplar (e.g. Surveillance, Aggregation, Disclosure, Decisional Interference). Treat the remaining subtypes as a reference catalog to map onto the 23andMe and Clearview cases. These four groups are the data lifecycle you'll use in Module 2. (Section labels exact; page numbers approximate.)
Recommended
Distinguishing Privacy Law: A Critique of Privacy as Social Taxonomy 124 Columbia Law Review 507 (2024)The critique of Solove's taxonomy — read it right after Solove. Read closely: the Introduction (pp. 508–513), Part I.B on Solove's family-resemblance / social-recognition method (pp. 519–522), the two-pronged critique in Part II — social recognition cannot set privacy's boundaries (II.A, pp. 530–541) and the unresolvable privacy-vs-privacy tradeoffs it creates (II.B, pp. 541–552) — and the post-taxonomy alternative in Part III (pp. 552–561). Optional depth: Part I.A's pre-Solove definitional history, I.C's field-expansion survey, and the case-study illustrations within Part II (read the section frames, sample the examples).
Recommended
Trump Taps Palantir to Compile Data on Americans New York Times, May 30, 2025Recommended cluster (this and the four Palantir items below): current, national-scale surveillance infrastructure. Optional for tonight — we return to it in Phase 3 (Surveillance, power, and asymmetry).
Recommended
Privacy Stanford Encyclopedia of PhilosophyReference, not a read-through — use it to place the theories against each other and to look up any account you want more on (the conceptual-accounts sections). Don't try to read it cover to cover.
Discussion
- What's something you'd never share online — and something you hand over without a second thought? What makes the difference?
- When something goes wrong with your data, whose fault is it: yours, the company's, or the government's?
- What would you trade your privacy for — convenience, safety, money, connection, nothing?
- 23andMe went bankrupt with roughly 15 million people’s DNA on its books. From your own digging: can you actually get your genetic data back — and who owns it now? Whose consent ever covered your relatives? Should bankruptcy law be the thing that decides the fate of intimate data?