Privacy Insider Newsletter | Data Privacy News Delivered Weekly

Should the U.S. Aim for a Data Privacy Ceiling or Floor?

Written by Arlo Gilbert | Jun 27, 2024 1:00:00 PM

Hello all, and happy Thursday! 

The American Privacy Rights Act (APRA) continues its slow but steady pace through the U.S. legislative process—but the Electronic Frontiers Foundation (EFF) has officially come out to oppose the bill. 

The grounds for their opposition won’t surprise anyone who followed the American Data Privacy Protection Act (ADPPA). As was the case with the ADPPA, APRA’s fatal flaw lies in preemption. 

Having learned from the ADPPA, the APRA does include some language that would allow certain features from other laws to take precedence when applicable, such as the CCPA’s requirements around employee data. However, in their statement, the EFF lists several laws that would be rendered effectively moot should the APRA become law, including laws protecting AI regulation in Colorado, internet privacy in Maine, healthcare and tenant privacy in New York, and biometric privacy in Illinois. 

Most businesses would obviously prefer a federal law that sets a ceiling: that way, they know with absolute certainty what the strictest requirements are that they’ll have to meet regardless of where they operate. But organizations like the EFF or ACLU that focus more on consumer protections prefer a federal law that sets a floor: that way, consumers know with absolute certainty that they have certain rights at minimum. 

With more and more state data privacy laws, it’s getting harder to picture a world where there’s enough political will and motivation to compromise on this issue. Ultimately, the APRA’s fate might boil down to whether the U.S. can best tolerate a data privacy ceiling or floor. 

Best, 

Arlo 


Top Privacy Stories of the Week

Apple Shelved the Idea of Integrating Meta’s AI Models Over Privacy Concerns, Report Says 

Apple briefly held talks with Meta about the possibility of integrating Meta’s AI models back in March. However, the company has shelved the idea of putting Meta’s AI models on iPhones over privacy concerns. Instead, Apple released its own suite of AI features earlier this month under the Apple Intelligence brand. Plus, it announced a partnership with OpenAI to let iPhone users invoke ChatGPT for certain queries. 

Read more 

Dutch Cops Could Use Commercial DNA Databases in Criminal Cases Despite Privacy Concerns 

The new Dutch government wants to allow the police to use commercial DNA databases in cold case criminal investigations. Though such a proposal could help solve unsolved crimes, legal experts have raised privacy concerns. 

Read more 

U.S. House Committee to Hold Markup Session on Draft Legislation, Including APRA 

Today (June 27th), the U.S. House Committee will mark up 11 proposed bills, notably including the American Privacy Rights Act (APRA) as well as the Kids Online Safety Act. It is widely believed that the APRA will need to go through multiple changes if it is to be enacted into law. 

Read more 

EFF Opposes the American Privacy Rights Act 

The Electronic Frontiers Foundation (EFF) has come out in opposition to the APRA, stating that “federal privacy laws should not roll back state privacy protections. And there is no reason that we must trade strong state laws for weaker national privacy protection.” The EFF has also released a statement indicating that it informed Congress of its opposition and signed two letters to reiterate why overriding stronger state laws and preventing states from passing stronger laws was a dangerous practice. 

Read more 

Apple Becomes First Company to Be Charged With Violating EU's DMA Rules 

European Union (EU) regulators on Monday opened a new investigation into Apple's support for alternative iOS marketplaces in Europe under the Digital Markets Act (DMA), adding that the App Store's "steering" policies violate the DMA meant to encourage competition. 
Read more 

Osano Blog: What Makes the Maryland Online Data Privacy Act (MODPA) Different? 

Most U.S. privacy laws have centered around a few common requirements—but Maryland has bucked the trend. Find out what’s unique about the MODPA and how you can comply here. 

Read more 

If you’re interested in working at Osano, check out our Careers page