Antitrust Law Daily Wrap Up, PRIVACY NEWS: House data privacy working group seeks public input, (Feb 25, 2025)
Organizations Mentioned:Federal Trade Commission
By Lynn Stanton, TR Daily
The all-Republican group asks for input to inform comprehensive data privacy legislation.
House Energy and Commerce Committee Chairman Brett Guthrie (R., Ky.) and Vice Chairman John Joyce (R., Pa.) are seeking public comment to inform the work of the committee’s recently established all-Republican data privacy working group to develop comprehensive data privacy legislation.
Rep. Joyce is leading the working group.
The request for information (RFI) released by the leadership asks about the appropriate obligations for different entities, such as controllers, processors, and third parties, and whether a comprehensive data privacy and security law should “take into consideration an entity’s size, and any accompanying protections, exclusions, or obligations.”
It seeks input on the definitions of personal information and sensitive personal information to be incorporated into the law, as well as consumer protections and heightened protections for sensitive personal information. “What disclosures should consumers be provided with regard to the collection, processing, and transfer of their personal information and sensitive personal information?” it asks.
The RFI asks for insights derived from existing comprehensive data privacy and security laws adopted by U.S. trading partners and individual U.S. states. It asks stakeholders to “describe the degree to which U.S. privacy protections are fragmented at the state-level and the costs associated with fragmentation, including uneven rights for consumers and costs to businesses and innovators” and for their views on “the appropriate degree of preemption that a federal comprehensive data privacy and security law should adopt.”
It also asks how a federal comprehensive privacy law should “account for existing federal and state sectoral laws,” such as the Health Insurance Portability and Accountability Act, Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, and the Children’s Online Privacy Protection Act.
The RFI asks how the law could “improve data security for consumers” and what data security requirements should be placed on regulated entities.
Regarding artificial intelligence (AI), the RFI asks how a federal comprehensive data privacy and security law should “account for state-level AI frameworks, including requirements related to automated decision-making.”
It asks about “the benefits and costs of expert agencies retaining sole authority to enforce a federal comprehensive data privacy and security law”; “[w]hat expertise, legal authorities, and resources are available—or should be made available—to the Federal Trade Commission and state Attorneys General for enforcing such a law”; and how a safe harbor might be “beneficial or harmful in promoting compliance with obligations related to data privacy and security.”
“Stakeholders should submit their responses to PrivacyWorkingGroup@mail.house.gov no later than April 7, 2025. We request that written responses be no longer than 3,500 words and be provided as a Word document and a PDF. Supplemental data, reports, and case studies are also welcome,” the RFI says.
News: Privacy AINews FederalTradeCommissionNews