American Data Privacy And Protection Act
   HOME

TheInfoList



OR:

The American Data Privacy and Protection Act (ADPPA) was a United States proposed federal online privacy
bill Bill(s) may refer to: Common meanings * Banknote, paper cash (especially in the United States) * Bill (law), a proposed law put before a legislature * Invoice, commercial document issued by a seller to a buyer * Bill, a bird or animal's beak Plac ...
that, if enacted into law, would have regulated how organizations keep and use consumer data. The bipartisan, bicameral bill was the first American consumer privacy bill to pass committee markup, which it did with near unanimity.


Contents

The American Data Privacy and Protection Act (ADPPA) aimed to regulate how organizations keep and use consumer data. The Act had several main principles: data minimization, individual ownership, and private right of action. The burden of evaluating each organization's programs would fall to the organization. Data collectors would have had to minimize the data they collected down to that which was "necessary, proportionate, and limited to" their purpose, whether administering a product or communicating. The bill would have given the
Federal Trade Commission The Federal Trade Commission (FTC) is an independent agency of the United States government whose principal mission is the enforcement of civil (non-criminal) antitrust law and the promotion of consumer protection. The FTC shares jurisdiction ov ...
a year to define those terms. Data minimization is a common principle among other privacy laws, but the ADPPA would have affected business functions beyond compliance operations. ADPPA would also have specifically limited transfer and some processing of
Social Security number In the United States, a Social Security number (SSN) is a nine-digit number issued to U.S. citizens, permanent residents, and temporary (working) residents under section 205(c)(2) of the Social Security Act, codified as . The number is issued to ...
s, precise geolocation, biometric and genetic data, passwords, browsing history, and physical activity tracking. Individuals would have had the right under ADPPA to know how their personal data was to be used and which third parties would have received it. They would have had the right to correct and download their user data. Organizations would have had up to 90 days to process these requests, depending on the organization's size. Individuals would also have had the right to take legal action against organizations in violation of the Act for four years after its execution after first giving their state Attorney General and Federal Trade Commission 60 days' notice to respond. Designated "large data holders"—with adjusted gross revenue over $250 million in the last calendar year and processing either five million personal records or 100,000 sensitive individual records—would have been subject to additional controls. These organizations would have been required to designate a corporate officer for administering data policy, training employees, keeping records, and communicating with the government. Large data holders' highest ranking corporate officers and data security officers would have had to certify reasonable compliance with the Federal Trade Commission. Large data holders would have needed to provide a privacy impact assessment of their controls and risk to users every two years. "Small data holders", on the other hand, would have been exempt from some requirements. Defined as organizations with adjusted gross revenue below $41 million over the past three calendar years, that process data for fewer than 100,000 individuals annually, and whose business does not primarily rely on transferring data, small data holders could delete records rather than processing corrective requests and would be exempt from many requirements apart from the user right to delete data no longer in use. Third-party data collectors, whose primary business revenue comes from user data collected for another platform's use, would also have been subject to specific rules, such as displaying a notice about data collected on behalf of another organization, allowing for data audits, and populating a registry for such data collectors. As the first federal user data privacy legislation, ADPPA would have largely superseded state laws like the California Consumer Privacy Act and Colorado Privacy Act, though carve-out state provisions about
biometric data Biometrics are body measurements and calculations related to human characteristics. Biometric authentication (or realistic authentication) is used in computer science as a form of identification and access control. It is also used to identify in ...
and data breaches would be protected. The federal bill would have include nonprofit organizations (whereas many state privacy laws do not), though nonprofits would largely fall under the "small data holder" exemptions.


History

There is no federal law governing online privacy in the United States. In July 2022, the American Data Privacy and Protection Act (ADPPA) became the first federal online privacy bill to pass committee, the House Energy and Commerce Committee, and did so with near unanimity. Sponsored by the committee chair Frank Pallone, the bicameral bill had bipartisan support and had included bipartisan concessions that had restricted prior attempts at a bipartisan privacy bill. The bill was additionally led by House Representative
Cathy McMorris Rodgers Cathy Anne McMorris Rodgers (born May 22, 1969) is an American politician who is the U.S. representative for , which encompasses the eastern third of the state and includes Spokane, the state's second-largest city. A Republican, McMorris Rodgers ...
and, in the other legislative chamber, Senator Roger Wicker. While
Consumer Reports Consumer Reports (CR), formerly Consumers Union (CU), is an American nonprofit consumer organization dedicated to independent product testing, investigative journalism, consumer-oriented research, public education, and consumer advocacy. Founded ...
and the Electronic Privacy Information Center both showed optimism towards the bill, several Democratic senators opposed the bill because it might nullify stronger protection from several state laws. Though the bill had bipartisan support as it advanced to the House floor, it faced opposition from California lawmakers, the chair of the Senate Commerce Committee Maria Cantwell, and
big tech Big Tech, also known as the Tech Giants, refers to the most dominant companies in the information technology industry, mostly located in the United States. The term also refers to the four or five largest American tech companies, called the Big ...
companies. As the chair of the Senate committee responsible for data privacy, Maria Cantwell was the gatekeeper for any such bill to reach the senate floor. Cantwell, who had her own online privacy bill in draft, had similarly declined another bipartisan online privacy bill proposed by Senators Richard Blumenthal and Marsha Blackburn earlier in the year. Her primary concern for ADPPA was its enforcement provisions. Cantwell's own draft bill had been grappling with a provision that would restrict consumers from creating class-action lawsuits against companies that had harmed them. The 2022 overruling of ''Roe v. Wade'' led to increased interest in a federal privacy bill, with concern over how unmitigated tracking by data brokers and app developers, such as user visits to abortion clinics or period app usage, could be used to target users in states where abortion is criminalized. ADPPA would have protected health privacy and not directly address ''Roe''. Internet safety and missing persons advocate Alicia Kozakiewicz—herself a victim of an Internet abduction in 2002—expressed concern about the ADPPA's effect on law enforcement efforts to quickly investigate and solve child abduction cases. Although she supported the majority of the provisions in the bill, Kozakiewicz worried that "If the current version of the American Data Privacy and Protection Act had been in place when hewas held captive, it may have been nearly impossible for law enforcement to find erand identify ercaptor as quickly as it did, if at all." Other privacy-related bills during ADPPA's advancement included Elizabeth Warren's Health and Location Data Protection Act,
Suzan DelBene Suzan Kay DelBene (née Oliver; ; born February 17, 1962) is an American politician and businesswoman who has been the United States House of Representatives, United States representative from Washington's 1st congressional district since 2012. ...
's Information Transparency and Personal Data Control Act, and
Sara Jacobs Sara Josephine Jacobs (born February 1, 1989) is an American politician serving as the United States House of Representatives, U.S. representative for . Her district includes central and eastern portions of San Diego, California, San Diego, as we ...
's My Body, My Data Act. In the absence of federal legislation, state laws have included California's Consumer Privacy Act and Privacy Rights Acts, Illinois's Biometric Information Privacy Act, and Vermont's Data Broker Act. Action on the ADPPA had not been completed prior to the adjournment of the 117th Congress on January 3, 2023.


See also

* State privacy laws of the United States * American Privacy Rights Act


References


Further reading

* * * * * * * * * * * * {{Portal bar, United States, Internet, Law Proposed legislation of the 117th United States Congress Privacy law in the United States United States federal privacy legislation Open digital policy proposals