Every year on the first day of my course on information privacy law, I ask my students to define the concept of privacy. Usually, I get a few different answers, each of which is built around some singular and definitive conceptualization of privacy. Some notions include: Privacy is “control over personal information.” Privacy is “secrecy.” Privacy is the “right to be left alone.” And so on. Then I gently push back, asking my students about notions of privacy that fall outside their definition. Which definition should the law adopt? All of these definitions seem right, yet somehow not enough. I ask whether it is a good idea to define privacy so broadly that it is synonymous with all personal interference. My goal is for students to appreciate that there are many ways to conceptualize privacy, each of which is underinclusive or overinclusive. I point to the many ways that scholars have explored various components of the important but remarkably vague notion of privacy, happy to leave its definitive boundaries undefined. Scholars and lawmakers are not always so comfortable with such uncertainty; I have made my peace.

Throughout history, privacy has evaded a precise meaning. Initially, lawmakers had no compelling need to give the concept a singular legal definition. The earliest personal information and surveillance rules and frameworks for privacy leveraged specific concepts such as solitude, confidentiality, and substantive due process.1 But after Samuel Warren and future-Justice Louis Brandeis called for a “right to privacy” in 1890, the concept took on new life as a term of art in legal frameworks.2 Plaintiffs in tort cases were asked to articulate the private nature of facts and actions.3 Judges confronted with the argument that the state had violated a defendant’s Fourth Amendment rights were asked to determine whether the defendant had a “reasonable expectation of privacy” in the activity or space that the state had invaded.4 State and federal legislators created numerous statutes that sought to protect “private” information from exposure.5 In short, from the early 1900s to the present day, lawmakers and judges have regularly been compelled to give the term “privacy” a broad and consistent legal meaning. It hasn’t gone well.

Daniel Solove, the John Marshall Harlan Research Professor of Law at the George Washington University Law School and perhaps the most prominent and influential privacy scholar of our day, wrote at the turn of the millennium that privacy was “a concept in disarray.”6 In his foundational book Understanding Privacy, Solove noted that people have defined privacy in many different ways, including “freedom of thought, control over one’s body, solitude in one’s home, control over personal information, freedom from surveillance, protection of one’s reputation, and protection from searches and interrogations.”7 In the twentieth century, privacy theorists seemed intent on crafting a definitive, singular meaning for privacy. Alan Westin wrote that “[p]rivacy is the claim of individuals, groups, or institutions to determine for themselves when, how, and to what extent information about them is communicated to others.”8 Charles Fried similarly argued that “[p]rivacy . . . is the control we have over information about ourselves.”9 Ernest Van Den Haag wrote that “[p]rivacy is the exclusive access of a person (or other legal entity) to a realm of his own.”10 Some of these theories defined privacy in service of autonomy.11 Others characterized privacy through its service of intimacy or dignity.12

But it turns out that a broad and singular conceptualization of privacy is unhelpful for legal purposes. It guides lawmakers toward vague, overinclusive, and underinclusive rules.13 It allows industry to appear to serve a limited notion of privacy while leaving people vulnerable when companies and people threaten notions of privacy that fall outside the narrow definition.14 And it often causes people who discuss privacy in social and political settings to talk past each other because they don’t share the same notion of privacy.15

The chaos and futility of competing conceptualizations of privacy is why Daniel Solove’s research on privacy has been so important and influential for our modern privacy predicament. In an ongoing series of articles and books starting in 2001, Solove worked to reshape the entire narrative around privacy by suggesting that we stop obsessing over what privacy is and start asking what privacy is for.16 To Solove, there is no singular common denominator of privacy. Scholars seeking it are destined to spin their wheels for eternity. “Privacy is not one thing,” Solove wrote, “but a cluster of many distinct yet related things.”17 Taking inspiration from Ludwig Wittgenstein’s concept of family resemblances, Solove argued that privacy is best thought of as an umbrella term that brings together a group of concepts that “draw from a common pool of similar characteristics.”18

Solove’s work in privacy has been extraordinarily influential for scholars, policymakers, and practitioners.19 His works are regularly invoked to counter the argument that privacy is important only to people with “something to hide.”20 Solove’s response is that privacy isn’t just about hiding things.21 Solove keenly understands the central role that narratives and stories play in our understanding of privacy. He presciently argued that the modern privacy predicament involving industry’s large-scale data processing efforts is more akin to Josef K.’s byzantine bureaucratic nightmare described by Franz Kafka in The Trial than the dystopian universal surveillance described by George Orwell in Nineteen Eighty-Four.22 Solove argued that automated systems fueled by personal data don’t just power surveillance tools. These tools power systems that make decisions about people’s personal lives. They control and obscure, leaving people frustrated and vulnerable.23 Much of Solove’s work, such as my collaborations with him regarding the Federal Trade Commission’s regulation and enforcement of privacy, aims to make sense of tumultuous areas involving the law of personal information.24

Perhaps most importantly, Solove’s work provides a structure that frees scholars and lawmakers of the burden of finding one, singular notion of privacy to rule them all. He also helped shepherd in the algorithmic turn in privacy scholarship, which opened the door for discussions of how privacy issues impact marginalized and vulnerable populations.25 There are many virtues to understanding privacy as a pluralistic, fluid concept. Such an ideal furthers diverse values and is capable of having both intrinsic and utilitarian worth and coexisting with many different policy goals. Under this notion, people in politics, commerce, and society can work to solve complex information problems without constantly relitigating privacy’s meaning.

Instead of squabbling over the binary boundaries of privacy, people who understand privacy as more of a vague umbrella term can leave the line-drawing question for another day and get to work identifying problems created by specific conduct, articulating the values implicated by those problems, and crafting solutions to the problems that serve those values.26 Starting in the late 1990s, Solove,27 along with other pioneering scholars such as Anita Allen,28 Danielle Citron,29 Julie Cohen,30 Helen Nissenbaum,31 Neil Richards,32 Joel Reidenberg,33 Paul Schwartz,34 and others35 —responded to the late-century ossification of privacy law with new insights for a world gone digital. They arrived not a moment too soon.

The world has never seen anything like the power held and used by modern technology companies. It has never been easier to surveil people and collect, store, search, analyze, and share their personal information. The fair information practices (FIPs), a set of principles developed in response to the risks created by electronic databases, are not enough to meet the moment.36 Regulatory manifestations of the FIPs such as the European Union’s General Data Protection Regulation (GDPR),37 Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA),38 and California’s Consumer Privacy Act (CCPA)39 seek transparency and accountability from companies and control for people over their own data. They are the closest thing the world has to a “common language for privacy.”40

Most of our modern data privacy rules, however, are built to serve individualistic notions of privacy—that is, to respect a person’s autonomy and dignity. Few are aimed at disrupting power disparities between people and companies,41 protecting individuals from harassment42 and manipulation,43 or seeking a collective wellbeing for a diverse population in which many people, including women, people of color, members of the LGBTQ+ community, and others, are particularly vulnerable to information systems.44 If lawmakers were tied to the notion of privacy as control over personal information, they might struggle to diagnose the problem as anything beyond a lack of adherence to fair information practices. Regulators might just engage in extreme FIPs enforcement in the hope that the companies will eventually reach full transparency and that people will have full command over how their data is processed.45 Companies would go along because the FIPs do little to interfere with business models built around exploiting data.46

Transparency, consent, and control solutions won’t be enough to get us out of this mess. First, as Solove has noted, the “privacy self-management” approach embodied by notice and choice regimes puts the onus on individuals to protect themselves.47 But the massive scale and widespread adoption of digital technology have made meaningful informational self-determination impossible. People are simply overwhelmed by the choices presented to them. The result is a threadbare accountability framework that launders risk by foisting it on people who have no practical alternative to clicking the “I Agree” button. Second, consent and control are a poor fit for certain information problems, like manipulation and harassment, that have little to do with how information is processed and more to do with how mediated environments put people at risk.48 Finally, seeking to give people control over their personal information doesn’t account for collective, societal harms from personal information technologies. Privacy exists for groups and communities, too.49 Your data can put other people at risk in ways that are hard to predict.50 We’re going to need richer, more diverse notions of privacy to solve these problems.

Thankfully, people have been hard at work converting privacy from a blunt tool into a Swiss Army knife, with each prong in service of a different value or purpose. Scholars have proposed a remarkable array of ways to think and talk about different notions of privacy, including intellectual privacy,51 sexual privacy,52 quantitative privacy,53 and more. They have built out conceptualizations of privacy as obscurity,54 trust,55 power,56 privilege,57 security,58 safety,59 procedural due process,60 a civil or human right,61 and the contextual integrity of information flows.62 They have argued that privacy protects democracy,63 “the processes of play and experimentation,”64 identity,65 the incomputable self,66 and significantly more. When lawmakers and judges accept privacy as a concept that contains multitudes, each of these different notions can explicitly be brought to bear on the real needs of people, groups, and institutions rather than deploying an ill-fitting theory in diverse contexts.

Lawmakers have started to embrace privacy as a concept with multiple overlapping dimensions. Legislators and regulators have begun to target problems such as nonconsensual pornography,67 microtargeting,68 manipulative user interfaces,69 and automated decision-making70 with innovative rules leveraging secondary liability for dangerous and abusive design choices,71 substantive limits on data collection and use,72 relational duties of loyalty and care,73 equitable relief,74 and criminal penalties75 in addition to implementing outright bans on particular technologies.76

Judges are also evolving in their thinking about privacy. For years, courts have struggled mightily trying to figure out what it means to have a “reasonable expectation of privacy.”77 Too often, that translates to things not exposed to others. But that has changed a little recently, as in Carpenter v. United States,78 in which a majority of the U.S. Supreme Court conceived of privacy as dependent upon several different factors such as the scope of exposure and the nature of the information.79

By getting us past the threshold question of what privacy is, Solove’s work provides room for scholars and lawmakers to tackle bigger phenomena, such as how capitalistic incentives cause companies to leverage information in harmful ways,80 how the design of information technologies matters just as much as data practices,81 and how marginalized populations are affected first and hardest by privacy-invasive actors.82 Solove is a pragmatist, and, as such, his work consciously looks at the nature of privacy-related problems.83 This focus also helps elevate the importance of scholarship aimed at the last legal mile of privacy solutions: how privacy harms are mitigated through legislation, regulation, and litigation.84 Solove’s own work with Danielle Citron on privacy and data security harms provides a map for judges and lawmakers to better articulate what harms result from bad information practices and which remedies are best to address those harms.85

The year is 2021, and privacy is still a concept in disarray. But that’s okay. There is now too much data that is collected by too many different entities and used in too many different ways for any singular definition of privacy to be legally useful anyway. Daniel Solove’s work on understanding privacy has imposed order upon chaos, shifting our focus away from questions about what privacy is and toward the different problems we want our privacy-based rules to address and the specific values we want them to serve.

