Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Privacy & Compliance

Key Lawmakers Float New Rules for Personal Data Protection; Bill Would Make Privacy a Consumer Right

The American Privacy Rights Act would preempt most state privacy laws — though it wouldn’t impact certain states’ laws already on the books that protect financial, health or employee data.

Two influential lawmakers from opposing parties have crafted a deal on legislation designed to strengthen privacy protections for Americans’ personal data.

The sweeping proposal announced Sunday evening would define privacy as a consumer right and create new rules for companies that collect and use personal information. It comes from the offices of Democratic Sen. Maria Cantwell and Republican Rep. Cathy McMorris Rodgers, both of Washington state.

Cantwell chairs the Senate Commerce Committee while McMorris Rodgers leads the House Energy and Commerce Committee. While the proposal has not been formally introduced and remains in draft form, the bipartisan support suggests the bill could get serious consideration.

Congress has long discussed ways to protect the personal data regularly submitted by Americans to a wide range of businesses and services. But partisan disputes over the details have doomed previous proposals.

According to a one-page outline released Sunday, the bill worked out by McMorris Rodgers and Cantwell would strengthen rules requiring consumer consent before a company can collect or transfer certain kinds of information. Companies would have to notify consumers about the details of data collection and retention policies and seek consumer permission for significant changes.

In addition, companies would have to ensure that any algorithms used to analyze personal data aren’t biased, and companies that buy and sell personal data would have to register with the Federal Trade Commission.

Consumers would also have greater control over how their data is used under the measure. One provision of the proposal would allow consumers to opt out of targeted ads — i.e., advertisements sent to them based on their personal data.

A new bureau focused on data privacy would be created within the FTC, which would have the authority to enact new rules as technology changes. Enforcement of the law would fall to the FTC as well as state attorneys general.

Advertisement. Scroll to continue reading.

If passed, the new standard would preempt most state privacy laws — though it wouldn’t impact certain states’ laws already on the books that protect financial, health or employee data.

Written By

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Cybersecurity Funding

Los Gatos, Calif-based data protection and privacy firm Titaniam has raised $6 million seed funding from Refinery Ventures, with participation from Fusion Fund, Shasta...

Privacy

Employees of Chinese tech giant ByteDance improperly accessed data from social media platform TikTok to track journalists in a bid to identify the source...

Privacy

Many in the United States see TikTok, the highly popular video-sharing app owned by Beijing-based ByteDance, as a threat to national security.The following is...

Mobile & Wireless

As smartphone manufacturers are improving the ear speakers in their devices, it can become easier for malicious actors to leverage a particular side-channel for...

Cloud Security

AWS has announced that server-side encryption (SSE-S3) is now enabled by default for all Simple Storage Service (S3) buckets.

Audits

The PCI Security Standards Council (SSC), the organization that oversees the Payment Card Industry Data Security Standard (PCI DSS), this week announced the release...

Application Security

Security researchers at Google’s Project Zero have picked apart one of the most notorious in-the-wild iPhone exploits and found a never-before-seen hacking roadmap that...