Crypto

DeFi Gives Financial Privacy — Will Regulation Take It Away?

The Fourth Amendment

The Fourth Amendment safeguards our privacy interests in things we keep private. The government can’t, for example, search our homes or computers unless it has a warrant supported by particular probable cause to think the search will reveal evidence of a crime.

Nor may the government simply drag us into court to give testimony that would produce such evidence of crime: that protection comes from the Fifth Amendment’s privilege against self-incrimination.

By contrast, the Fourth Amendment has been interpreted as offering very little protection for material we hand to third parties — even a single trusted one, like a bank. This “third-party doctrine,” which is central to the government’s authority to collect information from financial intermediaries, allows the government to obtain transaction data from businesses with ease, and without a search warrant or probable cause. (The Court has also upheld requirements that banks maintain records of financial transactions.[1])

The third-party doctrine, whether for good or ill, is firmly in place. But when technological change — such as DeFi (decentralized finance) — removes the third party, the government can no longer rely on the third-party doctrine to watch those transactions.

That then raises the issue: May the government ban such DeFi tools, and compel people to use third-party intermediaries, precisely so it can take advantage of the added surveillance authority the third-party doctrine would supply?

The relationship between coders and users

That question has become even more significant in the setting of developing web3 technologies, with consequences for coders, customers, and entrepreneurs.

The relationships between coders and users

Take one proposal that has circulated in recent years: requiring developers of DeFi products (whom we’ll call “coders” for brevity) to comply with “know your customer” rules for the users of those products. At present, the developers have no existing business relationship — and therefore no information-gathering power — as to their end users.

But suppose the government requires coders to monitor their users’ conduct. Such a requirement would in practice bar the creation of intermediary-free, off-the-shelf DeFi protocols and code that any third party may use. Some argue that parts of the Infrastructure Investment and Jobs Act (HR 3684), enacted in mid-November, could be construed by the government as creating just such an obligation for coders.[2]

Suppose the government requires coders to monitor their users’ conduct. Such a requirement would in practice bar the creation of intermediary-free, off-the-shelf DeFi protocols and code that any third party may use.

I believe that is the wrong reading of the statute, but assume instead that the statute is in fact read that way, specifically to halt the development of technologies the government views as too effective at preserving financial privacy. A government enforcement agency might think DeFi platforms are enabling tax evasion; by requiring DeFi coders to generate tax returns for transfers made under the protocol, the agency would force the coders to give up their aim of supplying hands-off, off-the-shelf DeFi technology. The coders would instead need to become exchanges, dealing directly with users and collecting users’ information.

How law has lagged behind evolving technology

That possible interpretation of the statute would intentionally push people away from conduct covered by strong Fourth Amendment protection (transactions without third parties) and toward conduct covered by weaker Fourth Amendment protection (transactions involving third parties). Below, I’ll explain why I think this kind of restriction on privacy-protecting technologies may itself violate the Fourth Amendment.

Evolving technology, lagging law

The core of the third-party doctrine is that “the issuance of a subpoena to a third party to obtain the records of that party does not violate the [Fourth Amendment] rights” of the person to whom the records relate.[3] The legal system “has a right to every man’s evidence,”[4] including evidence from businesses that have learned something about you while doing business. If you bring such financial intermediaries into your financial transactions, your privacy becomes exposed.

And technology has made that exposure worse. When our transactions were mainly face-to-face cash dealings, there were no financial intermediaries for the government to subpoena. The government could in theory subpoena the people we dealt with, but those people would often be difficult to locate, or they might not recall who handed over cash for something three months earlier. Technology has vastly expanded our commercial possibilities by letting us deal with people at a distance; but because that has depended on checks, credit cards, and similar tools, it has added intermediaries. The outcome: far more convenience but far less privacy.

The balance of power is moving back from the government to individuals. And, as expected, the government is considering how to move that balance back to itself.

From cash, to credit cards, to DeFi

Now enters modern financial technology: By allowing us to eliminate the intermediary, it lets us have the old advantages of cash along with the modern advantages of electronic transactions. The balance of power is moving back from the government to individuals. And, as expected, the government is considering how to move that balance back to itself. To sketch a timeline:

A right to use rights-protecting technologies?Possible violations of the Fourth Amendment

Still, a requirement that coders track who uses their code — in effect, a ban on privacy-protecting financial technologies — may well run afoul of the Fourth Amendment. That conclusion is itself a reason not to read HR 3684 as reaching coders: When there are “competing plausible interpretations of a statutory text,” “the canon of constitutional avoidance” chooses “the reasonable presumption that Congress did not intend the alternative which raises serious constitutional doubts.”[5] And that conclusion may also provide a basis for striking down any statutory provisions that are in fact construed this broadly.

Injecting third parties precisely to facilitate surveillance

To start with, if the government aims to halt the creation and spread of intermediary-less DeFi code,[6] it would be doing so specifically in order to restore the third party — not because of financial need (as when a third party historically had to exist for electronic transactions), but for the convenience of surveillance.[7] The third-party doctrine rests on the idea that “a person has no legitimate expectation of privacy in information he voluntarily turns over to third parties,” because he “assume[s] the risk that the [third party] would reveal to police the [information].”[8] If the government removes the option of a private transaction, and compels information to be handed to third parties, then the handing over is no longer truly voluntary. Nor are such people taking on the risk of disclosure: the government, by mandate, is imposing that risk on them.[9]

If the government aims to halt the creation and spread of intermediary-less DeFi code, it would be doing so specifically in order to restore the third party — not because of financial need but for the convenience of surveillance.

Similarly, the third-party doctrine is based on the view that, once a person passes informa­tion to a third party, that person “is deemed to surrender any privacy interest he may have had” in that information.[10] So if the government bans privacy-preserving technologies precisely to bring third parties back into transactions, it would be forcing people to “surrender” their “privacy interest[s]” that the Fourth Amendment would otherwise protect — something the government may not compel.

Prohibitions on privacy-protecting tools

By way of analogy: The Court has said that when a car driver is arrested, (1) police may inspect the passenger compartment for weapons that might be within the driver’s reach without showing probable cause, but (2) they may not inspect a separately locked trunk. Suppose a state ordered that every car on the road have no separate trunk at all (that is, that cars must be SUVs, hatchbacks, or station wagons), specifically so that drivers would have fewer Fourth Amendment protections.[11] Or, by extending the analogy to the broad reading of HR 3684, imagine a state imposing impossible recordkeeping duties on manufacturers of cars with separate trunks: Say the manufacturers had to report the names and addresses of everyone who drives such a trunk-less car, even though the manufacturers have no business relationship with many drivers (who may have bought or borrowed a car from a third party).

Suppose a state required that all cars on the road have no separate trunk, specifically so that drivers would have fewer Fourth Amendment protections.

Although there is no precedent directly on point, this would probably be unconstitutional as an evasion of the ordinary Fourth Amendment rules. Just as the government cannot, for example, get around the Fifth Amendment’s ban on “be[ing] compelled in any criminal case to be a witness against [your]self” by forcing you to testify in a civil case and then using that information in a criminal case,[12] it should not be able to evade the Fourth Amendment’s privacy protection by depriving you of privacy-protecting tools.

Constitutional rights to technologies that protect other constitutional rightsThe courts and technology

Indeed, courts have long acknowledged that some technologies are needed to safeguard constitutional rights, and that barring their use would therefore violate those rights. For example, lower courts have held that the First Amendment includes the right to video-record government employees (such as police officers) in public places.[13] The courts started from the premise that the public has a First Amendment right to “access … information about their officials’ public activities.”[14] They therefore concluded that the First Amendment must also protect the technology required to gather that information effectively — technology that allows one to “record what there is the right for the eye to see or the ear to hear,” “corroborat[ing] or lay[ing] aside subjective impressions for objective facts.”[15]

Of course, for much of the nation’s history, that kind of spontaneous video-recording was simply not technologically available, at least for ordinary laypeople. But once the technology exists, the government may not ban it and thereby force people to depend on perception unaided by technology.

Courts have long acknowledged that some technologies are needed to safeguard constitutional rights, and that barring their use would therefore violate those rights.

Likewise, the right to use contraceptives is actually grounded in a right to make “decision whether or not to beget or bear a child.”[16] But meaningfully exercising that right needs technological assistance — whether from long-standing technologies like condoms, or from much newer and more advanced pharmaceuticals — and so that technology is also protected by the underlying right. Using a latex device or a pill is not itself a “decision … not to beget … a child”: the decision comes before the device is used. Yet the use of such technologies makes reproductive autonomy possible, and limiting the use of such devices or pills substantially burdens people’s right to turn decisions about family and parenthood into reality.

Constitutional rights to technologies that protect constitutional privacy rights

The same reasoning applies to informational privacy, and not only to the “right of privacy” recognized by the Court’s contraceptives decisions. The Fourth Amendment protects the privacy of people’s communications, so long as people actually keep those communications private and do not give information to third parties whom the government could subpoena. To exercise that right effectively, and to avoid giving it up by introducing a third party, people may use Fourth-Amendment-protecting technologies, such as cryptographic tools that coders build to eliminate the middleman. Banning such technologies (or requiring that they be arranged in a way that forfeits the Fourth Amendment right) would violate the Fourth Amendment privacy right.

These questions are not settled. Courts may be hesitant to reject the government’s arguments, especially when those arguments are framed in terms of public safety and law-enforcement necessity.

For instance, some states have antimask laws, which forbid people from appearing in public while wearing masks; the laws were mostly enacted to stop terrorist groups like the Ku Klux Klan, but they apply just as much to all masked protesters. Some courts have invalidated such laws, reasoning that masks are important tools for protecting privacy even in public places, and for encouraging people to speak without fear of governmental or private-sector retaliation for their unpopular views.[17] But other courts have upheld antimask laws.[18] So it is impossible to predict confidently how courts would respond to constitutional challenges to a hypothetical law banning the use of other privacy-protecting technologies, such as various DeFi tools.

My point here is only that the argument supporting such constitutional challenges is strong, and may succeed. Courts should at least refrain from reading laws in a way that creates such a constitutional problem.[19] And Congress should avoid enacting laws that create the problem.

***

Footnotes

[1] E.g., California Bankers Ass’n v. Shultz, 416 U.S. 21 (1974).

[2] See § 80603 (amending 26 U.S.C. § 6045(a)).

[3] United States v. Miller, 425 U.S. 435, 444 (1976).

[4] Branzburg v. Hayes, 408 U.S. 665, 688 (1972).

[5] Clark v. Martinez, 543 U.S. 371, 381 (2005).

[6] Cf. Peter Van Valkenburgh, Electronic Cash, Decentralized Exchange, and the Constitution (“In practical terms, the regulator would be telling these developers to modify the protocols and smart contract software they release so that users are required to give identifying information to some other party on the network before they can take part . . . .”).

[7] This would be much like the government’s recurring efforts to restrict encryption. During the 1990s, the government tried to put in place (and perhaps eventually require) the “Clipper chip”: a tool that let people communicate in encrypted form, but made the encryption keys “escrowed” somewhere the government could later reach. More recently, in the late 2010s, federal law enforcement officials urged technology companies to build comparable key escrow systems, so that (for example) the government could always open the data on your cell phone (assuming law enforcement had a warrant or another similar judicial authorization). This was called the “going dark” debate: law enforcement feared that encryption might let criminals and terrorists completely evade the government’s surveillance and search methods. See Rianna Pfefferkorn, The Risks of “Responsible Encryption”, Ctr. for Internet & Soc’y paper (Feb. 2018)

Still, at least the Clipper chip and key escrow systems seemed to assume that the government could use escrowed material only with a warrant supported by probable cause — seeking to outlaw DeFi so that financial transactions are routinely sent to the government would be a way to sidestep the warrant and probable cause requirement.

[8] Smith v. Maryland, 422 U.S. 735, 744 (1979) (emphasis added); see also United States v. Miller, 425 U.S. 435, 442 (1976) (holding that people “lack . . . any legitimate expectation of privacy concerning the information kept in bank records” because they “contain only information voluntarily conveyed to the banks”); id. (emphasizing that “[t]he depositor takes the risk, in revealing his affairs to another, that the information will be conveyed by that person to the Government”).

[9] Cf. Peter Van Valkenburgh, Electronic Cash, Decentralized Exchange, and the Constitution (“If users do not willingly give this information to a third party because no third party is needed to complete their transactions or exchanges, then they logically keep a reasonable expectation of privacy in their personal records and law enforcement would need a warrant to get those records.”).

[10] United States v. Flores-Lopez, 670 F.3d 803, 807 (7th Cir. 2012); United States v. Wurie, 728 F.3d 1, 16 (1st Cir. 2013).

[11] Limits on windows with excessive tint may be constitutional, but they are supported by the need “to ensure a necessary degree of transparency in motor vehicle windows for driver visibility,” Klarfeld v. State, 142 Cal. App. 3d 541, 545 (1983) (quoting 49 C.F.R. § 571.205 S2 (1982)); People v. Niebauer, 214 Cal. App. 3d 1278, 1290 (1989) (observing that some tint levels are “permitted on certain windows not required for driver visibility”).

[12] McCarthy v. Arnstein, 266 U.S. 34, 40 (1924); cf. Guinn v. United States, 238 U.S. 347, 360, 364-65 (1915) (invalidating a grandfather clause that plainly tried to evade the Fifteenth Amendment’s bar on racial discrimination in voting qualifications); State v. Morris, 42 Ohio St. 2d 307, 322 (1975) (holding that private searches are outside the Fourth Amendment unless they are arranged by the government “with[] intent to evade constitutional protections”).

[13] Fields v. City of Philadelphia, 862 F.3d 353 (3d Cir. 2017); Turner v. Lieutenant Driver, 848 F.3d 678 (5th Cir. 2017); ACLU of Illinois v. Alvarez, 679 F.3d 583 (7th Cir. 2012); Glik v. Cunniffe, 655 F.3d 78, 82 (1st Cir. 2011); Smith v. City of Cumming, 212 F.3d 1332 (11th Cir. 2000); Fordyce v. City of Seattle, 55 F.3d 436 (9th Cir. 1995).

[14] Fields, 862 F.3d at 359.

[15] Id.

[16] Carey v. Population Servs. Int’l, 431 U.S. 678, 685 (1977).

[17] See American Knights of the KKK v. City of Goshen, 50 F. Supp. 2d 835, 839 (N.D. Ind. 1999); Ghafari v. Municipal Court, 87 Cal. App. 3d 255, 261 (1979) (challenge filed by protesters who were opposed to the Iranian government); Aryan v. Mackey, 462 F. Supp. 90, 92 (N.D. Text. 1979) (same).

[18] See Church of American Knights of the KKK v. Kerik, 356 F.3d 197, 208-09 (2d Cir. 2004); State v. Berrill, 474 S.E.2d 508, 515 (W. Va. 1996); State v. Miller, 398 S.E.2d 547, 553 (Ga. 1990).

[19] See supra note 5 and accompanying text.

About the author

Zoran Basich is an editor and podcast host who covered crypto and web3 at Andreessen Horowitz.