Home / Blogs

Email Snooping Can Be Intrusion Upon Seclusion

Evan D. Brown

Analysis could also affect liability of enterprises using cloud computing technologies.

Steinbach v. Village of Forest Park, No. 06-4215, 2009 WL 2605283 (N.D. Ill. Aug. 25, 2009)

Local elected official Steinbach had an email account that was issued by the municipality. Third party Hostway provided the technology for the account. Steinbach logged in to her Hostway webmail account and noticed eleven messages from constituents had been forwarded by someone else to her political rival.

Steinbach sued the municipality, her political rival and an IT professional employed by the municipality. She brought numerous claims, including violation of the Federal Wiretap Act, the Stored Communications Act, and the Computer Fraud and Abuse Act. She also brought a claim under Illinois common law for intrusion upon seclusion, and the court's treatment of this claim is of particular interest.

The defendant IT professional moved to dismiss the intrusion upon seclusion claim under Fed. R. Civ. P. 12(b)(6)(for failure to state a claim upon which relief can be granted). The court denied the motion.

The court looked to the case of Busse v. Motorola, Inc., 813 N.E.2d 1013 (Ill.App. 1st. Dist. 2004) for the elements of the tort of intrusion upon seclusion. These elements are:

  • defendant committed an unauthorized prying into the plaintiff's seclusion;
  • the intrusion would be highly offensive to the reasonable person;
  • the matter intruded upon was private; and
  • the intrusion caused the plaintiff to suffer.

The defendant presented three arguments as to why the claim should fail, but the court rejected each of these. First, the defendant argued that the facts allegedly intruded upon were not inherently private facts such as plaintiff's financial, medical or sexual life, or otherwise of an intimate personal nature. Whether the emails were actually private, the court held, was a matter of fact that could not be determined at the motion to dismiss stage. Plaintiff's claim that emails from her constituents were private was not unreasonable.

The defendant next argued that Steinbach had not kept the facts in the email messages private. But the court soundly rejected this argument, stating that the defendant failed to explain how Steinbach displayed anything openly. Plaintiff asserted that she had an expectation of privacy in her email, and defendant cited no authority to the contrary.

Finally, the defendant argued that the intrusion was authorized, looking to language in the Federal Wiretap Act and the Stored Communications Act that states there is no violation when the provider of an electronic communication services intercepts or accesses the information. The court rejected this argument, finding that even though the municipality provided the email address to Steinbach, Hostway was the actual provider. The alleged invasion, therefore, was not authorized by statute.

The court's analysis on this third point could have broader implications as more companies turn to cloud computing services rather than hosting those services in-house. In situations where an employer with an in-house provided system has no policy getting the employee's consent to employer access to electronic communications on the system, the employer — as provider of the system — could plausibly argue that such access would be authorized nonetheless. But with the job of providing the services being delegated to a third party, as in the case of a cloud-hosted technology, the scope of this exclusion from liability is narrowed.

By Evan D. Brown, Attorney. Evan focuses on technology and intellectual property law. He maintains a law & technology focused blog called Internet Cases as well as a blog called UDRP Tracker which focuses on domain name disputes.

Related topics: Access Providers, Cloud Computing, Data Center, Email, Law, Privacy

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

ISP, cloud computing provider etc etc .. doesnt really matter and this is not unique Suresh Ramasubramanian  –  Sep 03, 2009 6:34 AM PST

Any provider of email that accesses its users' mailboxes without due process (and in specific cases, such as on receipt of a subpoena, or by prior concent of the user in order to troubleshoot some issue with her account) can, and will, be hung out to dry.

Doesnt really matter whether its hosting on a shared webhost, a standalone exchange / notes server, or a large cloud based email provider

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

Verisign to Award New Infrastructure Research Grants

Facets of gTLD Registry Technical Operations - Registry Services

Afilias Says "No" to SOPA

Breaking the DNS: Another Look at How SOPA Could Be Destructive

BlueCat Networks Partners with Computacenter to Deliver Cloud-Ready IP Address Management (IPAM)

Giving VIP Treatment to IPAM with Nixu NameSurfer Suite 7.0.2

Asymmetric DHCP Failover Support with Nixu DHCP Server 2.4 Series

Minds + Machines to Announce New .brand gTLD Pricing at INTA

Introduction to Nixu Software: End-to-End Software-Based DNS, DHCP, IPAM Solutions for Your Network

dotMobi Launches Low-Cost Cloud Version of Market-Leading DeviceAtlas Device Detection Service

Dyn Releases New Powerhouse in Enterprise Class Email Delivery

Nixu Software Participates in World IPv6 Day

.CO Recognized Alongside Industry Giants in Trademark Industry Awards

Verisign and Coalition for ICANN Transparency, Inc. ("CFIT") Resolve Litigation

MarkMonitor to Co-Chair International Anti-Counterfeiting Coalition Spring Conference

Hostway Named Microsoft Hyper-V Cloud Provider of the Year

Verisign Enhances Its Managed DNS Service With Full Support for DNSSEC Compliance and Geo Location

Global Company Leads the Pack as One of the First Microsoft Partners to Offer Exchange 2010

New Verisign Uptime Bundle Combines DDoS Protection, Managed DNS and Threat Intelligence Services

Q4 2010 Fraud Intelligence Report

Hot Topics

Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
Afilias

DNSSEC

Sponsored by
Afilias
dotMobi

Mobile

Sponsored by
dotMobi
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS
Verisign

Security

Sponsored by
Verisign