{"id":2018,"date":"2019-02-18T11:33:49","date_gmt":"2019-02-18T09:33:49","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=2018"},"modified":"2020-12-15T12:50:27","modified_gmt":"2020-12-15T09:50:27","slug":"the-us-federal-privacy-law-picks-up-steam","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/the-us-federal-privacy-law-picks-up-steam\/","title":{"rendered":"The US Federal Privacy Law Picks Up Steam"},"content":{"rendered":"<p>As the adoption of the EU <a href=\"https:\/\/www.endpointprotector.com\/epp\/gdpr-the-most-in-depth-guide-to-stay-compliant\">General Data Protection Regulation<\/a> (GDPR) created a domino effect across the world, leading to more and more countries adopting <a href=\"https:\/\/www.endpointprotector.com\/blog\/data-protection-in-canada-pipeda\/\">data protection<\/a> legislations, the US, that was, until recently, strongly in favor of self-regulation, is now debating the idea of a federal privacy law that will regulate data protection nationwide, rather than leaving the issue of privacy to be settled at state level.<\/p>\n<p>What triggered this change of heart? A string of high-profile data breaches and, most of all, the <a href=\"https:\/\/www.nytimes.com\/2018\/04\/04\/us\/politics\/cambridge-analytica-scandal-fallout.html\" target=\"_blank\" rel=\"noopener noreferrer\">Cambridge Analytica scandal<\/a> which saw a consulting firm harvesting the data of millions of Facebook users and using it to influence their political views, raised public awareness on the dangers of unchecked data collection and use. <a href=\"http:\/\/www.pewinternet.org\/2017\/01\/26\/americans-and-cybersecurity\/\" target=\"_blank\" rel=\"noopener noreferrer\">A survey<\/a> conducted by the Pew Research Center showed that roughly half of Americans believe their data is less secure now than it was five years ago.<\/p>\n<p>Growing concern over data privacy and the entry into force of the GDPR, lead to legislation initiatives appearing at state level across the US. In 2018, California passed the <a href=\"https:\/\/www.endpointprotector.com\/blog\/all-you-need-to-know-about-ccpa\/\">Consumer Privacy Act<\/a>, the most exhaustive and consumer-friendly privacy law in the US, setting an example other states are now looking to follow.<\/p>\n<h2>The tech industry rallies behind a nationwide privacy law<\/h2>\n<p>Last week, networking giant CISCO joined the chorus of tech industry voices calling for a US Federal Privacy legislation. In a <a href=\"https:\/\/blogs.cisco.com\/news\/cisco-calls-for-us-federal-privacy-legislation-leveling-the-privacy-playing-field\" target=\"_blank\" rel=\"noopener noreferrer\">blog post<\/a> published by its top lawyer, Mark Chandler, CISCO called for \u201ca comprehensive US federal data protection legislation anchored to core principles of transparency, fairness, and accountability because the right to privacy is a fundamental right.\u201d<\/p>\n<p>The statement comes only three months after Apple CEO Tim Cook\u2019s <a href=\"https:\/\/www.theverge.com\/2018\/10\/24\/18017842\/tim-cook-data-privacy-laws-us-speech-brussels\" target=\"_blank\" rel=\"noopener noreferrer\">headline-grabbing speech<\/a> at the 40<sup>th<\/sup> International Conference of Data Protection and Privacy Commissioners in Brussels in which he spoke of the dangers posed by uncontrolled data collection and use that allows for private and everyday information to be \u201cweaponized against us with military efficiency.\u201d<\/p>\n<p>While Apple, whose main source of income comes from the sale of hardware such as iPhones and Macs and cloud services rather than user-targeted online advertisements, has always advocated for strong standards in data privacy, it was the first time it explicitly called for the adoption of a federal privacy law.<\/p>\n<p>Intel went one step further and not only did it show support for a potential legislation, but drafted <a href=\"https:\/\/usprivacybill.intel.com\/legislation\/\" target=\"_blank\" rel=\"noopener noreferrer\">its own model<\/a> for a federal privacy law with the aim to inform policymakers and spark a discussion on personal data privacy.<\/p>\n<p>While their public statements emphasize the dangers of unregulated data collection, a concern for individuals\u2019 privacy and the advantages of one all-encompassing data protection law instead of 50 distinct state laws, privacy advocates are skeptical of big tech\u2019s intentions.<\/p>\n<p>Alastair MacTaggart, the U.S. privacy campaigner who spearheaded the <a href=\"https:\/\/www.endpointprotector.com\/epp\/ccpa-compliance-the-most-in-depth-guide\" target=\"_blank\" rel=\"noopener noreferrer\">California Consumer Privacy Act (CCPA)<\/a>, <a href=\"https:\/\/www.politico.eu\/article\/tim-cook-apple-privacy-brussels-data-protection-facebook-google\/\" target=\"_blank\" rel=\"noopener noreferrer\">claims<\/a> that tech giants\u2019 priorities changed in the wake of the CCPA\u2019s adoption and that their new-found enthusiasm for federal legislation is linked to their hopes of influencing the passing of lax federal rules.<\/p>\n<h2>Federal Privacy Law Proposals<\/h2>\n<p>The debate surrounding the legislation however is not a purely theoretical one. Several data privacy bills have been introduced in the current session of the US Congress. The most notable of these, the so-called <a href=\"https:\/\/www.wyden.senate.gov\/imo\/media\/doc\/Wyden%20Privacy%20Bill%20Discussion%20Draft%20Nov%201.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Consumer Data Protection Act<\/a> (CDPA) was proposed by Senator Ron Wyden of Oregon in November 2018 and is the most comprehensive privacy bill to date. Like the CCPA it sets a clear application threshold: only companies that generate $50 million or more in annual revenue and collect personal information on more than one million consumers would fall under its incidence. It assigns the Federal Trade Commission (FTC) the responsibilities of a data protection authority, including the power to issue cease and desist orders and fines similar to those enforced under the GDPR of up to 4% of a company\u2019s gross annual revenue for noncompliance.<\/p>\n<p>The National Telecommunications and Information Administration (NTIA) started a discussion on a national approach to consumer privacy by requesting <a href=\"https:\/\/www.ntia.doc.gov\/other-publication\/2018\/comments-developing-administration-s-approach-consumer-privacy\" target=\"_blank\" rel=\"noopener noreferrer\">comments<\/a> on a set of privacy outcomes proposed by the Trump Administration that any national privacy framework should contain. These included, among others, transparency, security safeguards and reasonable user access to data.<\/p>\n<p>The US Chamber of Commerce that previously advocated for self-regulation, announced <a href=\"https:\/\/www.uschamber.com\/issue-brief\/us-chamber-privacy-principles\" target=\"_blank\" rel=\"noopener noreferrer\">its support<\/a> for a national privacy framework and released a set of privacy principles policymakers should consider when drafting a privacy bill. While it considers transparency and the need for data breach notifications essential, it also argues for harm-focused enforcement that promotes efficient and collaborative compliance rather than an adversarial enforcement system, in effect suggesting that a federal privacy framework should not create a private right of action for privacy enforcement.<\/p>\n<p>At the other end of the spectrum, a group of consumer and privacy organizations that include the Center for Digital Democracy, the Consumer Federation of America and the Electronic Privacy Information Center, made a <a href=\"https:\/\/www.citizen.org\/sites\/default\/files\/privacy-and-digital-rights-for-all-framework.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">framework proposal<\/a> that calls not only for the granting of private rights of action, but the creation of a federal data protection agency independent of the FTC and a broad definition of personal data.<\/p>\n<h2>Towards a US Federal Privacy Law<\/h2>\n<p>As debates around a nationwide privacy framework intensify, 2019 might be the year when the US proposes and passes its answer to the GDPR. With the democrats now controlling the House, the bill is likely to be a priority as its passing is sure to be considered a political win given prevailing public anger over data vulnerability and the increasing number of data breaches.<\/p>\n<p>The tech industry\u2019s own change of tune is a sign of the law\u2019s inevitability: big companies have given up fighting against it and have instead turned to lobbying to ensure a federal privacy law will not have catastrophic consequences on their bottom lines when it will be adopted.<\/p>\n<p>While the final provisions of the bill are likely to come to light only at the end of a bitter fight between legislators, lobbyists and advocates, companies can prepare by taking measures to ensure that the data they collect is secure, used only for the purposes it was collected and consumer consent is well documented.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As the adoption of the EU General Data Protection Regulation (GDPR) created a domino effect across the world, leading to more and more countries adopting data protection legislations, the US, that was, until recently, strongly in favor of self-regulation, is now debating the idea of a federal privacy law that will regulate data protection nationwide, &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/the-us-federal-privacy-law-picks-up-steam\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;The US Federal Privacy Law Picks Up Steam&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":2022,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[115],"tags":[],"class_list":["post-2018","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2018","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=2018"}],"version-history":[{"count":9,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2018\/revisions"}],"predecessor-version":[{"id":3813,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2018\/revisions\/3813"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/2022"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=2018"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=2018"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=2018"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}