Showing posts with label Broadband Privacy Order. Show all posts
Showing posts with label Broadband Privacy Order. Show all posts

Wednesday, September 20, 2017

California Privacy Act Fails to Pass

Last week, the “California Privacy Act,” modeled after the FCC’s Broadband Privacy Order, failed to make it to the floor before California’s 2017 legislative session ended. This is not the first time a state tried to pass problematic privacy legislation. The Maryland State Senate proposed a similar bill in April 2017 and it also failed to pass. As I stated in an April 2017 blog, state-level broadband privacy laws raise many practical questions about enforcement efforts. Ultimately, privacy jurisdiction should return to the FTC, where privacy matters can be adjudicated on a case-by-case basis. 

Friday, June 09, 2017

Why the FTC Should Oversee Broadband Internet Service Providers

The Free State Foundation hosted its Ninth Annual Telecom Policy Conference on May 31. Knowledgeable speakers offered policymakers forward-looking insights befitting the Conference’s title: “A New Direction in Communications Policy: Less Regulation, More Investment and Innovation.”

As explained below, insights offered by Conference speakers reinforce two critical ways that communications policy ought to be made more conducive to fostering innovation and investment by Internet service providers. First, the Federal Communications Commission should cede jurisdiction over broadband privacy practices back to the Federal Trade Commission because the FTC is better suited to the task. Second, to the extent the FCC retains any regulatory authority at all over Internet service providers, the agency generally should adopt only the fact-specific, complaint-based ex post approach of the FTC. Public utility-like regulation of Internet service providers should be repealed. To the extent that the FCC retains any regulatory authority at all over Internet providers, which we do not here concede, any replacement regulatory framework adopted should be tied to market power analysis and target specific instances of claimed consumer harm or anticompetitive conduct.

The remarks of the panelists at the Conference session, “The View from the FTC: Overseeing Internet Practices in the Digital Age,” as detailed below, are very instructive, as well as very timely.

Return Oversight of Broadband Privacy to the FTC

The FCC’s Title II Order (2015) declared broadband Internet access services to be a “telecommunications service” subject to public utility regulation. The Title II Order thereby effectively stripped the FTC of jurisdiction over broadband Internet access service providers’ (ISP) privacy practices. Onerous, one-sided privacy regulation adopted in the FCC’s Broadband Privacy Order (2016) was repealed by Congress in March 2017. Now the FCC’s proposed Restoring Internet Freedom rulemaking would declare broadband Internet access services to be a Title I “information service.” In effect, this would repeal public utility regulation and return broadband privacy jurisdiction to the FTC.

The FTC’s expertise and analytical approach toward privacy issues were discussed during the Conference’s panel: “The View from the FTC: Overseeing Internet Practices in the Digital Age.” Thomas Pahl, Acting Director of the FTC’s Bureau of Consumer Protection, critiqued the FCC’s Broadband Privacy Order and contrasted it with his agency’s privacy policy:
[T]he FCC chose a more rigid and prescriptive approach to broadband data security and privacy issues than the FTC’s traditional case-by-case approach to these topics. The FCC’s rules also set standards for broadband providers separate and apart from standards applicable to others in the online space, eschewing the FTC’s more comprehensive approach. 
Mr. Pahl described what the public could expect if the FCC adopts its Restoring Internet Freedom proposal and thereby returns jurisdiction over broadband ISP privacy practices to the FTC:
The FTC is ready, willing, and able to protect the data security and privacy of broadband subscribers . . . .  We have a wealth of consumer protection and competition experience and expertise, which we will bring to bear on online data security and privacy laws. We will apply data security and privacy standards to all companies that compete in the online space regardless of whether the companies provide broadband services, data analysis, social media, or other services. Our approach would ensure the standards the government applies are comprehensive, consistent, and pro-competitive. 
The FTC’s Case-by-Case Approach Is Preferred for ISP Oversight

Tad Lipsky, Acting Director of the FTC’s Bureau of Competition, also participated on the panel. Drawing on his expertise in antitrust and competition law and policy, he described case-by-case enforcement by the FTC and private litigation as ready means to address any anticompetitive practices that might arise in the broadband Internet access services market. Mr. Lipsky rejected “the idea that a lessening of the regulatory burden on the FCC side would lead to a situation in which anticompetitive conduct was free to occur without fear of further consequence.” According to Mr. Lipsky: “That is demonstrably false. The FTC is waiting” and able to address anticompetitive concerns that might arise.

Characterizing himself as a “light touch regulator” and as “a fan of antitrust as the way of ensuring that dynamic free competition gives the consumer what he wants,” Mr. Lipsky also criticized the public utility model of regulation embodied in the 1887 Interstate Commerce Act, stating: “[I]t is a fact that the FCC Title II regulation is a direct descendant of that form of regulation.” Mr. Lipsky added:
[T]he temptation to look at the problems of a dynamic and quickly developing industry and to immediately apply this structure of economic regulation as a way of anticipating and making sure that future problems don’t arise has largely been a failure. 
Of course, the FCC’s Title II Order succumbed to such temptation. The order imposed public utility regulation on broadband Internet access services with no evidentiary findings of market failure or consumer harm. Indeed, the Title II Order dismissed market power’s relevance.

Professor Daniel Lyons, a member of FSF’s Board of Academic Advisers, also characterized broadband Internet access service regulation as “an antitrust and a consumer protection issue.” Recounting the FTC’s antitrust analytical tools, including its test for market power, Professor Lyons stated:
The FTC is well equipped to evaluate on a case-by-case basis whether a particular agreement is one that might harm consumers. Using robust law that’s been developed from a number of different cases elsewhere in the economy… they have a broader scope informed by a lot more history than the Federal Communications Commission. I agree that the ex post review and flexibility the FTC brings is a lot better in a dynamic marketplace than the more rigid FCC ex ante rulemaking. 
Thus, the FTC’s institutional competencies and case-by-case approach to anticompetitive conduct – as attested by Messrs. Pahl and Lipsky and Professor Lyons – bolster the basic direction set out in the FCC’s Restoring Internet Freedom proposal. The FTC has wide-ranging experience in addressing privacy practices and should be empowered to apply that experience to all online services alike. The FCC should follow through on its proposal and return jurisdiction over broadband ISP privacy practices to the FTC.

Going forward, the FCC should repeal its Title II public utility regulation of broadband Internet access services. To the extent the FCC determines in its Restoring Internet Freedom proceeding that it retains any regulatory authority at all over Internet service providers, which we do not here concede, the agency should adopt only the fact-specific, complaint-based ex post approach of the FTC. To the extent any replacement regulatory framework is retained, it should be tied to market power analysis and target specific instances of claimed consumer harm or anticompetitive conduct.

The C-SPAN video of the conference session, “The View from the FTC: Overseeing Internet Practices in the Digital Age,” is here.

[Note: The quotations by the panel speakers included in this post were taken from the C-SPAN transcription of the Conference, with minor edits made for purposes of correcting obvious syntax, grammar, and punctuation errors. None of the meaning was changed.]

Wednesday, April 19, 2017

Maryland’s Broadband Privacy Bill Was a Solution in Search of Problem

On April 4, 2017, the Maryland State Senate allowed for the late introduction of the Internet Consumer Privacy Rights Act of 2017. The bill was introduced just days before the legislative session ended, purportedly as a response to President Trump signing the repeal of the Federal Communications Commission’s (FCC) unnecessary and overly burdensome Broadband Privacy Order. The Maryland bill showed that Maryland policymakers misunderstand how Internet service providers (ISPs) and edge providers, like Google and Facebook, use the advertising business model to offer innovative and consumer-friendly services.
Fortunately, the bill went nowhere during the legislative session. Nevertheless, because it was introduced, it’s worth examining why the effort was misguided.
Consumers expect consistent, common sense rules throughout the entire Internet ecosystem. Had the FCC’s broadband privacy regulations gone into effect, there would have been asymmetric privacy regulations between ISPs and edge providers, like Google. The FCC’s Broadband Privacy Order would have enabled Google and Facebook, which currently dominate over 60% of the online advertising market, to capture an even larger share of the market by creating additional privacy regulations for only ISPs. One Maryland Senator called the repeal of the Broadband Privacy Order an “emergency.” But the status quo regarding broadband privacy did not change with the repeal because the FCC’s rules never actually went into effect. And given that ISPs only have access to 30% of consumer data, it was not an emergency before the FCC adopted the Broadband Privacy Order, and it is not an emergency now that Congress and President Trump have repealed those unnecessary regulations.
The Maryland bill would have banned ISPs in Maryland from displaying “certain advertisements to a consumer” and refusing “to provide services to a consumer because the consumer refuses to take a certain action.” In an August 2016 Perspective from FSF Scholars entitled “FCC Privacy Rules Would Harm Consumers by Creating Barriers for ISP Advertising,” I explained how ISPs and edge providers use the advertising business model as a means of offering, without charge, innovative services to consumers.
ISPs cannot offer free data and sponsored data services and businesses often cannot offer public WiFi without ISPs collecting consumer data. The advertising revenue that ISPs generate from these services is the incentive they have to offer free services and content. Maryland’s bill would have banned ISPs from refusing to offer services and content to consumers who choose not to share their consumer information, which, literally, is the business model that enables consumers to enjoy free services. Had the Maryland legislation been adopted, ISPs may well have stopped offering free data services and businesses might well have stopped offering public WiFi to any consumers in Maryland, because the law would have heavily restricted ISPs from delivering targeted advertising.
Many practical questions would have arisen about the enforcement of these rules because the Internet economy does not end at state borders. What makes the relationship between a consumer and an ISP a Maryland or state-level issue? If a person has a home address in Maryland but accesses the Internet elsewhere, do the rules apply to that individual? If a Maryland resident travels to Virginia or Pennsylvania and uses his or her mobile device, do the rules no longer apply? If ISPs refused to offer innovative services to Maryland consumers because of these burdensome regulations, this may have pushed residents and businesses into neighboring states where they could connect to free data services and offer public WiFi with tailored advertising.
In a March 2017 Perspectives from FSF Scholars entitled “The Right Way to Protect Privacy Throughout the Internet Ecosystem,” Daniel Lyons, a member of FSF’s Board of Academic Advisors, discussed how, in the short term, the FCC should enact privacy rules that mirror existing Federal Trade Commission (FTC) practices, adjudicating privacy matters on a case-by-case basis. And in the long run, he says that repealing the Title II common carrier classification in the FCC’s Open Internet Order would “return privacy jurisdiction back to the FTC, where it belongs.”
Thankfully, the Maryland privacy bill died a quick death. That’s the right result for Maryland residents and businesses who value the availability of innovative Internet services, along with information they want without charge.