Showing posts with label online privacy. Show all posts
Showing posts with label online privacy. Show all posts

Friday, June 26, 2026

Alabama, Louisiana, and Vermont Enact Privacy Laws: The Number of Such States Is Now One Shy of Half

As I noted in an April post to the FSF Blog, the Sooner State, with the enactment of the Oklahoma Consumer Data Privacy Act, became the first in nearly two years to enact a comprehensive data privacy statute. In the intervening months, three more states – Alabama, Louisiana, and Vermont – have followed suit, bringing the total to 24.

As the number of state-specific privacy regimes increases, so, too, do the complexity burdens for consumers seeking to understand their rights and the compliance questions for companies seeking to satisfy their regulatory obligations.

Alabama

Yellowhammer State Governor Kay Ivey signed the Alabama Personal Data Protection Act (APDPA) into law on April 16. It will take effect on May 1, 2027.

"Fun" differentiating fact: the APDPA has a lower applicability bar than most, covering companies that (1) control or process the personal information of just 25,000 Alabama residents, or (2) earn over 25 percent of their gross revenues from the sale of personal data, no matter how many Alabama residents that involves.

Louisiana

Pelican State Governor Jeff Landry signed the Louisiana Data Privacy Act (LDPA) on May 29. It will take effect on January 1, 2027.

"Fun" differentiating fact: the LDPA includes a temporary 30-day cure period that applies before the Attorney General may initiate an investigation; in other states, the cure period typically runs after the investigation but before the commencement of an enforcement action.

Vermont

Green Mountain State Governor Phil Scott signed the Vermont Data Privacy and Online Surveillance Act (VDPOSA) on June 16. It will take effect on January 1, 2028.

"Fun" differentiating fact: Vermont residents whose "personal data were processed for the purposes of profiling in furtherance of any automated decision" may "question the result of such profiling."

All three statutes assign enforcement authority to the state attorney general. The Louisiana and Vermont laws expressly exclude a private right of action while the Alabama law is silent on the topic.

*    *    *

A comprehensive federal regime could take the "fun" out of data privacy and put in its place a single, straightforward set of consumer rights and corporate responsibilities that apply nationwide.

Which brings us to the Securing and Ensuring Consumer Uniform Rights and Enforcement over Data Act (SECURE Data Act), legislation introduced by a group of House Republicans on April 21.

As noted by Free State Foundation Adjunct Senior Fellow Michael O'Rielly in "The House Builds a Sound Privacy Bill," a May Perspectives from FSF Scholars, The SECURE Data Act (1) embraces "strong federal preemption that recognizes the interstate nature of data collection and consumption" and (2) rejects a private right of action in favor of exclusive enforcement by the FTC and state attorneys general, thereby "prevent[ing] abusive class-action lawsuits by trial attorneys that have plagued many other sectors of our economy."

The House Energy and Commerce Committee's Subcommittee on Commerce, Manufacturing, and Trade held a hearing on the SECURE Data act on June 3. The Press Release included the following quote from Subcommittee Chairman Gus Bilirakis (R-FL): "Americans, regardless of political affiliation, share a fundamental expectation that their personal data be protected and secure…. The productive dialogue during today's hearing represents an important step toward creating a framework that puts constituents back in control of their personal information while holding bad actors accountable."

Tuesday, April 21, 2026

Later Rather Than Sooner: Oklahoma Enacts State Privacy Law No. 21

After a steady stream of state-level privacy statutes, capped by passage of the Rhode Island Data Transparency and Privacy Protection Act in June 2024, for nearly two years the pipeline ran dry. That drought ended on March 20, when Sooner State Governor Kevin Stitt signed into law the Oklahoma Consumer Data Privacy Act (OCDPA). With that, the list of states to have passed a comprehensive data privacy statute now stands (by my count) at 21.

At the federal level, meanwhile, the pickings remain slim. In late March, Representative Zoe Lofgren (D-CA) for the fourth time introduced the Online Protection Act, the shortcomings of which I rehashed in a contemporaneous post to the Free State Foundation blog. Beyond that, hopeful eyes can look only to the House Commerce Committee Privacy Working Group, which was created in February 2025 and sought public input a month later. As I noted in a January Perspectives from FSF Scholars, reporting at that time suggested that the working group could release a draft bill … "soon."

The good news about the OCDPA, which closely tracks the Virginia Consumer Data Protection Act, is that it does not impose more burdensome obligations than existing state laws – and therefore is regarded as a relatively "business-friendly" addition to the state-level "patchwork."

The bad news, of course, is that it further expands that "patchwork," thereby compounding compliance headaches for companies – especially smaller companies and start-ups – and making it even more challenging for consumers to comprehend their rights.

*    *    *

More targeted than other state laws, the OCDPA applies only to businesses operating in Oklahoma or targeting Oklahoma residents that control or process the personal data of either (1) 100,000 or more Oklahoma consumers, or (2) at least 25,000 Oklahoma consumers while deriving over 50 percent of their gross revenue from the "sale" of personal data. (By comparison, that threshold is lower – 25 percent – in most state laws.) In addition, the OCDPA defines "sale" relatively narrowly – that is, only where personal data is exchanged for monetary consideration.

The law establishes a now-familiar set of consumer rights: to access and confirm the processing of personal data, to correct inaccuracies, to delete, and to obtain a portable copy. In addition, consumers can opt out of the processing of personal data for targeted advertising, the sale of their personal data, and profiling.

"Sensitive data" – defined to include racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship status, genetic or biometric data used for identification, and precise geolocation data – may not be processed without the consumer's opt-in consent.

Covered businesses must abide by data-minimization principles, limiting collection to what is adequate, relevant, and reasonably necessary. They also must conduct data protection assessments before engaging in activities such as targeted advertising, the sale of personal data, and the processing of "sensitive data."

Two additional features of the OCDPA are worth highlighting. First, enforcement authority rests exclusively with the Oklahoma Attorney General; there is no private right of action. Second, the law includes a permanent, mandatory 30-day "right to cure" period for alleged violations – a feature that stands in contrast to the trend in other states toward sunsetting or eliminating cure periods altogether. Violations may result in penalties of up to $7,500 per incident.

The OCDPA will go into effect on January 1, 2027.

*    *    *

As I've stated countless times, the absence of a comprehensive federal data privacy law that would preempt this now-larger "patchwork" remains a glaring gap. With each new state law – and each set of idiosyncratic definitions of rights, responsibilities, thresholds, exemptions, enforcement mechanisms, and so on – the compliance burden on businesses grows heavier and the regulatory landscape confronting consumers grows murkier.

Friday, March 27, 2026

Representative Lofgren's Online Privacy Act Has Reentered the Chat

As we eagerly await word from the House Energy and Commerce Committee's data privacy working group, Representative Zoe Lofgren (D-CA) once again has resurrected the problematic Online Privacy Act (OPA).

In February 2025, Committee Chairman Brett Guthrie (R-KY) and Vice Chairman John Joyce, M.D. (R-PA) announced the establishment of a data privacy working group "to bring members and stakeholders together to explore a framework for legislation that can get across the finish line." (For more information please see my contemporaneous post to the Free State Foundation blog).

Shortly thereafter, the working group solicited public comment on a Request for Information that I summarized in a follow-up blog post.

In a January Perspectives from FSF Scholars summarizing privacy-related legislative activity in 2025, I shared speculation that the working group might introduce a bill "soon." Separate reporting around the same time indicated that the working group "intend[s] to take up action on a broader, comprehensive federal privacy measure in spring 2026."

In the interim, Representative Lofgren for the fourth time has introduced the OPA, a draft bill first unveiled in 2019 and then again in 2021 and 2023.

As I pointed out in "A Tale of Three Data Privacy Bills: Federal Legislative Stalemate Enables Bad State Laws," a January 2022 Perspectives, the OPA has two top-level shortcomings: (1) it "is silent on the issue of preemption," and thus fails to address the state-level "patchwork" problem that in the intervening years has only gotten worse; and (2) it creates a private right of action that, unlike exclusive enforcement by the FTC, would be far more likely to benefit the plaintiffs' bar than consumers.

With the vernal equinox exactly one week in the rear-view mirror, it remains possible that the working group will introduce (presumably preferable) comprehensive data privacy legislation this spring.

Time will tell.

Tuesday, March 04, 2025

House Commerce Privacy Working Group Seeks Input

In a February 2025 post to the FSF Blog, I reported on a press release from House Commerce Committee Chairman Brett Guthrie (R-KY) and Vice Chairman John Joyce, M.D. (R-PA) announcing the creation of a working group focused on federal comprehensive data privacy legislation. That working group is now asking interested parties to provide responses to a Request for Information (RFI).

Released on February 21, 2025, the RFI begins by acknowledging two points I have highlighted repeatedly in writings for the Free State Foundation, most recently in a December 2024 Perspectives from FSF Scholars.

One, that "the challenge of providing clear digital protections for Americans is compounded by the fast pace of technological advancement and the complex web of state and federal data privacy and security laws, which in some cases create conflicting legal requirements."

And two, that "Members of Congress have spent many years working toward federal comprehensive data privacy and security standards to bring consumer protections into the digital age while ensuring that the U.S. continues to lead in a globally competitive environment."

The information sought by the RFI is organized into the following six specific categories:

  • Roles and Responsibilities: What types of entities collect, process, and sell personal information? What obligations should apply to each?
  • Personal Information, Transparency, and Consumer Rights: What specific consumer protections should a privacy law include? What heightened safeguards should apply to sensitive personal information? How should covered entities provide disclosures to consumers?
  • Existing Privacy Frameworks and Protections: What can be learned from the existing "patchwork" of state privacy laws? To what extent should a federal privacy law preempt state privacy laws?
  • Data Security: How can federal lawmakers ensure the security of consumer data?
  • Artificial Intelligence (AI): How might a federal privacy law account for existing state laws addressing AI, including those relating to automated decision-making?
  • Accountability and Enforcement: What are the pros and cons of exclusive enforcement by the FTC and state Attorneys General? Should a federal privacy law include a safe harbor?

A seventh, catch-all, category encourages interested parties to submit "any additional information that may be relevant to the working group as it develops a comprehensive data privacy and security law."

Responses, due by April 7, 2025, should be emailed to PrivacyWorkingGroup@mail.house.gov.

Tuesday, February 18, 2025

House Commerce Leaders Create Privacy Working Group

On February 12, 2025, House Commerce Committee Chairman Brett Guthrie (R-KY) and Vice Chairman John Joyce, M.D. (R-PA) issued a press release announcing the formation of a comprehensive data privacy working group.

This marks the first notable federal legislative step forward on privacy since a full House Commerce Committee markup of the American Privacy Rights Act of 2024 (APRA), scheduled for June 27, 2024, was cancelled at the last minute. For more on the fate of the APRA, please see my year-end comprehensive recap of developments at both the federal and state levels, "2024 Data Privacy Legislative Review: Federal Lawmakers Fall Short As More State Laws Gain Teeth," a December 2024 Perspectives from FSF Scholars.

In the press release, Chairman Guthrie and Vice Chairman Joyce stated that:

We strongly believe that a national data privacy standard is necessary to protect Americans' rights online and maintain our country's global leadership in digital technologies, including artificial intelligence. That's why we are creating this working group, to bring members and stakeholders together to explore a framework for legislation that can get across the finish line…. The need for comprehensive data privacy is greater than ever, and we are hopeful that we can start building a strong coalition to address this important issue.

They also encouraged interested parties to engage with the working group by sending an email to PrivacyWorkingGroup@mail.house.gov.

Tuesday, December 17, 2024

Michigan Could Become State No. 21 to Pass a Data Privacy Law

In a Perspectives from FSF Scholars on privacy legislation in 2024 published just last week, I wrote that seven additional states adopted comprehensive data privacy statutes this year, bringing the total to twenty. But did I speak too soon? The very same day, Michigan Senator Rosemary Bayer (D) announced via press release that the Personal Data Privacy Act (Senate Bill 659) had passed the Senate.

Should Senate Bill 659 clear the House before the current legislative session ends on December 23, the Wolverine State could become the eighth state in 2024, and the twenty-first overall, to forge a unique data privacy path.

Senate Bill 659 would establish familiar consumer rights including: the right to know that personal data is being processed, the right to access that personal data, the right to correct inaccuracies, the right to delete, and the right to obtain a portable copy. Consumers also would be able to opt out of the sale of personal data, targeted advertising, and "[p]rofiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer."

As is the case with the Maryland Online Data Privacy Act of 2024, which I summarized in a February post to the Free State Foundation blog, Senate Bill 659 includes "data minimization" provisions that "limit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a product or service requested by the consumer … consistent with the consumer's reasonable expectations" (emphases added) and place similarly subjective limits on the processing of personal data. Sensitive data may be collected and/or processed only where "strictly necessary."

Senate Bill 659 would not create a private right of action. Instead, the state attorney general would have exclusive enforcement authority. It would go into effect a year from the date of enactment.

Friday, June 28, 2024

Federal Privacy Bill Hits Roadblock, State Activity Picks Up Speed

At the eleventh hour, the House Energy and Commerce Committee cancelled a markup scheduled for Thursday that included the American Privacy Rights Act of 2024 (APRA). At the state level, by contrast, Minnesota and Rhode Island recently enacted their own comprehensive data privacy laws, bringing the total to 20. And previously adopted statutes in three states – Oregon, Texas, and Florida – go into effect on July 1.

Having cleared the Innovation, Data, and Commerce Subcommittee late last month, the APRA was one of eleven bills on the agenda for yesterday's full committee markup. Chair Cathy McMorris Rodgers (R-WA) did not state a reason for the last-minute cancellation, but The Hill reported that House Republican leadership objected to the private right of action created by the discussion draft.

As it happens, in "Congressional Leaders Return Privacy to the Front Burner," an April Perspectives from FSF Scholars, I anticipated that "the APRA's problematic inclusion of a private right of action may – and should – prove once again to be a sticking point."

The already sizeable patchwork of state comprehensive data privacy laws, meanwhile, continues to grow. (So, too, do the associated compliance headaches for companies and confusion faced by consumers.) On May 24, 2024, North Star State Governor Tim Walz signed the Minnesota Consumer Data Privacy Act, a law similar – though not identical, of course – to those passed in New Hampshire and Maryland.

And on June 25, 2024, Ocean State Governor Dan McKee transmitted with no signature the Rhode Island Data Transparency and Privacy Protection Act, bringing the total of state comprehensive data privacy laws to 20. The Rhode Island statute is notable for its relatively large fines: up to $10,000 per violation, plus additional penalties for "intentional disclosures of personal data."

The Minnesota act will not go into effect until July 31, 2025, the Rhode Island law not until January 1, 2026. Laws in three other states, however, kick in on the first day of July: the Oregon Consumer Privacy Act, the Texas Data Privacy and Security Act, and – by my measure, at least – the Florida Digital Bill of Rights.

For additional details on these statutes, please see "More States Compound the Dreaded Privacy 'Patchwork' Problem," a July 2023 Free State Foundation Perspectives.

Monday, May 13, 2024

18 … and Up? Maryland Is the Latest State to Enact a Privacy Law

Last Thursday, Free State Governor Wes Moore signed into law the Maryland Online Data Privacy Act of 2024 (MODPA). With the stroke of his pen, Maryland became the eighteenth state to adopt a comprehensive data privacy statute – one with the most onerous "data-minimization" requirements we have seen thus far.

Forgive me if I sound like a broken record, but this most-recent addition to the already substantial set of state-specific data privacy laws further compounds the confusion experienced by consumers and the compliance challenges faced by companies, particularly small businesses.

Should it become federal law, the American Privacy Rights Act (APRA) discussion draft, about which I wrote in a recent Perspectives from FSF Scholars, would preempt this patchwork and establish a desperately needed nationwide data privacy regime.

For a general overview of the MODPA, please see my two previous posts to the Free State Foundation blog on the topic, which can be found here and here. For present purposes, I want to focus specifically on the MODPA's data-minimization language, which states that "controllers" must "[l]imit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains" (emphasis added).

The data-minimization model differs from the notice-and-consent approach – pursuant to which the bounds of permissible data collection are set forth in a company's privacy policy – that until recently served as the de facto standard nationwide. And Maryland's version is the most extreme data-minimization implementation to date.

Strict data-minimization requirements such as this, and the one spelled out in the APRA, could have unintended anti-consumer consequences. Limitations on the collection of personal data beyond what is "reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains" – or, in the case of the APRA, "beyond what is necessary, proportionate, or limited to provide or maintain a product or service requested by an individual" (emphases added) – are inherently subjective standards that create substantial uncertainty and risk for companies. And that uncertainty and risk could have a chilling effect.

For example, companies may refrain from offering the "free" (that is, ad-supported) services that many consumers have come to rely on. The notice-and-consent model traditionally has allowed consumers to weigh the benefits of sharing personal information in exchange for these free services. The shift to a data-minimization approach could undermine that model, potentially leading to a reduction in the availability of complimentary online offerings.

The MODPA will go into effect on October 1, 2025, a year later than originally proposed.

Monday, April 29, 2024

Nebraska Is State 17 to Pass Privacy Law; House Holds Hearing on APRA

In a recent Perspectives from FSF Scholars summarizing the American Privacy Rights Act (APRA) Discussion Draft, I added New Hampshire (number fifteen) and Kentucky (number sixteen) to the Free State Foundation's running list of states that have passed a comprehensive data privacy statute. The Cornhusker State in the interim has joined their ranks, upping that total to seventeen. Meanwhile, at a House Commerce Committee hearing on the APRA, more than one representative indicated that they are "fired up" (subscription required) to turn that bill into preempting federal law.

New Jersey was the first state in 2024 (and the fourteenth overall) to enact privacy legislation, a development I noted in a January post to the FSF Blog. The New Hampshire Privacy Act followed in March, the Kentucky Consumer Data Protection Act in early April. (Two days later the Maryland Online Data Privacy Act of 2024, about which I blogged here and here, cleared both legislative houses. Should it be signed by Governor Wes Moore, it will bring the tally to eighteen. That is, assuming another state – Pennsylvania, perhaps? – doesn't beat it to the punch.)

And on April 12, Governor Jim Pillen enacted the Nebraska Data Privacy Act, a statute very similar in substance to the Texas Data Privacy and Security Act, a bill that I summarized in July 2023's aptly titled "More States Compound the Dreaded Privacy 'Patchwork' Problem."

Of course, one of the aspects of the APRA Discussion Draft that I praised in "Congressional Leaders Return Privacy to the Front Burner," the Perspectives referenced above, is its language preempting state comprehensive data privacy laws: "no State or political subdivision thereof may adopt, maintain, enforce, or continue in effect any law, regulation, rule, or requirement covered by the provisions of this Act or a rule, regulation, or requirement promulgated under this Act."

As such, passage of the APRA – by no means a foregone conclusion – would eliminate the chaos and compliance contradictions created by the expanding number of state laws.

At an April 17 hearing held by the House Commerce Committee's Subcommittee on Innovation, Data, and Commerce, APRA co-author and Committee Chair Cathy McMorris Rodgers (R-WA) acknowledged that "Congress has been trying to develop and pass comprehensive data privacy and security legislation for decades" and argued that "[w]ith the American Privacy Rights Act, we are at a unique moment in history where we finally have the opportunity to imagine the internet as a force for prosperity and good."

In response, Subcommittee Chair Gus Bilirakis (R-FL) reportedly stated that he is "fired up" – and Representative Frank Pallone (D-NJ) indicated that he is "fired up too."

Friday, February 16, 2024

Free State Lawmakers Debate Data Privacy Legislation

Maryland soon could join the not-so-exclusive club for states that have forged divergent data privacy regulatory paths. Last month, New Jersey became the fourteenth state (and the first this year) to enact a comprehensive data privacy law, a development that I highlighted in a January 2024 post to the Free State Foundation's blog. Yet another bill awaits the signature of New Hampshire Governor Chris Sununu.

As I detailed most recently in "More States Compound the Dreaded Privacy 'Patchwork' Problem," a July 2023 Perspectives from FSF Scholars, the longstanding lack of a federal data privacy regime – specifically, one that preempts inconsistent state-specific approaches – has fostered an unworkable situation that creates compliance headaches for companies and confusion for consumers.

Hearings on the Maryland Online Data Privacy Act of 2024 (the Act) were held on February 13, 2024, by the House Economic Matters Committee (House Bill 567) and on February 14, 2024 by the Senate Finance Committee (Senate Bill 541).

The Act establishes a familiar set of consumer rights: to know that personal data is being collected; to access, correct, delete, and receive a copy of personal data; to obtain a list of the categories of third parties to which personal data is disclosed; to opt out of the processing of personal data for targeted advertising and automated profiling; and to opt out of its sale.

Perhaps most notably, the Act goes further than other state laws in limiting the personal data that companies may collect – that is, "data minimization" ("A controller shall … [l]imit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains.")

On its face, the Act does not create a private right of action. As was the case with the New Jersey law reference above, however, the Act's draft language has prompted concerns that it "do[es] not explicitly provide for exclusive Attorney General enforcement" (emphasis added). Specifically, Section 14-4613, which defines a violation of the Act as "[a]n unfair, abusive, or deceptive trade practice … [s]ubject to the enforcement and penalty provisions contained in Title 13 of this article," also ambiguously asserts that it "does not prevent a consumer from pursuing any other remedy provided by law."

Breaking from the approach embraced by other states, and thus further complicating compliance for companies, the Act does not provide businesses with an opportunity to cure alleged violations.

If enacted, the Act would go into effect on October 1, 2024.

Friday, January 19, 2024

New Jersey Passes 2024's First State Privacy Law

The privacy plot thickens: New Jersey just became the first state in 2024 – and (by my count) the fourteenth overall – to enact a comprehensive data privacy law. Bill S332, formally titled "An Act concerning online services, consumers, and personal data and supplementing Title 56 of the Revised Statutes" (the Act), was signed on Tuesday by Governor Phil Murphy.

At the federal level, sadly, there has been little news to report in well over a year. Consequently, each additional state that forges its own unique path further muddies the waters, creating more chaos for consumers and more compliance nightmares for companies.

The Act establishes a number of familiar consumer rights with respect to personal data: to confirm its collection and processing, to correct, to delete, to receive a portable copy, to opt out of its processing for targeted advertising as well as its sale, and to opt in to the processing of "sensitive data."

Not surprisingly, however, the Act includes several provisions that distinguish it from other state privacy statutes – and thereby unduly complicate nationwide compliance efforts. For one, it does not set a minimum-revenue threshold for covered companies. For another, its definition of "sensitive data" includes certain types of financial information.

The New Jersey Department of Law and Public Safety's Division of Consumer Affairs is tasked with adopting regulations implementing the Act. The New Jersey Attorney General has exclusive enforcement authority. For the first year and a half, companies will enjoy a 30-day cure period.

The Act does not create a private right of action, However, an eleventh-hour amendment deleting the phrase "under any other law" did prompt Governor Murphy to note in his Statement Upon Signing that:

I understand that concerns have been raised that removing that language thereby establishes a private right of action under other laws for violations of this bill. However, nothing in this bill expressly establishes such a private right of action, and the provision as amended states that the bill shall not be "construed as providing the basis for … a private right of action for violations of [the bill]."

The bulk of the Act will go into effect on January 15, 2025. The obligation to abide universal opt-out mechanisms (such as web browser-based privacy signals) will kick in six months later.

Tuesday, October 31, 2023

Maine May Join the State Privacy Law Club

Might the Pine Tree State in 2024 become the fourteenth state to pass a comprehensive data privacy law – and thereby further compound the problem of multiple, conflicting state statutes? It's possible. The Maine legislature's bicameral Judiciary Committee considered "An Act to Create the Data Privacy and Protection Act" (LD 1977) at a hearing two weeks ago.

LD 1977 is modeled on the American Data Privacy and Protection Act (ADPPA), a piece of federal legislation that easily cleared the House Commerce Committee back in August 2022 before losing forward momentum. That LD 1977 takes its lead from the ADPPA is somewhat ironic, as one of the primary motivating factors driving the ADPPA was the problem of a "patchwork" of state-specific laws, a problem that LD 1977 threatens to exacerbate.

To make matters worse, LD 1977 problematically diverges from the ADPPA by including an extremely broad private right of action. Specifically, Section 9620(2) states that:

A violation of this chapter or a rule adopted under this chapter with respect to the covered data of an individual constitutes an injury to that individual. The injured individual may bring a civil action against the party that commits the violation, except that an individual may not bring a civil action against a small business.

Possible remedies include actual damages or statutory damages starting at $5,000 per violation, whichever are greater; punitive damages; attorney's fees and costs; and injunctive and declaratory relief. A "small business" is a "covered entity" or "service provider" (but not a "data broker") that (1) generates less than $41 million in annual revenues, and (2) does not collect or process the personal data or more than 200,000 individuals.

Something else to consider: as I described in "Maine's ISP-Only Privacy Law Will Not Protect Consumers," an April 2020 Perspectives from FSF Scholars, Maine adopted a privacy law in June 2019 that singles out broadband Internet service providers (ISPs), requiring them – but not other participants in the broader online ecosystem, such as "edge providers" like Alphabet, Meta, and Amazon – to obtain "opt-in" consent from customers before using their personal information.

At an absolute minimum, any additional privacy legislation must acknowledge – and address – this disparate treatment of broadband ISPs.

Thursday, September 28, 2023

Delaware Privacy Law Makes a Dozen – or a Baker's Dozen?

First State Governor John Carney signed the Delaware Personal Data Privacy Act (the DPDPA) into law on September 11, 2023.

For those keeping score, Delaware increases the number of states to have passed a comprehensive data privacy law either to twelve – "Delaware Becomes Twelfth State to Enact Comprehensive Privacy Law" – or thirteen – "The 'First State' Officially Becomes the Thirteenth State with a Comprehensive Data Privacy Law" – depending on how one defines "comprehensive."

And for those concerned with the confusion and cost caused by the growing patchwork of inconsistent state laws, the fact that commenters cannot agree even on what the current total is underscores the extent of the problem.

In "More States Compound the Dreaded Privacy 'Patchwork' Problem," a July 2023 Perspectives from FSF Scholars, I noted that the DPDPA cleared the Delaware legislature on June 30, 2023. I also made the case that:

[T]he … "patchwork" of laws has become so complicated that interested observers can no longer agree even on the precise number of comprehensive data privacy statutes that have been passed. That fact alone speaks volumes about how difficult it has become for both companies and consumers to make sense of the ever-evolving regulatory landscape – and how important it is for Congress to establish a uniform national data privacy framework that preempts state laws.

For what it's worth, I am one of those keeping score – and I do include the Florida Digital Bill of Rights (FDBR) for a running total of thirteen. While many provisions of the FDBR apply only to companies with at least $1 billion in annual gross revenues, its requirements regarding the handling of "sensitive personal data" apply to all for-profit businesses. As such, "it undeniably represents yet another item on the growing list of data privacy statutes with which businesses must grapple."

Tuesday, June 06, 2023

Montana Makes Nine: Another State Passes a Data Privacy Law

On May 19, 2023, Governor Greg Gianforte signed into law the Montana Consumer Data Privacy Act (MCDPA). With that, the number of states to adopt comprehensive data privacy statutes expanded to nine. And the regulatory headache that consumers and companies alike must endure grew by an equal measure.

In other ways similar to legislation passed in Virginia and Connecticut, the MCDPA forges its own unique path with regard to applicability. Perhaps as a reflection of Big Sky Country's relatively low population level, the MCDPA covers a wider range of businesses: those that possess the personal information of just 50,000 (rather than the more common 100,000) residents. Consequently, some smaller businesses that were exempt under other state statutes may now be on the hook for costly compliance programs.

The MCDPA establishes a familiar set of consumer rights: to know, to access, to correct, to delete, and to port collected personal data. In addition, consumers (1) can opt out of targeted advertising, data sales, and "profiling in furtherance of solely automated decisions that produce legal or similarly significant effects," and (2) must opt-in before a business can make use of "sensitive" personal data.

Businesses must abide by "privacy by design" principles, which include purpose-specific constraints on data usage and an obligation to adopt reasonable security measures. They also must conduct data protection assessments before engaging in a number of activities that "present[] a heightened risk of harm to a consumer." And starting in January 2025, they must recognize browser-based universal opt-out mechanisms.

Notably, the MCDPA will go into effect before laws recently adopted in Iowa (January 1, 2025) and Indiana (July 1, 2026): on October 1, 2024.

Meanwhile, it appears likely that Texas will be next: the Texas Data Privacy and Security Act has reached Governor Greg Abbott's desk.

Friday, March 31, 2023

Iowa Is State No. 6 to Pass a Privacy Statute

On March 28, Iowa Governor Kim Reynolds signed Senate File (SF) 262, "an Act relating to consumer data protection, providing civil penalties, and including effective date provisions." Following in the footsteps of California (here and here), Virginia, Colorado, Utah, and Connecticut, Iowa has become the sixth state to pass its own unique take on a comprehensive data privacy law.

With Congress still unable to agree upon the details of a national privacy framework, this most recent addition to the steadily expanding list of inconsistent state statutes further exacerbates compliance headaches for companies and adds to consumer confusion.

Laws in California and Virginia already are in effect. The start date for those in Colorado and Connecticut is July 1, 2023. Utah's statute becomes valid at the end of this year. And Iowa's SF 262 kicks in on January 1, 2025.

In other state-level privacy news, both California and Colorado recently finalized rulemaking proceedings arising from their respective comprehensive data privacy statutes:

  • On March 29, the California Office of Administrative Law approved the initial set of rules implementing the California Privacy Rights Act, also known as Proposition 24. Adopted by the California Privacy Protection Agency (CPPA), the first-of-its-kind state agency specifically dedicated to privacy, the rules became effective immediately. By statute, however, California's Office of Attorney General cannot initiate enforcement efforts until July 1. (Once officially processed, those rules, which substantively are unchanged from the drafts voted on by the CPPA in February, will be available here.)
  • On March 15, the Colorado Attorney General's Office announced that it had filed with the Colorado Secretary of State's Office final versions of its rules implementing the Colorado Privacy Act. Like the statute itself, those rules will go into effect on July 1.

At the federal level, meanwhile, the American Data Privacy and Protection Act, the first bill of its kind to make it out of congressional committee, remains in limbo. However, there have been two House Commerce Committee hearings on the topic of privacy thus far in 2023.

The first, entitled "Promoting U.S. Innovation and Individual Liberty through a National Standard for Data Privacy," was held by the Innovation, Data, and Commerce Subcommittee on March 1.

The second, a full Committee hearing entitled "TikTok: How Congress Can Safeguard American Data Privacy and Protect Children from Online Harms," took place on March 23.

In a media appearance shortly thereafter, Chair Cathy McMorris Rodgers (R-WA) stated that the testimony of TikTok CEO Shou Chew puts "more urgency on us passing a national data privacy law to protect [America] from the next technological tool or weapon that China may put together'" and that "[w]e need a national data privacy standard … and that's what Ranking Member Pallone and I have worked on and we're going to introduce this Congress because we need to take action."

Thursday, August 18, 2022

FTC Initiates Privacy Rulemaking Despite Congressional Momentum: Republican Commissioners Issue Strong Dissents

At a virtual news conference last Thursday, the FTC announced the adoption of an Advance Notice of Proposed Rulemaking (ANPR) on "commercial surveillance" (that is, the use of personal information) and "lax" data security practices.

Over forceful objections from the two Republican Commissioners, and in the face of significant congressional progress on a bipartisan, bicameral federal comprehensive data privacy bill, this action by the majority initiates a "Magnuson-Moss" rulemaking pursuant to Section 18 of the FTC Act.

The ANPR:

[I]nvites comment on whether it should implement new trade regulation rules or other regulatory alternatives concerning the ways in which companies (1) collect, aggregate, protect, use, analyze, and retain consumer data, as well as (2) transfer, share, sell, or otherwise monetize that data in ways that are unfair or deceptive.

It poses a total of 95 wide-reaching questions, grouped into the following broad categories:

  • The extent to which personal data practices and security measures harm consumers, particularly children and teenagers;
  • The appropriate way to balance costs and benefits; and
  • Whether the FTC should regulate prevalent data privacy and security practices.

In just one troubling example of the ANPR's explicit bias against the prevailing notice-and-consent paradigm – a point of view that Commissioner Noah Phillips in his dissent characterizes as "a rather dystopic view of modern commerce" – question 74 asks under "which circumstances, if any, is consumer consent likely to be effective" and question 77 seeks input on "[h]ow demonstrable or substantial must consumer consent be if it is to remain a useful way of evaluating whether a commercial surveillance practice is unfair or deceptive" (emphases added).

In her Dissenting Statement, Commissioner Christine Wilson objected to the ANPR primarily on the basis of the risk it poses to the continued progress of the American Data Privacy and Protection Act (ADPPA). As I noted two weeks ago in a Perspectives from FSF Scholars, an amended version of the ADPPA on July 20, 2022, cleared the House Commerce Committee on a 53-1 vote.

Emphasizing her unwavering preference for congressional, rather than agency, action, Commissioner Wilson made plain that "[t]he momentum of ADPPA plays a significant role in [her] 'no' vote" – and that she is "gravely concerned that opponents of the bill will use the [ANPR] as an excuse to derail the ADPPA."

Commissioner Wilson did acknowledge that, at an earlier point in time, she "became willing to consider whether the Commission should undertake a Section 18 rulemaking to address privacy and data security."

However, for a litany of reasons – including "changes to the Section 18 Rules of Practice that decrease opportunities for public input and vest significant authority for the rulemaking proceedings solely with the Chair" and "Chair Khan's public statements [that] give [Commissioner Wilson] no basis to believe that she will seek to ensure that proposed rule provisions fit within the Congressionally circumscribed jurisdiction of the FTC" – the Commissioner has had an abrupt change of heart.

I documented this evolution in a series of posts to the Free State Foundation's blog.

In his Dissenting Statement, Commissioner Phillips reiterated a similarly longstanding conviction that Congress, rather than the FTC, "is where national privacy law should be enacted." In that vein, he wrote that he is "heartened to see Congress considering just such a law today" and hopes that "this Commission process does nothing to upset that consideration."

Taking issue with the ANPR's foundational terminology, Commissioner Phillips labeled the phrase "commercial surveillance" an "academic pejorative," one that is "defined so broadly (and with such foreboding) that it captures any collection or use of consumer data" – and one that "trades a serious attempt to understand business practices it would regulate for the chance to liken untold companies large and small to J. Edgar Hoover's COINTELPRO."

Expanding upon this concern, Commissioner Phillips makes the following additional points:

  • The ANPR "provides no notice whatsoever of the scope and parameters of what rule or rules might follow" – thereby "undermining the public input and congressional notification processes" required by Section 18.
  • It exceeds the FTC's congressionally delegated Section 5 authority over "unfair or deceptive acts or practices" and "signal[s] the majority's view that the scope of the rules passed by the unelected commissioners of an independent agency should be on par with statutes passed by elected legislators." Referencing (1) "personalized" or "targeted" advertising, and (2) consent, which he refers to as "one of the traditional bedrocks of privacy policy," he argues that the ANPR portends regulating "common business practices we have never before even asserted are illegal."
  • Overstepping the limits of the FTC's jurisdiction, "[i]t seeks to recast the agency as a civil rights enforcer, contemplating policing algorithms for disparate impact without a statutory command."
  • It "shortchanges data security, one area ripe for FTC rulemaking."

Critically, Commissioner Phillips highlights how the ANPR in practice could result in consumer harm: "Reducing the ability of companies to use data about consumers, which today facilitates the provision of free services, may result in higher prices – an effect that policymakers would be remiss not to consider in our current inflationary environment."

On September 8, 2022, the FTC will host a virtual public forum on the ANPR.

Comments on the ANPR will be due 60 days after its publication in the Federal Register.

Thursday, May 26, 2022

#FSFConf14 Speakers on Need for Federal Privacy Law

At the Free State Foundation's recent Fourteenth Annual Policy Conference, FTC Commissioners Christine Wilson and Noah Phillips voiced their support for a federal data privacy regime. And on May 23, 2022, another speaker at #FSFConf14, USTelecom President & CEO Jonathan Spalter, authored a blog post urging the Biden Administration and Congress to work together "on this essential national priority."

In the meantime, Connecticut has compounded the confusion and chaos wrought by multiple, inconsistent state-level comprehensive data privacy statutes. On May 10, 2022, Governor Ned Lamont signed into law "An Act Concerning Personal Data Privacy and Online Monitoring." Connecticut is the fifth state to date – following California (twice), Virginia, Colorado, and Utah – to fill the federal void.

Nevertheless – and forgive me if I sound like a broken record – recent reporting suggests that federal lawmakers may be making progress behind the scenes toward a workable consensus on data privacy.

During #FSFConf14's "The View from the FTC," a Fireside Chat hosted by Maureen Ohlhausen, former FTC Acting Chairman and Commissioner (a video of which is available here), Commissioner Wilson echoed that optimistic sentiment (direct link here). Describing herself as one who "tend[s] to be a Pollyanna," she stated that "I'm actually hopeful, more hopeful than I have been, because I hear there's a concerted push to get federal privacy legislation across the finish line soon."

Commissioner Wilson also reiterated her position that federal privacy legislation is necessary:

I have been advocating for federal privacy legislation almost from the day that I was sworn in as a Commissioner. And I do think it's important, I think there is a market failure that needs to be addressed. I think consumers have very little understanding of the data that's collected from them and how that data is collected, used, and sold.

I also think that businesses need guardrails, they need to understand the rules of the road. And right now we have states with conflicting opinions about what those guardrails should be, and we have a developing international regime also with conflicting ideas. And so, businesses need clarity and certainty in order to know how to comply with the law, but also to invest and to grow. 

Responding to a related query regarding what the FTC can do in the interim to "to fill the gap," Commissioner Wilson noted the agency's authority under Section 5 of the FTC Act to address "unfair and deceptive acts or practices in or affecting commerce" and subject-matter-specific jurisdiction pursuant to other statutes, such as the Children's Online Privacy Protection Act (COPPA). She also highlighted a "body of consents that provide very good rules of the road."

Later in the Fireside Chat (direct link here), Commissioner Phillips, responding to a question from an audience member regarding smartphone apps, acknowledged the existence, with respect to personal data, of an "information asymmetry" – a concept familiar to those who attended Commissioner Wilson's keynote address during FSF's Twelfth Annual Policy Conference in 2020.

Given that "[c]onsumers may not understand fully what they're engaging in," Commissioner Phillips indicated his support for a "nutrition label" solution:

[O]ne of the things I've always felt would be very useful is to look more carefully at things like labels. And understand, you know, what are ways that we can get good information out to people? We do this in a lot of other areas, right?
And you think about food, right? It's maybe not efficient for me every day to, you know, if I'm at the grocery store, examine each label. But if I care, and if I want to, and the cost to you, the producer of Honey Nut Cheerios, is fairly low, that can be a really beneficial rule. A rule that is good for competition. A rule that allows consumers to shop across products, including for those features. 
So let's take what are you doing with your data, right? And Apple has a version of this, in iOS 14, they have these "nutrition labels," they call them. But it's a way of taking complex subject matter and boiling it down in terms that allow people to sort of shop across products and compare. And perhaps even to create markets around features where markets may not naturally arise.

Relatedly, USTelecom's Mr. Spalter, who participated in Free State Foundation President Randolph May's #FSFConf14 "The 'Hottest Topics' in Communications and Internet Policy" Fireside Chat (a video of which is available here), earlier this week published a blog post titled "Global Privacy Leadership Begins Here at Home."

After acknowledging the Biden Administration's "efforts toward harmonizing strong consumer privacy protections around the world" via the Global Cross-Border Privacy Rules Declaration, Mr. Spalter made the salient point that "for the U.S. to truly lead this worldwide endeavor, our nation must first lead by example here at home."

He therefore "urge[d] the Administration and Congress to work together, with a sense of urgency and purpose, to [adopt national privacy legislation] in the current legislative session." Specifically, a bill that "deliver[s] consistent online privacy protections that apply uniformly across the country and to all companies in the internet ecosystem."