News: 1684259168

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google sued over 'interception' of abortion data on Planned Parenthood website

(2023/05/16)


An anonymous complainant has filed a lawsuit against Google, claiming it unlawfully collects health data, including abortion searches, on third-party websites that use Google technology.

Jane Doe, whose legal representation is looking to get the case certified as a class action, claims her private information was intercepted by Google when she used the scheduling pages on Planned Parenthood's website in 2018 to search for an abortion provider.

Doe alleges Google wrongfully collected her medical information and that of other would-be class members "without authorization and proper compensation" when its tracking tech was used by her healthcare provider.

[1]

The suit asks Google to establish a compensation fund and to stop the practice, claiming it "aided and abetted" the healthcare provider's violations of the California Confidentiality of Medical Information Act (CMIA) and is therefore liable for any infractions.

[2]

[3]

The lawsuit also cites the California Invasion of Privacy Act (CIPA), which is supposed to guard Californians against companies eavesdropping on their private communications and the invasion of privacy [4]resulting from the "continual and increasing use of such devices and techniques."

The full [5]complaint [PDF] alleges that Google's tracking tech pulled in information about Doe's interactions with the healthcare provider's website and also "intercepted" data about treatment she received at the Planned Parenthood affiliate in Burbank, California, that she ultimately selected using the site.

[6]

The suit claimed the plaintiff and class members didn't "authorize or consent" to the tracking, adding that they have:

a reasonable expectation of privacy in their confidential communications, including information relating to their searches for and scheduling of abortions and other medical services, and their sensitive medical information.

[7]FTC sues VoIP provider over 'billions of illegal robocalls'

[8]Privacy Framework draft isn't 'future-proof', say MEPs

[9]This won't hurt a bit: Amazon now a US healthcare provider

[10]Hey, online pharmacies: Quit spreading around everyone's data already

The lawsuit states that Google used Doe's data "to provide marketing and analytics services as well as improve its ad targeting capabilities and data points on users". It requests a jury trial.

At the time of publication, Google had not yet filed a response.

Prior lawsuits have concentrated on healthcare websites themselves – i.e. the websites that implemented Google solutions such as Google Analytics, or Facebook/Meta's Pixel – pointing out that the providers, and especially those who handle confidential medical information, should have had oversight of tracking data and its implementation.

One such example is the [11]recently settled BetterHelp lawsuit. In the settlement, in which it made no admission of wrongdoing, online counselling provider BetterHelp had to pay $7.8 million and was banned from sharing consumers' health data with advertisers. The settlement resolved a 2022 complaint that claimed BetterHelp pushed users to complete an unskippable questionnaire in order to obtain services and then passed on that info to Meta (then Facebook) as well as others in order to promote its services.

[12]

The reason you'll see US privacy cases filed with claims specific to US state law is because there is no general federal legislation on data protection in the US. The lack of federal regulation is one of the reasons the US and EU are having [13]such a hard time agreeing on Privacy Framework, their third attempt at an outline of promises that would mean EU residents' data can flow freely to US tech giants and be processed by them onshore. The EU is looking for equivalent protections that mean the privacy Europeans get would be as good as they get at home before they grant America data adequacy, something many legal experts believe may be close to impossible without a huge shift in the US.

We have asked Google for comment. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZGP9CDFO@RXkP3AoXJq-@gAAAA4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZGP9CDFO@RXkP3AoXJq-@gAAAA4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZGP9CDFO@RXkP3AoXJq-@gAAAA4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://law.justia.com/codes/california/2005/pen/630-637.9.html

[5] https://regmedia.co.uk/2023/05/16/doe_v_google.pdf

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZGP9CDFO@RXkP3AoXJq-@gAAAA4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/05/16/ftc_xcast_illegal_robocalls/

[8] https://www.theregister.com/2023/05/12/eu_us_privacy_framework/

[9] https://www.theregister.com/2023/02/23/amazon_one_medical_merger/

[10] https://www.theregister.com/2023/01/20/online_pharmacies_data_sharing/

[11] https://www.theregister.com/2023/03/03/ftc_online_counseling_betterhelp/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZGP9CDFO@RXkP3AoXJq-@gAAAA4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2023/05/12/eu_us_privacy_framework/

[14] https://whitepapers.theregister.com/



Someone Else

/me likes!

Anything that can put a crimp in the unfettered collection of personal data, especially medical data, especially in a post-Roe dystopic Amerika, is a good thing. You go, Jane!

(As I read the article, I was a little disappointed that Jane didn't choose the pseudonym Jane Roe.)

The data you store in our cloudy appendages will be fondled.

elDog

Unless you (the consumer) has entered into some special non-sharing agreement. And unless your provider also has explicitly said that they will not share with *any* third party (including network and data services), your data will be examined. The robe will be removed, the probes will be inserted.

This is true for all the major vendors (Amazon, google, Microsoft/Azure, ...) Just today a story about how Microsoft actually opens password-protected zip files to look at the contents. That's getting pretty damn personal.

The USofA does have HIPAA (mostly written as if it's a large mammal: HIPPA) which protects (sort of) health information. Very poorly enforced and very hard to use.

Just to add the obligatory: As all of this data is munged together into these wonderful AI "models", your name, sex, last act, etc. may come bopping out - all without any way of attributing to any actual incoming data set.

Yee Haw - it's the wild west, again!

Re: The data you store in our cloudy appendages will be fondled.

John Brown (no body)

"Just today a story about how Microsoft actually opens password-protected zip files to look at the contents. That's getting pretty damn personal."

Not only pretty damned personal, but the fact it's password protected is explicitly denying consent to allow others to look at the contents without authorisation. That ought to be the equivalent of a "Keep Out, No Trespassing" sign which under the right circumstance lets the owner shoot offenders. But, of course, as the article states, there are very few privacy laws in the USA so password protecting your data probably is overruled by the small print in the contract with the host or service that probably says they can do anything they want with any and all information you place on their servers. So, agreed, the Wild West never really went away.

Re: The data you store in our cloudy appendages will be fondled.

DrSunshine0104

The pipe dream that will never happen in the US is that changes to privacy notices should also NOT be retroactive. If you change your policy and I don't agree, then you cannot use my personal data any longer. It is a little concerning that company X can claim to be privacy focused, get bought out by company Y or simply change their policy and then suddenly all the agreed private data is suddenly sold to the latest LLM or start-up.

Anonymous Coward

I'm pretty sure Google announced they would not collect or use data connected to abortion, but I guess they couldn't deliver that, and suing them is good money to make sure they do deliver.

Google should get a free pass

Anonymous Coward

If they didn't install their tracking code on the planned parenthood website, then their liability should be NONE.

Re: Google should get a free pass

Anonymous Coward

But EVERY website has tracking loaded.

Because funding depends on showing usage stats.

I thought there was something fishy about the butler. Probably a Pisces,
working for scale.
-- Firesign Theatre, "The Further Adventures of Nick Danger"