Counsel for a digital health start-up is briefing the board on how the information fiduciary duty of care would shape obligations if the company adopted a fiduciary posture. Which obligation best reflects the duty of care as distinct from the duty of loyalty?
- ARefraining from selling user data to parties whose interests conflict with those of the users.
- BTaking reasonable, competent steps to keep user data accurate and secure so users are not harmed by careless handling. Correct
- CDisclosing in a privacy notice every third party with which user data is shared.
- DObtaining renewed opt-in consent each time the company introduces a new processing purpose.
Why A is wrong: Avoiding conflicted onward sales is a genuine fiduciary obligation, but it is an expression of loyalty (not acting against users' interests) rather than the competence-and-diligence focus of the duty of care.
Why B is correct: The duty of care obliges an information fiduciary to handle entrusted data competently and protect it from foreseeable harm, paralleling the professional standard of care owed by doctors and lawyers to those who depend on them.
Why C is wrong: Transparency about recipients is good practice and feels like a fiduciary act, but it reflects notice-and-choice transparency rather than the duty of care, which is about safeguarding competence, not disclosure lists.
Why D is wrong: Refreshing consent for new purposes is a defensible compliance habit, but it belongs to the consent model the fiduciary theory supplements; the duty of care concerns diligent stewardship, not consent collection.