Language

The WeRead Case: Discussion on Reasonable Digital Privacy Expectation

Authored by Yingying Zhu

 

March 2021

Each of us leaves a lasting digital footprint on the internet and would expect businesses that we are dealing with could treat our digital privacy with reasonable care and consideration. Can users have a reasonable privacy expectation in the friends made and the books read online? The Beijing Internet Court in its recently released WeRead judgment holds that, friends list and reading data are not eligible for privacy protection in the case under dispute but nevertheless entitled to protection as personal information.

Background

The judgment is in relation to a dispute between an individual, Huang, a user of a book reading app named WeRead, and the digital giant, Tencent, the operator of the most successful social media in China, WeChat, and its sister app WeRead. The WeRead app wishes to set up an app-based reading community, where people who enjoy reading can read & connect. The plaintiff Huang was complaining that WeRead sneaked away her friends list from WeChat and then automatically turned those who are also subscribers of WeRead as her connections. Huang was also complaining that the information regarding the books she read and how she felt about the reading was widely open to all her connections without her permission while she intended to keep such information private. In its defense, the defendant Tencent alleged that users’ friends list and reading data were obtained with a preapproval from users therefore it should not be held liable for the utilization of the data.

Decision of Beijing Internet Court[1]

The Beijing Internet Court (hereinafter the “BIC”), the Court of First Instance, decides that Huang’s friends list and reading data shall not be categorized as private information, hence not eligible for privacy protection.

To define what constitutes private information, the BIC’s reasoning is based on the classification of the following three layers of personal information:

1.     personal information reasonably recognized by the society as private information, such as one’s sextual orientation, sex life, history of disease and unreleased criminal records, etc.

2.     personal information on which one may hold a defensive expectation or a utilization expectation; and

3.     general information that has no traits of privacy at all.

 

The BIC holds, because one’s friends list and reading data do not constitute private information as listed in layer 1 in the above classification, Tencent is not liable for invasion of the plaintiff’s privacy.

 

The BIC goes on to reason that one’s friends list and reading data shall be classified under layer 2 in the above classification, where the information is considered personal but not private and therefore the emphasis of protection is to give the data subject a right to decide whether to hide or to use such information.

 

The BIC further holds that in this case the plaintiff did not get the chance to decide how to deal with her personal information, because Tencent failed to give proper and transparent notices to the plaintiff and failed to obtain her affirmative consent before utilizing the information under dispute. The BIC then decides that Tencent should be held liable for violation of the plaintiff’s legitimate interests in her personal information. The BIC’s decision is majorly based on Article 43 of the Cybersecurity Law of China. [2]

Discussion

1.    What is Privacy?

According to Eric Hughes, an American mathematician, computer programmer, and cypherpunk, “Privacy is the power to selectively reveal oneself to the world.” [3] Broadly speaking, privacy is the right to be let alone, or freedom from interference or intrusion. Information privacy is the right to have some control over how your personal information is collected and used.[4]

 

The Civil Code of China (2021) defines privacy as peace in a person’s private life and the private space, private activities and private information that a person does not intend for others to know.[5]

 

As a governing law, the Civil Code’s definition of privacy is vague. As we know, privacy varies greatly from person to person: while one person may be comfortable with showing his or her diet recipe online, another person may be embarrassed to let others know how little (or how much) he or she eats over a meal. Similarly, while one person may be at ease with disclosing many details of his or her personal life to online social connections, another person may feel ashamed of posting anything personal on the internet. So exactly what kind of privacy does the Civil Code protect? Some guidance from a concurring opinion in a US Supreme Court decision might shed some light on this.

 

2.    Reasonable Expectation of Privacy

To define the right to privacy under the Fourth Amendment, [6]  the US Supreme Court Justice John Marshall Harlan, in his concurring opinion in Katz, [7]  formulated a “reasonable expectation of privacy” test. The test has two prongs:

1)     the person must exhibit an “actual (subjective) expectation of privacy”; and

2)     society recognizes the expectation as “reasonable.”

The Katz “reasonable expectation of privacy” test, while particularly useful in terms of defining privacy, also provokes further questions: what is reasonable? where to draw the line between “reasonable” expectation and expectation that is “unreasonable”? These questions matter hugely in today’s digital world, because every time a user creates a new account at an online platform, the user provides information with personal details, including name, birthdate, geographic location, and personal interests, etc. Users are entitled to know if they can have a “reasonable expectation of privacy” in such information and if such expectation could be respected by the platform.

 

3.    Exceptions to the Reasonable Expectation of Privacy

 

There are several recognized exceptions to the reasonable expectation of privacy, such as the Third-Party Doctrine, which means once an individual invests a third party with information, and voluntarily agrees to share information with a recipient, the individual loses any reasonable expectation of privacy in that information, [8] and the Voluntary consent Doctrine, which means individuals lose a reasonable expectation of privacy when they consent to a search of private information.[9]Other exceptions include the following: unlawful information is not protectable by the law and therefore there should be no reasonable expectation of privacy,[10] and public disclosure of private information will cause forfeiture of any reasonable expectation of privacy.[11]

 

4.    Where did the Court draw the Line?

 

The BIC obviously referenced the Katz test by reasoning that “the privateness in the information that one does not intend to disclose depends on a subjective intent, however, such subjective intent shall be reasonably recognized by the society.”

 

Then the BIC made the point that the information about one’s social relationship could only invoke reasonable expectation of privacy under the following circumstances: the relationship between the data subject and certain connections would be too intimate to let others know, or the disclosure of some social relationship would negatively affect the data subject’s social image.

 

With respect to the book reading data, the BIC made another similar point that one could only have reasonable expectation of privacy in one’s reading data if certain reading contents fall into some private and secret information region or the reading data, when generated at certain amounts, would reflect negatively on the data subject.

 

Then the BIC commented that the plaintiff’s online social relationship, i.e., the listed friends, is being identified by open-ID, profile and nickname, which should not show the real social relationship or the degree of intimacy between the plaintiff and her social connections. The BIC also went through the contents of the plaintiff’s reading data and found that neither of the two books displayed to her connections would cause any damage to the plaintiff’s social image. The plaintiff’s reading data therefore should not be categorized as private information, hence no reasonable privacy expectation in the data.

 

In a nutshell, the BIC was defining “reasonable expectation of privacy” in the digital world based on the content of certain information. If a piece of information contains nothing intimate or cannot reflect negatively on the data subject, then the data subject should not have a “reasonable expectation of privacy” in the information. The content-based approach is how the BIC drew the line between privacy and non-privacy related information.

 

5.    Content-based Approach is not Fair

 

The BIC’s views on this issue are deeply disturbing. Back to the definition of privacy, broadly speaking, privacy is the right to be “let alone”. It means when a person walks into an isolated space, the person could expect to be in a state in which one is not observed or disturbed by other people,[12] as long as nothing illegal is ongoing under the roof. By applying the Katz test, this person has a reasonable expectation of privacy because the person demonstrates a subjective expectation of privacy by “walking into the isolated space”, which is well recognized by the society as reasonable.  Furthermore, the person’s act does not fall into any of the aforesaid exceptions.

 

 In solitude, a decent citizen could expect the same degree of privacy as much as anyone would. The right to privacy does not depend on whether something shameful is being conducted inside that isolated space. The right to privacy does not depend on the activity happened inside. Instead, it depends on whether one’s demonstration of intent to be let alone could be accepted as reasonable by the society. However, under the content-based approach, a decent citizen would have less expectation of privacy than someone who conducts shameful behaviour in solitude, and this approach apparently leads to unfair results.

 

Here comes the digital world version of the above scenario. When an individual, like the plaintiff Huang, subscribes to open an account at an online platform, like WeRead, and secures it with a password, this would create an isolated space where this person could expect digital privacy. By applying the Katz test, this individual has a reasonable expectation of privacy as he or she demonstrates a subjective expectation of privacy by “creating a password-secured account”, which is well recognized by the society as reasonable.  Likewise, the person’s act does not fall into any of the aforesaid exceptions.

 

This person is fully entitled to assert a digital privacy right to be “let alone”. One can choose not to have any improper friends, and not to read any obscene books, but can still enjoy full privacy rights over one’s personal information. It literally means that being a decent netizen should not compromise one’s digital privacy rights. The content of the information stored in a password-secured account, if it is nothing unlawful, should not dictate if and how the person would enjoy the right to privacy.

 

The above scenario shows that the content-based approach taken by the BIC is not fair because it makes users’ digital privacy rights conditional on the content of personal information, i.e., if the information includes any embarrassing content or not. This approach leads to the unfair conclusion that being a decent netizen, one has nothing shameful to hide and therefore would not have reasonable expectation of digital privacy.

 

Conclusion

 

With the storage and processing of exabytes of data, social media users’ concerns about their privacy have been on the rise in recent years. Incidents of illegal use of data and data breaches have alerted many users and caused them to reconsider their interaction with social media and the security of their personal data.

The disputes caused by unauthorized use of personal information over the internet have spiked in the privacy law landscape. The Beijing Internet Court’s present decision, which echoes with the same court’s decision on the “Dou Yin (Tik Tok Chinese version) collection of personal information” case, [13] is among the first few decisions made by Chinese courts on this controversial issue. Significantly, the decision might impact ongoing litigation stemming from similar disputes. Other courts around the country might follow suit. Therefore, it is imperative to have a more clear and fair approach towards defining reasonable digital privacy expectation.

In the era of big data, defining privacy is under pressure in the digital world. As Bill Gates put it: “whether it’s digital cameras or satellites or just what you click on, we need to have more explicit rules — not just for governments but for private companies.” [14]

 

 




[1] Beijing Internet Court, (2019) Jing 0491Min Chu Zi No. 16142.

[2]  China Cybersecurity Law, Article 43, provides, “Where an individual finds that any network operator collects or uses his or her personal information in violation of the provisions of any law, administrative regulation or the agreement of both parties, the individual shall be entitled to request the network operator to delete his or her personal information. If the individual finds that his or her personal information collected or stored by the network operator has any error, he or she shall be entitled to request the network operator to make corrections. The network operator shall take measures to delete the information or correct the error.”

[3] Eric Hughes, The Cypherpunk Manifesto (1993), see https://www.activism.net/cypherpunk/manifesto.html.

[4] See https://iapp.org/about/what-is-privacy/.

[5] Article 1032, China Civil Code (2021).

[6] The Fourth Amendment of the US Constitution, ratified on December 15, 1791, protects the right of people “to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures.”

[7]See Katz v. United States, 389 U.S. 347 (1967). Concurring opinion written by Justice Harlan.

[8] See Smith v. Maryland, 442 U.S. 735, 743-44 (1979).

[9] See Katz v. United States, 389 U.S. 347 (1967).

[10] See https://civillaw.com.cn/bo/t/?id=37410.

[11] Ibid.

[12] See https://www.igi-global.com/dictionary/privacy-data-protection-towards-elderly/23405.

[13]See Beijing Internet Court, (2019) Jing 0491Min Chu Zi No. 6694.

[14] See https://www.oipc.bc.ca/news/quote-of-the-day-bill-gates/.


  • 相关资讯 More
  • 点击次数: 0
    2026 - 06 - 08
    2020年9月国务院国资委印发《关于加快推进国有企业数字化转型工作的通知》,明确提出要“构建数据治理体系”,定期评估数据治理能力成熟度,要求“以构建企业数字时代核心竞争能力为主线,制定数字化转型方案,纳入企业年度工作计划”后,我国数据基础制度建设进入快车道。继《民法典》《个人信息保护法》《数据安全法》等法律法规为数据安全与流通合规奠定基础后,2022年中共中央、国务院印发《关于构建数据基础制度更好发挥数据要素作用的意见》(“数据二十条”),创新确立数据资源持有权、数据加工使用权、数据产品经营权“三权分置”框架,2026年4月3日国家数据局综合司发布关于向社会公开征求《数据产权登记工作指引(试行)》(公开征求意见稿),也加快构建了数据确权、登记、交易等基础制度。这一系列法律法规、政策文件的协同推进,也为国有企业数字化转型提供了发展新思路,如何推动国企数据要素从“资源”走向“资产”,从合规必答题转化为增值新引擎成为亟待深度探索的命题。一、国企数字化转型过程中面临的机遇与挑战国有企业作为国民经济“顶梁柱”,在数字化转型与高质量发展进程中,既面临战略机遇,也面临多重挑战。当前国企数字化转型过程可能存在两大挑战:一方面,数据资源甄别能力不足,国企在各行各业经营过程中可能积累了大量不同的业务数据,但对哪些数据资源可以申请产权登记、哪些数据资源可以入表、如何归集成本、怎样评估等存在模糊界限,导致大量潜在数据资产未能有效识别和挖掘;另一方面,数据产权界定复杂,因国企自身的所有制属性,其数据资源往往涉及政府部门、产业链上下游等多方主体,在数据持有权、加工使用权、产品经营权框架下,各方权责利边界尚未完全厘清,收益分配机制缺位,使得数据资源难以顺利转化为可确认、可计量的数据资产。二、为什么国企要重视数据资产入表根据财政部《企业数据资源相关会计处理暂行规定》,“企业合法拥有或控制的、预期会给企业带...
  • 点击次数: 1000031
    2026 - 04 - 10
    作者:金涟伊一、官网的定义与功能定位“官网”是“官方网站”的简称,在中国法律语境下,通常指由特定组织、企业或政府机构正式设立和运营的网站,使用经合法注册的域名(如.cn、.com.cn等)。官网应当完成ICP备案(非经营性)或取得ICP许可证(经营性),代表该主体的正式立场,具有公示和公信力。在实践中,政府官网使用.gov.cn域名,需经严格审批,且仅限政府机构注册。企业自称“官网”则主要受《反不正当竞争法》《广告法》约束,不得进行虚假宣传。本文主要聚焦于企业官网,即由企业自行或委托他人创建、注册和运营,代表企业意志、面向社会公众、展示企业信息的网站。企业官网通常包含首页、关于我们、产品(服务)中心、技术服务、新闻中心、联系我们等板块。它作为数字时代的核心商业基础设施,承载着多维度的功能。有些官网构成运营场所,用于展示产品/服务信息、技术参数、应用场景,发布促销活动、案例故事,有些官网还具有交易功能,如在线支付、订单管理。对于中小企业而言,官网更重要的功能是输出统一的视觉识别系统、品牌故事、企业价值观,进而为企业获得消费者信任。二、官网展示行为的法律定性如前所述,官网承载着对外展示企业形象、品牌美誉的功能,因此大部分官网都会展示企业相关产品。那么,企业在官网上发布自家产品及品牌的行为是否构成广告宣传,是否构成商标法意义上的使用?从广告法的角度来说,根据《广告法》第二条,商品经营者或者服务提供者通过一定媒介和形式直接或者间接地介绍自己所推销的商品或者服务的商业广告活动,适用本法。企业作为产品的生产者或者销售者,在自己所能控制的互联网空间中向不特定的人群介绍自己的产品或服务,符合广告法的定义,属于应当被广告法所规制的行为,即广告宣传行为。如果未介绍产品或服务,仅是单纯发布自身名称(姓名)、简称、商标、标识、经营范围、成立时间、发展历程、企业简介等信息,且未直接或者间接推销商品或...
  • 点击次数: 1000018
    2026 - 04 - 03
    作者:张嘉畅3月29日,歌手李荣浩在社交媒体上公开指出歌手单依纯在其演唱会“纯妹妹2.0”上演唱了《李白》一作,侵犯了自己的著作权。3月30日凌晨,单依纯长文回复致歉,并承诺不再演唱《李白》。此争议引发了大众的广泛讨论,大部分网友支持原创者维权,也有小部分网友支持新版本翻唱,也有一些过往的类似案件被再度提及。在本文中,笔者将对不同的观点从法律角度进行解读。 一、争议观点 著作权,又称版权,是作品的作者依法享有的权利。根据《著作权法》第十条,著作权包括“发表权”、“署名权”、“修改权”、“保护作品完整权”……等13项权利。在本次争议当中,网友提出了以下几种观点: (1)该行为侵犯了修改权 修改权,即修改,或者授权他人修改作品的权利。修改权属于人身权,只有作者本人或受到授权的人可以对作品进行修改。网络上有部分观点认为对歌曲进行再加工侵犯了作者的修改权。然而在本案中,因为《李白》一作已经发表,且翻唱并未对《李白》作品本身进行修改,不影响原作的呈现方式,所以笔者认为本案不涉及到侵犯修改权。 (2)改编作品具有独立著作权 其实,单依纯并非首次演唱《李白》。早在去年的《歌手2025》节目上,单依纯团队就已对《李白》一歌进行了改编和翻唱。有小部分网友依据《著作权法》第十三条提出观点,认为单依纯团队对改编后的《李白》享有著作权,因此其演唱行为并无不当。但这一说法在法律上并非没有争议。首先,对于公众而言,目前并不清楚《歌手 2025》节目录制时,双方就《李白》一歌的改编权具体是如何约定的,权利基础尚不明确。其次,从司法实践来看,法院在类似案件中已形成较为一致的裁判观点:改编后的作品能否产生独立的著作权,核心取决于改编过程中新增的创作部分是否具备独创性。具体到本案,新增的念白与编曲是否达到独创性标准、能否构成新的作品,仍需要结合行业标...
  • 点击次数: 10000011
    2026 - 03 - 13
    作者:杨秀芸2021年,《刑法修正案(十一)》将“服务商标”作为假冒注册商标罪的对象之一,赋予了其和“商品商标”同等的受保护地位。这一立法完善,为规制新型服务领域商标侵权行为提供了明确法律依据。本文评析的黃某等人假冒注册商标罪案,正是这一立法背景下,司法实践打击“傍名牌”式服务侵权的典型案例。 一、基本案情 1、案件背景与事实2020至2023年3月,被告人黄某先后经营多家公司,雇佣被告人王某,未经注册商标所有人许可,在上海、沈阳、武汉等地开展带有“DIOR”注册商标的儿童时装表演活动,以此收取报名费用。 2、涉案金额与权利基础经审计查明:1、被告人黄某:共组织7场带有“DIOR”注册商标的时装表演活动,违法所得共计人民币80余万元;2、被告人王某:参与组织其中4场时装表演活动,个人违法所得50余万元。3、权利基础:“DIOR”商标在我国被核定使用的服务类别包括第41类“组织和安排文化、艺术、教育和体育讨论会、报告会或代表大会、时装表演”等,注册号为G1102827,注册有效期经续展至2031年11月18日。 3、裁判结果一审判决(上海市浦东新区人民法院,案号:(2025)沪0115刑初857号):被告人黄某犯假冒注册商标罪,判处有期徒刑三年六个月,并处罚金人民币160万元;被告人王某犯假冒注册商标罪,判处有期徒刑一年,缓刑一年,并处罚金人民币5万元。宣判后,被告人黄某提出上诉。 二审裁定(上海市第三中级人民法院,案号:(2025)沪03刑终52号):驳回上诉,维持原判。 二、争议焦点与法律分析本案审理过程中,法院重点厘清了服务商标侵权的刑法适用边界、量刑标准及共同犯罪责任划分三个核心问题。 (一)服务商标侵权的刑法适用被告人黄某辩称,其使用“DIOR”标识,系为了指示服务中使用的“DIOR”服装,属合理...
× 扫一扫,关注微信公众号
铭盾MiNGDUN   www.mdlaw.cn                                               犀牛云提供企业云服务 
Copyright© 2008 - 2026 铭盾京ICP备14029762号-1                                                                                                                                隐私政策   免责声明       
X
1

QQ设置

3

SKYPE 设置

4

阿里旺旺设置

5

电话号码管理

6

二维码管理

展开