Did Blockbuster, Facebook break video privacy law with Beacon?
A 1988 law restricts the sharing of someone's video choices
Computerworld - Did Facebook and Beacon partner Blockbuster violate a 1988 video privacy protection law when movie choices that Facebook members made on the latter's Web site were made available to other members of the social network?
According to a professor at the New York Law School, the answer is a definite "yes" -- at least for Blockbuster -- and "quite possibly so" for Facebook.
"The case against Blockbuster is quite straightforward," said James Grimmelmann, associate professor at the New York Law School. "I'm surprised that there haven't been lawsuits already in terms of Blockbuster. The one against Facebook requires a couple more steps. It's one of those interesting issues" that can be viewed in multiple ways legally.
The law in question is the Video Privacy Protection Act (VPPA) of 1988. It basically prohibits movie rental companies such as Blockbuster from disclosing personally identifiable rental records of the people who rent or buy movies from them to others -- unless the customer consents to the practice in writing.
The rarely invoked law was passed after Supreme Court nominee Robert Bork's video rental records were published in a newspaper. It "stands as one of the strongest protections of consumer privacy against a specific form of data collection," according to a description of the law on the Electronic Privacy Information Center (EPIC) Web site.
Civil remedies under the law include fines of at least $2,500 for each violation. In the few situations where the law has been invoked, the cases involved the disclosure of customer movie rental records to law enforcement authorities by rental companies. The law has never been tested in an online situation such as the one involving Blockbuster and Facebook, and could raise interesting issues, according to Grimmelmann.
Facebook's Beacon ad service was released in early November as a part of the Facebook Ads platform. It is ostensibly designed to track the activities of Facebook users on more than 44 participating Web sites and to report those activities to the users' Facebook friends, unless specifically told not to do so. The idea is to give participating online companies a way to monitor the activities of Facebook users on their Web sites and to use that information to then deliver targeted messages to Facebook friends.
The problem with that arrangement, at least for Blockbuster, is that such information sharing put it in violation of VPPA before Facebook changed its privacy policies following an outcry over Beacon, Grimmelmann said. The mere fact that Blockbuster passed on movie choice information to Facebook friends without user consent is a violation of VPPA, he said. That information exchange between Blockbuster and Facebook took place in the background without the Facebook user's knowledge, even though the user's consent might have been needed for it to have been shared with other Facebook members, he said.
It is less clear what, if any, culpability Facebook might have, he said. Under tort law, it could be argued that this was a joint enterprise and since Blockbuster is liable, Facebook is, too, Grimmelmann said. Even so, Facebook has a "much better argument" than Blockbuster, he said.
Blockbuster did not respond immediately to a request for comment on Grimmelmann's assertions. A spokesman for Facebook said the company "does not have a comment here."
Grimmelmann wrote about the issue in his blog earlier this week.
Read more about Privacy in Computerworld's Privacy Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Privacy White Papers
- A Road Map for Best Practice Social Media Acceptable Use Policy
- Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and... All Privacy Webcasts