Showing posts with label Preemption. Show all posts
Showing posts with label Preemption. Show all posts

Friday, April 24, 2026

"Soon" (But Not Too Soon), House Republicans Introduce Privacy Bills

In a Tuesday post to the Free State Foundation blog, I repeated the quote – which I first referenced in a January Perspectives from FSF Scholars – that the House Energy and Commerce Committee Privacy Working Group could introduce comprehensive data privacy legislation "soon." In this instance, "soon" translated to "Wednesday." That's when the House Committees on Energy and Commerce and Financial Services jointly introduced a pair of companion bills: the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act (SECURE Data Act) and the Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act (GUARD Financial Data Act).

The SECURE Data Act is the handiwork of the aforementioned working group, led by Representative John Joyce, M.D. (R-PA). The working group is composed of Republican members of the House Energy and Commerce Committee, which is chaired by Representative Brett Guthrie (R-KY). The GUARD Financial Data Act, meanwhile, is the product of the Financial Services Committee, led by Chairman French Hill (R-AR).

The two bills are designed to work in tandem: the SECURE Data Act covers consumer data handled by nonfinancial entities but exempts financial institutions and data subject to the Gramm-Leach-Bliley Act (GLBA), while the GUARD Financial Data Act modernizes the GLBA for the financial sector but exempts nonfinancial firms. As a joint one-pager released by the two committees explained, together the bills "form a common-sense Federal approach that will bring American privacy protections into the twenty-first century."

At a high level, the SECURE Data Act builds on – and, crucially, would preempt – the state-level "patchwork" that I have long lamented. It also wisely rejects a private right of action, leaving enforcement to the FTC and state attorneys general.

*    *    *

The SECURE Data Act establishes a set of now-familiar consumer rights, including the right to access, correct, delete, and transfer personal data. It also creates opt-out rights for targeted advertising, data sales, and certain automated profiling decisions. Processing of "sensitive data" would require opt-in consent, and parental consent would be required for the processing of data of teens (that is, those between the ages of 13 and 16). The processing of data of children under the age of 13 would remain subject to the provisions of the Children's Online Privacy Protection Act of 1998.

On the business side, the bill imposes data-minimization obligations that would limit the collection of data to what is "adequate, relevant, and reasonably necessary." It also includes data security requirements, privacy notice mandates, and data-protection-assessment requirements. Data brokers would be required to register with the FTC, which would maintain a searchable public registry. And businesses would have to disclose whether personal data is transferred to, processed in, or sold to foreign adversaries.

The SECURE Data Act would apply to businesses that process the personal data of at least 200,000 consumers annually. A separate threshold would cover data sellers that process the data of at least 100,000 consumers and derive over 25 percent of their revenue from the sale of personal data. Businesses with less than $25 million in adjusted gross annual revenue would be exempt.

As noted above, the bill does not create a private right of action. Instead, the FTC and state attorneys general would share enforcement authority. As I previously argued, exclusive enforcement by the FTC is far more likely to serve consumer interests than a private right of action, which would create problematic financial incentives for the plaintiffs' bar.

Perhaps most significant is the SECURE Data Act's broad preemption language, which provides that no state may "prescribe, maintain, or enforce any law, rule, regulation, requirement, standard, or other provision having the force and effect of law, if such law, rule, regulation, requirement, standard, or other provision relates to the provisions of this Act." This would appear to preempt the entire "patchwork" of state-specific privacy laws, now numbering 21, replacing them with a single, workable, nationwide standard.

*    *    *

Of course, the standard caveats apply. As a Republican-only bill, the SECURE Data Act will need to attract bipartisan support if it is to become law. And the usual sticking points – in particular, the bill's rejection of a private right of action and its strong preemption language – could impede its progress, something we certainly have seen happen before to similar pieces of legislation.

Nevertheless, the SECURE Data Act seems to strike an appropriate balance between protecting privacy and fostering innovation, a point made by NCTA – The Internet & Television Association in its supportive statement: the SECURE Data Act's "unified approach will strengthen consumer trust, give individuals meaningful control over their personal information, and provide businesses the certainty needed to innovate, protect data, and drive growth while eliminating the confusing patchwork of state laws that burdens consumers and businesses."

Tuesday, April 21, 2026

Later Rather Than Sooner: Oklahoma Enacts State Privacy Law No. 21

After a steady stream of state-level privacy statutes, capped by passage of the Rhode Island Data Transparency and Privacy Protection Act in June 2024, for nearly two years the pipeline ran dry. That drought ended on March 20, when Sooner State Governor Kevin Stitt signed into law the Oklahoma Consumer Data Privacy Act (OCDPA). With that, the list of states to have passed a comprehensive data privacy statute now stands (by my count) at 21.

At the federal level, meanwhile, the pickings remain slim. In late March, Representative Zoe Lofgren (D-CA) for the fourth time introduced the Online Protection Act, the shortcomings of which I rehashed in a contemporaneous post to the Free State Foundation blog. Beyond that, hopeful eyes can look only to the House Commerce Committee Privacy Working Group, which was created in February 2025 and sought public input a month later. As I noted in a January Perspectives from FSF Scholars, reporting at that time suggested that the working group could release a draft bill … "soon."

The good news about the OCDPA, which closely tracks the Virginia Consumer Data Protection Act, is that it does not impose more burdensome obligations than existing state laws – and therefore is regarded as a relatively "business-friendly" addition to the state-level "patchwork."

The bad news, of course, is that it further expands that "patchwork," thereby compounding compliance headaches for companies – especially smaller companies and start-ups – and making it even more challenging for consumers to comprehend their rights.

*    *    *

More targeted than other state laws, the OCDPA applies only to businesses operating in Oklahoma or targeting Oklahoma residents that control or process the personal data of either (1) 100,000 or more Oklahoma consumers, or (2) at least 25,000 Oklahoma consumers while deriving over 50 percent of their gross revenue from the "sale" of personal data. (By comparison, that threshold is lower – 25 percent – in most state laws.) In addition, the OCDPA defines "sale" relatively narrowly – that is, only where personal data is exchanged for monetary consideration.

The law establishes a now-familiar set of consumer rights: to access and confirm the processing of personal data, to correct inaccuracies, to delete, and to obtain a portable copy. In addition, consumers can opt out of the processing of personal data for targeted advertising, the sale of their personal data, and profiling.

"Sensitive data" – defined to include racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship status, genetic or biometric data used for identification, and precise geolocation data – may not be processed without the consumer's opt-in consent.

Covered businesses must abide by data-minimization principles, limiting collection to what is adequate, relevant, and reasonably necessary. They also must conduct data protection assessments before engaging in activities such as targeted advertising, the sale of personal data, and the processing of "sensitive data."

Two additional features of the OCDPA are worth highlighting. First, enforcement authority rests exclusively with the Oklahoma Attorney General; there is no private right of action. Second, the law includes a permanent, mandatory 30-day "right to cure" period for alleged violations – a feature that stands in contrast to the trend in other states toward sunsetting or eliminating cure periods altogether. Violations may result in penalties of up to $7,500 per incident.

The OCDPA will go into effect on January 1, 2027.

*    *    *

As I've stated countless times, the absence of a comprehensive federal data privacy law that would preempt this now-larger "patchwork" remains a glaring gap. With each new state law – and each set of idiosyncratic definitions of rights, responsibilities, thresholds, exemptions, enforcement mechanisms, and so on – the compliance burden on businesses grows heavier and the regulatory landscape confronting consumers grows murkier.

Wednesday, April 01, 2026

Sanders' AI Bill Is a Red Herring and Blackburn's Has Problems

With the White House calling for a national AI framework to end the patchwork of state regulation, two notable proposed pieces of federal legislation have emerged. And the one getting less attention at the moment is the one that matters more.

Senator Marsha Blackburn (R-TN) released a discussion draft of the TRUMP AMERICA AI Act (you read that right, The Republic Unifying Meritocratic Performance Advancing Machine Intelligence by Eliminating Regulatory Interstate Chaos Across American Industry Act) on March 18, 2026, a 291-page federal framework developed in response to the Trump administration's call for a national AI policy. Senator Bernie Sanders (D-VT), joined by Representative Alexandria Ocasio-Cortez (D-NY), introduced the 13-page Artificial Intelligence Data Center Moratorium Act on March 25, 2026. It would halt data center construction until Congress enacts legislation to ensure: that future AI products are "safe and effective"; that AI does “not threaten the health and well-being of working families”; and that AI does not displace jobs. The two AI bills are not comparable in scope or consequence.

The Sanders moratorium bill has received the most mainstream coverage, possibly in part because it is the only one of the two to be formally introduced. But it’s easy to see why all the fuss. The moratorium bill takes advantage of anxieties that translate directly into headlines: job displacement, strain on the power grid, and industrial construction in people's backyards. While these concerns affect real people, the bill's moratorium is ill-conceived and would be harmful. Pausing data center construction pending new AI legislation would be a significant brake on American AI infrastructure at precisely the moment the Trump administration is pushing to accelerate it and would let foreign competitors move ahead.

But Sanders’ moratorium bill is almost certainly a political statement about AI as a threat rather than a realistic proposal. It is unlikely to gain serious legislative traction, and its primary practical effect may be to divert attention from more consequential legislation.

The Blackburn bill is one piece of potentially more consequential legislation. As a proposed comprehensive federal AI framework, it is more technically complex and far-reaching than the moratorium bill. Yet it has received a fraction of the coverage. Other think tanks including the Competitive Enterprise Institute and the Cato Institute have explained how the bill would impose heavy-handed regulation across the AI ecosystem.

Some aspects of Senator Blackburn’s bill that may be problematic and require close attention include: a full-on repeal of Section 230 of the Communications Act of 1934; imposing “duty of care” on chatbot developers; holding AI developers liable for harms beyond existing laws on fair and deceptive practices; requiring federal contracts to use "unbiased" large language models; creating a Department of Energy testing program for adverse incidents in AI systems; and directing DOE to develop certification procedures, licensing requirements, and broad regulatory oversight.

I wrote last week that the federal AI framework needs a light-handed approach grounded in free market competition. I explained that “robust competition among American companies is the precondition for national competitiveness” and consumer satisfaction. While established developers may fare fine under such a burdensome scheme, their products would fall behind other nations not facing such operating and compliance costs. And startups and emerging competitors would fare even worse.

The Sanders moratorium deserves the criticism it has received. But the current Blackburn bill has problematic provisions that deserve scrutiny it has not yet gotten.

Friday, March 27, 2026

Representative Lofgren's Online Privacy Act Has Reentered the Chat

As we eagerly await word from the House Energy and Commerce Committee's data privacy working group, Representative Zoe Lofgren (D-CA) once again has resurrected the problematic Online Privacy Act (OPA).

In February 2025, Committee Chairman Brett Guthrie (R-KY) and Vice Chairman John Joyce, M.D. (R-PA) announced the establishment of a data privacy working group "to bring members and stakeholders together to explore a framework for legislation that can get across the finish line." (For more information please see my contemporaneous post to the Free State Foundation blog).

Shortly thereafter, the working group solicited public comment on a Request for Information that I summarized in a follow-up blog post.

In a January Perspectives from FSF Scholars summarizing privacy-related legislative activity in 2025, I shared speculation that the working group might introduce a bill "soon." Separate reporting around the same time indicated that the working group "intend[s] to take up action on a broader, comprehensive federal privacy measure in spring 2026."

In the interim, Representative Lofgren for the fourth time has introduced the OPA, a draft bill first unveiled in 2019 and then again in 2021 and 2023.

As I pointed out in "A Tale of Three Data Privacy Bills: Federal Legislative Stalemate Enables Bad State Laws," a January 2022 Perspectives, the OPA has two top-level shortcomings: (1) it "is silent on the issue of preemption," and thus fails to address the state-level "patchwork" problem that in the intervening years has only gotten worse; and (2) it creates a private right of action that, unlike exclusive enforcement by the FTC, would be far more likely to benefit the plaintiffs' bar than consumers.

With the vernal equinox exactly one week in the rear-view mirror, it remains possible that the working group will introduce (presumably preferable) comprehensive data privacy legislation this spring.

Time will tell.

Wednesday, March 25, 2026

Talkie's Preemption Petition Looks Persuasive - Part II

On March 12, I posted a blog titled, "Talkie's Preemption Petition Looks Persuasive." As I explained, in its petition Talkie asks the FCC to preempt Queen Anne's County in Maryland from enforcing what it claims are local zoning requirements that have the effect of prohibiting Talkie from attaching its communications equipment to a utility pole owned by Talkie. The county's purported justification for obstructing Talkie's proposed broadband service is that it would be delivered over multi-use (that is, comingled) facilities.

 

In my March 12 post, I concluded:

 

This is just one of many instances in which local cities and counties across the country implement onerous and often costly requirements, or engage in bureaucratic delay tactics, that prevent the timely deployment of new communications services and advanced broadband infrastructure. It's important that, when appropriate, the FCC grant meritorious preemption petitions. Talkie's petition looks like it may be just such a case.

 

While I hope that the Marylanders who might be served by Talkie proposed broadband service will not be denied that service because of improper actions by local officials, I'm also interested, of course, in the principle at stake in this particular preemption spat and other similar ones. That's why, in the above excerpt, I referred to "many instances" involving tactics similar to those confronted by Talkie in Maryland.





I'm pleased to see that INCOMPAS, representing a broad coalition of competitive communications providers and broadband builders, has submitted comments to the FCC supporting Talkie's preemption petition. INCOMPAS reports that its members "regularly

encounter discriminatory zoning requirements, excessive fees, sequential permitting processes, and de facto moratoria that significantly hinder broadband deployment."

 

INCOMPAS states that "the Commission has consistently preempted fees and requirements that disrupt deployment of advanced services over commingled facilities. The County’s opposition asks the Commission to retreat from that settled position, and INCOMPAS urges the Commission to decline to do so." Therefore, according to INCOMPAS, "the outcome of this proceeding will affect every INCOMPAS member deploying modern multi-use networks."

 

It is this potentially broader impact of the Commission's disposition of Talkie's preemption petition –aside from concern regarding the immediate impact on those residents who might benefit from having available Talkie's services – that prompted me to highlight Talkie's petition in the first place. Absent affirmative Commission action on Talkie's petition pursuant to Section 253 of the Communications Act, the ability to deliver broadband services over multi-use infrastructure could be put in jeopardy.

 

If that is the case, the full realization of FCC Chairman Brendan Carr's much-needed "Build America" agenda, which is necessarily dependent on rapid deployment of broadband infrastructure, could be adversely impacted. It still looks to me like Talkie has presented a persuasive case that should be given close attention by the Commission in a timely fashion.

 

Tuesday, March 24, 2026

White House to Congress: Fix the AI Patchwork

The Trump Administration issued seven AI policy recommendations for Congress on Friday, March 20, 2026, including one for preemption, asking Congress to make sure state legislatures don’t get in the way of AI innovation (Recommendation VII). 

This recommendation is exactly what the moment calls for. Last week, I wrote a FSF Blog post about just this issue. After describing the extraordinarily wide range and volume of AI bills moving through statehouses across the country, I wrote: “What the nation really needs is an overarching federal framework that avoids ex ante heavy-handed regulation and that supplants the growing patchwork of state laws.” The White House has now said the same thing. 

Recommendation VII reads: “Congress should preempt state AI laws that impose undue burdens to ensure a minimally burdensome national standard consistent with these recommendations, not fifty discordant ones.” It clarifies the distinction between federal and state domains of AI regulation. The federal government is better positioned to “supporting innovation” because AI is “an interstate phenomenon” that is part of the “national strategy to achieve global AI dominance.” Absent preepmtion, states may otherwise “unduly burden Americans’ use of AI.” State governments are positioned to regulate AI as it pertains to issues specific to their state such as consumer protection, zoning, law enforcement, and public education.


Here are a few additional details encouraging innovation among the White House’s six other recommendations: “lead the world in AI by removing barriers to innovation” (Recommendation V); “not create any new federal rulemaking body to regulate AI” (Recommendation V); and “streamline federal permitting for AI infrastructure construction and operation” (Recommendation II); The White House also recommends preventing censorship and protecting free speech (Recommendation IV).

Noticeably absent from the seven recommendations, however, is an explicit acknowledgment that free market competition is both a means of achieving the White House’s ambitions and an essential benefit to American consumers. Recommendation VII frames preemption in terms of competing with other nations but overlooks a foundational point: robust competition among American companies is the precondition for national competitiveness. A truly pro-innovation framework would make free market competition an explicit objective in recognition that this helps ensure that the best products and services are made available to consumers at the lowest prices. 

Now, Congress needs to follow through on the White House’s recommendation for preemption. And with a strong commitment to fostering market competition, Congress and existing federal agencies have the opportunity to get AI regulation right.

Friday, March 20, 2026

State Lawmakers Are Not Waiting for Washington to Regulate AI

With annual legislative sessions beginning to wind down, lawmakers in 44 states and D.C. have introduced over 800 bills related to artificial intelligence during the 2026 session so far, according to the National Council of State Legislature’s AI bill tracker. This is a remarkable volume of regulatory interest from lawmakers who have not had much of a chance to understand any possible related market failures or to study the costs and benefits of regulations for a new technology that has only recently entered mainstream use. This regulatory interest represents continued momentum from the past few years. In the 2025 session, the 50 states and D.C. introduced over 1,000 AI bills altogether.

The bills during this and recent sessions cover an extraordinarily wide range of targets and approaches. Some bills target AI developers such as Anthropic and OpenAI. Some target deployers of AI such as social media companies or businesses that use AI internally. Others target other parties such as data brokers. Many bills are sector-specific: AI in healthcare, AI in housing, AI in employment, AI in insurance, and AI in elections. And many bills are issue-specific: for example, lawmakers in the 2026 session have introduced 188 bills in 38 states on AI deepfakes and 22 bills in 22 states covering AI chatbots.


A few examples illustrate the range of the 726 bills pending in statehouses and awaiting governor signatures: An Illinois bill would require AI developers to report safety incidents and publicly publish their protocol on risk management, transparency, and cybersecurity (2026 IL SB3312). A Hawaii bill would require AI deployers to run risk management programs for algorithmic discrimination and cybersecurity, including pre-market and ongoing testing, and recordkeeping (2026 HI SB2967). A Minnesota bill would prohibit, “surveillance-based price discrimination,” or the use of AI in using certain consumer data to set prices (2026 MN HF 3764). A New Jersey bill would require companies to conduct AI safety tests and report results to the state (2026 NJ S 1802). A New York bill would hold companies liable for harm caused by AI chatbots offering medical, legal, and other types of regulated speech (2025 NY S7263). 

So far, 13 states this session have enacted or adopted 14 pieces of legislation. A few examples illustrate the range of what lawmakers are passing: Indiana placed restrictions on when healthcare insurance providers can use AI (2026 IN H 1271). New York state and local government may not use AI to reduce staffing, or as the language reads, from using AI in a way that would displace governments jobs (2025 NY S 8831). South Carolina placed restrictions on how data can be collected from minors and implicated AI in the law (2025 SC H 3431). In Vermont, AI videos of political candidates must now be labeled as such (2025 VT S 23).

In a recent Perspectives from FSF Scholars, my colleague, Joe Kennedy, suggests the need for a streamlined AI regulatory framework that incentivizes the build-out of a robust supporting infrastructure and that encourages competition and innovation. What the nation really needs is an overarching federal framework that avoids ex ante heavy-handed regulation and that supplants the growing patchwork of state laws.

Without such a framework, companies must navigate a growing and inconsistent patchwork of state regulations, each with varied definitions, thresholds, compliance timelines, and enforcement mechanisms. States may still decide to pass legislation on AI as it pertains to their specific state criminal codes, public education requirements, state government use of AI, or other state matters. But at the current rate, an AI developer, deployer, or other AI party could theoretically face 51 different pieces of legislation regulating the same activity. And the burden of complying with this patchwork falls even harder on startups and emerging competitors trying to offer better alternatives for consumers. AI has potential to improve countless dimensions of everyday life. The emerging regulate-first patchwork of state laws is not the path to realizing that potential.

Monday, March 17, 2025

Pennsylvania Bill Would Turn Broadband Internet Networks into Public Utilities

On March 17, Pennsylvania House Bill 924 was referred to a legislative committee in that state's lower chamber. If it were to become law, the bill would change the definition of "public utility" under Pennsylvania law to include "[p]roviding persons with the ability to connect to the Internet through equipment that is located in this Commonwealth." In short, PA House Bill 924 is a state net neutrality bill, that would impose no blocking, no throttling, no paid prioritization, and other restrictions on provider network management, and delegate authority to the state's public utility commission to regulate broadband Internet access services.  

PA House Bill 924 was filed in the wake of the Sixth Circuit's March 11 order denying a rehearing en banc on that court’s January 2 three-judge panel decision to vacate the FCC's 2024 Title II Order. The state bill also follows closely on the heels of the Supreme Court's February 24 order deny a rehearing on its prior order to deny a writ of certiorari in New York State Telecommunications Association v. James. The denial of a rehearing in James leaves in place a Second Circuit decision from April 2024 that upheld New York State’s Affordable Broadband Act that imposed rate regulation on interstate Internet broadband access services offered by broadband providers in that state.

 

It seems unlikely, if not implausible, that Congress intended to open up jurisdictionally interstate information services (previously known as "enhanced services") like broadband access to state regulation when it established non-regulated or lightly-lightly regulated Title I classification for "information services" in the Telecommunications Act of 1996. But according to three circuit courts of appeal, that apparently is what Congress did. The Second, Ninth, and D.C. Circuits – have concluded that the FCC's decision in the 2017 Restoring Internet Freedom order to classify broadband access services as Title I services had the effect of removing the agency's jurisdiction over interstate broadband services, thus preventing the Commission from preempting state public utility regulation of those same services. 

 

For some further context, the FCC's proceeding that led up to the FCC's 2024 Title II Order cited zero instances of blocking, throttling, or harmful paid prioritization arrangements. Moreover, all or nearly all broadband ISPs in America have terms of service pledges to not engage in blocking, throttling, or harmful paid prioritization. So long as broadband access services are Title I "information services" (and not Title II "telecommunications services") those service term pledges are enforceable by the Federal Trade Commission under its authority to address unfair and deceptive trade practices. 

 

Expect the issue of state-level public utility regulation of broadband Internet access services, including price controls, to be a subject of discussion at the Free State Foundation's Seventeenth Annual Policy Conference – #FSFConf17 – on March 25, in Washington, D.C. Register today for the conference. 

Tuesday, March 04, 2025

House Commerce Privacy Working Group Seeks Input

In a February 2025 post to the FSF Blog, I reported on a press release from House Commerce Committee Chairman Brett Guthrie (R-KY) and Vice Chairman John Joyce, M.D. (R-PA) announcing the creation of a working group focused on federal comprehensive data privacy legislation. That working group is now asking interested parties to provide responses to a Request for Information (RFI).

Released on February 21, 2025, the RFI begins by acknowledging two points I have highlighted repeatedly in writings for the Free State Foundation, most recently in a December 2024 Perspectives from FSF Scholars.

One, that "the challenge of providing clear digital protections for Americans is compounded by the fast pace of technological advancement and the complex web of state and federal data privacy and security laws, which in some cases create conflicting legal requirements."

And two, that "Members of Congress have spent many years working toward federal comprehensive data privacy and security standards to bring consumer protections into the digital age while ensuring that the U.S. continues to lead in a globally competitive environment."

The information sought by the RFI is organized into the following six specific categories:

  • Roles and Responsibilities: What types of entities collect, process, and sell personal information? What obligations should apply to each?
  • Personal Information, Transparency, and Consumer Rights: What specific consumer protections should a privacy law include? What heightened safeguards should apply to sensitive personal information? How should covered entities provide disclosures to consumers?
  • Existing Privacy Frameworks and Protections: What can be learned from the existing "patchwork" of state privacy laws? To what extent should a federal privacy law preempt state privacy laws?
  • Data Security: How can federal lawmakers ensure the security of consumer data?
  • Artificial Intelligence (AI): How might a federal privacy law account for existing state laws addressing AI, including those relating to automated decision-making?
  • Accountability and Enforcement: What are the pros and cons of exclusive enforcement by the FTC and state Attorneys General? Should a federal privacy law include a safe harbor?

A seventh, catch-all, category encourages interested parties to submit "any additional information that may be relevant to the working group as it develops a comprehensive data privacy and security law."

Responses, due by April 7, 2025, should be emailed to PrivacyWorkingGroup@mail.house.gov.

Tuesday, February 25, 2025

High Court Again Declines to Rule on State-Level Price Controls for Broadband

On February 24, the Supreme Court issued an order denying a petition for a rehearing on its order to deny a writ of certiorari in New York State Telecommunications Association v. James. That is a wordy way of saying the Court declined to change its mind about its earlier refusal to take up the case. The Court's order leaves in place an April 2024 decision by the U.S. Court of Appeals for the Second Circuit rejecting ISPs' claims that the New York broadband price control law is subject to field preemption and conflict preemption.

The Supreme Court's prior order denying certiorari in NYSTA v. James is the subject of my blog post from December 18, 2024. Reconsideration was requested by the petitioners following the January 2, 2025, decision by the Sixth Circuit in In re: MCP No. 185. The Sixth Circuit's decision vacated the FCC's April 2024 order that reclassified broadband services as Title II "telecommunications services" and thereby left in place the agency’s prior order that classified broadband as a Title I "information service." The petitioners argued that the result in the Sixth Circuit constituted intervening circumstances substantial enough to warrant the granting of a rehearing and certiorari. But the Court declined to see it that way. 

 

New York's Affordable Broadband Act imposes price ceilings—a type of rate regulation—on broadband Internet service providers (ISPs) offering service in the state. Under the law, ISPs must offer low-income individuals plans of $15 per month and $20 per month. After being involved in litigation, the law finally went into effect on January 15 of this year. As a result of the Supreme Court's recent order, it appears the New York price control law will remain in effect for the foreseeable future. 

 

There are early signs that the New York law has unintended consequences for broadband competition and new deployments in that state. For more, see my February 20 FedSoc Blog post, "States Should Keep Broadband Internet Services Free From Price Controls."

Friday, October 04, 2024

Competition and Federal Law Preclude COLR Regulation of Wireless

The California Public Utilities Commission (PUC) has an open rulemaking proceeding in which it is considering whether to impose "carrier of last resort" (COLR) regulation on wireless voice providers. COLR rules are outdated and unjustifiable in today’s competitive market environment. And federal law preempts state COLR regulation of wireless voice providers.

A voice services carrier designated as a COLR typically is required to serve all customers within a territory, even if that means requiring them to build out their networks. COLRs must obtain permission from regulators before exiting the market. Also, COLRs typically are required to charge rates that are limited to what the regulating authority deems “just and reasonable.” 


COLR obligations are premised upon the existence of local monopoly conditions for voice telephone services. But those conditions do not exist anymore. Instead, today's voice market gives consumers choices among competing providers. As comments filed by CTIA on September 30 with the California PUC observed: 

Wireless providers in California operate in an intensely competitive market where “there are multiple providers that compete for wireless subscribers” and “consumers have the ability to switch providers” if they wish to do so. Due to this fierce competition, wireless providers in California experience customer switching rates between 9% and 34%.


FSF President Randolph May made a similar point about the competitive landscape for voice services and the outdatedness of COLR obligations in a blog post from June of this year:

In an era before consumers in almost all areas of the country, including California, had more than a single option from which to choose for the provision of basic voice telephone service, it may have made sense for the government to have the power to require that a service provider be designated as the Carrier of Last Resort. Needless to say, nowadays, consumers in most all areas have several options for acquiring voice telephone service from various providers that employ different technologies – copper wires, coaxial cable, fiber, cellular, satellite, and hybrid networks combining these facilities.

Additionally, Section 332(c)(3)(A) of the Communications Act contains a state preemption provision that effectively precludes states from imposing COLR obligations on wireless providers. The statute provides, in relevant part, that “no State or local government shall have any authority to regulate the entry of or the rates charged by any commercial mobile service or any private mobile service.” CTIA’s comments correctly point out that “[r]ate regulation has always been a key element of COLR regulation” and point out various ways that the California PUC regulates the rates of COLRs. Any attempt by California regulators to control the basic rate for wireless service would be preempted by federal law. 

 

Moreover, any COLR obligation that required a wireless provider to build out its network to serve customers surely would be preempted as a regulation of entry under Section 332(c)(3)(A). Indeed, any state COLR regulation regarding wireless providers exit likely would clash with the FCC’s decision, in its 1994 CMRS Order, to forbear from exit approval requirements for wireless providers. As CTIA’s comments described that order:

The FCC specifically elected to forbear from exercising its statutory authority to require CMRS providers to obtain approval for market exit for specific policy reasons, including that “barriers to exit may also deter potential entrants from entering the marketplace” and “the time involved in the decertification process can impose additional losses on a carrier after competitive circumstances have made a particular service uneconomic,” such that “forbearance will better serve the public interest by avoiding the social costs identified in this paragraph.”

COLR obligations impose costs on voice providers, and those costs can undermine a provider’s competitiveness. For the California PUC, the better policy for voice consumers, and the lawful one, would be to promote competition and not undermine it with outdated COLR regulations. 

Wednesday, August 28, 2024

ISPs Request High Court Ruling on State-Level Rate Regulation of Broadband

On August 10, a handful of trade associations representing broadband Internet service providers (ISPs) filed a petition for a writ of certiorari with the Supreme Court in New York State Telecommunications Association v. James. The petition presents the question of whether the Communications Act preempts New York's broadband rate-regulation law.

New York's Affordable Broadband Act imposes price ceilings – a form of rate regulation – on broadband ISPs offering service within the state. Under the New York law, ISPs offering service in the state must offer $15-per-month and $20-per-month plans to low-income individuals. 

 

On April 26 of this year, a Second Circuit panel's 2-1 majority rejected broadband ISPs' claims that the New York rate regulation law was subject to field preemption and conflict preemption. My summary of the court's decision in NYTSA v. James is presented in a May 3 Perspectives from FSF Scholars, "Second Circuit Rejects Preemption Challenge to New York's Broadband Rate Regulation."

 

At the time it was released, the Second Circuit's decision in NYSTA v. James was expected to be short-lived because the ruling was based on the FCC's Title I "information services" classification of broadband Internet access services under the Restoring Internet Freedom Order. The court's decision was issued a day after the Commission repealed the RIF Order and made its Title II "telecommunications services" reclassification decision in the Securing and Safeguarding the Open Internet Order. As I observed in a June 20 blog post, the petitioners in NYSTA v. James declined to file a petition for a rehearing en banc at the Second Circuit. They similarly declined to file a motion for reconsideration by the panel in light of the FCC’s new Title II Order. 

 

However, the legal ground shifted dramatically once again following the Supreme Court's decision in Loper Bright Enterprises v. Raimondo overturning the "Chevron doctrine" and especially after the Sixth Circuit's August 1 order staying the new Title II Order pending a decision on the merits in that case. For more, see Free State Foundation President Randolph May's August 23 Perspectives from FSF Scholars, "The Sixth Circuit Stays the FCC's Latest Net Neutrality Flip Flop."

 

On August 2, the petitioners in NYSTA v. James filed an emergency petition with Supreme Court Justice Sotomayor, seeking a stay on the Second Circuit's decision. On August 8, the petitioners filed a letter with an attached stipulated agreement by the parties. Under the stipulation, New York agreed to not enforce its rate regulation law pending the Supreme Court's decision on the ISPs' now-pending petition for a writ of certiorari. In their cert petition, filed on August 10, the ISPs renewed their arguments that New York's rate regulation law is subject to both field preemption and conflict preemption. According to the docket, New York is required to file its response by September 13.

 

For a critique of the Second Circuit's narrow understanding of conflict preemption, check out a May 10 Perspectives from FSF Scholars titled "Second Circuit Preemption Decision Won't Save New York Broadband Rate Regulation Scheme," by Law Professor Daniel Lyons, a member of the Free State Foundation's Board of Academic Advisors.  

Thursday, June 20, 2024

State-Level Rate Regulation of Broadband Faces Reckoning with Title II Preemption

On June 17, the U.S. Court of Appeals for the Second Circuit issued its mandate reversing and vacating the District Court decision that enjoined enforcement of New York's Affordable Broadband Act, a state law regulating the rates of broadband Internet access services. The New York law at issue requires broadband providers offering Internet access services in the state to make available plans that are subject to rate ceilings. Apparently, as many as one-third of New York households would qualify for such rate regulated plans. The law was challenged under the FCC's 2017 Restoring Internet Freedom Order.

In a May 10 Perspectives from FSF Scholars titled "Second Circuit Preemption Decision Won’t Save New York Broadband Rate Regulation Scheme," Law Professor Daniel Lyons – a member of the Free State Foundation’s Board of Academic Advisors – analyzed Second Circuit’s decision in NYSTA v. James. Prof. Lyons critiqued the court's narrow understanding of conflict preemption, while recognizing the court's acknowledgment that the decision would be short-lived because of a change in law. Just a day before the Second Circuit’s decision, the FCC's 2024 Safeguarding and Securing Order reclassified broadband Internet access service from a Title I "information service" to a Title II "telecommunications service." Prof. Lyons explained that the Commission's decision to forbear from ex ante and ex postrate regulation in its new Title II order preempts similar rate regulation at the state level. 

By a June 14 letter to the Second Circuit the broadband providers challenging the New York Affordable Broadband Act declined to seek a rehearing en banc. They similarly declined to file a motion to reconsider the court's decision based on the change in law from Title I to Title II. In his Perspectives, Prof. Lyons wrote that if a motion to reconsider proves unavailing that broadband providers "should seek relief from the Commission and hold it to its promise that it 'will not hesitate to exercise…authority' to preempt state laws that 'interfere or are incompatible with the federal regulatory framework' established under the order."

Will there soon be a petition filed at the FCC seeking a declaratory order preempting state-level rate regulation of broadband Internet access services under Title II? Whether it's the Commission or a future court decision, one should expect that the state-level rate regulation of broadband services will face a reckoning under the new Title II order. Stay tuned. 

For further background on the case and the likely bad effects of the FCC's new Title II order, see the summary of the Second Circuit's decision in NYTSA v. James in my May 3 Perspectives from FSF Scholars, "Second Circuit Rejects Preemption Challenge to New York's Broadband Rate Regulation" as well as my May 24 Perspectives, "The FCC's New Title II Order Allows Harmful Rate Regulation." 

Monday, May 13, 2024

18 … and Up? Maryland Is the Latest State to Enact a Privacy Law

Last Thursday, Free State Governor Wes Moore signed into law the Maryland Online Data Privacy Act of 2024 (MODPA). With the stroke of his pen, Maryland became the eighteenth state to adopt a comprehensive data privacy statute – one with the most onerous "data-minimization" requirements we have seen thus far.

Forgive me if I sound like a broken record, but this most-recent addition to the already substantial set of state-specific data privacy laws further compounds the confusion experienced by consumers and the compliance challenges faced by companies, particularly small businesses.

Should it become federal law, the American Privacy Rights Act (APRA) discussion draft, about which I wrote in a recent Perspectives from FSF Scholars, would preempt this patchwork and establish a desperately needed nationwide data privacy regime.

For a general overview of the MODPA, please see my two previous posts to the Free State Foundation blog on the topic, which can be found here and here. For present purposes, I want to focus specifically on the MODPA's data-minimization language, which states that "controllers" must "[l]imit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains" (emphasis added).

The data-minimization model differs from the notice-and-consent approach – pursuant to which the bounds of permissible data collection are set forth in a company's privacy policy – that until recently served as the de facto standard nationwide. And Maryland's version is the most extreme data-minimization implementation to date.

Strict data-minimization requirements such as this, and the one spelled out in the APRA, could have unintended anti-consumer consequences. Limitations on the collection of personal data beyond what is "reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains" – or, in the case of the APRA, "beyond what is necessary, proportionate, or limited to provide or maintain a product or service requested by an individual" (emphases added) – are inherently subjective standards that create substantial uncertainty and risk for companies. And that uncertainty and risk could have a chilling effect.

For example, companies may refrain from offering the "free" (that is, ad-supported) services that many consumers have come to rely on. The notice-and-consent model traditionally has allowed consumers to weigh the benefits of sharing personal information in exchange for these free services. The shift to a data-minimization approach could undermine that model, potentially leading to a reduction in the availability of complimentary online offerings.

The MODPA will go into effect on October 1, 2025, a year later than originally proposed.

Monday, April 29, 2024

Nebraska Is State 17 to Pass Privacy Law; House Holds Hearing on APRA

In a recent Perspectives from FSF Scholars summarizing the American Privacy Rights Act (APRA) Discussion Draft, I added New Hampshire (number fifteen) and Kentucky (number sixteen) to the Free State Foundation's running list of states that have passed a comprehensive data privacy statute. The Cornhusker State in the interim has joined their ranks, upping that total to seventeen. Meanwhile, at a House Commerce Committee hearing on the APRA, more than one representative indicated that they are "fired up" (subscription required) to turn that bill into preempting federal law.

New Jersey was the first state in 2024 (and the fourteenth overall) to enact privacy legislation, a development I noted in a January post to the FSF Blog. The New Hampshire Privacy Act followed in March, the Kentucky Consumer Data Protection Act in early April. (Two days later the Maryland Online Data Privacy Act of 2024, about which I blogged here and here, cleared both legislative houses. Should it be signed by Governor Wes Moore, it will bring the tally to eighteen. That is, assuming another state – Pennsylvania, perhaps? – doesn't beat it to the punch.)

And on April 12, Governor Jim Pillen enacted the Nebraska Data Privacy Act, a statute very similar in substance to the Texas Data Privacy and Security Act, a bill that I summarized in July 2023's aptly titled "More States Compound the Dreaded Privacy 'Patchwork' Problem."

Of course, one of the aspects of the APRA Discussion Draft that I praised in "Congressional Leaders Return Privacy to the Front Burner," the Perspectives referenced above, is its language preempting state comprehensive data privacy laws: "no State or political subdivision thereof may adopt, maintain, enforce, or continue in effect any law, regulation, rule, or requirement covered by the provisions of this Act or a rule, regulation, or requirement promulgated under this Act."

As such, passage of the APRA – by no means a foregone conclusion – would eliminate the chaos and compliance contradictions created by the expanding number of state laws.

At an April 17 hearing held by the House Commerce Committee's Subcommittee on Innovation, Data, and Commerce, APRA co-author and Committee Chair Cathy McMorris Rodgers (R-WA) acknowledged that "Congress has been trying to develop and pass comprehensive data privacy and security legislation for decades" and argued that "[w]ith the American Privacy Rights Act, we are at a unique moment in history where we finally have the opportunity to imagine the internet as a force for prosperity and good."

In response, Subcommittee Chair Gus Bilirakis (R-FL) reportedly stated that he is "fired up" – and Representative Frank Pallone (D-NJ) indicated that he is "fired up too."

Friday, February 16, 2024

Free State Lawmakers Debate Data Privacy Legislation

Maryland soon could join the not-so-exclusive club for states that have forged divergent data privacy regulatory paths. Last month, New Jersey became the fourteenth state (and the first this year) to enact a comprehensive data privacy law, a development that I highlighted in a January 2024 post to the Free State Foundation's blog. Yet another bill awaits the signature of New Hampshire Governor Chris Sununu.

As I detailed most recently in "More States Compound the Dreaded Privacy 'Patchwork' Problem," a July 2023 Perspectives from FSF Scholars, the longstanding lack of a federal data privacy regime – specifically, one that preempts inconsistent state-specific approaches – has fostered an unworkable situation that creates compliance headaches for companies and confusion for consumers.

Hearings on the Maryland Online Data Privacy Act of 2024 (the Act) were held on February 13, 2024, by the House Economic Matters Committee (House Bill 567) and on February 14, 2024 by the Senate Finance Committee (Senate Bill 541).

The Act establishes a familiar set of consumer rights: to know that personal data is being collected; to access, correct, delete, and receive a copy of personal data; to obtain a list of the categories of third parties to which personal data is disclosed; to opt out of the processing of personal data for targeted advertising and automated profiling; and to opt out of its sale.

Perhaps most notably, the Act goes further than other state laws in limiting the personal data that companies may collect – that is, "data minimization" ("A controller shall … [l]imit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains.")

On its face, the Act does not create a private right of action. As was the case with the New Jersey law reference above, however, the Act's draft language has prompted concerns that it "do[es] not explicitly provide for exclusive Attorney General enforcement" (emphasis added). Specifically, Section 14-4613, which defines a violation of the Act as "[a]n unfair, abusive, or deceptive trade practice … [s]ubject to the enforcement and penalty provisions contained in Title 13 of this article," also ambiguously asserts that it "does not prevent a consumer from pursuing any other remedy provided by law."

Breaking from the approach embraced by other states, and thus further complicating compliance for companies, the Act does not provide businesses with an opportunity to cure alleged violations.

If enacted, the Act would go into effect on October 1, 2024.