American Data Privacy and Protection Act: Difference between revisions
→History: Cantwell |
|||
Line 106: | Line 106: | ||
* {{Cite web |last1=Brody |first1=Ben |last2=Chitkara |first2=Hirsh |title=What Microsoft, IBM and others won as the privacy bill evolved |work=Protocol |date=2022-08-03 |url=https://www.protocol.com/newsletters/policy/cloud-enterprise-privacy |language=en |access-date=2022-08-06 |df=mdy-all }} |
* {{Cite web |last1=Brody |first1=Ben |last2=Chitkara |first2=Hirsh |title=What Microsoft, IBM and others won as the privacy bill evolved |work=Protocol |date=2022-08-03 |url=https://www.protocol.com/newsletters/policy/cloud-enterprise-privacy |language=en |access-date=2022-08-06 |df=mdy-all }} |
||
* {{Cite web |last1=Cameron |first1=Dell |title=What's Stopping the American Data Privacy Act From Passing? |work=[[Gizmodo]] |date=2022-08-18 |url=https://gizmodo.com/can-american-data-privacy-protection-act-pass-1849413911 |language=en-us |access-date=2022-08-21 |df=mdy-all }} |
|||
* {{Cite web |last1=Castro |first1=Daniel |title=A Review: The American Data Privacy and Protection Act |work=GovTech |date=2022-06-13 |url=https://www.govtech.com/policy/a-review-the-american-data-privacy-and-protection-act |language=en |access-date=2022-07-30 |df=mdy-all |archive-date=July 17, 2022 |archive-url=https://web.archive.org/web/20220717141916/https://www.govtech.com/policy/a-review-the-american-data-privacy-and-protection-act |url-status=live }} |
* {{Cite web |last1=Castro |first1=Daniel |title=A Review: The American Data Privacy and Protection Act |work=GovTech |date=2022-06-13 |url=https://www.govtech.com/policy/a-review-the-american-data-privacy-and-protection-act |language=en |access-date=2022-07-30 |df=mdy-all |archive-date=July 17, 2022 |archive-url=https://web.archive.org/web/20220717141916/https://www.govtech.com/policy/a-review-the-american-data-privacy-and-protection-act |url-status=live }} |
||
* {{Cite news |last1=Edelman |first1=Gilad |title=Congress Might Pass an Actually Good Privacy Bill |work=[[Wired (magazine)|Wired]] |date=2022-07-21 |url=https://www.wired.com/story/american-data-privacy-protection-act-adppa/ |language=en-US |issn=1059-1028 |df=mdy-all |access-date=July 29, 2022 |archive-date=July 29, 2022 |archive-url=https://web.archive.org/web/20220729134053/https://www.wired.com/story/american-data-privacy-protection-act-adppa/ |url-status=live }} |
* {{Cite news |last1=Edelman |first1=Gilad |title=Congress Might Pass an Actually Good Privacy Bill |work=[[Wired (magazine)|Wired]] |date=2022-07-21 |url=https://www.wired.com/story/american-data-privacy-protection-act-adppa/ |language=en-US |issn=1059-1028 |df=mdy-all |access-date=July 29, 2022 |archive-date=July 29, 2022 |archive-url=https://web.archive.org/web/20220729134053/https://www.wired.com/story/american-data-privacy-protection-act-adppa/ |url-status=live }} |
Revision as of 03:01, 21 August 2022
Long title | An act to provide consumers with foundational data privacy rights, create strong oversight mechanisms, and establish meaningful enforcement |
---|---|
Acronyms (colloquial) | ADPPA |
Legislative history | |
|
American Data Privacy and Protection Act (ADPPA) is a United States proposed federal online privacy bill that would regulate how organizations keep and use consumer data. The bipartisan, bicameral bill is the first American consumer privacy bill to pass committee markup, which it did with near unanimity.
Contents
The American Data Privacy and Protection Act (ADPPA) would regulate how organizations keep and use consumer data. The Act has several main principles: data minimization, individual ownership, and private right of action. The burden of evaluating each organization's programs would fall to the organization.[1]
Data collectors would have to minimize the data they collect down to that which is "necessary, proportionate, and limited to" their purpose, whether administering a product or communicating. The bill would give the Federal Trade Commission a year to define those terms. Data minimization is a common principle among other privacy laws but would affect business functions beyond compliance operations. ADPPA would also specifically limit transfer and some processing of Social Security numbers, precise geolocation, biometric and genetic data, passwords, browsing history, and physical activity tracking.[1]
Individuals would have the right to know how their personal data will be used and which third parties receive it. They would have the right to correct and download their user data. Organizations would have up to 90 days to process these requests, depending on the organization's size. Individuals would also have the right to take legal action against organizations in violation of the Act for four years after its execution after first giving their state Attorney General and Federal Trade Commission 60 days' notice to respond.[1]
Designated "large data holders"—with adjusted gross revenue over $250 million in the last calendar year and processing either five million personal records or 100,000 sensitive individual records—would be subject to additional controls. These organizations would have to designate a corporate officer for administering data policy, training employees, keeping records, and communicating with the government. Large data holders' highest ranking corporate officers and data security officers would have to certify reasonable compliance with the Federal Trade Commission. Large data holders would need to provide a privacy impact assessment of their controls and risk to users every two years.[1]
"Small data holders", on the other hand, would be exempt from some requirements. Defined as organizations with adjusted gross revenue below $41 million over the past three calendar years, that process data for fewer than 100,000 individuals annually, and whose business does not primarily rely on transferring data, small data holders could delete records rather than processing corrective requests and would be exempt from many requirements apart from the user right to delete data no longer in use.[1]
Third-party data collectors, whose primary business revenue comes from user data collected for another platform's use, would also be subject to specific rules, such as displaying a notice about data collected on behalf of another organization, allowing for data audits, and populating a registry for such data collectors.[1]
As the first federal user data privacy legislation, ADPPA would largely supersede state laws like the California Consumer Privacy Act and Colorado Privacy Act, though carve-out state provisions about biometric data and data breaches would be protected. The federal bill would include nonprofit organizations whereas many state privacy laws do not, though nonprofits would largely fall under the "small data holder" exemptions.[1]
History
There is no federal law governing online privacy in the United States.[2] In July 2022, the American Data Privacy and Protection Act (ADPPA) became the first federal online privacy bill to pass committee, the House Energy and Commerce Committee, and did so with near unanimity.[2][3] Sponsored by the committee chair Frank Pallone,[2] the bicameral bill had bipartisan support and had included bipartisan concessions that had restricted prior attempts at a bipartisan privacy bill.[3] The bill is additionally led by House Representative Cathy McMorris Rodgers and, in the other legislative chamber, Senator Roger Wicker.[4] While Consumer Reports and the Electronic Privacy Information Center both showed optimism towards the bill, several democratic senators still opposed the bill.[3]
Though the bill had bipartisan support as it advanced to the House floor, it faced opposition from California lawmakers, the chair of the Senate Commerce Committee Maria Cantwell, and big tech companies.[2]
As the chair of the Senate committee responsible for data privacy, Maria Cantwell is the gatekeeper for any such bill to reach the senate floor. Cantwell, who has her own online privacy bill in draft, had similarly declined another bipartisan online privacy bill proposed by Senators Richard Blumenthal and Marsha Blackburn earlier in the year. Her primary concern for ADPPA was its enforcement provisions. Cantwell's own draft bill had been grappling with a provision that would restrict consumers from creating class-action lawsuits against companies that had harmed them.[4]
The 2022 overturning of Roe v. Wade led to increased interest in a federal privacy bill, with concern over how unmitigated tracking by data brokers and app developers, such as user visits to abortion clinics or period app usage, could be used to target users in places where criminalization of abortion. ADPPA would protect health privacy and not directly address Roe.[3]
Other privacy-related bills during ADPPA's advancement have included Elizabeth Warren's Health and Location Data Protection Act, Suzan DelBene's Information Transparency and Personal Data Control Act, and Sara Jacobs's My Body, My Data Act. In the absence of federal legislation, states laws have included California's Consumer Privacy Act and Privacy Rights Acts, Illinois's Biometric Information Privacy Act, and Vermont's Data Broker Act.[3]
References
- ^ a b c d e f g Dumiak, Matt (June 24, 2022). "Federal Privacy Bill: Breaking Down the ADPPA". JD Supra. Archived from the original on June 25, 2022. Retrieved July 30, 2022.
- ^ a b c d McGill, Margaret Harding (August 4, 2022). "Online privacy bill faces daunting roadblocks". Axios. Retrieved August 6, 2022.
- ^ a b c d e Morrison, Sara (July 21, 2022). "The end of Roe could finally convince Americans to care more about privacy". Vox. Archived from the original on July 27, 2022. Retrieved July 30, 2022.
- ^ a b Lima, Cristiano (June 30, 2022). "Cantwell's elusive endorsement hinders privacy talks". Washington Post.
Further reading
- Brody, Ben; Chitkara, Hirsh (August 3, 2022). "What Microsoft, IBM and others won as the privacy bill evolved". Protocol. Retrieved August 6, 2022.
- Cameron, Dell (August 18, 2022). "What's Stopping the American Data Privacy Act From Passing?". Gizmodo. Retrieved August 21, 2022.
- Castro, Daniel (June 13, 2022). "A Review: The American Data Privacy and Protection Act". GovTech. Archived from the original on July 17, 2022. Retrieved July 30, 2022.
- Edelman, Gilad (July 21, 2022). "Congress Might Pass an Actually Good Privacy Bill". Wired. ISSN 1059-1028. Archived from the original on July 29, 2022. Retrieved July 29, 2022.
- Keary, Tim (June 20, 2022). "What is the American Data Privacy and Protection Act (ADPPA) and what does it mean to enterprises?". VentureBeat. Archived from the original on July 27, 2022. Retrieved July 30, 2022.
- Klar, Rebecca (July 20, 2022). "House panel advances landmark federal data privacy bill". The Hill. Retrieved July 30, 2022.
- Lima, Cristiano (July 26, 2022). "Analysis - Pelosi in a bind as California leaders object to federal privacy bill". Washington Post. ISSN 0190-8286. Archived from the original on July 26, 2022. Retrieved July 30, 2022.
- McKinnon, John D. (July 20, 2020). "Data-Privacy Bill Advances in Congress, but States Throw Up Objections". Wall Street Journal. Archived from the original on July 20, 2022. Retrieved July 30, 2022.
- Ostwal, Trishla (July 21, 2022). "States Retaliate as the Federal Privacy Bill Advances". Adweek. Retrieved July 30, 2022.
- Seitz, Jacob (July 21, 2022). "Congress' big new privacy bill might just neuter the agency that should be enforcing it". The Daily Dot. Retrieved July 30, 2022.
- Shatz, Sanford (July 12, 2022). "Congress Introduces the American Data Privacy and Protection Act". JD Supra. Archived from the original on July 14, 2022. Retrieved July 30, 2022.
- Tsukayama, Hayley; Schwartz, Adam; McKinney, India; Tien, Lee (July 24, 2022). "Americans Deserve More Than The Current American Data Privacy Protection Act". Electronic Frontier Foundation. Archived from the original on July 29, 2022. Retrieved July 30, 2022.