NOTEREF _Ref445303279  Certain types of encryption can obscure the payload of customers’ communications packets from BIAS providers, but will not prevent BIAS providers from obtaining significant source, destination, and traffic type information, among others. For instance, a BIAS provider will still need to know the source and eventual destination of encrypted content in order to properly route the information; will still know the time and frequency of communications, and can determine other information from packet headers as well as from domain name resolution requests. See, e.g., New America, Open Technology Institute, The FCC’s Role in Protecting Online Privacy 3-5 (2016),; Center for Democracy and Technology, Applying Communications Act Consumer Privacy Protections to Broadband Providers 2 (2016),; Letter from Twelve Public Interest Organizations to Tom Wheeler, Chairman, FCC at 2-3 (Mar. 7, 2016). Furthermore, even more detailed information can be derived from encrypted content via traffic analysis. See Brad Miller, Ling Huang, et al., I Know Why You Went to the Clinic: Risks and Realization of HTTPS Traffic Analysis, 14th International Symposium on Privacy Enhancing Technologies (2014) available at

NOTEREF _Ref445303279  See FCC, Location-Based Services: An Overview of Opportunities and Other Considerations (May 2012), Individual companies have taken a variety of approaches to consumer choice. For example, “Apple acknowledges the importance of ‘provid[ing] its customers with the ability to control the location-based services capabilities of their devices’”; Microsoft has stated that it “does not collect information to determine the approximate location of a device unless a user has expressly allowed an application to collect location information”; and Google states that “[o]pt-in consent and clear notice are required for collection and use of location information on Android.” Id. at 26. For one of its location tracking programs, Verizon says that it participates in the “Mobile location analytics Code of Conduct developed by the Future of Privacy Forum” and links to an opt-out option. Verizon, Mobile Location Analytics Privacy Notice, (last visited Mar. 24, 2016). But Verizon also collects location information through other services and apps, with differing customer choice mechanisms. See Verizon, Full Privacy Policy, (last visited Mar. 24, 2016). AT&T and Comcast, in contrast, do not offer customer choice options specifically pertaining to location-based services. See AT&T, Privacy Policy, (last visited Mar. 24, 2016); AT&T, Choices and Controls, (last visited Mar. 24, 2016); Comcast, Comcast Customer Privacy Notice, (last visited Mar. 24, 2016). T-Mobile promises that “[w]hen we request use of your location information, you will be given options for managing when and how such information should be shared.” T-Mobile, T-Mobile Privacy Policy Highlights (Mar. 24, 2016),

NOTEREF _Ref445303279  See 18 U.S.C. § 2701 et seq. (Stored Communications Act); 18 U.S.C. § 2510 et seq. (Wiretap Act). See also 47 U.S.C. § 605 (Except as authorized under 18 U.S.C. § 2511(2), no person receiving or transmitting any interstate or foreign communication by wire or radio “shall divulge or publish the existence, contents, substance, purport, effect, or meaning thereof, except through authorized channels of transmission or receipt” to any person other than the addressee, his agent, or attorney (or in other specifically-delineated circumstances)) (emphasis added). In the cable context, Congress observed that “[c]able systems, particularly those with a ‘two-way’ capability, have an enormous capacity to collect and store personally identifiable information about each cable subscriber.” H.R. Rep. No. 934, 98th Cong., 2d Sess. 29 (1984), quoted in Scofied v. Telecable of Overland Park, Inc., 973 F.2d 874, 876 (10th Cir. 1992). “Subscriber records from interactive systems can reveal details about bank transactions, shopping habits, political contributions, viewing habits, and other significant personal decisions.” Id. The Cable Privacy Act prohibits operators from disclosing this personally identifiable information “without the prior written or electronic consent of the subscriber concerned.” 47 U.S.C. 551(c)(1).

NOTEREF _Ref445303279  If too much context is removed from data, it may no longer provide the insights for which BIAS providers and others value the information. See, e.g., Robert Gellman, The Deidentification Dilemma: A Legislative and Contractual Proposal, 21 Fordham Intell. Prop. Media & Ent. L.J. 33, 39 (2010).

NOTEREF _Ref445303279  See, e.g., U.S. Public Policy Council of the Association for Computing Machinery, Response to Request for Information, Big Data Review, 79 FR 12251 at 2, (“It has become significantly easier to extract personally identifiable information from nominally de-identified data as more data becomes available. In recent years academic researchers have shown that many data sets thought to be ‘de-identified’ or ‘anonymized’ can be re-identified when the data are correlated with other information that is publicly available.”). There is a rich scientific literature on re-identifying data that has been de-identified. Additionally, in 2000, Latanya Sweeney, now the Director of the Data Privacy Lab in the Institute for Quantitative Social Science at Harvard University, demonstrated that 87 percent of the population in the United States had reported characteristics that likely made them unique based only on 5-digit ZIP, gender, and date of birth. Latanya Sweeney, Abstract, Uniqueness of Simple Demographics in the U.S. Population (Carnegie Mellon Univ., Lab. for Int’l Data Privacy 2000), In 2008, researchers at the University of Texas at Austin succeeded in using publicly available information to identify Netflix subscribers in a dataset of movie ratings from which personal identifiers had been removed, explaining that “[r]emoving identifying information is not sufficient for anonymity.” Arvind Narayanan & Vitaly Shmatikov, Robust De-anonymization of Large Sparse Datasets, in Proceedings of the 2008 IEEE Symposium on Security and Privacy, 111, 118 (2008),

NOTEREF _Ref445303279  Paul Ohm, Broken Promises of Privacy: Responding to the Surprising Failure of Anonymization, 57 UCLA L. Rev. 1701, 1732 (2010). Ohm further argues that “[e]asy reidentification makes PII-focused laws like HIPAA underprotective by exposing the arbitrariness of their intricate categorization and line drawing. Although HIPAA treats eighteen categories of information as especially identifying, it excludes from this list data about patient visits—like hospital name, diagnosis, year of visit, patient’s age, and the first three digits of ZIP code—that an adversary with rich outside information can use to defeat anonymity.” Id. at 1740.

