Showing posts with label Privacy Legislation. Show all posts
Showing posts with label Privacy Legislation. Show all posts

Friday, June 26, 2026

Alabama, Louisiana, and Vermont Enact Privacy Laws: The Number of Such States Is Now One Shy of Half

As I noted in an April post to the FSF Blog, the Sooner State, with the enactment of the Oklahoma Consumer Data Privacy Act, became the first in nearly two years to enact a comprehensive data privacy statute. In the intervening months, three more states – Alabama, Louisiana, and Vermont – have followed suit, bringing the total to 24.

As the number of state-specific privacy regimes increases, so, too, do the complexity burdens for consumers seeking to understand their rights and the compliance questions for companies seeking to satisfy their regulatory obligations.

Alabama

Yellowhammer State Governor Kay Ivey signed the Alabama Personal Data Protection Act (APDPA) into law on April 16. It will take effect on May 1, 2027.

"Fun" differentiating fact: the APDPA has a lower applicability bar than most, covering companies that (1) control or process the personal information of just 25,000 Alabama residents, or (2) earn over 25 percent of their gross revenues from the sale of personal data, no matter how many Alabama residents that involves.

Louisiana

Pelican State Governor Jeff Landry signed the Louisiana Data Privacy Act (LDPA) on May 29. It will take effect on January 1, 2027.

"Fun" differentiating fact: the LDPA includes a temporary 30-day cure period that applies before the Attorney General may initiate an investigation; in other states, the cure period typically runs after the investigation but before the commencement of an enforcement action.

Vermont

Green Mountain State Governor Phil Scott signed the Vermont Data Privacy and Online Surveillance Act (VDPOSA) on June 16. It will take effect on January 1, 2028.

"Fun" differentiating fact: Vermont residents whose "personal data were processed for the purposes of profiling in furtherance of any automated decision" may "question the result of such profiling."

All three statutes assign enforcement authority to the state attorney general. The Louisiana and Vermont laws expressly exclude a private right of action while the Alabama law is silent on the topic.

*    *    *

A comprehensive federal regime could take the "fun" out of data privacy and put in its place a single, straightforward set of consumer rights and corporate responsibilities that apply nationwide.

Which brings us to the Securing and Ensuring Consumer Uniform Rights and Enforcement over Data Act (SECURE Data Act), legislation introduced by a group of House Republicans on April 21.

As noted by Free State Foundation Adjunct Senior Fellow Michael O'Rielly in "The House Builds a Sound Privacy Bill," a May Perspectives from FSF Scholars, The SECURE Data Act (1) embraces "strong federal preemption that recognizes the interstate nature of data collection and consumption" and (2) rejects a private right of action in favor of exclusive enforcement by the FTC and state attorneys general, thereby "prevent[ing] abusive class-action lawsuits by trial attorneys that have plagued many other sectors of our economy."

The House Energy and Commerce Committee's Subcommittee on Commerce, Manufacturing, and Trade held a hearing on the SECURE Data act on June 3. The Press Release included the following quote from Subcommittee Chairman Gus Bilirakis (R-FL): "Americans, regardless of political affiliation, share a fundamental expectation that their personal data be protected and secure…. The productive dialogue during today's hearing represents an important step toward creating a framework that puts constituents back in control of their personal information while holding bad actors accountable."

Friday, April 24, 2026

"Soon" (But Not Too Soon), House Republicans Introduce Privacy Bills

In a Tuesday post to the Free State Foundation blog, I repeated the quote – which I first referenced in a January Perspectives from FSF Scholars – that the House Energy and Commerce Committee Privacy Working Group could introduce comprehensive data privacy legislation "soon." In this instance, "soon" translated to "Wednesday." That's when the House Committees on Energy and Commerce and Financial Services jointly introduced a pair of companion bills: the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act (SECURE Data Act) and the Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act (GUARD Financial Data Act).

The SECURE Data Act is the handiwork of the aforementioned working group, led by Representative John Joyce, M.D. (R-PA). The working group is composed of Republican members of the House Energy and Commerce Committee, which is chaired by Representative Brett Guthrie (R-KY). The GUARD Financial Data Act, meanwhile, is the product of the Financial Services Committee, led by Chairman French Hill (R-AR).

The two bills are designed to work in tandem: the SECURE Data Act covers consumer data handled by nonfinancial entities but exempts financial institutions and data subject to the Gramm-Leach-Bliley Act (GLBA), while the GUARD Financial Data Act modernizes the GLBA for the financial sector but exempts nonfinancial firms. As a joint one-pager released by the two committees explained, together the bills "form a common-sense Federal approach that will bring American privacy protections into the twenty-first century."

At a high level, the SECURE Data Act builds on – and, crucially, would preempt – the state-level "patchwork" that I have long lamented. It also wisely rejects a private right of action, leaving enforcement to the FTC and state attorneys general.

*    *    *

The SECURE Data Act establishes a set of now-familiar consumer rights, including the right to access, correct, delete, and transfer personal data. It also creates opt-out rights for targeted advertising, data sales, and certain automated profiling decisions. Processing of "sensitive data" would require opt-in consent, and parental consent would be required for the processing of data of teens (that is, those between the ages of 13 and 16). The processing of data of children under the age of 13 would remain subject to the provisions of the Children's Online Privacy Protection Act of 1998.

On the business side, the bill imposes data-minimization obligations that would limit the collection of data to what is "adequate, relevant, and reasonably necessary." It also includes data security requirements, privacy notice mandates, and data-protection-assessment requirements. Data brokers would be required to register with the FTC, which would maintain a searchable public registry. And businesses would have to disclose whether personal data is transferred to, processed in, or sold to foreign adversaries.

The SECURE Data Act would apply to businesses that process the personal data of at least 200,000 consumers annually. A separate threshold would cover data sellers that process the data of at least 100,000 consumers and derive over 25 percent of their revenue from the sale of personal data. Businesses with less than $25 million in adjusted gross annual revenue would be exempt.

As noted above, the bill does not create a private right of action. Instead, the FTC and state attorneys general would share enforcement authority. As I previously argued, exclusive enforcement by the FTC is far more likely to serve consumer interests than a private right of action, which would create problematic financial incentives for the plaintiffs' bar.

Perhaps most significant is the SECURE Data Act's broad preemption language, which provides that no state may "prescribe, maintain, or enforce any law, rule, regulation, requirement, standard, or other provision having the force and effect of law, if such law, rule, regulation, requirement, standard, or other provision relates to the provisions of this Act." This would appear to preempt the entire "patchwork" of state-specific privacy laws, now numbering 21, replacing them with a single, workable, nationwide standard.

*    *    *

Of course, the standard caveats apply. As a Republican-only bill, the SECURE Data Act will need to attract bipartisan support if it is to become law. And the usual sticking points – in particular, the bill's rejection of a private right of action and its strong preemption language – could impede its progress, something we certainly have seen happen before to similar pieces of legislation.

Nevertheless, the SECURE Data Act seems to strike an appropriate balance between protecting privacy and fostering innovation, a point made by NCTA – The Internet & Television Association in its supportive statement: the SECURE Data Act's "unified approach will strengthen consumer trust, give individuals meaningful control over their personal information, and provide businesses the certainty needed to innovate, protect data, and drive growth while eliminating the confusing patchwork of state laws that burdens consumers and businesses."

Tuesday, April 21, 2026

Later Rather Than Sooner: Oklahoma Enacts State Privacy Law No. 21

After a steady stream of state-level privacy statutes, capped by passage of the Rhode Island Data Transparency and Privacy Protection Act in June 2024, for nearly two years the pipeline ran dry. That drought ended on March 20, when Sooner State Governor Kevin Stitt signed into law the Oklahoma Consumer Data Privacy Act (OCDPA). With that, the list of states to have passed a comprehensive data privacy statute now stands (by my count) at 21.

At the federal level, meanwhile, the pickings remain slim. In late March, Representative Zoe Lofgren (D-CA) for the fourth time introduced the Online Protection Act, the shortcomings of which I rehashed in a contemporaneous post to the Free State Foundation blog. Beyond that, hopeful eyes can look only to the House Commerce Committee Privacy Working Group, which was created in February 2025 and sought public input a month later. As I noted in a January Perspectives from FSF Scholars, reporting at that time suggested that the working group could release a draft bill … "soon."

The good news about the OCDPA, which closely tracks the Virginia Consumer Data Protection Act, is that it does not impose more burdensome obligations than existing state laws – and therefore is regarded as a relatively "business-friendly" addition to the state-level "patchwork."

The bad news, of course, is that it further expands that "patchwork," thereby compounding compliance headaches for companies – especially smaller companies and start-ups – and making it even more challenging for consumers to comprehend their rights.

*    *    *

More targeted than other state laws, the OCDPA applies only to businesses operating in Oklahoma or targeting Oklahoma residents that control or process the personal data of either (1) 100,000 or more Oklahoma consumers, or (2) at least 25,000 Oklahoma consumers while deriving over 50 percent of their gross revenue from the "sale" of personal data. (By comparison, that threshold is lower – 25 percent – in most state laws.) In addition, the OCDPA defines "sale" relatively narrowly – that is, only where personal data is exchanged for monetary consideration.

The law establishes a now-familiar set of consumer rights: to access and confirm the processing of personal data, to correct inaccuracies, to delete, and to obtain a portable copy. In addition, consumers can opt out of the processing of personal data for targeted advertising, the sale of their personal data, and profiling.

"Sensitive data" – defined to include racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship status, genetic or biometric data used for identification, and precise geolocation data – may not be processed without the consumer's opt-in consent.

Covered businesses must abide by data-minimization principles, limiting collection to what is adequate, relevant, and reasonably necessary. They also must conduct data protection assessments before engaging in activities such as targeted advertising, the sale of personal data, and the processing of "sensitive data."

Two additional features of the OCDPA are worth highlighting. First, enforcement authority rests exclusively with the Oklahoma Attorney General; there is no private right of action. Second, the law includes a permanent, mandatory 30-day "right to cure" period for alleged violations – a feature that stands in contrast to the trend in other states toward sunsetting or eliminating cure periods altogether. Violations may result in penalties of up to $7,500 per incident.

The OCDPA will go into effect on January 1, 2027.

*    *    *

As I've stated countless times, the absence of a comprehensive federal data privacy law that would preempt this now-larger "patchwork" remains a glaring gap. With each new state law – and each set of idiosyncratic definitions of rights, responsibilities, thresholds, exemptions, enforcement mechanisms, and so on – the compliance burden on businesses grows heavier and the regulatory landscape confronting consumers grows murkier.

Friday, March 27, 2026

Representative Lofgren's Online Privacy Act Has Reentered the Chat

As we eagerly await word from the House Energy and Commerce Committee's data privacy working group, Representative Zoe Lofgren (D-CA) once again has resurrected the problematic Online Privacy Act (OPA).

In February 2025, Committee Chairman Brett Guthrie (R-KY) and Vice Chairman John Joyce, M.D. (R-PA) announced the establishment of a data privacy working group "to bring members and stakeholders together to explore a framework for legislation that can get across the finish line." (For more information please see my contemporaneous post to the Free State Foundation blog).

Shortly thereafter, the working group solicited public comment on a Request for Information that I summarized in a follow-up blog post.

In a January Perspectives from FSF Scholars summarizing privacy-related legislative activity in 2025, I shared speculation that the working group might introduce a bill "soon." Separate reporting around the same time indicated that the working group "intend[s] to take up action on a broader, comprehensive federal privacy measure in spring 2026."

In the interim, Representative Lofgren for the fourth time has introduced the OPA, a draft bill first unveiled in 2019 and then again in 2021 and 2023.

As I pointed out in "A Tale of Three Data Privacy Bills: Federal Legislative Stalemate Enables Bad State Laws," a January 2022 Perspectives, the OPA has two top-level shortcomings: (1) it "is silent on the issue of preemption," and thus fails to address the state-level "patchwork" problem that in the intervening years has only gotten worse; and (2) it creates a private right of action that, unlike exclusive enforcement by the FTC, would be far more likely to benefit the plaintiffs' bar than consumers.

With the vernal equinox exactly one week in the rear-view mirror, it remains possible that the working group will introduce (presumably preferable) comprehensive data privacy legislation this spring.

Time will tell.

Tuesday, March 04, 2025

House Commerce Privacy Working Group Seeks Input

In a February 2025 post to the FSF Blog, I reported on a press release from House Commerce Committee Chairman Brett Guthrie (R-KY) and Vice Chairman John Joyce, M.D. (R-PA) announcing the creation of a working group focused on federal comprehensive data privacy legislation. That working group is now asking interested parties to provide responses to a Request for Information (RFI).

Released on February 21, 2025, the RFI begins by acknowledging two points I have highlighted repeatedly in writings for the Free State Foundation, most recently in a December 2024 Perspectives from FSF Scholars.

One, that "the challenge of providing clear digital protections for Americans is compounded by the fast pace of technological advancement and the complex web of state and federal data privacy and security laws, which in some cases create conflicting legal requirements."

And two, that "Members of Congress have spent many years working toward federal comprehensive data privacy and security standards to bring consumer protections into the digital age while ensuring that the U.S. continues to lead in a globally competitive environment."

The information sought by the RFI is organized into the following six specific categories:

  • Roles and Responsibilities: What types of entities collect, process, and sell personal information? What obligations should apply to each?
  • Personal Information, Transparency, and Consumer Rights: What specific consumer protections should a privacy law include? What heightened safeguards should apply to sensitive personal information? How should covered entities provide disclosures to consumers?
  • Existing Privacy Frameworks and Protections: What can be learned from the existing "patchwork" of state privacy laws? To what extent should a federal privacy law preempt state privacy laws?
  • Data Security: How can federal lawmakers ensure the security of consumer data?
  • Artificial Intelligence (AI): How might a federal privacy law account for existing state laws addressing AI, including those relating to automated decision-making?
  • Accountability and Enforcement: What are the pros and cons of exclusive enforcement by the FTC and state Attorneys General? Should a federal privacy law include a safe harbor?

A seventh, catch-all, category encourages interested parties to submit "any additional information that may be relevant to the working group as it develops a comprehensive data privacy and security law."

Responses, due by April 7, 2025, should be emailed to PrivacyWorkingGroup@mail.house.gov.

Tuesday, February 18, 2025

House Commerce Leaders Create Privacy Working Group

On February 12, 2025, House Commerce Committee Chairman Brett Guthrie (R-KY) and Vice Chairman John Joyce, M.D. (R-PA) issued a press release announcing the formation of a comprehensive data privacy working group.

This marks the first notable federal legislative step forward on privacy since a full House Commerce Committee markup of the American Privacy Rights Act of 2024 (APRA), scheduled for June 27, 2024, was cancelled at the last minute. For more on the fate of the APRA, please see my year-end comprehensive recap of developments at both the federal and state levels, "2024 Data Privacy Legislative Review: Federal Lawmakers Fall Short As More State Laws Gain Teeth," a December 2024 Perspectives from FSF Scholars.

In the press release, Chairman Guthrie and Vice Chairman Joyce stated that:

We strongly believe that a national data privacy standard is necessary to protect Americans' rights online and maintain our country's global leadership in digital technologies, including artificial intelligence. That's why we are creating this working group, to bring members and stakeholders together to explore a framework for legislation that can get across the finish line…. The need for comprehensive data privacy is greater than ever, and we are hopeful that we can start building a strong coalition to address this important issue.

They also encouraged interested parties to engage with the working group by sending an email to PrivacyWorkingGroup@mail.house.gov.

Tuesday, December 17, 2024

Michigan Could Become State No. 21 to Pass a Data Privacy Law

In a Perspectives from FSF Scholars on privacy legislation in 2024 published just last week, I wrote that seven additional states adopted comprehensive data privacy statutes this year, bringing the total to twenty. But did I speak too soon? The very same day, Michigan Senator Rosemary Bayer (D) announced via press release that the Personal Data Privacy Act (Senate Bill 659) had passed the Senate.

Should Senate Bill 659 clear the House before the current legislative session ends on December 23, the Wolverine State could become the eighth state in 2024, and the twenty-first overall, to forge a unique data privacy path.

Senate Bill 659 would establish familiar consumer rights including: the right to know that personal data is being processed, the right to access that personal data, the right to correct inaccuracies, the right to delete, and the right to obtain a portable copy. Consumers also would be able to opt out of the sale of personal data, targeted advertising, and "[p]rofiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer."

As is the case with the Maryland Online Data Privacy Act of 2024, which I summarized in a February post to the Free State Foundation blog, Senate Bill 659 includes "data minimization" provisions that "limit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a product or service requested by the consumer … consistent with the consumer's reasonable expectations" (emphases added) and place similarly subjective limits on the processing of personal data. Sensitive data may be collected and/or processed only where "strictly necessary."

Senate Bill 659 would not create a private right of action. Instead, the state attorney general would have exclusive enforcement authority. It would go into effect a year from the date of enactment.

Tuesday, July 16, 2024

Will AI Help or Hinder Federal Privacy Legislative Efforts?

Efforts to pass a federal data privacy law have dragged on for many years. During that time, unrelenting technological advancement simultaneously has produced new innovations that amplify calls for clear rules and complicated congressional conversations that might lead to such legislation. Artificial Intelligence (AI) is the latest such instigator/troublemaker.

Generative AI offerings – such as OpenAI's ChatGPT, Google's Gemini, and Meta AI – depend upon Large Language Models (LLMs) trained on massive amounts of data. The more data used to train the LLM, the better the results. Consequently, generative AI raises substantial questions relating to privacy. (By way of example, the image below was created with OpenAI's DALL-E using the prompt "create an image of generative AI and data privacy.")

In her Opening Statement regarding a recent Senate Commerce, Science and Transportation Committee hearing titled "The Need to Protect Americans' Privacy and the AI Accelerant," Chair Maria Cantwell (D-WA) wrote that "[w]e are being surveilled … tracked online in the real world, through connected devices. And now, when you add AI, it is like putting fuel on a campfire in the middle of a windstorm." AI, she argued, "increases the need for passing legislation soon."

This heightened concern, however, to date has not generated legislative progress on data privacy. The American Privacy Rights Act of 2024, about which I wrote in "Congressional Leaders Return Privacy to the Front Burner," an April 2024 Perspectives from FSF Scholars, has yet to advance beyond a discussion draft. It was scheduled for markup by the House Energy and Commerce Committee on June 27, 2024, but that markup was cancelled at the last minute, a development I described in a post to the Free State Foundation's blog.

Prompting an unsettling sense of déjà vu, already one state has taken stalled congressional matters into its own hands. On May 17, 2024, Colorado Governor Jared Polis signed into law Senate Bill 24-205, "Concerning Consumer Protections in Interactions with Artificial Intelligence Systems."

Broadly speaking, Senate Bill 24-205, which goes into effect on February 1, 2026, requires that developers of "high-risk" AI systems "use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination."

We shall see if other states follow Colorado's lead – and, if so, whether another unwanted privacy-related "patchwork" emerges.

Friday, June 28, 2024

Federal Privacy Bill Hits Roadblock, State Activity Picks Up Speed

At the eleventh hour, the House Energy and Commerce Committee cancelled a markup scheduled for Thursday that included the American Privacy Rights Act of 2024 (APRA). At the state level, by contrast, Minnesota and Rhode Island recently enacted their own comprehensive data privacy laws, bringing the total to 20. And previously adopted statutes in three states – Oregon, Texas, and Florida – go into effect on July 1.

Having cleared the Innovation, Data, and Commerce Subcommittee late last month, the APRA was one of eleven bills on the agenda for yesterday's full committee markup. Chair Cathy McMorris Rodgers (R-WA) did not state a reason for the last-minute cancellation, but The Hill reported that House Republican leadership objected to the private right of action created by the discussion draft.

As it happens, in "Congressional Leaders Return Privacy to the Front Burner," an April Perspectives from FSF Scholars, I anticipated that "the APRA's problematic inclusion of a private right of action may – and should – prove once again to be a sticking point."

The already sizeable patchwork of state comprehensive data privacy laws, meanwhile, continues to grow. (So, too, do the associated compliance headaches for companies and confusion faced by consumers.) On May 24, 2024, North Star State Governor Tim Walz signed the Minnesota Consumer Data Privacy Act, a law similar – though not identical, of course – to those passed in New Hampshire and Maryland.

And on June 25, 2024, Ocean State Governor Dan McKee transmitted with no signature the Rhode Island Data Transparency and Privacy Protection Act, bringing the total of state comprehensive data privacy laws to 20. The Rhode Island statute is notable for its relatively large fines: up to $10,000 per violation, plus additional penalties for "intentional disclosures of personal data."

The Minnesota act will not go into effect until July 31, 2025, the Rhode Island law not until January 1, 2026. Laws in three other states, however, kick in on the first day of July: the Oregon Consumer Privacy Act, the Texas Data Privacy and Security Act, and – by my measure, at least – the Florida Digital Bill of Rights.

For additional details on these statutes, please see "More States Compound the Dreaded Privacy 'Patchwork' Problem," a July 2023 Free State Foundation Perspectives.

Monday, May 13, 2024

18 … and Up? Maryland Is the Latest State to Enact a Privacy Law

Last Thursday, Free State Governor Wes Moore signed into law the Maryland Online Data Privacy Act of 2024 (MODPA). With the stroke of his pen, Maryland became the eighteenth state to adopt a comprehensive data privacy statute – one with the most onerous "data-minimization" requirements we have seen thus far.

Forgive me if I sound like a broken record, but this most-recent addition to the already substantial set of state-specific data privacy laws further compounds the confusion experienced by consumers and the compliance challenges faced by companies, particularly small businesses.

Should it become federal law, the American Privacy Rights Act (APRA) discussion draft, about which I wrote in a recent Perspectives from FSF Scholars, would preempt this patchwork and establish a desperately needed nationwide data privacy regime.

For a general overview of the MODPA, please see my two previous posts to the Free State Foundation blog on the topic, which can be found here and here. For present purposes, I want to focus specifically on the MODPA's data-minimization language, which states that "controllers" must "[l]imit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains" (emphasis added).

The data-minimization model differs from the notice-and-consent approach – pursuant to which the bounds of permissible data collection are set forth in a company's privacy policy – that until recently served as the de facto standard nationwide. And Maryland's version is the most extreme data-minimization implementation to date.

Strict data-minimization requirements such as this, and the one spelled out in the APRA, could have unintended anti-consumer consequences. Limitations on the collection of personal data beyond what is "reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains" – or, in the case of the APRA, "beyond what is necessary, proportionate, or limited to provide or maintain a product or service requested by an individual" (emphases added) – are inherently subjective standards that create substantial uncertainty and risk for companies. And that uncertainty and risk could have a chilling effect.

For example, companies may refrain from offering the "free" (that is, ad-supported) services that many consumers have come to rely on. The notice-and-consent model traditionally has allowed consumers to weigh the benefits of sharing personal information in exchange for these free services. The shift to a data-minimization approach could undermine that model, potentially leading to a reduction in the availability of complimentary online offerings.

The MODPA will go into effect on October 1, 2025, a year later than originally proposed.

Monday, April 29, 2024

Nebraska Is State 17 to Pass Privacy Law; House Holds Hearing on APRA

In a recent Perspectives from FSF Scholars summarizing the American Privacy Rights Act (APRA) Discussion Draft, I added New Hampshire (number fifteen) and Kentucky (number sixteen) to the Free State Foundation's running list of states that have passed a comprehensive data privacy statute. The Cornhusker State in the interim has joined their ranks, upping that total to seventeen. Meanwhile, at a House Commerce Committee hearing on the APRA, more than one representative indicated that they are "fired up" (subscription required) to turn that bill into preempting federal law.

New Jersey was the first state in 2024 (and the fourteenth overall) to enact privacy legislation, a development I noted in a January post to the FSF Blog. The New Hampshire Privacy Act followed in March, the Kentucky Consumer Data Protection Act in early April. (Two days later the Maryland Online Data Privacy Act of 2024, about which I blogged here and here, cleared both legislative houses. Should it be signed by Governor Wes Moore, it will bring the tally to eighteen. That is, assuming another state – Pennsylvania, perhaps? – doesn't beat it to the punch.)

And on April 12, Governor Jim Pillen enacted the Nebraska Data Privacy Act, a statute very similar in substance to the Texas Data Privacy and Security Act, a bill that I summarized in July 2023's aptly titled "More States Compound the Dreaded Privacy 'Patchwork' Problem."

Of course, one of the aspects of the APRA Discussion Draft that I praised in "Congressional Leaders Return Privacy to the Front Burner," the Perspectives referenced above, is its language preempting state comprehensive data privacy laws: "no State or political subdivision thereof may adopt, maintain, enforce, or continue in effect any law, regulation, rule, or requirement covered by the provisions of this Act or a rule, regulation, or requirement promulgated under this Act."

As such, passage of the APRA – by no means a foregone conclusion – would eliminate the chaos and compliance contradictions created by the expanding number of state laws.

At an April 17 hearing held by the House Commerce Committee's Subcommittee on Innovation, Data, and Commerce, APRA co-author and Committee Chair Cathy McMorris Rodgers (R-WA) acknowledged that "Congress has been trying to develop and pass comprehensive data privacy and security legislation for decades" and argued that "[w]ith the American Privacy Rights Act, we are at a unique moment in history where we finally have the opportunity to imagine the internet as a force for prosperity and good."

In response, Subcommittee Chair Gus Bilirakis (R-FL) reportedly stated that he is "fired up" – and Representative Frank Pallone (D-NJ) indicated that he is "fired up too."

Tuesday, March 19, 2024

Maryland House of Delegates, Senate Approve Data Privacy Bills

On Saturday – just ahead of yesterday's "crossover day" deadline – the Maryland House of Delegates voted 105-32 to approve HB-567, comprehensive data privacy legislation. The cross-filed Senate bill, SB-541, passed unanimously last Thursday.

Should the Maryland Online Data Privacy Act of 2024, which has been referred to conference, become law, it would represent the sixteenth contribution to the state-level "patchwork" of comprehensive data privacy laws that has emerged in the face of Congress's continuing failure to act.

For an overview of the law's specific provisions, please see "Free State Lawmakers Debate Data Privacy Legislation," a February 2024 post to the FSF Blog.

Friday, February 16, 2024

Free State Lawmakers Debate Data Privacy Legislation

Maryland soon could join the not-so-exclusive club for states that have forged divergent data privacy regulatory paths. Last month, New Jersey became the fourteenth state (and the first this year) to enact a comprehensive data privacy law, a development that I highlighted in a January 2024 post to the Free State Foundation's blog. Yet another bill awaits the signature of New Hampshire Governor Chris Sununu.

As I detailed most recently in "More States Compound the Dreaded Privacy 'Patchwork' Problem," a July 2023 Perspectives from FSF Scholars, the longstanding lack of a federal data privacy regime – specifically, one that preempts inconsistent state-specific approaches – has fostered an unworkable situation that creates compliance headaches for companies and confusion for consumers.

Hearings on the Maryland Online Data Privacy Act of 2024 (the Act) were held on February 13, 2024, by the House Economic Matters Committee (House Bill 567) and on February 14, 2024 by the Senate Finance Committee (Senate Bill 541).

The Act establishes a familiar set of consumer rights: to know that personal data is being collected; to access, correct, delete, and receive a copy of personal data; to obtain a list of the categories of third parties to which personal data is disclosed; to opt out of the processing of personal data for targeted advertising and automated profiling; and to opt out of its sale.

Perhaps most notably, the Act goes further than other state laws in limiting the personal data that companies may collect – that is, "data minimization" ("A controller shall … [l]imit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains.")

On its face, the Act does not create a private right of action. As was the case with the New Jersey law reference above, however, the Act's draft language has prompted concerns that it "do[es] not explicitly provide for exclusive Attorney General enforcement" (emphasis added). Specifically, Section 14-4613, which defines a violation of the Act as "[a]n unfair, abusive, or deceptive trade practice … [s]ubject to the enforcement and penalty provisions contained in Title 13 of this article," also ambiguously asserts that it "does not prevent a consumer from pursuing any other remedy provided by law."

Breaking from the approach embraced by other states, and thus further complicating compliance for companies, the Act does not provide businesses with an opportunity to cure alleged violations.

If enacted, the Act would go into effect on October 1, 2024.

Friday, January 19, 2024

New Jersey Passes 2024's First State Privacy Law

The privacy plot thickens: New Jersey just became the first state in 2024 – and (by my count) the fourteenth overall – to enact a comprehensive data privacy law. Bill S332, formally titled "An Act concerning online services, consumers, and personal data and supplementing Title 56 of the Revised Statutes" (the Act), was signed on Tuesday by Governor Phil Murphy.

At the federal level, sadly, there has been little news to report in well over a year. Consequently, each additional state that forges its own unique path further muddies the waters, creating more chaos for consumers and more compliance nightmares for companies.

The Act establishes a number of familiar consumer rights with respect to personal data: to confirm its collection and processing, to correct, to delete, to receive a portable copy, to opt out of its processing for targeted advertising as well as its sale, and to opt in to the processing of "sensitive data."

Not surprisingly, however, the Act includes several provisions that distinguish it from other state privacy statutes – and thereby unduly complicate nationwide compliance efforts. For one, it does not set a minimum-revenue threshold for covered companies. For another, its definition of "sensitive data" includes certain types of financial information.

The New Jersey Department of Law and Public Safety's Division of Consumer Affairs is tasked with adopting regulations implementing the Act. The New Jersey Attorney General has exclusive enforcement authority. For the first year and a half, companies will enjoy a 30-day cure period.

The Act does not create a private right of action, However, an eleventh-hour amendment deleting the phrase "under any other law" did prompt Governor Murphy to note in his Statement Upon Signing that:

I understand that concerns have been raised that removing that language thereby establishes a private right of action under other laws for violations of this bill. However, nothing in this bill expressly establishes such a private right of action, and the provision as amended states that the bill shall not be "construed as providing the basis for … a private right of action for violations of [the bill]."

The bulk of the Act will go into effect on January 15, 2025. The obligation to abide universal opt-out mechanisms (such as web browser-based privacy signals) will kick in six months later.

Tuesday, October 31, 2023

Maine May Join the State Privacy Law Club

Might the Pine Tree State in 2024 become the fourteenth state to pass a comprehensive data privacy law – and thereby further compound the problem of multiple, conflicting state statutes? It's possible. The Maine legislature's bicameral Judiciary Committee considered "An Act to Create the Data Privacy and Protection Act" (LD 1977) at a hearing two weeks ago.

LD 1977 is modeled on the American Data Privacy and Protection Act (ADPPA), a piece of federal legislation that easily cleared the House Commerce Committee back in August 2022 before losing forward momentum. That LD 1977 takes its lead from the ADPPA is somewhat ironic, as one of the primary motivating factors driving the ADPPA was the problem of a "patchwork" of state-specific laws, a problem that LD 1977 threatens to exacerbate.

To make matters worse, LD 1977 problematically diverges from the ADPPA by including an extremely broad private right of action. Specifically, Section 9620(2) states that:

A violation of this chapter or a rule adopted under this chapter with respect to the covered data of an individual constitutes an injury to that individual. The injured individual may bring a civil action against the party that commits the violation, except that an individual may not bring a civil action against a small business.

Possible remedies include actual damages or statutory damages starting at $5,000 per violation, whichever are greater; punitive damages; attorney's fees and costs; and injunctive and declaratory relief. A "small business" is a "covered entity" or "service provider" (but not a "data broker") that (1) generates less than $41 million in annual revenues, and (2) does not collect or process the personal data or more than 200,000 individuals.

Something else to consider: as I described in "Maine's ISP-Only Privacy Law Will Not Protect Consumers," an April 2020 Perspectives from FSF Scholars, Maine adopted a privacy law in June 2019 that singles out broadband Internet service providers (ISPs), requiring them – but not other participants in the broader online ecosystem, such as "edge providers" like Alphabet, Meta, and Amazon – to obtain "opt-in" consent from customers before using their personal information.

At an absolute minimum, any additional privacy legislation must acknowledge – and address – this disparate treatment of broadband ISPs.

Thursday, September 28, 2023

Delaware Privacy Law Makes a Dozen – or a Baker's Dozen?

First State Governor John Carney signed the Delaware Personal Data Privacy Act (the DPDPA) into law on September 11, 2023.

For those keeping score, Delaware increases the number of states to have passed a comprehensive data privacy law either to twelve – "Delaware Becomes Twelfth State to Enact Comprehensive Privacy Law" – or thirteen – "The 'First State' Officially Becomes the Thirteenth State with a Comprehensive Data Privacy Law" – depending on how one defines "comprehensive."

And for those concerned with the confusion and cost caused by the growing patchwork of inconsistent state laws, the fact that commenters cannot agree even on what the current total is underscores the extent of the problem.

In "More States Compound the Dreaded Privacy 'Patchwork' Problem," a July 2023 Perspectives from FSF Scholars, I noted that the DPDPA cleared the Delaware legislature on June 30, 2023. I also made the case that:

[T]he … "patchwork" of laws has become so complicated that interested observers can no longer agree even on the precise number of comprehensive data privacy statutes that have been passed. That fact alone speaks volumes about how difficult it has become for both companies and consumers to make sense of the ever-evolving regulatory landscape – and how important it is for Congress to establish a uniform national data privacy framework that preempts state laws.

For what it's worth, I am one of those keeping score – and I do include the Florida Digital Bill of Rights (FDBR) for a running total of thirteen. While many provisions of the FDBR apply only to companies with at least $1 billion in annual gross revenues, its requirements regarding the handling of "sensitive personal data" apply to all for-profit businesses. As such, "it undeniably represents yet another item on the growing list of data privacy statutes with which businesses must grapple."

Tuesday, June 06, 2023

Montana Makes Nine: Another State Passes a Data Privacy Law

On May 19, 2023, Governor Greg Gianforte signed into law the Montana Consumer Data Privacy Act (MCDPA). With that, the number of states to adopt comprehensive data privacy statutes expanded to nine. And the regulatory headache that consumers and companies alike must endure grew by an equal measure.

In other ways similar to legislation passed in Virginia and Connecticut, the MCDPA forges its own unique path with regard to applicability. Perhaps as a reflection of Big Sky Country's relatively low population level, the MCDPA covers a wider range of businesses: those that possess the personal information of just 50,000 (rather than the more common 100,000) residents. Consequently, some smaller businesses that were exempt under other state statutes may now be on the hook for costly compliance programs.

The MCDPA establishes a familiar set of consumer rights: to know, to access, to correct, to delete, and to port collected personal data. In addition, consumers (1) can opt out of targeted advertising, data sales, and "profiling in furtherance of solely automated decisions that produce legal or similarly significant effects," and (2) must opt-in before a business can make use of "sensitive" personal data.

Businesses must abide by "privacy by design" principles, which include purpose-specific constraints on data usage and an obligation to adopt reasonable security measures. They also must conduct data protection assessments before engaging in a number of activities that "present[] a heightened risk of harm to a consumer." And starting in January 2025, they must recognize browser-based universal opt-out mechanisms.

Notably, the MCDPA will go into effect before laws recently adopted in Iowa (January 1, 2025) and Indiana (July 1, 2026): on October 1, 2024.

Meanwhile, it appears likely that Texas will be next: the Texas Data Privacy and Security Act has reached Governor Greg Abbott's desk.

Thursday, May 18, 2023

Tennessee Is State Number Eight to Pass a Privacy Law

On May 11, 2023, Governor Bill Lee signed the Tennessee Information Protection Act ("TIPA"). The Volunteer State is the third to adopt a comprehensive data privacy statute in 2023 (after Indiana and Iowa) and the eighth overall (joining the Golden State's California Consumer Privacy Act and California Privacy Rights Act and similar-yet-unique laws passed in Virginia, Colorado, Connecticut, and Utah).

As I cautioned in a March 2021 Perspectives from FSF Scholars, multiple, inconsistent state laws inevitably will lead to "[c]ounterproductive consumer confusion, along with unreasonably burdensome and unjustifiably costly compliance obligations." At that time, just two states – California and Virginia – had enacted legislation. Today, with that total rapidly approaching double digits, such concerns exponentially are greater.

Consumer rights established by the TIPA include the right to know that a covered entity is processing personal information; to access, correct, delete, and obtain a copy of that data; and to opt out of the sale of personal information. In addition, a covered entity must disclose, upon request, categorical information regarding personal information that was sold, and obtain a consumer's consent before processing "sensitive data."

Covered entities ("controllers") that share personal information with third parties ("processors") must include certain provisions in their contracts to protect these consumer privacy rights. Controllers also must conduct data protection assessments under certain circumstances (for example, if they engage in targeted advertising, process "sensitive data," or sell personal information).

The TIPA does not create a private right of action. The Attorney General is responsible for enforcing its provisions. Covered entities have 60 days to cure an alleged violation.

Perhaps most notably, the TIPA requires that covered entities "create, maintain, and comply with a written privacy program that reasonably conforms to the National Institute of Standards and Technology (NIST) privacy framework entitled 'A Tool for Improving Privacy through Enterprise Risk Management Version 1.0.'"

The TIPA becomes effective on July 1, 2024.

Friday, May 05, 2023

Seven States and Counting: Indiana Passes Privacy Law

Activity at the state level continues to complicate further the overall privacy landscape. On May 1st, Indiana Governor Eric Holcomb signed into law Senate Bill 5 (S.B. 5), the Indiana Consumer Data Privacy Act (ICDPA). Indiana is the second state to pass a comprehensive data privacy law in 2023 (Iowa was the first, as I noted in a recent post to the Free State Foundation blog) and the seventh overall (after California, not once but twice, Virginia, Colorado, Connecticut, Utah, and the aforementioned Iowa).

Meanwhile, Montana and Tennessee could follow quickly: bills in both states have made it to their respective governor's desks.

Uniquely, and apparently to provide an opportunity to learn how similar (but by no means identical) statutes in other states fare, the ICDPA will not go into effect until July 1, 2026. (Currently, only the laws enacted in California and Virginia are in force. The big day in Colorado and Connecticut is July 1st of this year, in Utah it is December 31st, and in Iowa it is January 1, 2025.)

Based largely (though, again, not entirely) on the Virginia Consumer Data Protection Act, the ICDPA creates several consumer rights: to know, to access, to correct, to delete, and to port data, as well as the ability to opt out of its processing/sale.

And it requires businesses, among other things, to provide a privacy notice and other disclosures, to obtain affirmative consent before processing "sensitive personal data," to conduct data protection impact assessments, and to enter binding contracts with third-party data processors to ensure that they, too, respect consumer privacy rights.

The ICDPA will be enforced exclusively by the Indiana attorney general. (It does not establish a private right of action.) In addition, it provides businesses with a 30-day cure period.

At the federal level, the House Committee on Energy & Commerce's Innovation, Data, and Commerce Subcommittee held a hearing on April 27th titled "Addressing America's Data Privacy Shortfalls: How a National Standard Fills Gaps to Protect Americans' Personal Information." It was the sixth Committee hearing on the topic of privacy thus far this legislative session.

In a joint statement, Committee Chair Cathy McMorris Rodgers (R – WA) and Subcommittee Chair Gus Bilirakis (R – FL) wrote that "[t]he Energy and Commerce Committee is building momentum this Congress towards enacting comprehensive national privacy and data security legislation."

Fittingly, in his opening statement, Subcommittee Chair Bilirakis acknowledged that the data privacy picture "only gets more complicated as fifty different states move towards their own data privacy laws, meaning an increasingly complicated and confusing landscape for consumers and for business."