Blog / Privacy law and data protection

Best Books on Privacy Law and Data Protection, in Order

August 8, 2026 · 4 min read

Start with Privacy is Power. Carissa Véliz is an Oxford philosopher, the book came out in 2020, and it is the most readable statement of why any of this matters — her position, that trade in personal data should be banned outright, is advocacy and the book says so. Then Why Privacy Matters, Neil Richards in 2021, which answers the nothing-to-hide reflex with a lawyer's precision and argues that privacy is about power and rules for information flow rather than about secrecy.

Privacy law has an unusual problem: its hardest question is definitional, and courts and regulators have spent a century trying to say what the interest actually is before deciding how to protect it. So the concept books come first here, and the statutes read afterwards as answers to identifiable questions. Two warnings apply to everything below. Nothing here is legal advice and none of it substitutes for a lawyer in your jurisdiction. And this subject dates faster than almost any other — the year is given for each book because the current European and Californian regimes arrived in 2016 to 2020, and anything published before that predates the rules practitioners now work with, even where its concepts remain excellent.

What privacy is

Understanding Privacy is Daniel Solove in 2008, and its move is to abandon the search for one essential definition in favour of a taxonomy of distinct harms — surveillance, aggregation, exclusion, disclosure, secondary use. It is the single most useful framework on the path and the one later regulation keeps reaching for; the concepts have aged well even though the legal landscape around them has not. Privacy in Context is Helen Nissenbaum in 2009, whose contextual integrity holds that information norms are specific to the setting a flow came from, so a disclosure violates privacy when it breaches those norms rather than when the information is merely public or private. It is the most demanding of the four and the most cited in modern rulemaking. Both remain current as theory; neither tells you what the law requires.

The American legal architecture

The Digital Person is Solove in 2004, and predates essentially every modern statute. It remains the best explanation of why American law took the shape it did — commercial databases shifted the problem from Orwellian surveillance to something closer to Kafka, decisions made about you from records you cannot see. Read it as history of ideas. Nothing to Hide is his 2011 short book on the security-versus-privacy trade and how dishonestly it is usually framed; same taxonomy, applied to government surveillance, and it predates the post-Snowden changes.

Privacy law fundamentals is the compact Solove and Paul Schwartz reference — statutes, leading cases and FTC actions in outline. It is a practitioner text revised every couple of years, and the record catalogued here is an early one from 2011, so buy whatever the current edition is and ignore the year shown. Federal Trade Commission Privacy Law and Policy is Chris Hoofnagle in 2016, on the agency that in practice writes American privacy law through consent decrees rather than legislation. It explains how the United States can lack a general privacy statute and still impose enforceable obligations, and although it predates the GDPR the institutional analysis has held up.

How the problem got this big

Privacy and freedom is Alan Westin in 1967, and it defined privacy as the individual's claim to control information about themselves — the framework standing behind notice-and-consent in nearly every data protection law since. It is a historical document and should be read as the source of the model the final stage attacks. The Known Citizen is Sarah Igo in 2018, a historian's account of how Americans came to think of privacy as a right at all — census controversies, Social Security numbers, psychological testing, the confessional talk show. The corrective to treating privacy as timeless.

The Age of Surveillance Capitalism is Shoshana Zuboff in 2018, arguing at great length that behavioural data has become a raw material extracted for prediction markets. It has been widely criticised for overreach and imprecision, and it is here because it names the economic engine most law books leave in the background. Bruce Schneier's Data and Goliath covers similar ground more technically in about a third of the pages.

Regulating design, and working across jurisdictions

Privacy's Blueprint is Woodrow Hartzog in 2018 and is the central argument of the modern field: consent boxes and privacy policies cannot do the work asked of them, so the law should constrain how products are designed instead. If you read one book from this stage, read this. Industry Unbound is Ari Ezra Waldman in 2021, interviewing the engineers and privacy professionals who convert legal obligations into compliance theatre — the empirical evidence for Hartzog's claim, so read it second; his earlier Privacy as Trust makes the positive case for a relational model.

Determann's field guide to data privacy law is the practical multi-jurisdiction handbook for people who have to comply rather than theorise, and it has the shortest shelf life of anything here. The record catalogued on this path is from 2015 and is several editions out of date; buy the current edition, because cross-border transfer rules in particular have been rewritten more than once since. More legal reading sits on Discover.

Follow the full ordered path here: Best Books on Privacy Law and Data Protection, in Order.

FAQ

Which of these books are still current, and which are historical?
Current as law and practice: Hoofnagle on the FTC, Hartzog, Waldman, Véliz and Richards. Current as theory but not as law: Solove's Understanding Privacy and Nissenbaum's Privacy in Context — the frameworks hold, the legal landscape around them has changed completely. Historical: Westin from 1967 and Solove's The Digital Person from 2004, both worth reading for how the model was built. And two are reference works whose catalogued editions are stale by design — Privacy Law Fundamentals and Determann's field guide should always be bought in the newest edition.
Is there a book here that covers the GDPR directly?
Not as its main subject. Determann's field guide is the closest, and it is the one to buy current rather than in the edition catalogued here. The rest of the path is either American law or conceptual work that applies across regimes. Hartzog and Waldman are the most useful for understanding why European-style design and accountability obligations took the form they did, even though neither is a GDPR commentary.

Get the books

As an Amazon Associate we earn from qualifying purchases. Some book links are affiliate links; you pay the same price and we may earn a small commission.

Follow the full reading path

Ready to learn something deeply?

Build a reading path — free

Keep reading

Explore related subjects