Aug 27, 2026
On August 27, Ben Neumeyer, Counsel at Enlightened Privacy, PC, and a former correspondent at The Capitol Forum, joined us for a discussion on his paper, “When The Call Is Coming from Inside the House,” published in the Quinnipiac Law Review, Vol. 44. The full transcript, which has been modified slightly for accuracy, can be found below.
TEDDY DOWNEY: Hello, everyone, and welcome. I’m Teddy Downey, Executive Editor here at The Capitol Forum. Today, I am so, so, so pleased to be joined by Ben Neumeyer, Counsel at Enlightened Privacy PC, and a former colleague here at The Capitol Forum.
He also was previously Privacy and Data Policy Manager at Meta. We’ll be talking about his paper, “When the Call is Coming from Inside the House,” published in the Quinnipiac Law Review, Volume 44, which examines the privacy and legal risks created when data shared by tech platforms can be combined with increasingly centralized government data sets. Ben, thanks so much for doing this today.
BEN NEUMEYER: Of course, my pleasure, Teddy. And one of the things I enjoyed the most as a correspondent at The Capitol Forum was doing my interviews and conference calls with experts. So, it’s exciting to be on the other side of the microphone.
TEDDY DOWNEY: This is just pure joy for me. I’m so excited to do this. I was loving reading the paper. There’s so much good insight in there, so many good ideas.
So, let’s get started with that. What caused you to write this paper? I know it’s really kind of in the time around the creation of Doge, but it’s still so relevant. It doesn’t really matter that that’s when it was primarily researched and written. But what was going on at the time that caused you to take a look at this?
BEN NEUMEYER: Well, to give you some background there, I actually want to go back to the sort of broader scope of the time that I worked in tech. And this is actually a good time to give the disclaimer that I worked at Facebook, later rebranded to Meta, for five years. And while a lot of the learnings from working in that space are reflected in this paper, any specifics that I discuss in the paper or that I’m discussing with you on the call today are all traced back to something that’s on the public record. Like either company publications or releases or things that have been recorded in the press.
So, with that said, during my work, I learned a lot about these tech platform data sharing programs and how the platforms perceive their value. And this came both through my own work and with my conversation with practitioners at other companies. I also got a closer view of how companies make decisions about this data, how they balance the risks and benefits and what data they share, and how they think about the privacy risks and protections.
So, in this article, I provided an overview of these data sharing programs briefly and looked at their values as business and policy tools, like the motivations for sharing them, before I looked at the risks. So, in short, these data sets are privacy protected through various techniques to make them safer for external sharing. This is very important.
However, these sharing programs also have a long history—as long as the history of these programs themselves—of privacy scandals and breaches, such as when supposedly anonymized data was reidentified, or when the data was exploited in a way that the companies didn’t expect. And I go into a few of these in the article. These have been very well documented in privacy scholarship.
This history of privacy incidents really illustrates something important, which is that the bar for what constitutes effective privacy protections that makes data sets like this safe to share outside of the platforms that collected the data, the bar is continuously moving. And one of the biggest factors in whether data is actually privacy protected—like whether everyone in it is actually anonymous, whether it can actually be reidentified or exploited—is the capability of the threat actors who might try to exploit that data and how much additional data they have available. I use this as a backdrop to argue a few key points in this article.
First, the surveillance state being created by the current Trump administration represents a powerful threat actor, both in its conduct, the disfavored groups that it targets, and its just general disregard for the law.
Second, the pooling of sensitive government data, enabled by Doge over the last year and a half, represents a transformative leap in the capabilities of that threat actor. I think that this set of facts significantly increases the risk profile of data sharing by tech platforms. And they need to reevaluate these programs in light of these heightened risks.
I also use this paper to posit a few ways these risks affect people and communities, and they create business and legal and policy risks for the platforms themselves. I propose a playbook for how those platforms should respond to navigate those risks.
TEDDY DOWNEY: I want to get to your solutions in a little bit. But first, one thing that strikes me as really interesting is you actually catalog what looks like illegal conduct by the government. And so, I think this just creates this tension throughout the paper where these are all laws put in place with the assumption that the government is a good faith actor. And they’re becoming criminals, basically. I don’t use that term lightly. That’s what you document. Just the things that they’re doing, downloading sensitive data onto a private Google Drive or whatever, that seems like criminal. I don’t know how to otherwise, interpret that. It’s appalling for someone who cares about their privacy. Obviously, there’s people out there who don’t.
How do you think about that tension in the paper? Because some of it feels like you’re looking at these laws, and these are kind of good faith laws, with the assumption that the government is good faith actor. Then they’re violating other laws as well. They’re violating privacy laws, but they’ve got to be violating other laws as well.
And I was wondering if you could first talk about what do you think is the illegal—or at a minimum improper—conduct that the government has done during the Trump administration regarding surveillance privacy data? You mentioned that they’re getting away with it because there’s no government oversight. But we’re a few months away where they possibly might have government oversight.
So, I think it’s just interesting to take a quick look at what are some of the things that they did in 2025 and since that are improper that require some investigation? And then maybe take a step back after that and start looking at other solutions. I think it’s kind of important to start there.
BEN NEUMEYER: Sure. I think this could be a multi-hour conversation in itself. But just to give you the legal backdrop, government collection and storage and sharing of data is, broadly speaking, governed by the Privacy Act of 1974 and its later amendments.
I think that actually going back to this in the record is very interesting because this piece of legislation, and the work in the Senate that enabled it, really set some of the foundational norms of privacy to begin with. This was a time when the computing power was exploding. This is relative. I’m sure a powerful computer then would look like a mainframe that fills an entire room, nothing compared to what we have now. This was a time when there was a lot of concern over the amounts of data held both by the government and private corporations and how it could be stored and pooled together and used to surveil people.
The concerns that underlay the Privacy Act of 1974 include things like a loss of autonomy and a sense of silent control from large powerful actors who have control over so much information and the ability to make decisions that are adverse to citizens based on it.
With that little history lesson out of the way, I think that there’s a few critiques of the Privacy Act and shortcomings that have been highlighted by what we’ve seen in the last 18 months.
First off, the Privacy Act is, I think, too limited in scope and it lacks enforcement teeth. So, when I say limited in scope, first, it only really deals with transfers of collection of data and transfers of data within the federal government itself. It doesn’t include sort of ingestion of external data, which really goes to some of the surveillance activities we’re going to touch on later. So, that scope limitation really doesn’t address sort of the current picture.
Second, the remedies are fairly narrow and the bar is high to actually exercising them. I think, kind of like you said, this piece of legislation assumes good faith conduct by the government and it sort of sets a set of norms that have limited teeth that the government is just sort of expected to follow.
So, when you have a government who does not do that, it’s shown that one of the shortcomings is the actual remedies that are available are pretty limited. There’s a very limited ability for private suits for people who have been impacted by some kind of transfer or processing of data by the federal government. And the actual sort of burden of proof on them is very high. And there isn’t so much of a proactive remedy.
While government agencies that want to start collecting data or processing it in new ways have to put up these sort of transparency documents called systems of record notices that give some transparency and opportunity for challenge, it’s just this sort of like transparency-based regime hasn’t been really adequate to deal with an actor that doesn’t really want to follow the rules in the first place. And I think that when you combine that with the fact that the administration has been able to sort of strip inspectors general offices through its removal power and get rid of other sort of internal checks and balances, there isn’t really enough room for private enforcement to make this happen.
So, if I could sort of get to really what the heart is of what you’re asking about, I think that one of the top reforms that we would need, as a result of the privacy violations we’ve seen, is a reform of the Privacy Act should be increased in scope. And there should probably be more proactive measures that actually give it teeth rather than just reactive ones where people can sue in the court once they sort of catch up to what’s going on.
TEDDY DOWNEY: You mentioned the Privacy Act, but there’s got to be other laws that govern use of confidential information. You list a lot of bad conduct, right? I mentioned the downloading to a private server of sensitive government data. There’s got to be some security laws or national security laws or whatever, something that overlaps here, where there are teeth. Or is there really just no accountability here? And so, you need an entirely new law.
I’m just curious. Because, again, in a world in which you’re getting—but even if there’s not, even if it’s not, even if I’m wrong and this is not like illegal in some shape or form, what do you think is the most untoward stuff that went on that a government investigator should take a closer look at. So, that we have not just the public reporting about what went wrong, but like a really in-depth probe that, hey, we need to know really what happened related to this conduct from Doge until now. So that we can assess where we are as a government and what reforms are needed. Who needs to be held accountable? And if they can’t be, what new laws do we need to prevent this going forward? Like where should the investigators focus to make sure that we get all that right?
BEN NEUMEYER: Sure. So, to provide a little bit of backdrop for your question, I think this sort of highlights the inadequacies of the American privacy regime, big picture. Because we don’t have a comprehensive privacy law. We see occasional moves towards one in Congress, but they never really sort of come to consensus.
We just have a limited sectoral system where certain types of data are treated as sensitive and highly regulated and others are sort of just subject to a much more flexible regime of just don’t do anything unfair or deceptive, with the Federal Trade Commission as a privacy regulator.
So, I think that if you could sort of create a dream system that would make this all work better, it would probably look a little bit more like Europe and the GDPR, where you have a comprehensive privacy law that deals with all personal data processing and applies to governments as well.
When it comes to actual conduct by investigators, oh boy, there’s a lot of things. I think that one of the biggest issues has been accountability. I think that when you have the way that Doge has sort of operated as this sort of office that employs people who are sort of quasi-private actors and doesn’t really rein them in or give them accountability, that’s where you see major breaches that can’t really be addressed. Like the downloading data to a personal drive and who knows what happened to it after that. I think that there probably needs to be more of a focus on that and sort of an overall understanding by investigators that if people deal with sensitive government data, they need to be accountable to the government.
When it comes to other activities, I mean, I don’t even know where to begin with some of the surveillance activities I’ve seen recently. I think that one of the major issues—that I’ll jump into later with ICE—has been that they have really been scouring and weaponizing posts on social media and assembling these dossiers with socalled anticipatory threat intelligence of statements on social media about ICE that are coarse, but they’re just criticism of the agency that is protected by the First Amendment.
So, I think that having some kind of rules of operation that actually govern where the agency can deal with real threats as opposed to people criticizing it seems especially important as well. I could probably go on, but those are things that came to mind.
TEDDY DOWNEY: Let’s stay on that. Because I think one thing, you sort of paint the impropriety of the use of this data to punish Trump’s enemies ostensibly or whoever is operating on his behalf to guess who his enemies are or at the direction of who he and Stephen Miller are saying their enemies are or what have you.
BEN NEUMEYER: Yeah.
TEDDY DOWNEY: Which is, obviously, the concern about an authoritarian government is you don’t have rule of law. You have the law to punish the king’s enemies and reward his friends.
Tell us a little bit about how ICE—and I don’t know if there are other companies that work for ICE or that enable ICE, like Palantir or what have you. You mentioned a public-private kind of mixing of Doge. There’s a lot of Thielaligned companies in that orbit.
I would be interested to just get how has this happened? What has gone on here for the sort of data that’s been combined into one place and then weaponized? Who’s involved in that? Who needs scrutiny of that? What would you like to see there?
BEN NEUMEYER: Who has been involved really extends from everyone like the names you see in the headlines, like Palantir, who builds the tools that Doge and ICE have used, to major consulting firms that do a lot of government work. We’ve actually seen Deloitte, and other larger names you’ve likely heard of, building some of these systems as well. This is just something that is kind of generally accepted as part of the political economy of D.C., where so much sensitive work is just outsourced to the private sector, from law enforcement to intelligence.
I think you also have to watch for some of the smaller contractors that are doing these more bespoke surveillance services. The ICE social media surveillance that I mentioned—this is all written up in a really terrific series of investigations by The Wall Street Journal, by the way. I would highly recommend that your readership check them out if they haven’t seen them already. These anticipatory threat intelligence reports that are really just sort of like dossiers of mean things that people have said about ICE are put together by smaller contractors like Guidehouse, Amivero, Babel Street. The risk profile for those may be a little bit different. So, they might need to be taken up differently.
TEDDY DOWNEY: You mentioned this is just the political economy of D.C. It strikes me as deeply wrong, right? Not only that the government is doing this misuse of the data, they’re contracting with companies to enable them to do this improper use of the data. Is that the right way to think about this? Does this all need to be essentially reassessed on what is allowed here?
I want to get into some of your specific recommendations. I’m jumping the gun here. You have very specific things. And I’m just like how can we possibly fix this? Do we need to look at all elements here and just have a holistic reassessment of not just what the government’s doing, but this entire ecosystem?
Also, when I think about that, I’m listening to you tell this story. It’s all the laws that enable surveillance, right? It’s not just privacy laws. All those special government laws that the government says, oh, well, I’m allowed to surveil. FISA comes up, and there’s just so many laws that I can’t keep track of or I’m not an expert in. You’re the expert here. Is it procurement? Is it national security? Is it administrative? Do all these laws need to be reassessed in terms of how to actually solve this problem? Or can you really do it just through privacy?
BEN NEUMEYER: That’s a great question. I think that the high-level issue that we’re really getting at here is just accountability. This seems normal as part of D.C. political economy. But I think that Congress and the public have allowed that to happen in bits and pieces as contractors take on more and more sensitive and important duties that really federal agencies and departments should be accountable for.
So, I think if the new Congress were to sort of reimagine what some of the contracting could look like, there would need to be more of a conversation about what is some of the most sensitive work that deals with the most sensitive data about Americans and people living here? And how does that accountability actually run upward to the federal government rather than these private actors who are more of at a remove?
TEDDY DOWNEY: I want to push back a little bit. Again, you sort of have a little bit of a vision of the government going back to eventually being a good faith actor, which is admirable of you. I applaud your optimism here.
However, is it the lesson that the government really can’t be trusted with this data ever? Because at some point, you’ll get another Trump, and they’ll do the same thing. Shouldn’t the laws be, the government can’t be trusted with this data, period. And they need to delete it all. And you can’t have it internally. Certainly, outside of any very small national security area, maybe you have an exception, a very small exception, for certain national security things, and they can access the data. And it has to be very specific. And it has to be approved by Congress, and reviewed by Congress, exactly what kind of data they’re allowed to have. It literally can’t be in the hands of anyone else.
And then when you’re talking about the companies with access to data, it’s like, shouldn’t we have a set of rules that prevents them from having any similarly problematic data? The government can’t be trusted. And if we can’t trust the government with that data, I don’t understand why we should trust any company with that data.
If you’re saying, well, they’re a threat actor, how could you possibly think of a non-democratically accountable institution as a proper steward of this data? I know this is a little philosophical, but I’m just trying to walk through the steps here of how you could possibly ever get comfortable having the government have access to big data again. That’s what’s tripping me up here.
BEN NEUMEYER: Sure. I think looking over what we’ve discussed so far, there are all areas where I think you could have mitigating factors that enable accountability and checks and balances—even assuming that the government is going to keep collecting data—but they all have flaws. Like I said, a more ex-ante rather than an ex-post system of giving permission to the government to collect data and process it and assemble it in new ways would be really helpful, but it still needs to have teeth.
However, if you look at the way that the balance of powers has been going in the Roberts’ court, they’ve really enabled an actor like Trump to strip out the internal checks and safeguards at agencies by just firing inspectors general and leaving those offices empty. That leaves a hole there. That’s what I’d really like to say—in my perfect world assumption—that will return to a good faith actor.
I think the broader fix would probably just be more legislative oversight and closer alignment with Congress on what agencies can actually do in terms of the data and how they process it, less deference. We’ve seen the Supreme Court hack away at deference to agency interpretations with respect to regulating industry. They should apply the same level of scrutiny to how much agencies can do with respect to collection of data and surveillance and send it back to Congress.
TEDDY DOWNEY: It makes the whole checks and balances really hard when the executive branch is a bad faith actor. Because the whole system is, well, we’re going to let you implement the laws. We’re going to let you implement and the courts shape the rules around the laws that we make. But in this other world where the executive branch is a bad faith actor, the Supreme Court is enabling the bad faith actor to have greater and greater power. The Congress ultimately ends up becoming a mechanism to take back that power, to rescind all that authority.
So, I think that’s probably the most interesting thing that will be happening when it comes to privacy, when it comes to corporate oversight of all these companies that you’re mentioning. You’re going to get Congress saying, we just can’t have you having this power. The Supreme Court’s power needs to be curbed, what their scope of review is needs to be curbed.
This whole system that we have right now is going to be Congress has deferred a tremendous amount of power to you and look at what has happened here. You talk about this in this threat actor language and all the different ways that they’re pooling information and surveilling. Then you also mentioned how that is sort of symbiotic with specific companies. That whole ecosystem just needs to be checked and reevaluated by Congress. I’m interested to see how that goes.
Let’s talk about how Meta, Google, data brokers, how some of these big companies use their own data, how they protect their own data, and how they could potentially get in trouble for the way in which they share with the government now that the government is a bad actor.
BEN NEUMEYER: Sure. I’m happy to discuss that a bit more. I think that to give you more of a backdrop, I’ll walk through a little bit more of the focus of my article, and then we can talk about how that relates to the risks to the platforms themselves.
Just a couple of definitional scoping issues of what I looked at in the article. I looked at what tech platforms share and why and how they protect it. Key scoping questions.
First, when I say tech platforms, I use the framing that the FTC has used. That is firms that provide services, enabling the exchange or sharing of information, goods or services, and collect a lot of data about that exchange. I’m primarily here talking about providing data voluntarily. That is not because of a compulsory order, like a judicial warrant or a national security order. That does leave aside one of the biggest concerns you flagged, but that is a whole other ball of wax.
So, platforms have various reasons for sharing this data. I would say that they have a mix of altruistic, business, and policy motivations.
First, sharing datasets publicly has business values, such as for recruiting or sharing their products that are on the cutting edge.
Importantly, it also has value as a policy tool to help build goodwill with key stakeholders who are going to be influential on the government or civil society organizations.
Finally, some are voluntold. Sometimes, platforms share data because of a crisis, like the datasets that were shared during the first year of COVID-19, or because of licensing requirements or regulatory requirements. Here, I’m thinking like mobility data from sharing economy companies. Or looking a little further out, something like the transparency requirements of the DSA. Although, that’s a bit outside the scope of my paper. What they share includes open datasets or more closely curated datasets that might represent like an aggregated roll-up of activity or trends on the platforms. And the subject matter really is a grab bag of things.
When you look at the biggest platforms, there’s a couple of major buckets of data that platforms share. You’ve got activity data, like posts or searches or trends in the way that people use social media or search engines. And you’ve also got mobility data or aggregated location data.
In addition to the use case I just mentioned, like trip data from sharing economy companies, knowing about movement patterns is very helpful, for example, during COVID-19 relief.
These categories are not fixed, though. And companies are always trying new things. And that opens up new potential risks for how they can be exploited. I think companies are very much aware of this, and they’re trying to do the right thing. And they protect it through a variety of measures.
First, you’ve got organizational measures, like sometimes curated datasets are only shared with vetted partners or shared directly with the government. And that sort of audience control can be a protective measure. Although, it can definitely be leaky.
Then you’ve got technical measures. These are some of the lessons learned. If you were to go back 20 years, there was sort of a general expectation that if you de-identified data by stripping out unique identifiers or just aggregated it by saying, well, 100 people searched for this show on Netflix, 200 people searched for that one, that it would be anonymous and it would be fine. But most of the privacy scandals have come about when researchers have found ways, or bad actors have found ways, to re-identify unique individuals from that data.
I think that technical privacy measures have matured a lot since then. A lot of these datasets are now curated with differential privacy baked in. That’s not just doing things like aggregation, so you can’t tell one person from 100 others, but adding statistical noise and using other techniques to make sure they can’t be picked out. We’ve really matured here. But I think that as new forms of data sharing are invented, there will be new ways that they can leak or be exploited in ways that weren’t intended.
I know there was a second part of your question here, so I wanted to get back to that.
TEDDY DOWNEY: Yeah, I mean, it’s more about how these companies—what’s changing? This is how they plan on protecting their data. You mentioned in the paper, well, companies change leadership. Sometimes they go out. They have good intentions. And then they sort of relax the intentions. They go from having a government that you could say is at least largely a good faith actor to a bad faith actor. Things change.
Then how do those policies then go from being standard, typical, compliant, legally defensible policies to risks, litigation risks, oversight risks? How do you as a company make that decision of, am I going to share this data? How can I make this data not a problem for the company and for the users whose data it is, the people, the citizenry? How can I act in a legal and ethical way?
I think that becomes a very difficult question. I actually think telling companies and asking them to do that is a recipe for disaster. What are they supposed to do? They’ve got the government saying give me the data. They’ve got an obligation legally. They’ve got legal obligations. And then we got moral—some of them more so than others—feel moral obligation not to expose people to undue surveillance. What’s the answer here for these companies? How do they navigate this?
BEN NEUMEYER: I think the companies need to update their view of the current risk landscape and take both a broader view of privacy risks that are more present in the current threat environment and how those risks flow downstream to the platforms themselves and become business risks.
I talk a little bit about this in the playbook section of the article where I cite a few examples of areas where platforms have done a really good job of curating data sets and showing that they were taking the broadest possible example of privacy risks. Like anonymizing movement data sets that had to do with COVID to a level that they couldn’t even unveil the movements of families or communities because of the risk of government surveillance and overactive quarantine enforcement. I think that requires some updating, but it’s something that the companies have the talent to do.
That said, it’s also an intensely cross-functional process and takes a lot of resourcing. You need people who are experts in the data set curation and actually know what it’s going to be useful for and how to make it actually useful. But you also need privacy engineering, people who can actually apply differential privacy techniques. And you also need legal and policy folks in the room to make those decisions happen. That takes a lot of resourcing. And I think we’re going back to one of the central risks here, which is that the incentives aren’t always going to be aligned.
I think when it comes to the actual policy risks from not treating this data well becoming business risks, I think it flows down in a few ways.
At the top level, you’ve got risks in the legislatures and in the news. As we mentioned earlier, it seems like we’re really going to see a lot of congressional investigations of companies that have enabled the Trump administration’s most controversial moves in policy, and this is probably going to create a lot of negative news cycles for them. Those news cycles can become waves of legislation. Like after the Supreme Court’s verdict in Dobbs overturning the right to abortion, 22 states responded with laws to protect reproductive health care and consumer health data in the wake of that ruling. And that has really increased the cost of doing business for companies.
Following on with that, you’ve got lots more potential for litigation and regulator enforcement. The various news cycles created by Meta Pixel have led to a huge volume of regulator investigations and litigation by states, by the FTC. And this regulatory enforcement is not just a liberal or democratic issue. It’s bipartisan. I think one of the most active attorney generals has been Texas, who leveraged news cycles about Facebook and facial recognition to commence an investigation and extract a record settlement.
Finally, all of these privacy scandals and press cycles create drops in key business metrics. Again, looking back at the history of Meta, both the Cambridge Analytica scandal and scandal over WhatsApp’s change to its privacy policy and terms led to drops in engagement numbers that were reported by external surveys and app store monitoring. I think that’s a whole risk of pictures that extends beyond just, well, what happens after Trump is President?
TEDDY DOWNEY: I want to ask you not to make everything an antitrust issue, but I’m going to make this an antitrust issue for a second. If the government can’t be trusted with this data, and the government is democratically accountable, why should corporations be allowed to have this data? What’s the solution?
If we’re saying, hey, the Congress is so disturbed by how this data is used by the federal government, are they going to look at this and say it’s not just investigations and new rules? It’s are you too big? Do you have too much data? Are you able to surveil us in the way that Trump is surveilling us, Palantir, Meta, Google, et cetera? Is this fundamentally wrong? Is there something more dangerous here? I think that’s a legitimate question.
Obviously, all these companies are already getting sued under numerous circumstances for faulty products and privacy and antitrust. You’re seeing this data now not just be used by ICE in improper ways, but to surveil and then price on an individual basis, to basically just extract rent from you in every move that you make throughout your economic life. At some point, I just think this is too much power.
I think that question is going to come up. Maybe not. Maybe it will never come up at that level. But that’s one of the things that kept coming up to me reading your paper. We’re talking about how the government can misuse this. But really at any moment, these companies can misuse it. You know that it was being misused when they went and sat in the front row at the inauguration, when they had been amenable to changing the algorithms, when Musk bought Twitter. You know that this is going on because you can see the—and you point out all the ways in which there’s collaboration between ICE and private business. But there’s other indicia that the data, the power of these companies, which often is through data, is being used in untoward ways by the government.
And so, I’m interested in any kind of solution to this. I’m not saying that’s the only solution. It’s just that it always seems to fall short if you don’t distribute the power, distribute the data, or force some kind of siloing of this data. Because you talk about it being pulled together and then misused, and that the companies can just do that themselves.
BEN NEUMEYER: Yeah. I mean, I agree with the underlying point of your comment here, that it’s really about competition. And just due to the bigness and network effects, some of these platforms, there isn’t really another place to go.
And I think when you see a celebrity who wants to make an announcement, for example, or apologize for something dumb they did, it’s going to be an Instagram post. That’s how you reach the most people. There’s no other medium that comes close in terms of its ability to reach that big of an audience. And I would say that for a number of online services. And I use these services. I think when we welcomed a daughter at the beginning of last year —
TEDDY DOWNEY: Congratulations.
BEN NEUMEYER: Thank you. The first place I went to tell as many friends as I could was an Instagram post. So, something like that is not without value to me. And taking that into account, the real solution should probably have something to do with competition.
So, if you don’t like a company’s data collection practices, you can go to a platform that collects less. I think that some of those remedies, some of those alternatives, are available. If you don’t like the way that Google is shoving AI into everything, you can go to DuckDuckGo. But none of them have the scale to really touch the whole population like the tech giants. And the actual solution for that is something that’s hard for me to speculate on.
TEDDY DOWNEY: We’ve got a question from a listener. If you have questions, put them in the chat, put them in the questions pane. We’ll try to get to them before we let Ben go here.
First question, I want to hear about the call for all customers to share sensitive personal data with telephone companies to store for four years.
I’m not familiar with this. I’m curious if you are sharing sensitive personal data with telephone companies.
BEN NEUMEYER: Yeah, I’m actually not familiar with this either. It does point to the very sectoral nature of U.S. privacy law, where this is likely a question that would fall to the FCC’s privacy rules. Because they have jurisdiction to regulate what is probably here, CPNI, which I think stands for Customer Proprietary Number Information. But the FCC is the sole regulator when it comes to privacy in a telecom question like this. So, it’s a little bit beyond my focus.
TEDDY DOWNEY: But maybe we can talk about the FCC here for a second. Because that is a place where they do have very specific authority and they’re being pretty explicit about we want to basically create more conservative media out there. And it’s gone from, I think, kind of this good faith concept of we need diversity of media voices—and therefore we need competition—to being like, actually, no, we want more concentrated ownership of media in the hands of conservative owners. And that’s the solution to sort of liberal media bias or what have you.
How is privacy, FCC control, privacy law at the FCC, being used? Is that really just a competition issue and not really a privacy issue? Or do you see concerns about how the FCC is not properly being a steward of privacy law like you would have in these other agencies, a more obviously sort of concentrated area like Doge?
FCC is sort of separate. Was there any concern about they’re deferring to companies like a telecom company or not cracking down on certain types of bad actors when it comes to privacy that you think needs a closer look?
BEN NEUMEYER: That’s a great question. And it really takes me back to when we first met in D.C. It was during the Obama administration. And I remember getting coffee with you and talking about what the FCC could do and how they could use their public interest authority to further competition and sort of do great things in the public interest in the world of telecom and the internet.
But now, you have Brendan Carr at the helm, who knows that public interest is a very squishy, murky doctrine. And he’s sort of molding it into something to sort of preserve conservative voices by basically silencing liberal late night hosts. And that is a pretty scary thing to see.
I think that one of the most interesting aspects of this is just that, with cord cutting and the switch to unbundled streaming services, there are all kinds of new privacy issues that are coming up that are sort of outside the traditional FCC remit and have more to do with like consumer privacy and tracking.
Now that almost everything is on a streaming platform, streaming platforms are also ad platforms. And that’s a really important source of monetization for the streamers. You see things like ad supported tiers of service, like HBO with ads, Disney with ads. And just the fact that like someone can like, the fact that a company like—I’m citing Disney because I’m going to come back to it in a second—that a company like Disney can access what content you’re consuming across multiple devices and also reach you with ads across multiple devices is really powerful.
And I think that’s an area where the states have actually stepped in to protect privacy. California has become the biggest defender of consumer privacy. And in particular, they have really hammered companies on not providing privacy options and controls that are easy to use and actually work for consumers. So, they actually announced a pretty important landmark settlement against Disney over their cross device tracking, which it was really, really hard to opt out of.
So, I think that as states step in—and some of the economic issues like monetization through ads come to the forefront—we’re going to see new actors who are bolder and less afraid to act.
TEDDY DOWNEY: I want to ask you more about this in a second in terms of state enforcement. What you just said reminds me of when I saw an article about how Vizio left their camera on to watch people watch TV. And then Vizio was bought by Walmart. And then if you have—and I know about this because I had Vizio TV. And I tried to download the Vizio app recently to like control my TV from my phone because I was out of batteries. And it was like share all the data from your phone with Walmart. Or it was some absurd request when I was trying to get the app. I’m like, no. I’m just not going to do that. Which brings me back to the personalized pricing. The more data they know about you, the better they can personalize price.
We have a question here. We have a saying customer proprietary network information. The question is storing a government issued driver’s license. It is beyond CPNI. Any thoughts on that? I guess that’s the listener question we just heard.
BEN NEUMEYER: No, I mean, thanks to the listener for generously stepping in with the right term behind the acronym there. Storing driver’s license is very interesting. A lot of platforms need it for verification to both comply with laws and to make sure that someone is who they say they are. So, I think that there are important use cases that could be captured by this.
However, if it is just a blanket requirement that isn’t actually tailored to the issues that the telecom companies are actually trying to solve, like with compliance or integrity, it seems worrisome, especially if there are no retention limits or limitations on use. So, this is something that’s concerning to me, but I just don’t know enough about the specific proposal.
TEDDY DOWNEY: Let’s talk about states quickly. That’s where we’re seeing the most interesting action on privacy related issues, privacy itself, data broker registration registries, fines, fees, surveillance, pricing bans, personalized pricing bans, algorithmic pricing bans. Do you think states are really the place to watch?
Obviously, we’re going to be looking for congressional oversight on all the stuff that you mentioned in the paper. But if you really want to be covering cutting edge privacy law, it’s going to be at the states. Is that a fair assessment?
BEN NEUMEYER: I think that’s where the game is right now. I think when you have a highly resourced state, like California, that’s willing to stand up their own data protection agency, that also collaborates with the attorney general’s office for enforcement and a legislature that will generally pass progressive privacy legislation, you can have a state that kind of acts as a de facto national regulator because of its scope. And I think that they’re doing pretty smart things.
And I think that you should read some write-ups of that Disney settlement that I mentioned and the other ones in that batch. I think that they really dealt with some strong anti-consumer practices. But they’re also standing in more ongoing oversight and more, I guess I would say, proactive action through their privacy audit division that’s just getting started. But I think that that’s going to be a really interesting next step in what California does.
And zooming back out to the national picture, I know that in more hopeful times, we’ve talked about broadening the FTC remit or standing up a standalone national data protection regulator. But that seems very far down the road at this point. I think that the states are where it’s at right now.
TEDDY DOWNEY: The last question here on social media companies and privacy. It seems like privacy is one aspect of a litany of concerns that the citizenry have around the use of children on social media or children’s use of social media. And so, we’ve seen, across the world and in some states in the U.S., efforts to ban social media for people under a certain age.
But then you get these bizarre, in my view, concerns from a social media company that they can’t feasibly implement that kind of thing because that would require some kind of age verification or what have you. I find this utterly absurd that the most powerful wealthy companies in the world can’t figure out how to comply with a law, like a pretty obvious law, right? Children cannot use your thing. You’ve got all the money in the world. I’m sure you can figure it out.
However, there’s this one thing which I’m curious to get your thoughts on, that as an approach that is both a privacy and a broader concern. That’s like one element of this that they’re not sure you’re really keeping this information of their kids private, along with also harming them in a myriad other ways. But what do you make of this defense that they can’t implement it because they can’t verify the age and things like that?
BEN NEUMEYER: So, I think that there is a kernel of truth to it in that making every single online service that children could access have to do their own age verification is enormously risky from a privacy perspective. That sets them up with having to collect a lot of sensitive data, like either by collecting photo ID or doing biometric age estimation. Or getting parental consent from parents who may not approve of content that their child is seeing online, even if it’s—this always comes down to like LGBTQ youth and their ability to find a community over the internet.
So, I think that there is a kernel of truth to that when it’s applied to the broader ecosystem. And I think that some of the policy remedies that have been proposed by Big Tech actors like Instagram’s campaign to push for device level age verification actually makes sense. Because then you have sort of like a central point of verification that establishes your ability to download and use apps.
That being said, I don’t think that really shakes out with respect to the big actors themselves. They have the greatest ability to build or to hire the best vendors to outsource age verification to. I think they’re kind of standing behind the smaller actors. Even though they have so much more power, they’re saying, hey, we’re standing in solidarity right now. So, I see that as a fault of that argument that they can’t comply.
TEDDY DOWNEY: The last way I would think of—I’m curious to get your thoughts on this – is, look, you can’t trust them when it comes to privacy or what have you, or their concerns about privacy, particularly around children. And so, you’re looking at a regulatory regime that increasingly looks a lot like sin industry, right? Tobacco, right? That’s banned for people under specific ages. There are warnings on it. There are strict regulation, big heavy taxes.
Is that really the way to think about these services going forward? Like what other things, other than alcohol and cigarettes, are banned for minors, right? Like products that are banned for minors inherently require, in every other facet, strict regulation, heavy taxation.
Ultimately, even you’re thinking about privacy, does that kind of regulatory regime make more sense? I mean, I know people have talked about utility regulation in the past, and that has come up at the Supreme Court level. But I actually think much more apt is the cigarette and alcohol industry, which are subject to strict, strict regulations, heavy taxation, and user limits. You have the store that’s in charge of making sure of that, right? Like to the analogy that you made, the app store can be in charge of the age, allowing it or not. That seems analogous. So, is that proper or improper? Am I reading a little too much into that?
BEN NEUMEYER: That’s a good question. I think that there’s a lot of discourse on this. I think that maybe there’s a hint of applicability there. But there are just so many distinctions. And I think, at the end of the day, that access to the internet—a lot of the time, which is intermediated through social media—is valuable for kids because they can find community there. And the way that products are structured and made to be addictive could be addressed. But there is an underlying value. Contrast that to alcohol or cigarettes, where our government has decided—we as a society have decided—that there should be no use under the age of 18 or 21.
TEDDY DOWNEY: Well, governments are saying that about social media, yeah. I mean, I think you get community by going outside and meeting people in real life as well. But we’ll see how this all plays out. Your paper, Ben, super interesting. I enjoyed it very thoroughly. Very thought provoking, a lot to digest, a lot to keep in mind. It is so great to see you. Thank you so much for doing this.
BEN NEUMEYER: Yeah, likewise. I’m glad we could sit down and riff on this for an hour. I’ve really enjoyed our talk.
TEDDY DOWNEY: Yeah. And before we wrap up, I want to remind listeners we have our podcast series, “Second Request.” This will be one of them, “TCF Investigates.” We’re also starting a podcast next month on private credit. Very excited for you all to go check those out. And thank you again to Ben and thanks to, thanks to everyone for joining the call today. This concludes the call. Bye-bye.