Live data from Hacker News

American Data Privacy and Protection Act

congress.gov

1–10 of 313 posts

Re: American Data Privacy and Protection Act

#2
Ten years or so ago, I was participating in a small business roundtable discussion with one of our state senators. At the time, I ran a consumer research agency and would often have multinational projects involving consumer data collection in both the US and EU; this is before GDPR had become ratified, but Safe Harbor was failing and there was ambiguity about what the future state would look like.

Of the 15 or 20 business owners in the room, I was the only "pro privacy" voice. People were very focused on what would be the perceived additional cost of complying with any GDPR-style rules in the US, and weren't yet thinking about the negative effects of having different privacy rules in different markets. "Different markets have different rules all the time," in short.

I maintain that it would be less complicated, less expensive, and more human-friendly to use data privacy rules as globally universal as can be achieved. There will always be capitalism leeches that drain money through arbitrage between the policy gaps, yes, but it would help.

(Also: there is zero chance this gets through the current US Senate. Would never clear filibuster.)

Re: American Data Privacy and Protection Act

#3
I see they are also annoyed at cookie banners:

> SEC. 210. UNIFIED OPT-OUT MECHANISMS. For the rights established under sections 204(b) and (c), and section 206(c)(3)(D) not later than 18 months after the date of enactment of this Act, the Commission shall establish one or more acceptable privacy protective, centralized mechanisms, including global privacy signals such as browser or device privacy settings, for individuals to exercise all such rights through a single interface for a covered entity to utilize to allow an individual to make such opt out designations with respect to covered data related to such individual.

Re: American Data Privacy and Protection Act

#6
For those following along at home:

So far five states have passed local Data Privacy laws (CA, VA, UT, CT, MA). They are all different. This situation makes it much more likely that federal data privacy legislation will happen: while companies wish they could have 0 laws, they would still much rather prefer 1 law rather than 5 (trending towards 50) different laws that contradict each other.

There's a whole buncha specifics about what data is covered and what companies are covered and bleh blah bluh. That's not the most important thing. There are two things which are more important than that. These two issues also happen to be the topics most hotly debated between Dems & Repubs.

1. Private Right of Action, aka "Can I, a private citizen, sue someone?"

Everyone violates GDPR a dozen ways to Sunday, and nothing happens. Why? Because no one can actually enforce the law except for the local regulators who are underfunded. By contrast, the ADA lets anyone sue over violations, and as a result companies care a lot about handicap accessibility.

To my understanding the current negotiations are trending towards a limited Private Right of Action. Meaning it will exist for some violations but not others. This is how CCPA works in California right now: private citizens can sue over data breaches, but any other violation can only be enforced by the Office of the Attorney General.

2. Pre-emption, aka "Does this repeal CCPA."

Can states give additional protections to their residents, or is the Federal government removing the ability of states to define additional requirements for businesses. Again, the current state of negotiations seems to trend towards partial, but not total, pre-emption.

Re: American Data Privacy and Protection Act

#7
> (B) any time beyond the initial 2 times described in subparagraph (A), may allow the individual to exercise such right for a reasonable fee for each request.

Paying any sum of money to receive a copy of or request to delete my private data is unreasonable in nature.

Re: American Data Privacy and Protection Act

#10
post #6

For those following along at home: So far five states have passed local Data Privacy laws (CA, VA, UT, CT, MA). They are all different. This situation makes it much more likely that federal data privacy legislation will happen: while companies wish they could have 0 laws, they would still much rather prefer 1 law rather than 5 (trending towards 50) different laws that contradict each other. There's a whole buncha spe…

Partial preemption leads to supreme court decisions that lead to near total preemption.
Post reply on HN