<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Privacy Act and &#8220;actual damages&#8221;</title>
	<atom:link href="http://emergentchaos.com/archives/2008/04/privacy-act-and-actual-damages.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2008/04/privacy-act-and-actual-damages.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2008/04/privacy-act-and-actual-damages.html/comment-page-1#comment-4545</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Sat, 12 Apr 2008 23:59:45 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2718#comment-4545</guid>
		<description>I&#039;d like to remind commenters that not all privacy issues are those of impersonation fraud, and not all privacy damages result from impersonation.
</description>
		<content:encoded><![CDATA[<p>I&#8217;d like to remind commenters that not all privacy issues are those of impersonation fraud, and not all privacy damages result from impersonation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://emergentchaos.com/archives/2008/04/privacy-act-and-actual-damages.html/comment-page-1#comment-4544</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Sat, 12 Apr 2008 22:38:35 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2718#comment-4544</guid>
		<description>&quot;Gather and analyze such data&quot; is precisely it.
What matters is understanding (and that means quantifying) the  linkage (if it exists to a non-trivial degree) between exposed PII and fraud or attempted fraud.
I know there are some smart people trying to do this, and we&#039;ve written about it here on a few occasions.
</description>
		<content:encoded><![CDATA[<p>&#8220;Gather and analyze such data&#8221; is precisely it.<br />
What matters is understanding (and that means quantifying) the  linkage (if it exists to a non-trivial degree) between exposed PII and fraud or attempted fraud.<br />
I know there are some smart people trying to do this, and we&#8217;ve written about it here on a few occasions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nick</title>
		<link>http://emergentchaos.com/archives/2008/04/privacy-act-and-actual-damages.html/comment-page-1#comment-4543</link>
		<dc:creator>nick</dc:creator>
		<pubDate>Sat, 12 Apr 2008 17:02:40 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2718#comment-4543</guid>
		<description>It&#039;s good to go beyond actual past financial damages, but &quot;emotional distress&quot; is far too subjective a standard, inviting judges, juries, and expert witnesses to play favorites.  If your distress is not of the kind the judges, juries, or psychiatrists sympathize with, or if you can&#039;t act out your distress in the courtroom, you&#039;re out of luck.  And on such subjective issues the expert witnesses usually cancel each other out, leaving one at the mercies of the subjective beliefs of judge and jury.
In any case, this test is far to narrow:
&lt;i&gt;[T]he plaintiffs&#039; alleged injury is not speculative nor dependent on any future event, such as a third party&#039;s misuse of the data.&lt;/i&gt;
But &lt;i&gt;risk&lt;/i&gt; is not the same thing as speculation.  If data is lost in a way that creates quantifiable risk, for example based on past amounts of identification theft based on this kind of data, it is straightforward to price the risk and assess this price as damages.  Assessing the contributions of different bits of data out of the assemblages an identity thief needs, e.g. loss of social security number but not birthday, is a little more speculative, but I suspect in the future we will have enough data to quantify even these partial and conditional risks with reasonable confidence.
One should also be able to collect damages for costs incurred in signing up for preventative or insurance services such as the much hyped LifeLock: some fraction of these charges is a reasonable proxy measure for the enhanced risk of identity theft from the data loss.
I expect that as society (and especially insurance companies) gather and analyze more such data, we will switch to risk-based damages in this area, rather than mere past actual damages at the one extreme or emotional damages at the other.  But it may take some activism to move us towards this middle ground, as judges love the discretion tests like &quot;emotional distress&quot; give them.
</description>
		<content:encoded><![CDATA[<p>It&#8217;s good to go beyond actual past financial damages, but &#8220;emotional distress&#8221; is far too subjective a standard, inviting judges, juries, and expert witnesses to play favorites.  If your distress is not of the kind the judges, juries, or psychiatrists sympathize with, or if you can&#8217;t act out your distress in the courtroom, you&#8217;re out of luck.  And on such subjective issues the expert witnesses usually cancel each other out, leaving one at the mercies of the subjective beliefs of judge and jury.<br />
In any case, this test is far to narrow:<br />
<i>[T]he plaintiffs&#8217; alleged injury is not speculative nor dependent on any future event, such as a third party&#8217;s misuse of the data.</i><br />
But <i>risk</i> is not the same thing as speculation.  If data is lost in a way that creates quantifiable risk, for example based on past amounts of identification theft based on this kind of data, it is straightforward to price the risk and assess this price as damages.  Assessing the contributions of different bits of data out of the assemblages an identity thief needs, e.g. loss of social security number but not birthday, is a little more speculative, but I suspect in the future we will have enough data to quantify even these partial and conditional risks with reasonable confidence.<br />
One should also be able to collect damages for costs incurred in signing up for preventative or insurance services such as the much hyped LifeLock: some fraction of these charges is a reasonable proxy measure for the enhanced risk of identity theft from the data loss.<br />
I expect that as society (and especially insurance companies) gather and analyze more such data, we will switch to risk-based damages in this area, rather than mere past actual damages at the one extreme or emotional damages at the other.  But it may take some activism to move us towards this middle ground, as judges love the discretion tests like &#8220;emotional distress&#8221; give them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://emergentchaos.com/archives/2008/04/privacy-act-and-actual-damages.html/comment-page-1#comment-4542</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Sat, 12 Apr 2008 16:56:25 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2718#comment-4542</guid>
		<description>Interesting, indeed.  The TSA could still easily win the case, of course.  This was a (partial) denial of a motion to dismiss.
</description>
		<content:encoded><![CDATA[<p>Interesting, indeed.  The TSA could still easily win the case, of course.  This was a (partial) denial of a motion to dismiss.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

