Language

The WeRead Case: Discussion on Reasonable Digital Privacy Expectation

Authored by Yingying Zhu

 

March 2021

Each of us leaves a lasting digital footprint on the internet and would expect businesses that we are dealing with could treat our digital privacy with reasonable care and consideration. Can users have a reasonable privacy expectation in the friends made and the books read online? The Beijing Internet Court in its recently released WeRead judgment holds that, friends list and reading data are not eligible for privacy protection in the case under dispute but nevertheless entitled to protection as personal information.

Background

The judgment is in relation to a dispute between an individual, Huang, a user of a book reading app named WeRead, and the digital giant, Tencent, the operator of the most successful social media in China, WeChat, and its sister app WeRead. The WeRead app wishes to set up an app-based reading community, where people who enjoy reading can read & connect. The plaintiff Huang was complaining that WeRead sneaked away her friends list from WeChat and then automatically turned those who are also subscribers of WeRead as her connections. Huang was also complaining that the information regarding the books she read and how she felt about the reading was widely open to all her connections without her permission while she intended to keep such information private. In its defense, the defendant Tencent alleged that users’ friends list and reading data were obtained with a preapproval from users therefore it should not be held liable for the utilization of the data.

Decision of Beijing Internet Court[1]

The Beijing Internet Court (hereinafter the “BIC”), the Court of First Instance, decides that Huang’s friends list and reading data shall not be categorized as private information, hence not eligible for privacy protection.

To define what constitutes private information, the BIC’s reasoning is based on the classification of the following three layers of personal information:

1.     personal information reasonably recognized by the society as private information, such as one’s sextual orientation, sex life, history of disease and unreleased criminal records, etc.

2.     personal information on which one may hold a defensive expectation or a utilization expectation; and

3.     general information that has no traits of privacy at all.

 

The BIC holds, because one’s friends list and reading data do not constitute private information as listed in layer 1 in the above classification, Tencent is not liable for invasion of the plaintiff’s privacy.

 

The BIC goes on to reason that one’s friends list and reading data shall be classified under layer 2 in the above classification, where the information is considered personal but not private and therefore the emphasis of protection is to give the data subject a right to decide whether to hide or to use such information.

 

The BIC further holds that in this case the plaintiff did not get the chance to decide how to deal with her personal information, because Tencent failed to give proper and transparent notices to the plaintiff and failed to obtain her affirmative consent before utilizing the information under dispute. The BIC then decides that Tencent should be held liable for violation of the plaintiff’s legitimate interests in her personal information. The BIC’s decision is majorly based on Article 43 of the Cybersecurity Law of China. [2]

Discussion

1.    What is Privacy?

According to Eric Hughes, an American mathematician, computer programmer, and cypherpunk, “Privacy is the power to selectively reveal oneself to the world.” [3] Broadly speaking, privacy is the right to be let alone, or freedom from interference or intrusion. Information privacy is the right to have some control over how your personal information is collected and used.[4]

 

The Civil Code of China (2021) defines privacy as peace in a person’s private life and the private space, private activities and private information that a person does not intend for others to know.[5]

 

As a governing law, the Civil Code’s definition of privacy is vague. As we know, privacy varies greatly from person to person: while one person may be comfortable with showing his or her diet recipe online, another person may be embarrassed to let others know how little (or how much) he or she eats over a meal. Similarly, while one person may be at ease with disclosing many details of his or her personal life to online social connections, another person may feel ashamed of posting anything personal on the internet. So exactly what kind of privacy does the Civil Code protect? Some guidance from a concurring opinion in a US Supreme Court decision might shed some light on this.

 

2.    Reasonable Expectation of Privacy

To define the right to privacy under the Fourth Amendment, [6]  the US Supreme Court Justice John Marshall Harlan, in his concurring opinion in Katz, [7]  formulated a “reasonable expectation of privacy” test. The test has two prongs:

1)     the person must exhibit an “actual (subjective) expectation of privacy”; and

2)     society recognizes the expectation as “reasonable.”

The Katz “reasonable expectation of privacy” test, while particularly useful in terms of defining privacy, also provokes further questions: what is reasonable? where to draw the line between “reasonable” expectation and expectation that is “unreasonable”? These questions matter hugely in today’s digital world, because every time a user creates a new account at an online platform, the user provides information with personal details, including name, birthdate, geographic location, and personal interests, etc. Users are entitled to know if they can have a “reasonable expectation of privacy” in such information and if such expectation could be respected by the platform.

 

3.    Exceptions to the Reasonable Expectation of Privacy

 

There are several recognized exceptions to the reasonable expectation of privacy, such as the Third-Party Doctrine, which means once an individual invests a third party with information, and voluntarily agrees to share information with a recipient, the individual loses any reasonable expectation of privacy in that information, [8] and the Voluntary consent Doctrine, which means individuals lose a reasonable expectation of privacy when they consent to a search of private information.[9]Other exceptions include the following: unlawful information is not protectable by the law and therefore there should be no reasonable expectation of privacy,[10] and public disclosure of private information will cause forfeiture of any reasonable expectation of privacy.[11]

 

4.    Where did the Court draw the Line?

 

The BIC obviously referenced the Katz test by reasoning that “the privateness in the information that one does not intend to disclose depends on a subjective intent, however, such subjective intent shall be reasonably recognized by the society.”

 

Then the BIC made the point that the information about one’s social relationship could only invoke reasonable expectation of privacy under the following circumstances: the relationship between the data subject and certain connections would be too intimate to let others know, or the disclosure of some social relationship would negatively affect the data subject’s social image.

 

With respect to the book reading data, the BIC made another similar point that one could only have reasonable expectation of privacy in one’s reading data if certain reading contents fall into some private and secret information region or the reading data, when generated at certain amounts, would reflect negatively on the data subject.

 

Then the BIC commented that the plaintiff’s online social relationship, i.e., the listed friends, is being identified by open-ID, profile and nickname, which should not show the real social relationship or the degree of intimacy between the plaintiff and her social connections. The BIC also went through the contents of the plaintiff’s reading data and found that neither of the two books displayed to her connections would cause any damage to the plaintiff’s social image. The plaintiff’s reading data therefore should not be categorized as private information, hence no reasonable privacy expectation in the data.

 

In a nutshell, the BIC was defining “reasonable expectation of privacy” in the digital world based on the content of certain information. If a piece of information contains nothing intimate or cannot reflect negatively on the data subject, then the data subject should not have a “reasonable expectation of privacy” in the information. The content-based approach is how the BIC drew the line between privacy and non-privacy related information.

 

5.    Content-based Approach is not Fair

 

The BIC’s views on this issue are deeply disturbing. Back to the definition of privacy, broadly speaking, privacy is the right to be “let alone”. It means when a person walks into an isolated space, the person could expect to be in a state in which one is not observed or disturbed by other people,[12] as long as nothing illegal is ongoing under the roof. By applying the Katz test, this person has a reasonable expectation of privacy because the person demonstrates a subjective expectation of privacy by “walking into the isolated space”, which is well recognized by the society as reasonable.  Furthermore, the person’s act does not fall into any of the aforesaid exceptions.

 

 In solitude, a decent citizen could expect the same degree of privacy as much as anyone would. The right to privacy does not depend on whether something shameful is being conducted inside that isolated space. The right to privacy does not depend on the activity happened inside. Instead, it depends on whether one’s demonstration of intent to be let alone could be accepted as reasonable by the society. However, under the content-based approach, a decent citizen would have less expectation of privacy than someone who conducts shameful behaviour in solitude, and this approach apparently leads to unfair results.

 

Here comes the digital world version of the above scenario. When an individual, like the plaintiff Huang, subscribes to open an account at an online platform, like WeRead, and secures it with a password, this would create an isolated space where this person could expect digital privacy. By applying the Katz test, this individual has a reasonable expectation of privacy as he or she demonstrates a subjective expectation of privacy by “creating a password-secured account”, which is well recognized by the society as reasonable.  Likewise, the person’s act does not fall into any of the aforesaid exceptions.

 

This person is fully entitled to assert a digital privacy right to be “let alone”. One can choose not to have any improper friends, and not to read any obscene books, but can still enjoy full privacy rights over one’s personal information. It literally means that being a decent netizen should not compromise one’s digital privacy rights. The content of the information stored in a password-secured account, if it is nothing unlawful, should not dictate if and how the person would enjoy the right to privacy.

 

The above scenario shows that the content-based approach taken by the BIC is not fair because it makes users’ digital privacy rights conditional on the content of personal information, i.e., if the information includes any embarrassing content or not. This approach leads to the unfair conclusion that being a decent netizen, one has nothing shameful to hide and therefore would not have reasonable expectation of digital privacy.

 

Conclusion

 

With the storage and processing of exabytes of data, social media users’ concerns about their privacy have been on the rise in recent years. Incidents of illegal use of data and data breaches have alerted many users and caused them to reconsider their interaction with social media and the security of their personal data.

The disputes caused by unauthorized use of personal information over the internet have spiked in the privacy law landscape. The Beijing Internet Court’s present decision, which echoes with the same court’s decision on the “Dou Yin (Tik Tok Chinese version) collection of personal information” case, [13] is among the first few decisions made by Chinese courts on this controversial issue. Significantly, the decision might impact ongoing litigation stemming from similar disputes. Other courts around the country might follow suit. Therefore, it is imperative to have a more clear and fair approach towards defining reasonable digital privacy expectation.

In the era of big data, defining privacy is under pressure in the digital world. As Bill Gates put it: “whether it’s digital cameras or satellites or just what you click on, we need to have more explicit rules — not just for governments but for private companies.” [14]

 

 




[1] Beijing Internet Court, (2019) Jing 0491Min Chu Zi No. 16142.

[2]  China Cybersecurity Law, Article 43, provides, “Where an individual finds that any network operator collects or uses his or her personal information in violation of the provisions of any law, administrative regulation or the agreement of both parties, the individual shall be entitled to request the network operator to delete his or her personal information. If the individual finds that his or her personal information collected or stored by the network operator has any error, he or she shall be entitled to request the network operator to make corrections. The network operator shall take measures to delete the information or correct the error.”

[3] Eric Hughes, The Cypherpunk Manifesto (1993), see https://www.activism.net/cypherpunk/manifesto.html.

[4] See https://iapp.org/about/what-is-privacy/.

[5] Article 1032, China Civil Code (2021).

[6] The Fourth Amendment of the US Constitution, ratified on December 15, 1791, protects the right of people “to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures.”

[7]See Katz v. United States, 389 U.S. 347 (1967). Concurring opinion written by Justice Harlan.

[8] See Smith v. Maryland, 442 U.S. 735, 743-44 (1979).

[9] See Katz v. United States, 389 U.S. 347 (1967).

[10] See https://civillaw.com.cn/bo/t/?id=37410.

[11] Ibid.

[12] See https://www.igi-global.com/dictionary/privacy-data-protection-towards-elderly/23405.

[13]See Beijing Internet Court, (2019) Jing 0491Min Chu Zi No. 6694.

[14] See https://www.oipc.bc.ca/news/quote-of-the-day-bill-gates/.


  • 相关资讯 More
  • 点击次数: 0
    2026 - 09 - 18
    从权利人视角:结构专利“相同或等同”的侵权判定之道                                                                    刘艳玲在机械装备、医疗器械行业,原封不动的“照抄式”侵权正逐步减少。更常见的是竞争对手拿走专利的核心结构构思,做形式上的改动:把螺栓连接改成焊接、把外壳支撑改成独立支架,甚至更换核心零部件后带动相邻零件“配套修改“”——改动一个,牵动一片。这样专利权人还能否成功主张专利侵权?这直接指向专利侵权判定中的技术特征相同或等同的认定规则。同时也衍生出新的思考,AI技术广泛应用的背景下,应当如何把握技术特征的等同认定标准。      一、判定基石:全面覆盖原则《专利法》第六十四条第一款规定,发明或者实用新型专利权的保护范围以权利要求的内容为准,说明书及附图可以用于解释。在此基础上,《最高人民法院关于审理侵犯专利权纠纷案件应用法律若干问题的解释》(下称《侵权解释一》)第七条确立了“全面覆盖原则”:被诉侵权技...
  • 点击次数: 3
    2026 - 09 - 09
    伴随新业态经济的快速持续发展,依托互联网平台的新就业形态从业规模不断扩大,劳动者与平台企业之间的法律关系日趋复杂,有的不良平台企业以“承揽合同”“自由职业者合作协议”等民事协议之名行直接用工之实,有的通过关联企业混同用工规避法律责任,有的公然要求劳动者自带车辆完成配送等等,给传统劳动关系的认定带来了很大冲击和挑战。这种形势下,劳动者权益如何保障?企业发展活力如何兼顾?这是司法必须回应的时代之问。【基本案情】2024年初,平台企业某驴公司发布广告称,在某市区公开招聘配送司机,要求应聘司机自带车内空间七方以上的面包车型车辆;在配送时间方面,要求配送司机半夜23时前到达仓库,配送在上午8-9时结束;月薪12000至18000元。作业内容对配送区域、配送食材以及司机的年龄、驾龄要求进行了具体描述;同时,要求配送司机熟悉基本手机软件操作,能够独立使用APP软件进行送货、签到、打卡等等。失业已有三月的袁先生,得知此消息兴奋不已,自己各方面条件都符合招聘要求,面对如此高薪,怎能在家“坐吃山空”,赶紧挣钱养家才是男人第一大要务。袁先生的应聘非常顺利,很快被录用。在办理入职过程中,某驴公司先是要求其在公司运营的APP软件注册,随后引导其与公司签订了承揽合同,并将其拉入工作微信群。一切都很顺利,一切又似乎让人迷茫。接下来的两年里,老实巴交的袁先生总是在夜间提前到达仓库,提前在APP里签到打卡,然后根据仓库领导在微信群里的工作安排,对配送的货物进行分拣、装车,再送往各个餐饮店,通常在次日上午10点配送结束后回到家里。几次因途中堵车延误时间,遭到客户投诉及某驴公司罚款。时不时接受某驴公司对全体配送司机的培训教育。老家有红白喜事,必须先在微信群向领导请假,获批后方可离开。两年来,袁先生虽有委屈,虽然辛苦,但每月看到某驴公司转给自己的一万多元的“收入”,心理还是有些许安慰的。然而,天有不测风云。202...
  • 点击次数: 7
    2026 - 08 - 17
    引言:创造性判断中,申请人常以“现有技术给出了反向教导”为由主张技术方案非显而易见。那么,什么情况下才能成立反向教导?最高人民法院在(2023)最高法知行终413号案中给出了明确裁判思路。为进一步理解这一标准,我们结合具体案件分析及相关案例一并探讨。一、基本案情德国某公司申请的发明专利“导线连接接触元件”(申请号20181015****.3)被国家知识产权局以不具备创造性为由驳回。复审及一审均维持驳回决定。申请人上诉至最高人民法院,核心理由之一是:对比文件1公开的结构给出了针对区别技术特征的反向教导,本领域技术人员不会作出本申请的改进。最高人民法院于2024年12月24日作出(2023)最高法知行终413号行政判决,驳回上诉,维持原判。二、裁判要旨最高人民法院明确指出:所谓的反向教导属于创造性评价中判断技术启示时可能涉及的问题。判断现有技术是否存在反向教导,应当以发明实际解决的技术问题为基础,如果现有技术公开的内容不构成本领域技术人员解决发明实际解决的技术问题的障碍,则通常不认为其构成反向教导。简言之,反向教导的认定必须锚定在发明实际解决的技术问题上,而非孤立地看待对比文件中的某个结构或功能。三、具体案例分析本案中,本申请权利要求1相对于对比文件1的区别技术特征主要在于提供了一种不同结构的SMD焊接接触件。该接触件并未保留对比文件1中的“摆动抑制作用”,也未实现其他新功能,其核心作用仍是提供支撑面。申请人主张对比文件1因强调摆动抑制功能而构成反向教导。法院对此不予支持,理由如下:以实际解决的技术问题为判断基准 本申请实际解决的技术问题并非“如何实现摆动抑制”,而是提供一种具有支撑功能的SMD焊接接触件结构。对比文件1公开的摆动抑制部位置和结构,并不妨碍本领域技术人员在此基础上进行简化或调整。放弃原有功能不必然构成反向教导 本领域技术人员完全可以从对比文件1公开的结构出发,放...
  • 点击次数: 7
    2026 - 08 - 07
    在侵权赔偿纠纷中,受害人自身疾病或特殊体质与侵权行为结合给受害人造成同一损害或导致损害扩大时,侵权人往往以此为由主张免除或减轻赔偿责任。对此,司法机关是如何考量的呢?本文即以案释法,对此进行分析探讨。一、典型案例(一)案例1:参见(2020)京01民终6829号民事判决书1.基本案情2018年3月21日,孙某到提供游泳服务的某公司处游泳,由于某公司工作人员在游泳池内尚有人在游泳时,将游泳池外围地面处铺设的防滑网垫移开,并用水冲洗游泳池外地面淤泥及桌椅,导致孙某从游泳池内出来后,在游泳池外围的地面滑倒后摔伤。当日,孙某即被送往医院紧急就诊,后住院治疗。住院病历诊断:1.颈椎外伤,无骨折脱位型颈脊髓损伤;2.冠状动脉粥样硬化性心脏病,陈旧性心梗,支架植入术后,心功能II级;3.高血压病3级,极高危;4.陈旧脑梗塞;5.高血脂症;6.II型糖尿病。手术志摘要:颈后正中纵切口12cm,充分暴露C3-7棘突及椎板,逐层缝合关闭切口。后孙某起诉至法院。案件审理过程中,某公司申请对孙某的医疗费合理性进行鉴定,鉴定中心表示,孙某自身患有先天性颈椎狭窄的疾病,这次摔伤加重了孙某的病情,且鉴定意见第2项中有控制高血压、血糖等用药,建议住院后产生的医疗费用外伤的原因力的诱发因素不超过50%。孙某向一审法院起诉请求:判令某公司支付孙某医疗费102991.85元、住院伙食补助费1600元、营养费4500元、护理费6700元、误工费10687元、交通费200元、精神损失费5000元,以上共计131678.85元。2.法院裁判要旨及判决结果(1)裁判要旨一审法院认为,我国侵权责任法规定,宾馆、商场、银行、车站、娱乐场所等公共场所的管理人或者群众性活动的组织者,未尽到安全保障义务,造成他人损害的,应当承担侵权责任。侵害他人造成人身损害的,应当赔偿医疗费、护理费、交通费等为治疗和康复支出的合理费用,以及因误...
× 扫一扫,关注微信公众号
铭盾MiNGDUN   www.mdlaw.cn                                               犀牛云提供企业云服务 
Copyright© 2008 - 2026 铭盾京ICP备14029762号-1                                                                                                                                隐私政策   免责声明       
X
1

QQ设置

3

SKYPE 设置

4

阿里旺旺设置

5

电话号码管理

6

二维码管理

展开