{"id":17280,"date":"2019-12-23T10:10:17","date_gmt":"2019-12-23T18:10:17","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/12\/23\/news-11016\/"},"modified":"2019-12-23T10:10:17","modified_gmt":"2019-12-23T18:10:17","slug":"news-11016","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/12\/23\/news-11016\/","title":{"rendered":"Online privacy in 2019: a legislative review"},"content":{"rendered":"<p><strong>Credit to Author: David Ruiz| Date: Mon, 23 Dec 2019 17:41:31 +0000<\/strong><\/p>\n<p>For decades, the United States treated data privacy like an aging home, patching individual leaks and drafts only when a new storm hit. The country passed a law protecting healthcare-related information, and not much else. It then passed a law protecting video rental information, and not much else. It continued this way, repeatedly passing sector-specific laws while failing to address a problem that, in the past two years, became impossible to ignore. <\/p>\n<p>Data privacy, as protected by law, is broken. <\/p>\n<p>Americans enjoy no federal rights to access their data, correct their data, easily move their data from one company to another, or <a href=\"https:\/\/blog.malwarebytes.com\/security-world\/2019\/04\/consumers-have-few-legal-options-for-protecting-privacy\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">individually sue a company that invades their private lives online<\/a>. <\/p>\n<p>Harmed by the <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/09\/equifax-breach-what-you-need-to-know\/\" target=\"_blank\">Equifax breach<\/a>? Good luck getting <a href=\"https:\/\/www.theverge.com\/2019\/7\/26\/8932398\/equifax-settlement-125-claim-wont-get-money-alternative-reimbursement-compensation\">more than literal pennies in the settlement<\/a>. Shocked that a company shared <a href=\"https:\/\/mashable.com\/article\/flo-period-tracking-app-will-stop-sharing-data-with-facebook\/#1RhsPF1sgsq0\">menstrual tracking info with Facebook<\/a>? Oh, well. Want to fight back against invasive online trackers? <a href=\"https:\/\/www.nytimes.com\/2019\/11\/24\/smarter-living\/privacy-online-how-to-stop-advertiser-tracking-opt-out.html\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Your options are limited<\/a>. <\/p>\n<p>Since mid-2018, <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/security-world\/privacy-security-world\/2019\/03\/what-congress-means-when-it-talks-about-data-privacy-legislation\/\" target=\"_blank\">several US Senators have sought to fix these types of failures<\/a>, introducing at least nine bills\u2014with six introduced in 2019 alone\u2014to provide comprehensive data privacy protections to every American. <\/p>\n<p>With so many bills, what&#8217;s the hold up on getting them passed? <\/p>\n<p>For starters, installing comprehensive data privacy protections is long, complex work\u2014the European Union spent more than five years drafting its own data privacy law, the General Data Protection Regulation (GDPR), and even after the EU approved the law, another two years passed before it took effect. Further, you could say that <a href=\"https:\/\/www.washingtonpost.com\/politics\/trump-impeachment-live-updates\/2019\/12\/18\/237147e8-2110-11ea-bed5-880264cc91a9_story.html\">Congress is a little, um, busy<\/a> as of late. <\/p>\n<p>Finally, though every bill may focus on data privacy as an end goal, many disagree with how to get there. <\/p>\n<p>One data privacy bill simply aims to stamp out legalese-infused end-user agreements. Another data privacy bill seeks to grant similar protections as <a rel=\"noreferrer noopener\" aria-label=\"those afforded in GDPR (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/security-world\/2019\/02\/max-schrems-lawyer-regulator-international-man-of-privacy\/\" target=\"_blank\">those afforded in GDPR<\/a>, like the rights to access, correct, and delete personal data. One proposal tries to stop invasive online tracking and data-sharing practices. The same proposal argues that dishonest tech CEOs should be jailed. Still more bills offer ideas like data ownership, data valuation, and something called \u201cinteroperability,\u201d which, in a perfect world, would let individuals talk to their friends on Facebook without actually needing a Facebook account. <\/p>\n<p>In combing through the many federal and state data privacy bills that emerged this year, we found some similarities. Here is a look at the legislative trends in data privacy for 2019. <\/p>\n<h3><strong>Data as property<\/strong><\/h3>\n<p>In November, one Democratic presidential hopeful latched onto a data privacy idea that has been around for at least six years: Paying people for their data. <\/p>\n<p>If data is more valuable than oil, as the candidate said, then shouldn\u2019t the people who produce that data get paid for it? Shouldn\u2019t Americans be compensated for their most valuable asset in today\u2019s data-driven economy? <\/p>\n<p>This is the \u201cdata as property\u201d model, and supporters of it argue that, by giving individuals the right to their own data, they can then control how their data is collected, shared, and sold. No more surprise data-sharing between one company and another. No more GPS location data falling into the hands of <a href=\"https:\/\/www.vice.com\/en_us\/article\/43z3dn\/hundreds-bounty-hunters-att-tmobile-sprint-customer-location-data-years\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">literal bounty hunters<\/a>. (Unless, of course, that\u2019s what you want.) And, perhaps most importantly, no more companies making it rich without consumers getting at least a little cut of the profit. <\/p>\n<p>Under a \u201cdata as property model,\u201d supporters believe that every day consumers could receive steady, passive income by selling their data on their own terms. Not only that, but data could be sold repeatedly, as it potentially maintains its value even after being sold.  <\/p>\n<p>Earlier this year, US Senators Mark Warner of Virginia and Josh Hawley of Missouri <a href=\"https:\/\/www.warner.senate.gov\/public\/index.cfm\/2019\/6\/warner-hawley-introduce-bill-to-force-social-media-companies-to-disclose-how-they-are-monetizing-user-data\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">hinted at this possible future<\/a> with their bill, the Designing Accounting Safeguards to Help Broaden Oversight And Regulations on Data, or DASHBOARD, Act. <\/p>\n<p><a href=\"https:\/\/www.scribd.com\/document\/414097245\/Data-Value-Transparency-SIL19753\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">The DASHBOARD Act<\/a> would require certain companies to assess and disclose the <em>value<\/em> of users\u2019 data, while also extending data privacy rights to consumers to delete all, or certain fields, of collected data.<\/p>\n<p>But privacy advocates argue that putting a price tag on data\u2014a process that is neither science or art\u2014only normalizes the idea that our data <em>privacy<\/em> can be bought. Once that type of relationship is codified into law, the potential risks would disproportionately harm low-income, struggling communities, said Chad Marlow, senior advocacy and policy counsel at ACLU.<\/p>\n<p>\u201cIf you have parents who are struggling to put food on the table\u2014who are eating bread and drinking water for multiple dinners\u2014and you say \u2018I will give you money if you sell your data\u2019 and you don\u2019t even say how much, they will say yes immediately,\u201d Marlow said. \u201cBecause they cannot afford to say no.\u201d<\/p>\n<p>This is the \u201cpay-for-privacy\u201d problem. It showed up a few times this year. <\/p>\n<h3><strong>Pay-for-privacy <\/strong><\/h3>\n<p>In November 2018, Democratic Senator Ron Wyden introduced the \u201cConsumer Data Protection Act,\u201d a draft proposal that would have empowered American consumers to opt-out of having their data shared with multiple third parties. Unfortunately, according to the proposal, that decision could sometimes come with a price. <\/p>\n<p>As Malwarebytes Labs <a href=\"https:\/\/blog.malwarebytes.com\/security-world\/privacy-security-world\/2019\/02\/will-pay-privacy-new-normal\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">explained earlier this year<\/a>, this is how proposal would have worked:<\/p>\n<p>\u201cSay a user, Alice, no longer feels comfortable having companies collect, share, and sell her personal information to third parties for the purpose of targeted ads and increased corporate revenue. First, Alice would register with the Federal Trade Commission\u2019s \u2018Do Not Track\u2019 website, where she would choose to opt-out of online tracking. Then, online companies with which Alice interacts would be required to check Alice\u2019s \u2018Do Not Track\u2019 status.<\/p>\n<p>\u201cIf a company sees that Alice has opted out of online tracking, that company is barred from sharing her information with third parties and from following her online to build and sell a profile of her Internet activity. Companies that are run almost entirely on user data\u2014including Facebook, Amazon, Google, Uber, Fitbit, Spotify, and Tinder\u2014would need to heed users\u2019 individual decisions. However, those same companies could present Alice with a difficult choice: She can continue to use their services, free of online tracking, so long as she pays a price.<\/p>\n<p>\u201cThis represents a literal price for privacy.\u201d<\/p>\n<p>Nearly one year after Sen. Wyden introduced this draft proposal, he formally introduced the \u201c<a href=\"https:\/\/www.wyden.senate.gov\/imo\/media\/doc\/Mind%20Your%20Own%20Business%20Act%20of%202019%20Bill%20Text.pdf\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Mind Your Own Business Act<\/a>\u201d before the US Senate with many of the same ideas\u2014including the same pay-for-privacy scheme. <\/p>\n<p>The problems with pay-for-privacy schemes are the same with the \u201cdata as property\u201d model\u2014the individuals most able to assert their data privacy rights will be those who can literally afford it. If such models move forward, we risk creating a world of the \u201cprivacy-have\u201d and \u201chave-nots\u201d\u2014a mirrored image of the already visible socioeconomic striation in America. <\/p>\n<p>These concerns are not hypothetical. <\/p>\n<p>In 2015, <a href=\"https:\/\/www.techdirt.com\/articles\/20160329\/08514034038\/att-tries-to-claim-that-charging-users-more-privacy-is-discount.shtml\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">AT&amp;T offered a broadband service package<\/a> with a $30-a-month discount so long as users agreed to have their Internet activity tracked. That type of browsing activity, AT&amp;T said, included \u201cthe webpages you visit, the time you spend on each, the links and or ads you see and follow, and the search terms you enter.\u201d <\/p>\n<p>Privacy is a human right, and online privacy should be no exception. That means no commodity pricing, and no selling it to the highest bidder. <\/p>\n<p>Thankfully, at least one state this year passed a law that explicitly forbid pay-for-privacy schemes. <\/p>\n<p>Over the summer this year, the governor of Maine <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2019\/06\/maine-governor-signs-isp-privacy-bill\/\" target=\"_blank\">signed into law<\/a> a bill that <a href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2019\/06\/maine-inches-closer-to-shutting-down-isp-pay-for-privacy-schemes\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">prohibits Internet Service Providers from sharing and selling Maine residents\u2019 data without their explicit approval<\/a>. <\/p>\n<p>The law includes another protection that does not allow ISPs to \u201ccharge a customer a penalty or offer a customer a discount based on the customer\u2019s decision to provide or not provide consent\u201d to having their data sold, shared, or accessed by third parties. <\/p>\n<p>Score one for data privacy. <\/p>\n<h3><strong>Interoperability <\/strong><\/h3>\n<p>In late October, three US Senators introduced a bill that they believed would increase data privacy by doing something else\u2014increasing competition with Big Tech. <\/p>\n<p>The idea, the Senators argued, was simple: Empower American consumers to leave the platforms that invade their online privacy without losing access to their social networks, where their friends, family, and acquaintances may still reside. <\/p>\n<p>Under the proposal, Americans would enjoy the benefits of data portability\u2014which would enable consumers to pack up their data and take it to another platform\u2014and interoperability\u2014a feature that would potentially allow different chat services to interact with one another. Think of it like Facebook\u2019s massive integration plan announced earlier this year for its chat platforms Messenger, WhatsApp, and Instagram, but for nearly the entire Internet. <\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2019\/11\/access-act-might-improve-data-privacy-through-interoperability\/?_thumbnail_id=40968\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">As we wrote before about this bill<\/a>, called the ACCESS Act: <\/p>\n<p>\u201cThese rules\u2026 would presumably allow Americans to, for example, download all their data from Facebook and move it to privacy-focused social network&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/ello.co\/\" target=\"_blank\">Ello<\/a>. Or talk directly to Twitter users while using the San Francisco-based company\u2019s smaller, decentralized competitor,&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/joinmastodon.org\/\" target=\"_blank\">Mastodon<\/a>. Or even, perhaps, log into their Vimeo account to comment on YouTube videos.\u201d<\/p>\n<p>Responses to the bill were mixed. <\/p>\n<p>Avery Gardiner, senior fellow of competition, data, and power for the Center for Democracy and Technology, lamented the lack of competition facing Big Tech, but she said that data privacy for Americans should come in a data privacy bill, not a competition bill. <\/p>\n<p>Cory Doctorow, a writer, activist, and research affiliate with MIT Media Lab, welcomed the bill because, unlike other efforts in Congress, it did not focus strictly on single bad actors in Big Tech, like Facebook. <\/p>\n<p>\u201cThis aims to fix the Internet,\u201d Doctorow said, \u201cso that Facebook\u2019s behavior is no longer so standard.\u201d<\/p>\n<h3><strong>What\u2019s next for 2020? <\/strong><\/h3>\n<p>On January 1, 2020, California\u2019s own privacy law, the California Consumer Privacy Act, takes effect. Passed in 2018, the law has survived <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2019\/07\/changing-californias-privacy-law-a-snapshot-at-the-support-and-opposition\/\" target=\"_blank\">multiple, legislative attempts to weaken and defang it<\/a>, and it has inspired similar legislation in other states. <\/p>\n<p>With the law&#8217;s enormous scope, it will likely serve as a trial run for any federal data privacy bill. <\/p>\n<p>Will companies receive serious fines, or will enforcement be lax? What will the first enforcement action be? What company will it be against? If penalties are severe, at what point will companies bandy together to prevent similar legislation from passing at the federal level? <a href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2019\/09\/ceos-offer-their-own-view-of-a-us-data-privacy-law\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"Hint: They're already trying (opens in a new tab)\">Hint: They&#8217;re already trying<\/a>.<\/p>\n<p>None of this is to mention, of course, next year&#8217;s mindshare-absorbing presidential election, too. <\/p>\n<p>Until then\u2014and after it\u2014Malwarebytes Labs will closely watch this space. We can only predict it will get more interesting, more complex, and more important. <\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2019\/12\/online-privacy-in-2019-a-legislative-review\/\">Online privacy in 2019: a legislative review<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2019\/12\/online-privacy-in-2019-a-legislative-review\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: David Ruiz| Date: Mon, 23 Dec 2019 17:41:31 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/privacy-2\/2019\/12\/online-privacy-in-2019-a-legislative-review\/' title='Online privacy in 2019: a legislative review'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/Washington-DC-Capitol-building.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Americans enjoy no federal rights to access their data, correct their data, easily move their data from one company to another, or individually sue a company that invades their private lives online. Several US Senators want to change that. <\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/privacy-2\/\" rel=\"category tag\">Privacy<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/access-act\/\" rel=\"tag\">ACCESS Act<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/california-consumer-privacy-act\/\" rel=\"tag\">California Consumer Privacy Act<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/comprehensive-data-privacy-law\/\" rel=\"tag\">comprehensive data privacy law<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/comprehensive-data-privacy-legislation\/\" rel=\"tag\">comprehensive data privacy legislation<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/copra\/\" rel=\"tag\">COPRA<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/dashboard-act\/\" rel=\"tag\">Dashboard Act<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-as-property\/\" rel=\"tag\">data as property<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-as-property-rights\/\" rel=\"tag\">data as property rights<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-interoperability\/\" rel=\"tag\">data interoperability<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-portability\/\" rel=\"tag\">data portability<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-privacy\/\" rel=\"tag\">Data privacy<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-privacy-law\/\" rel=\"tag\">data privacy law<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-privacy-legislation\/\" rel=\"tag\">data privacy legislation<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/european-union\/\" rel=\"tag\">European Union<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/gdpr\/\" rel=\"tag\">gdpr<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/general-data-protection-regulation\/\" rel=\"tag\">General Data Protection Regulation<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/interoperability\/\" rel=\"tag\">interoperability<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/mind-your-own-business-act\/\" rel=\"tag\">Mind Your Own Business Act<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/online-privacy\/\" rel=\"tag\">online privacy<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/online-privacy-law\/\" rel=\"tag\">online privacy law<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/online-privacy-legislation\/\" rel=\"tag\">online privacy legislation<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/pay-for-privacy\/\" rel=\"tag\">pay-for-privacy<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/us-data-privacy-legislation\/\" rel=\"tag\">US data privacy legislation<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/privacy-2\/2019\/12\/online-privacy-in-2019-a-legislative-review\/' title='Online privacy in 2019: a legislative review'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2019\/12\/online-privacy-in-2019-a-legislative-review\/\">Online privacy in 2019: a legislative review<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[23364,21011,21395,21396,23781,23534,23535,23536,23366,23367,11063,21400,21401,3037,12116,12210,23369,23828,10470,22006,22007,21066,5897,22224],"class_list":["post-17280","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-access-act","tag-california-consumer-privacy-act","tag-comprehensive-data-privacy-law","tag-comprehensive-data-privacy-legislation","tag-copra","tag-dashboard-act","tag-data-as-property","tag-data-as-property-rights","tag-data-interoperability","tag-data-portability","tag-data-privacy","tag-data-privacy-law","tag-data-privacy-legislation","tag-european-union","tag-gdpr","tag-general-data-protection-regulation","tag-interoperability","tag-mind-your-own-business-act","tag-online-privacy","tag-online-privacy-law","tag-online-privacy-legislation","tag-pay-for-privacy","tag-privacy","tag-us-data-privacy-legislation"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17280","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17280"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17280\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17280"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17280"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17280"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}