Showing posts with label private right of action. Show all posts
Showing posts with label private right of action. Show all posts

Friday, June 26, 2026

Alabama, Louisiana, and Vermont Enact Privacy Laws: The Number of Such States Is Now One Shy of Half

As I noted in an April post to the FSF Blog, the Sooner State, with the enactment of the Oklahoma Consumer Data Privacy Act, became the first in nearly two years to enact a comprehensive data privacy statute. In the intervening months, three more states – Alabama, Louisiana, and Vermont – have followed suit, bringing the total to 24.

As the number of state-specific privacy regimes increases, so, too, do the complexity burdens for consumers seeking to understand their rights and the compliance questions for companies seeking to satisfy their regulatory obligations.

Alabama

Yellowhammer State Governor Kay Ivey signed the Alabama Personal Data Protection Act (APDPA) into law on April 16. It will take effect on May 1, 2027.

"Fun" differentiating fact: the APDPA has a lower applicability bar than most, covering companies that (1) control or process the personal information of just 25,000 Alabama residents, or (2) earn over 25 percent of their gross revenues from the sale of personal data, no matter how many Alabama residents that involves.

Louisiana

Pelican State Governor Jeff Landry signed the Louisiana Data Privacy Act (LDPA) on May 29. It will take effect on January 1, 2027.

"Fun" differentiating fact: the LDPA includes a temporary 30-day cure period that applies before the Attorney General may initiate an investigation; in other states, the cure period typically runs after the investigation but before the commencement of an enforcement action.

Vermont

Green Mountain State Governor Phil Scott signed the Vermont Data Privacy and Online Surveillance Act (VDPOSA) on June 16. It will take effect on January 1, 2028.

"Fun" differentiating fact: Vermont residents whose "personal data were processed for the purposes of profiling in furtherance of any automated decision" may "question the result of such profiling."

All three statutes assign enforcement authority to the state attorney general. The Louisiana and Vermont laws expressly exclude a private right of action while the Alabama law is silent on the topic.

*    *    *

A comprehensive federal regime could take the "fun" out of data privacy and put in its place a single, straightforward set of consumer rights and corporate responsibilities that apply nationwide.

Which brings us to the Securing and Ensuring Consumer Uniform Rights and Enforcement over Data Act (SECURE Data Act), legislation introduced by a group of House Republicans on April 21.

As noted by Free State Foundation Adjunct Senior Fellow Michael O'Rielly in "The House Builds a Sound Privacy Bill," a May Perspectives from FSF Scholars, The SECURE Data Act (1) embraces "strong federal preemption that recognizes the interstate nature of data collection and consumption" and (2) rejects a private right of action in favor of exclusive enforcement by the FTC and state attorneys general, thereby "prevent[ing] abusive class-action lawsuits by trial attorneys that have plagued many other sectors of our economy."

The House Energy and Commerce Committee's Subcommittee on Commerce, Manufacturing, and Trade held a hearing on the SECURE Data act on June 3. The Press Release included the following quote from Subcommittee Chairman Gus Bilirakis (R-FL): "Americans, regardless of political affiliation, share a fundamental expectation that their personal data be protected and secure…. The productive dialogue during today's hearing represents an important step toward creating a framework that puts constituents back in control of their personal information while holding bad actors accountable."

Friday, April 24, 2026

"Soon" (But Not Too Soon), House Republicans Introduce Privacy Bills

In a Tuesday post to the Free State Foundation blog, I repeated the quote – which I first referenced in a January Perspectives from FSF Scholars – that the House Energy and Commerce Committee Privacy Working Group could introduce comprehensive data privacy legislation "soon." In this instance, "soon" translated to "Wednesday." That's when the House Committees on Energy and Commerce and Financial Services jointly introduced a pair of companion bills: the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act (SECURE Data Act) and the Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act (GUARD Financial Data Act).

The SECURE Data Act is the handiwork of the aforementioned working group, led by Representative John Joyce, M.D. (R-PA). The working group is composed of Republican members of the House Energy and Commerce Committee, which is chaired by Representative Brett Guthrie (R-KY). The GUARD Financial Data Act, meanwhile, is the product of the Financial Services Committee, led by Chairman French Hill (R-AR).

The two bills are designed to work in tandem: the SECURE Data Act covers consumer data handled by nonfinancial entities but exempts financial institutions and data subject to the Gramm-Leach-Bliley Act (GLBA), while the GUARD Financial Data Act modernizes the GLBA for the financial sector but exempts nonfinancial firms. As a joint one-pager released by the two committees explained, together the bills "form a common-sense Federal approach that will bring American privacy protections into the twenty-first century."

At a high level, the SECURE Data Act builds on – and, crucially, would preempt – the state-level "patchwork" that I have long lamented. It also wisely rejects a private right of action, leaving enforcement to the FTC and state attorneys general.

*    *    *

The SECURE Data Act establishes a set of now-familiar consumer rights, including the right to access, correct, delete, and transfer personal data. It also creates opt-out rights for targeted advertising, data sales, and certain automated profiling decisions. Processing of "sensitive data" would require opt-in consent, and parental consent would be required for the processing of data of teens (that is, those between the ages of 13 and 16). The processing of data of children under the age of 13 would remain subject to the provisions of the Children's Online Privacy Protection Act of 1998.

On the business side, the bill imposes data-minimization obligations that would limit the collection of data to what is "adequate, relevant, and reasonably necessary." It also includes data security requirements, privacy notice mandates, and data-protection-assessment requirements. Data brokers would be required to register with the FTC, which would maintain a searchable public registry. And businesses would have to disclose whether personal data is transferred to, processed in, or sold to foreign adversaries.

The SECURE Data Act would apply to businesses that process the personal data of at least 200,000 consumers annually. A separate threshold would cover data sellers that process the data of at least 100,000 consumers and derive over 25 percent of their revenue from the sale of personal data. Businesses with less than $25 million in adjusted gross annual revenue would be exempt.

As noted above, the bill does not create a private right of action. Instead, the FTC and state attorneys general would share enforcement authority. As I previously argued, exclusive enforcement by the FTC is far more likely to serve consumer interests than a private right of action, which would create problematic financial incentives for the plaintiffs' bar.

Perhaps most significant is the SECURE Data Act's broad preemption language, which provides that no state may "prescribe, maintain, or enforce any law, rule, regulation, requirement, standard, or other provision having the force and effect of law, if such law, rule, regulation, requirement, standard, or other provision relates to the provisions of this Act." This would appear to preempt the entire "patchwork" of state-specific privacy laws, now numbering 21, replacing them with a single, workable, nationwide standard.

*    *    *

Of course, the standard caveats apply. As a Republican-only bill, the SECURE Data Act will need to attract bipartisan support if it is to become law. And the usual sticking points – in particular, the bill's rejection of a private right of action and its strong preemption language – could impede its progress, something we certainly have seen happen before to similar pieces of legislation.

Nevertheless, the SECURE Data Act seems to strike an appropriate balance between protecting privacy and fostering innovation, a point made by NCTA – The Internet & Television Association in its supportive statement: the SECURE Data Act's "unified approach will strengthen consumer trust, give individuals meaningful control over their personal information, and provide businesses the certainty needed to innovate, protect data, and drive growth while eliminating the confusing patchwork of state laws that burdens consumers and businesses."

Tuesday, April 21, 2026

Later Rather Than Sooner: Oklahoma Enacts State Privacy Law No. 21

After a steady stream of state-level privacy statutes, capped by passage of the Rhode Island Data Transparency and Privacy Protection Act in June 2024, for nearly two years the pipeline ran dry. That drought ended on March 20, when Sooner State Governor Kevin Stitt signed into law the Oklahoma Consumer Data Privacy Act (OCDPA). With that, the list of states to have passed a comprehensive data privacy statute now stands (by my count) at 21.

At the federal level, meanwhile, the pickings remain slim. In late March, Representative Zoe Lofgren (D-CA) for the fourth time introduced the Online Protection Act, the shortcomings of which I rehashed in a contemporaneous post to the Free State Foundation blog. Beyond that, hopeful eyes can look only to the House Commerce Committee Privacy Working Group, which was created in February 2025 and sought public input a month later. As I noted in a January Perspectives from FSF Scholars, reporting at that time suggested that the working group could release a draft bill … "soon."

The good news about the OCDPA, which closely tracks the Virginia Consumer Data Protection Act, is that it does not impose more burdensome obligations than existing state laws – and therefore is regarded as a relatively "business-friendly" addition to the state-level "patchwork."

The bad news, of course, is that it further expands that "patchwork," thereby compounding compliance headaches for companies – especially smaller companies and start-ups – and making it even more challenging for consumers to comprehend their rights.

*    *    *

More targeted than other state laws, the OCDPA applies only to businesses operating in Oklahoma or targeting Oklahoma residents that control or process the personal data of either (1) 100,000 or more Oklahoma consumers, or (2) at least 25,000 Oklahoma consumers while deriving over 50 percent of their gross revenue from the "sale" of personal data. (By comparison, that threshold is lower – 25 percent – in most state laws.) In addition, the OCDPA defines "sale" relatively narrowly – that is, only where personal data is exchanged for monetary consideration.

The law establishes a now-familiar set of consumer rights: to access and confirm the processing of personal data, to correct inaccuracies, to delete, and to obtain a portable copy. In addition, consumers can opt out of the processing of personal data for targeted advertising, the sale of their personal data, and profiling.

"Sensitive data" – defined to include racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship status, genetic or biometric data used for identification, and precise geolocation data – may not be processed without the consumer's opt-in consent.

Covered businesses must abide by data-minimization principles, limiting collection to what is adequate, relevant, and reasonably necessary. They also must conduct data protection assessments before engaging in activities such as targeted advertising, the sale of personal data, and the processing of "sensitive data."

Two additional features of the OCDPA are worth highlighting. First, enforcement authority rests exclusively with the Oklahoma Attorney General; there is no private right of action. Second, the law includes a permanent, mandatory 30-day "right to cure" period for alleged violations – a feature that stands in contrast to the trend in other states toward sunsetting or eliminating cure periods altogether. Violations may result in penalties of up to $7,500 per incident.

The OCDPA will go into effect on January 1, 2027.

*    *    *

As I've stated countless times, the absence of a comprehensive federal data privacy law that would preempt this now-larger "patchwork" remains a glaring gap. With each new state law – and each set of idiosyncratic definitions of rights, responsibilities, thresholds, exemptions, enforcement mechanisms, and so on – the compliance burden on businesses grows heavier and the regulatory landscape confronting consumers grows murkier.

Friday, March 27, 2026

Representative Lofgren's Online Privacy Act Has Reentered the Chat

As we eagerly await word from the House Energy and Commerce Committee's data privacy working group, Representative Zoe Lofgren (D-CA) once again has resurrected the problematic Online Privacy Act (OPA).

In February 2025, Committee Chairman Brett Guthrie (R-KY) and Vice Chairman John Joyce, M.D. (R-PA) announced the establishment of a data privacy working group "to bring members and stakeholders together to explore a framework for legislation that can get across the finish line." (For more information please see my contemporaneous post to the Free State Foundation blog).

Shortly thereafter, the working group solicited public comment on a Request for Information that I summarized in a follow-up blog post.

In a January Perspectives from FSF Scholars summarizing privacy-related legislative activity in 2025, I shared speculation that the working group might introduce a bill "soon." Separate reporting around the same time indicated that the working group "intend[s] to take up action on a broader, comprehensive federal privacy measure in spring 2026."

In the interim, Representative Lofgren for the fourth time has introduced the OPA, a draft bill first unveiled in 2019 and then again in 2021 and 2023.

As I pointed out in "A Tale of Three Data Privacy Bills: Federal Legislative Stalemate Enables Bad State Laws," a January 2022 Perspectives, the OPA has two top-level shortcomings: (1) it "is silent on the issue of preemption," and thus fails to address the state-level "patchwork" problem that in the intervening years has only gotten worse; and (2) it creates a private right of action that, unlike exclusive enforcement by the FTC, would be far more likely to benefit the plaintiffs' bar than consumers.

With the vernal equinox exactly one week in the rear-view mirror, it remains possible that the working group will introduce (presumably preferable) comprehensive data privacy legislation this spring.

Time will tell.

Wednesday, April 30, 2025

NO FAKES Act to Combat "Deepfakes" is Reintroduced in Congress

On April 11, the "Nurture Originals, Foster Art, and Keep Entertainment Safe Act of 2025" or "NO FAKES Act" was re-introduced in the U.S. House of Representatives (H.R. 2794) and Senate (S. 1367). The House bill is sponsored by Rep. Maria Elvira Salazar and the Senate bill is sponsored by Sen. Christopher Coons. The NO FAKES Act would bolster individuals' intellectual property rights in their likenesses and voices by recognizing a private right of action against unauthorized and harmful "deepfakes." The bill has bipartisan backing as well as the endorsement of a cross-section of the creative and tech industries. The NO FAKES Act is strong on the merits and the 119th Congress should give it due consideration. 

 


Although generative AI technologies offer potential benefits, they also may be abused. Public displays and dissemination of "deepfake" songs misappropriate the value of recording artists’ voices, damaging the artists economically. Also, generative artificial intelligence (AI) tools and services on the Internet allow users to create "deepfake" explicit pictures and videos of individuals.

 

The NO FAKES Act would address those "deepfake" dangers in a targeted way by establishing a national uniform baseline of legal protection for an individual’s likeness and voice from unauthorized digital replicas. If passed by the 119th Congress and signed into law by President Donald Trump, the Act would make civilly liable anyone who knowingly produces a digital replica without the consent of the rights owner. It also would make civilly liable anyone who knowingly publishes, reproduces, displays, distributes, transmits, or makes the digital replica available to the public without the rights owner's consent. Persons harmed under the Act would have a right to seek statutory or actual damages, recovery of costs and attorneys’ fees, and injunctive relief. 

 

Recognizing the potential benefits of authorized digital replicas, the NO FAKES Act provides that individuals would have the right to license their personas for digital replication by third parties. Additionally, the Act is carefully written to address abuses and it includes safeguards for First Amendment-protected free speech and expression using generative AI tech. It bears emphasis that the NO FAKES Act is about private law – personal rights and intellectual property rights; it is not a federal criminal law bill.

 

A more detailed review of the same bill, previously introduced in the 118th Congress, is provided in my August 2024 Perspectives from FSF Scholars, "The 'NO FAKES Act' Would Protect Americans' Rights Against Harmful Digital Replicas."

Tuesday, March 04, 2025

House Commerce Privacy Working Group Seeks Input

In a February 2025 post to the FSF Blog, I reported on a press release from House Commerce Committee Chairman Brett Guthrie (R-KY) and Vice Chairman John Joyce, M.D. (R-PA) announcing the creation of a working group focused on federal comprehensive data privacy legislation. That working group is now asking interested parties to provide responses to a Request for Information (RFI).

Released on February 21, 2025, the RFI begins by acknowledging two points I have highlighted repeatedly in writings for the Free State Foundation, most recently in a December 2024 Perspectives from FSF Scholars.

One, that "the challenge of providing clear digital protections for Americans is compounded by the fast pace of technological advancement and the complex web of state and federal data privacy and security laws, which in some cases create conflicting legal requirements."

And two, that "Members of Congress have spent many years working toward federal comprehensive data privacy and security standards to bring consumer protections into the digital age while ensuring that the U.S. continues to lead in a globally competitive environment."

The information sought by the RFI is organized into the following six specific categories:

  • Roles and Responsibilities: What types of entities collect, process, and sell personal information? What obligations should apply to each?
  • Personal Information, Transparency, and Consumer Rights: What specific consumer protections should a privacy law include? What heightened safeguards should apply to sensitive personal information? How should covered entities provide disclosures to consumers?
  • Existing Privacy Frameworks and Protections: What can be learned from the existing "patchwork" of state privacy laws? To what extent should a federal privacy law preempt state privacy laws?
  • Data Security: How can federal lawmakers ensure the security of consumer data?
  • Artificial Intelligence (AI): How might a federal privacy law account for existing state laws addressing AI, including those relating to automated decision-making?
  • Accountability and Enforcement: What are the pros and cons of exclusive enforcement by the FTC and state Attorneys General? Should a federal privacy law include a safe harbor?

A seventh, catch-all, category encourages interested parties to submit "any additional information that may be relevant to the working group as it develops a comprehensive data privacy and security law."

Responses, due by April 7, 2025, should be emailed to PrivacyWorkingGroup@mail.house.gov.

Tuesday, December 17, 2024

Michigan Could Become State No. 21 to Pass a Data Privacy Law

In a Perspectives from FSF Scholars on privacy legislation in 2024 published just last week, I wrote that seven additional states adopted comprehensive data privacy statutes this year, bringing the total to twenty. But did I speak too soon? The very same day, Michigan Senator Rosemary Bayer (D) announced via press release that the Personal Data Privacy Act (Senate Bill 659) had passed the Senate.

Should Senate Bill 659 clear the House before the current legislative session ends on December 23, the Wolverine State could become the eighth state in 2024, and the twenty-first overall, to forge a unique data privacy path.

Senate Bill 659 would establish familiar consumer rights including: the right to know that personal data is being processed, the right to access that personal data, the right to correct inaccuracies, the right to delete, and the right to obtain a portable copy. Consumers also would be able to opt out of the sale of personal data, targeted advertising, and "[p]rofiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer."

As is the case with the Maryland Online Data Privacy Act of 2024, which I summarized in a February post to the Free State Foundation blog, Senate Bill 659 includes "data minimization" provisions that "limit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a product or service requested by the consumer … consistent with the consumer's reasonable expectations" (emphases added) and place similarly subjective limits on the processing of personal data. Sensitive data may be collected and/or processed only where "strictly necessary."

Senate Bill 659 would not create a private right of action. Instead, the state attorney general would have exclusive enforcement authority. It would go into effect a year from the date of enactment.

Friday, June 28, 2024

Federal Privacy Bill Hits Roadblock, State Activity Picks Up Speed

At the eleventh hour, the House Energy and Commerce Committee cancelled a markup scheduled for Thursday that included the American Privacy Rights Act of 2024 (APRA). At the state level, by contrast, Minnesota and Rhode Island recently enacted their own comprehensive data privacy laws, bringing the total to 20. And previously adopted statutes in three states – Oregon, Texas, and Florida – go into effect on July 1.

Having cleared the Innovation, Data, and Commerce Subcommittee late last month, the APRA was one of eleven bills on the agenda for yesterday's full committee markup. Chair Cathy McMorris Rodgers (R-WA) did not state a reason for the last-minute cancellation, but The Hill reported that House Republican leadership objected to the private right of action created by the discussion draft.

As it happens, in "Congressional Leaders Return Privacy to the Front Burner," an April Perspectives from FSF Scholars, I anticipated that "the APRA's problematic inclusion of a private right of action may – and should – prove once again to be a sticking point."

The already sizeable patchwork of state comprehensive data privacy laws, meanwhile, continues to grow. (So, too, do the associated compliance headaches for companies and confusion faced by consumers.) On May 24, 2024, North Star State Governor Tim Walz signed the Minnesota Consumer Data Privacy Act, a law similar – though not identical, of course – to those passed in New Hampshire and Maryland.

And on June 25, 2024, Ocean State Governor Dan McKee transmitted with no signature the Rhode Island Data Transparency and Privacy Protection Act, bringing the total of state comprehensive data privacy laws to 20. The Rhode Island statute is notable for its relatively large fines: up to $10,000 per violation, plus additional penalties for "intentional disclosures of personal data."

The Minnesota act will not go into effect until July 31, 2025, the Rhode Island law not until January 1, 2026. Laws in three other states, however, kick in on the first day of July: the Oregon Consumer Privacy Act, the Texas Data Privacy and Security Act, and – by my measure, at least – the Florida Digital Bill of Rights.

For additional details on these statutes, please see "More States Compound the Dreaded Privacy 'Patchwork' Problem," a July 2023 Free State Foundation Perspectives.

Tuesday, October 31, 2023

Maine May Join the State Privacy Law Club

Might the Pine Tree State in 2024 become the fourteenth state to pass a comprehensive data privacy law – and thereby further compound the problem of multiple, conflicting state statutes? It's possible. The Maine legislature's bicameral Judiciary Committee considered "An Act to Create the Data Privacy and Protection Act" (LD 1977) at a hearing two weeks ago.

LD 1977 is modeled on the American Data Privacy and Protection Act (ADPPA), a piece of federal legislation that easily cleared the House Commerce Committee back in August 2022 before losing forward momentum. That LD 1977 takes its lead from the ADPPA is somewhat ironic, as one of the primary motivating factors driving the ADPPA was the problem of a "patchwork" of state-specific laws, a problem that LD 1977 threatens to exacerbate.

To make matters worse, LD 1977 problematically diverges from the ADPPA by including an extremely broad private right of action. Specifically, Section 9620(2) states that:

A violation of this chapter or a rule adopted under this chapter with respect to the covered data of an individual constitutes an injury to that individual. The injured individual may bring a civil action against the party that commits the violation, except that an individual may not bring a civil action against a small business.

Possible remedies include actual damages or statutory damages starting at $5,000 per violation, whichever are greater; punitive damages; attorney's fees and costs; and injunctive and declaratory relief. A "small business" is a "covered entity" or "service provider" (but not a "data broker") that (1) generates less than $41 million in annual revenues, and (2) does not collect or process the personal data or more than 200,000 individuals.

Something else to consider: as I described in "Maine's ISP-Only Privacy Law Will Not Protect Consumers," an April 2020 Perspectives from FSF Scholars, Maine adopted a privacy law in June 2019 that singles out broadband Internet service providers (ISPs), requiring them – but not other participants in the broader online ecosystem, such as "edge providers" like Alphabet, Meta, and Amazon – to obtain "opt-in" consent from customers before using their personal information.

At an absolute minimum, any additional privacy legislation must acknowledge – and address – this disparate treatment of broadband ISPs.

Tuesday, June 06, 2023

Montana Makes Nine: Another State Passes a Data Privacy Law

On May 19, 2023, Governor Greg Gianforte signed into law the Montana Consumer Data Privacy Act (MCDPA). With that, the number of states to adopt comprehensive data privacy statutes expanded to nine. And the regulatory headache that consumers and companies alike must endure grew by an equal measure.

In other ways similar to legislation passed in Virginia and Connecticut, the MCDPA forges its own unique path with regard to applicability. Perhaps as a reflection of Big Sky Country's relatively low population level, the MCDPA covers a wider range of businesses: those that possess the personal information of just 50,000 (rather than the more common 100,000) residents. Consequently, some smaller businesses that were exempt under other state statutes may now be on the hook for costly compliance programs.

The MCDPA establishes a familiar set of consumer rights: to know, to access, to correct, to delete, and to port collected personal data. In addition, consumers (1) can opt out of targeted advertising, data sales, and "profiling in furtherance of solely automated decisions that produce legal or similarly significant effects," and (2) must opt-in before a business can make use of "sensitive" personal data.

Businesses must abide by "privacy by design" principles, which include purpose-specific constraints on data usage and an obligation to adopt reasonable security measures. They also must conduct data protection assessments before engaging in a number of activities that "present[] a heightened risk of harm to a consumer." And starting in January 2025, they must recognize browser-based universal opt-out mechanisms.

Notably, the MCDPA will go into effect before laws recently adopted in Iowa (January 1, 2025) and Indiana (July 1, 2026): on October 1, 2024.

Meanwhile, it appears likely that Texas will be next: the Texas Data Privacy and Security Act has reached Governor Greg Abbott's desk.

Friday, March 25, 2022

Utah Becomes Fourth State to Pass a Privacy Law

On March 25, 2022, Beehive State Governor Spencer J. Cox signed the Utah Consumer Privacy Act (the Act), making Utah the fourth state to enact its own unique take on comprehensive data privacy legislation.

In a March 8, 2022, post to the Free State Foundation's blog, I reported that the Act had passed both state legislative chambers unanimously and was "nearly certain" to become law. I also provided a general overview of the consumer rights and corporate responsibilities set forth therein.

Yesterday, Utah officially joined California (the California Consumer Privacy Act and the California Privacy Rights Act), Virginia (the Virginia Consumer Data Protection Act), and Colorado (the Colorado Privacy Act) on the steadily expanding list of states occupying the vacuum created by the absence of a preempting federal privacy law.

Consequently, the logistic headaches for both consumers and businesses I described in "Inconsistent State Data Privacy Laws Increase Confusion and Costs," a March 2021 Perspectives from FSF Scholars, have become more intense.

On the bright side, the Act, which is based on the Virginia statute and appears to strike a workable balance between protecting the rights of individuals and allowing businesses to continue to innovate, potentially could serve as a promising model for the federal law we all eagerly await.

For one thing, it comes down on what I view as the right side regarding the contentious issue of a private right of action, leaving enforcement exclusively to the Office of the Attorney General.

Tuesday, March 08, 2022

Utah "Nearly Certain" to Become Fourth State to Pass a Privacy Law

Any day now, Utah almost certainly will become the fourth state to enact comprehensive data privacy legislation. As I have written previously, in a series of posts to the Free State Foundation's blog and Perspectives from FSF Scholars, Congress bears the increasingly urgent responsibility to pass a federal privacy statute, one that preempts state laws, rejects a private right of action, and establishes a single set of clear rules that businesses can abide and consumers can understand.

Even President Biden, in his State of the Union Address, acknowledged the need for Congress to break the privacy logjam.

The California Consumer Privacy Act and the California Privacy Rights Act. The Virginia Consumer Data Protection Act. The Colorado Privacy Act. Four laws in three states, each imposing a unique set of rights and responsibilities on the border-defying Internet.

In "Inconsistent State Data Privacy Laws Increase Confusion and Costs," a March 2021 Perspectives from FSF Scholars, I explained the headaches that result. Companies must either (1) take high-risk pains to associate accurately each customer interaction with the appropriate state, or (2) craft one-size-fits-all compliance programs that reflect the "greatest hits" imposed by the growing list of states taking steps to fill the federal void. Consumers, meanwhile, are left to try to make sense of these overlapping and contradictory state-specific regimes on their own.

The Utah Consumer Privacy Act is poised to further complicate this already untenable situation. Based upon, but by no means identical to, the Virginia Consumer Data Protection Act, it was passed unanimously by both the Utah Senate and House of Representatives. Last Friday, it landed on the desk of Governor Spencer Cox, who is "nearly certain" to sign it into law. Assuming he does, it will become effective at the end of next year.

Similar to the other state privacy laws already enacted, the Utah Consumer Privacy Act (Act) would establish rights for consumers (to know what personal data is collected, to access or delete that information, to opt out of the collection, use, and sale of personal data for certain purposes, and so on) and responsibilities for covered entities (such as obligations to provide adequate notice to consumers, to safeguard collected personal data, and to respond within a defined window to consumer requests).

However, and as is already the case regarding the laws passed in California, Virginia, and Colorado, the specifics of the Act in many instances are one of a kind.

For example, and subject to exceptions, the Act would apply to a "controller" (defined as "a person … who determines the purposes for which and the means by which personal data is processed") or "processor" (defined as "a person who processes personal data on behalf of a controller") who:

  • Does business in Utah or targets state residents with a product or service;
  • Generates at least $25 million in annual revenues; and
  • Either (a) accesses the personal data of at least 100,000 consumers in a year or (b) derives more than half of its gross revenues from the sale of personal data and accesses the personal data of more than 25,000 consumers.

In the March 2021 Perspectives referenced above, I pointed out that applicability is one of the many ways in which the various state laws deviate from one another – and thereby complicate matters for all involved: "As an initial matter, these bills establish different minimum thresholds – including annual gross revenue amounts and number of individuals, or individuals, households, and devices, subject to data collection – for a business to be deemed covered."

Other ways in which the Act would differ from other state laws:

  • The Act would create the consumer right to delete personal information – but only that data in fact provided by the consumer, not data the covered entity has obtained from other sources.
  • It would define "sensitive data," a subset of personal data, to include information such as racial and ethnic origin, religious beliefs, sexual orientation, medical history, and genetic, biometric data, and geolocation data. Covered entities would be required to provide notice and an opportunity to opt-out of the collection and/or use of "sensitive data" – rather than requiring that consumers first opt-in.
  • It would define "sale" in a manner that, unlike, say, the California Privacy Rights Act, does not include "other monetary consideration."

To be clear, I am not saying these variations are good or bad – just complicating.

Finally, I want to point out approvingly that the Act states unambiguously that "[a] violation of this chapter does not provide a basis for, nor is a violation of this chapter subject to, a private right of action under this chapter or any other law."

Instead, the Act would task the Department of Commerce's Division of Consumer Protection with investigating consumer complaints. The Office of the Attorney General, in turn, would have exclusive enforcement responsibility. Covered entities would be provided with a 30-day right to cure, after which penalties up to $7,500 per violation could be imposed.

Friday, October 01, 2021

Privacy Recap: Senate Commerce Committee Holds Hearing on Data Privacy; Op-Ed Authors Oppose FTC Privacy Rulemaking

On Wednesday, September 29, 2021, the Senate Committee on Commerce, Science, & Transportation held its first hearing of the year on data privacy, "Protecting Consumer Privacy."

Witnesses included:

  • Georgetown Law Professor David Vladeck, a former Director of the FTC's Bureau of Consumer Protection (written testimony)
  • President of The App Association Morgan Reed (written testimony)
  • Maureen Ohlhausen, a partner at Baker Botts and a former Acting Chair of the FTC (written testimony)
  • Independent Researcher and Technologist Ashkan Soltani, who once served as the FTC's Chief Technologist (written testimony)

As one might expect, there was widespread agreement on the need to both pass a federal data privacy law and provide the FTC with greater resources.

The disagreements centered on the usual suspects – that is, preemption of state laws and a private right of action – along with (1) the amount of additional dollars to be allocated to the FTC, and (2) whether it would be appropriate for the agency to initiate a privacy rulemaking in the absence of congressional progress, an issue I touched upon in a Wednesday post to the FSF Blog.

In her Majority Statement, Chair Maria Cantwell (D - WA) emphasized the need to better empower the FTC, noting with approval that the Budget Reconciliation Act in its current form would make $1 billion available over ten years to establish and fund a new Privacy Bureau.

In his Minority Statement, Ranking Member Roger Wicker (R - MS) wrote that "the need for strong data privacy rules has become more urgent" over the past year and reiterated that he is "open" to a narrow private right of action that does not "stifl[e] innovation and marketplace competition or lead[] to unjustified financial windfalls for plaintiff attorneys."

In addition, he urged President Biden "to appoint someone – a specific person – among his senior staff to be a liaison to Congress on this issue and to prioritize the enactment of a data privacy law this year."

Finally, he voiced his objection to the possibility of an FTC rulemaking, asserting that "[o]nly Congress can develop longstanding data protections for consumers that meaningfully safeguard their personal information." (See below for more on this topic from Senator Wicker.)

A video archive of the hearing can be found here.

This was the first in a series of three Senate Commerce Committee hearings on data privacy and security. The next, entitled "Enhancing Data Security," will take place at 10 am EDT on Wednesday, October 6, 2021.

*    *    *

Also on Wednesday, the Washington Examiner published an op-ed by Senator Wicker, Representative Cathy McMorris Rodgers (R - WA), ranking member of the House Energy and Commerce Committee, and Republican FTC Commissioner Noah Phillips opposing a possible FTC rulemaking on privacy.

That same day, The Wall Street Journal (subscription required) reported that agency Chair Lina Khan is considering such a step.

The trio wrote that Congress has not granted the FTC "the authority to write comprehensive national privacy rules" and that "[a]ttempting to rewrite privacy law by executive fiat would be a blatant overreach that would almost certainly invite legal challenges."

They also argued that, as a matter of sound policy, "[a] national law must be the product of debate and compromise among the people's representatives."

The authors did, however, acknowledge that the FTC is the appropriate government entity to enforce a federal law once enacted, describing it as "the most effective privacy enforcer in the world."

Wednesday, September 29, 2021

FTC Commissioner Wilson Recruits Student Researchers to Inform and Inspire Efforts to Pass a Federal Data Privacy Law

Citing what she describes as "significant information asymmetries," Republican FTC Commissioner Christine Wilson long has advocated for a comprehensive federal data privacy law. In fact, she discussed that very issue in her keynote address at the Free State Foundation's Twelfth Annual Telecom Policy Conference in March 2020.

More recently, she partnered with Duke University on a research project designed to expedite the currently stalled legislative process.

To date, efforts to pass a federal privacy law have been stymied by partisan disagreements regarding two issues in particular.

One, whether a federal data privacy law should preempt similar state laws. As I have argued on numerous occasions, most recently in "Pressures Multiply for Congress to Act on Data Privacy," a Perspectives from FSF Scholars published earlier this month, it should.

The growing list of states with their own, inconsistent statutes – which currently includes California (both the California Consumer Privacy Act and the California Privacy Rights Act), Virginia (the Virginia Consumer Data Protection Act), and Colorado (the Colorado Privacy Act) – unreasonably complicates companies' compliance efforts and creates chaos for consumers.

Two, whether it should provide for a private right of action. It should not. Generally speaking, class-action lawsuits benefit attorneys, not consumers. Case-by-case enforcement by the FTC is the better approach.

Unable to find common ground on these questions, lawmakers have made no observable progress of late. However, the fact that the Senate Commerce Committee is holding a hearing today titled "Protecting Consumer Privacy," the first of its kind this year, perhaps offers a glimmer of hope.

Given the failure to date of Congress to pass privacy legislation, there have been repeated calls for the FTC to commence a rulemaking. On September 20, a group of Democratic Senators led by Richard Blumenthal (CT) wrote to FTC Chair Lina Khan urging her to do just that.

Notably, and in specific response to the lack of legislative momentum, at one point Commissioner Wilson herself reluctantly expressed her support for an FTC privacy rulemaking, a statement that I highlighted in a July 2021 post to the FSF Blog.

But in light of a pattern of agency actions that Commissioner Wilson troublingly regards as an "abrupt departure from regular order" – including, most recently, the September 15th decision along party lines to withdraw the Vertical Merger Guidelines that were issued in 2020, to which she and fellow Republican Commissioner Noah Phillips responded with a co-authored Dissenting Statement – she has had a change of heart.

In an Oral Statement submitted to the House Commerce Committee's Subcommittee on Consumer Protection and Commerce in July of this year, she wrote the following:

In recent months, I had become more receptive to a [Magnuson]-Moss rulemaking on privacy to address the information asymmetry between the providers of goods and services and their users. But the Commission recently voted along party lines to pare back procedural safeguards and limit opportunities for public input during agency rulemakings. Given these changes, I am less inclined to support a Mag-Moss rulemaking on privacy. Federal privacy legislation remains the optimal solution.

In an attempt to facilitate that "optimal solution," Commissioner Wilson several months ago partnered with Duke University's Professor David Hoffman, along with students from its law school and Sanford School of Public Policy, to produce "a resource for legislators" – specifically, research-driven insight into how other federal statutes have addressed these two sticking points.

The fruits of that effort, which focused on both federal statutes (ten on the topic of preemption, six regarding remedies) and the European Union's General Data Protection Regulation (GDPR), have been made available publicly here.

In a keynote address delivered at "Exploring Options: Overcoming Barriers to Comprehensive Federal Privacy Legislation," a related event held on September 21, 2021 (video available here), Commissioner Wilson offered her perspective on these findings.

While acknowledging that the research revealed that "federal statutes that preempt an entire field of law are rare," Commissioner Wilson argued that the more common approach — where Congress "establish[es] a federal floor and allow[s] states to pass more stringent laws" — is not well suited to "fields like … the Internet that transcend state and national borders."

Given that:

  1. "[T]he very nature of the Internet makes it likely that the most stringent state standard will become the de facto national standard," and
  2. A primary regulatory objective should be to ensure that businesses are subject to consistent obligations,

Commissioner Wilson suggested that a better way forward would be to ensure that those rights and responsibilities established at the federal level are sufficiently robust on their own: "If the [federal] law provides strong rights and imposes appropriate standards and obligations on businesses, as well as robust and accessible remedies, more stringent state laws should not be necessary."

She also indicated that, given the dynamic and constantly evolving nature of the online experience, she would support "vesting the FTC with carefully tailored rulemaking authority … to facilitate updating key definitions and provisions over time."

With respect to remedies, Commissioner Wilson began with the point that a strong privacy law, one that empowers and adequately funds the FTC's efforts, would undercut one of the primary arguments as to why a private right of action may be necessary – that is, the perception that current levels of enforcement are inadequate.

She also highlighted research demonstrating that "abusive class action practices increase costs for businesses – while providing little in the way of redress for consumers, changed business practices, and deterrence."

Stepping back, Commissioner Wilson then made the foundational recommendation that "we … broaden the conversation" beyond solely whether or not to include a private right of action to "focus on establishing a constructive remedial framework."

In that vein, she cited "Breaking the Privacy Gridlock: A Broader Look at Remedies" by Jim Dempsey, Chris Hoofnagle, Ira Rubinstein, and Katherine Strandburg, when making the following three points:

  1. Remedies should be tied to policy goals,
  2. No one remedy can successfully promote even a simple goal and therefore an effective law should include multiple remedies, and
  3. Intermediaries and third parties play a powerful role.

Asserting that "an 'all or nothing' approach will not serve the goals of privacy legislation," Commissioner Wilson suggested that alternative enforcement proposals be given serious consideration, including those that involve:

  • A supervisory authority and/or third-party intermediaries, or
  • A private right of action "in limited circumstances [with] substantive and procedural limits," exclusively "for specific, highly sensitive types of data," or providing only for injunctive relief.

In conclusion, she stated the following: "Ideally, the remedies contained in privacy legislation will turn on the kinds of injuries consumers may suffer."

At the same time, she teed up the question as to how the standing test set forth by the Supreme Court in its 2021 Transunion, LLC v. Ramirez decision might impact the options available to Congress.

Tuesday, July 20, 2021

Ohio Legislators Introduce the Latest Comprehensive State Data Privacy Bill

The data privacy legal landscape grows steadily more complicated as more states take steps to occupy the void created by the absence of a much-needed federal statute.

Just last week, I noted in a post to the Free State Foundation's blog that Colorado had become the third state, after California and Virginia, to adopt comprehensive data privacy legislation. (Please click here and here for Perspectives from FSF Scholars addressing the two laws passed in California and here for a blog post describing the Virginia Consumer Data Protection Act.)

And now it appears that Ohio could be next.

Introduced on July 12, the Ohio Personal Privacy Act (OPPA) is a product of Governor Mike DeWine's InnovateOhio technology initiative, which is led by Lieutenant Governor Jon Husted.

Considered in isolation, the OPPA includes a number of relatively palatable provisions. Indeed, commenters have characterized the OPPA as a bill "that would impose fewer restrictions on businesses" and "more limited in scope than other state data protection laws that recently have been enacted."

Most notably, the OPPA expressly rejects a private right of action: "Any violation of this chapter shall not serve as the basis for, or be subject to, a private right of action, including a class action lawsuit, under this chapter or under any other law." The Ohio Attorney General's Office would have "exclusive authority" to enforce the OPPA.

It also would (1) provide businesses with a 30-day opportunity to cure alleged violations, and (2) create an affirmative defense to liability for any business that "creates, maintains, and complies with a written privacy program that reasonably conforms to" the Privacy Framework promulgated by the National Institute of Standards and Technology (NIST).

With some exceptions, the OPPA generally would cover those businesses that (1) earn at least $25 million in gross annual revenues within Ohio, (2) control or process the personal information of at least 100,000 consumers, or (3) derive more than half of their gross revenues from the sale of data and process/control the data of at least 25,000 consumers.

Businesses would be required to make available "a reasonably accessible, clear, and conspicuously posted privacy policy" that, among other things, details (1) the categories of personal information processed, and (2) the reasons for collecting or selling that data.

Where a business seeks to make a material change to its privacy policy, it would have the option to (1) obtain prior affirmative consent from affected consumers or (2) provide them with notice and "a reasonable means to opt out."

The OPPA would empower consumers in a number of ways, such as by establishing a right to know what personal information is collected, a right to request a copy of that information once during a twelve-month period, a right to demand that that data be deleted, and a right to prohibit its sale.

As Carrie Kuroc, deputy director of InnovateOhio, recently explained, "[o]ur goal isn't to copy, we want to lead. We wanted to craft privacy legislation that other states and the federal government can use as a model."

The big-picture problem with that goal, of course, is that the passage of yet another unique state law, regardless of the particulars of its approach, would serve to further confuse consumers as to their rights and exacerbate the compliance challenge for businesses.

The only solution to this increasingly complicated legal scenario is a comprehensive federal data privacy statute. Specifically, one that requires adequate consumer disclosures, establishes reasonable individual rights, embraces an "opt out" approach for non-sensitive personal information, treats all businesses equally, preempts state laws, and rejects a private right of action in favor of exclusive FTC enforcement.

In a July 16 letter to President Biden, four Republican lawmakers – Senators Roger Wicker (MS) and Marsha Blackburn (TN) and Representatives Cathy McMorris Rodgers (WA) and Gus Bilirakis (FL) – "urge[d him] to prioritize comprehensive data privacy legislation as part of [his] Administration's agenda."