Insights
Publications

A Roadmap to Litigating Privacy Claims? A Look at a Recent Order From the Google Assistant Privacy Litigation

May 27, 2020 Blog

As privacy-related litigation continues to heat up, Judge Beth Freeman (ND Cal.) recently laid out in In re Google Assistant Privacy Litigation (Case No. 19-cv-04286)[1] a potential roadmap for surviving or winning a motion to dismiss on privacy-related causes of action. 

The consolidated lawsuit against Google alleges violations on twelve counts, all relating to the Google Assistant product – a voice-activated technology used in mobile and home devices that listens for “hotwords” in order to carry out user commands. This case is an important one to watch and should be broadly instructive as many companies, big and small, are and have been hard at work on voice-activated technologies (compare, for instance, to Amazon’s Alexa, Apple’s Siri, and countless speech recognition start-ups around the world). Huge numbers of households and individuals currently have these devices in their homes and/or on their person at all times.

Plaintiffs allege that while devices with Google Assistant await user commands, short audio recordings are constantly made and continuously overwritten. This litigation is based almost entirely on a VRT NWS news article published in 2019 claiming that Google stores and analyzes the short pieces of audio recorded before the hotwords are said in order to improve the software’s accuracy.

This case involves five named plaintiffs residing in New York and California. Plaintiffs allege privacy or privacy-type violations under federal and California state laws including the federal Wiretap Act, California Invasion of Privacy Act, intrusion upon seclusion under California common law, invasion of privacy in violation of Article I, Section 1 of the California Constitution, violation of California Unfair Competition Law § 17200, and various breach of contract and warranty claims relating to Google’s applicable privacy policy.

Google’s motion to dismiss sought dismissal of all but one count (for declaratory judgment). With some minor exceptions, Judge Freeman granted dismissal with leave to amend on the eleven counts on which Google moved. 

With respect to the Stored Communications Act (SCA), which is modeled on the common law of trespass, Judge Freeman held that the plaintiffs had not yet pled a claim for unlawful access, but had pled sufficiently on an unlawful disclosure theory. As to the unlawful access prong, Judge Freeman observed that the Ninth Circuit has failed to provide guidance on the meaning of “facility” under the SCA (to succeed, the plaintiff must show the defendant gained unauthorized access to a “facility” where it accessed electronic communication in “electronic storage”). The court laid out the limited Ninth Circuit precedent on the meaning of a “facility” under the SCA, expressing skepticism that plaintiffs would be able to plead facts sufficient to show that their Google Assistant devices constitute “facilities.” In denying Google’s motion to dismiss on the unlawful disclosure theory, the court pointed in part to what it characterized as vague language in Google’s privacy policy, and found plaintiffs had adequately pled unlawful disclosure based upon the allegations of “disclosure of audio and transcripts to subcontractors for analysis ‘to improve the functionality’ of the Google Assistant.”

As to the counts for the common law tort of intrusion upon seclusion and invasion of privacy under California Constitution, Article 1, Section 1, the court noted that the sources of these two privacy protections are closely related, dismissing the claims with leave to amend. Both claims essentially require the existence of an expectation of privacy, and an intrusion into that private space. Here, the plaintiffs have alleged that the “false accept” recordings constitute such an intrusion, alleging that short audio recordings are constantly made and continuously overwritten while the devices await user commands. But the court observed that the plaintiffs’ failure to allege sufficient information to show that recorded conversations were had under circumstances that would give rise to a reasonable expectation of privacy was “fatal” to these claims at this stage. At the same time, however, the court noted that a reasonable person could find the alleged conduct to be “highly offensive,” one of the prongs required to meet the legal standard for intrusion upon seclusion, and warned that courts have found surreptitious recordings can constitute “an actionable intrusion,” and that these circumstances may be more akin to surreptitious recording cases than to browsing history cases . While the court found the pleadings deficient on reasonable expectation of privacy, it noted that if the pleadings were cured to address that deficiency, whether or not the conduct was “offensive,” would not likely be resolvable on a future motion to dismiss.

Plaintiffs also sought relief under California’s UCL Sec. 17200 alleging economic injury due to overpayment for their Google Assistant devices. As an initial matter, because not all plaintiffs alleged payment for any such device, their claims were dismissed with leave to amend. 17200 claims may be brought under the unlawful, fraudulent, and/or unfair prongs of the UCL. The unlawful prong failed as it was based on the other asserted counts which the court had already dismissed without prejudice. The court dismissed the fraudulent prong for plaintiffs’ failure to identify any misrepresentations or omissions with the particularity required by Rule 9(b)’s heightened pleading standards. Finally, the court dismissed plaintiffs’ UCL claim under the unfair prong, noting that plaintiffs have failed to allege any harm to competition or incipient violation of the antitrust laws as Cel-Tech Commc’ns, Inc. v. Los Angeles Cellular Tel. Co., 20 Cal. 4th 163 (1999) requires. Here, the court noted Google’s objection that “considering the substantial benefit the Google Assistant provides to consumers, Plaintiffs ‘cannot reasonably allege’ that the utility of their Google Assistant Enabled Devices is outweighed by the ‘occasional error’ of false accepts.” The court also warned that invasion of privacy is a harm that is difficult to quantify, and that it would not be possible to determine as a matter of law that the utility of the Google Assistant product outweighs the harm from the false accepts. The court then granted dismissal, warning plaintiffs to properly plead “harm to the alleged victim” to meet the requirements of the “unfair” prong.

The roadmap Judge Freeman laid out on many of these claims can provide valuable guidance to assessing the strength of possible privacy claims, and the ability to defeat claims at the motion to dismiss stage, for plaintiffs and defendants alike. Given the popularity of and innovation in the voice recognition technology space, this case is certainly one to watch.


[1] This is a consolidation of cases Kumandan, et al. v. Google LLC and Galvan, et al. v. Google LLC.

Firm Highlights

Publication

Cybersecurity Regulation: Key Takeaways From an Unusual FTC Order That Will Follow CEO for a Decade

The FTC recently issued a proposed order that would settle an enforcement action against Drizly, LLC and its co-founder and CEO, James Rellas, arising from data breaches in 2018 and 2020 that affected over...

Read More
Publication

Privacy Policy Best Practices for Nonprofits

Welcome to EO Radio Show – Your Nonprofit Legal Resource . I’m happy to have my colleague Nate Garhart back for a discussion on privacy laws and how they affect website content development and online...

Read More
Publication

California Attorney General Announces Enforcement Sweep of Mobile Applications

Shortly before Privacy Day, California Attorney General (Cal AG) Rob Bonta  announced  a California Consumer Privacy Act (CCPA) enforcement sweep that targeted mobile applications. The sweep focused on popular apps in the retail, travel...

Read More
Publication

Uber’s Former Chief Security Officer Found Guilty of Obstruction For Coverup of Data Breaches

On October 5, 2022, after a monthlong jury trial, former Uber Chief Information Security Officer Joseph Sullivan was found guilty of obstructing proceedings of the Federal Trade Commission (FTC) and misprision of a felony...

Read More
Publication

Employee Data under the CCPA: Expiration of Employer Exemptions Requires Compliance as of January 1, 2023

Since the California Consumer Privacy Act (“CCPA”) was passed in 2018, employers have been watching carefully to see how the law will apply to data collected and maintained about their employees. Up until now, ...

Read More
Publication

I Always Feel Like AI Is Watching Me: Artificial Intelligence and Privacy

ChatGPT got the early press, and every day we learn of new generative artificial intelligence products that can create new and creative visual and text responses to human input. Following on ChatGPT’s fame, Google’s...

Read More
Publication

Nonprofit Websites and Terms of Use - Best Practices and Common Pitfalls

Welcome to EO Radio Show – Your Nonprofit Legal Resource . Happy New Year, everyone!  In episode 26, Cynthia Rowland and her guest Nate Garhart discuss websites and terms of use and the legal concepts...

Read More
Publication

Platform Ecosystems: Computer Fraud and Abuse Act and Other Scraping Law Developments (Webinar)

Erik Olson and Stephanie Skaff discuss "Platform Ecosystems: Computer Fraud and Abuse Act and Other Scraping Law Developments." Web scraping has existed as long as the World Wide Web has, and as data has...

Read More
Publication

What Recent Rulings in 'hiQ v. LinkedIn' and Other Cases Say About the Legality of Data Scraping

LinkedIn obtained a permanent injunction on Dec. 6 in its six-year-old lawsuit against data scraping company hiQ Labs, which LinkedIn quickly cheered as a “final, decisive victory” that established an “important legal precedent.” While...

Read More
Publication

California Passes Landmark Privacy Protections for Children With Big Implications for Online Providers

Governor Newsom recently signed into law AB 2273 , the California Age-Appropriate Design Code Act (CA AADCA), making California the first state to pass broad privacy protections for children. The CA AADCA is modeled...

Read More