{"id":17628,"date":"2020-02-04T09:10:03","date_gmt":"2020-02-04T17:10:03","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2020\/02\/04\/news-11363\/"},"modified":"2020-02-04T09:10:03","modified_gmt":"2020-02-04T17:10:03","slug":"news-11363","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2020\/02\/04\/news-11363\/","title":{"rendered":"Washington Privacy Act welcomed by corporate and nonprofit actors"},"content":{"rendered":"<p><strong>Credit to Author: David Ruiz| Date: Tue, 04 Feb 2020 16:35:25 +0000<\/strong><\/p>\n<p>The steady <a rel=\"noreferrer noopener\" aria-label=\"parade of US data privacy legislation (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2019\/12\/online-privacy-in-2019-a-legislative-review\/\" target=\"_blank\">parade of US data privacy legislation<\/a> continued last month in Washington with the introduction of an improved bill that would grant state residents the rights to access, control, delete, and port their data, as well as opting out of data sales. <\/p>\n<p>The bill, called the <a href=\"https:\/\/app.leg.wa.gov\/committeeschedules\/Home\/Document\/209620#toolbar=0&amp;navpanes=0\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Washington Privacy Act<\/a>, also improves upon its earlier 2019 version, providing stronger safeguards on the use of facial recognition technology. According to some analysts, when compared to its coastal neighbor\u2019s data privacy law\u2014the California Consumer Privacy Act, which went into effect this year\u2014the Washington Privacy Act excels. <\/p>\n<p>Future of Privacy Forum CEO Jules Polonetsky called the bill \u201cthe most comprehensive state privacy legislation proposed to date.\u201d <\/p>\n<p>\u201cIt includes provisions on data minimization, purpose limitations, privacy risk assessments, anti-discrimination requirements, and limits on automated profiling that other state laws do not,\u201d <a href=\"https:\/\/fpf.org\/2020\/01\/13\/statement-by-future-of-privacy-forum-ceo-jules-polonetsky-on-the-washington-privacy-act\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Polonetsky said<\/a>. <\/p>\n<p>Introduced on January 20 by state Senator Reuven Carlyle, the Washington Privacy Act would create new responsibilities for companies that handle consumer data, including the implementation of data protection processes and the development and posting of privacy policies. <\/p>\n<p>Already, the bill has gained warm reception from corporate and nonprofit actors. Washington-based tech giant <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2020\/01\/24\/washington-privacy-act-protection\/\" target=\"_blank\">Microsoft said it was encouraged<\/a>, and Consumer Reports <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/advocacy.consumerreports.org\/press_release\/consumer-reports-washington-state-data-privacy-bill-is-big-improvement-over-2019-bill-cr-urges-lawmakers-to-go-further-to-help-protect-consumers\/\" target=\"_blank\">welcomed the thrust of the bill, while urging for even more improvements<\/a>. <\/p>\n<p>\u201cThis new draft is definitely a step in the right direction toward protecting Washington residents\u2019 personal data,\u201d said Consumer Reports Director of Consumer Privacy and Technology Policy Justin Brookman. \u201cWe do hope to see further improvements to get rid of inadvertent loopholes that remain in the text.\u201d<\/p>\n<h3><strong>What the Washington Privacy Act would do<\/strong><\/h3>\n<p>Like the many US data privacy bills introduced in the past 18 months, the Washington Privacy Act approaches the problem of lacking data privacy with two prongs\u2014better rights for consumers, tighter restrictions for companies. <\/p>\n<p>On the consumer side, the Washington Privacy Act would grant several new rights to Washington residents, including the rights to access, correct, delete, and port their data. Further, consumers would receive the right to \u201copt out\u201d of having their personal data used in multiple, potentially invasive ways. Consumers could say no to having their data sold and to having their data used for \u201ctargeted advertising\u201d\u2014the somewhat inescapable practice that results in advertisements for a pair of shoes, a fetching sweater, or an 4K TV following users around from device to device.\u00a0 <\/p>\n<p>Consumers could exercise their rights with simple requests to the companies that handle their data. According to the bill, these requests would require a response within 45 days. If a company cannot meet that deadline, it can file for an extension, but it is required to notify the consumer about the extension and about why it could not meet the deadline. <\/p>\n<p>Further, unfulfilled requests are not a dead end for consumers\u2014companies must also offer an appeals process to the consumers whose requests they deny or do not fulfil. Requests must also be responded to free of charge, up to two times a year per consumer.<\/p>\n<p>Perhaps one of the most welcome provisions in the bill is its anti-discrimination rules. Companies cannot, the bill says, treat consumers differently because of their choices to exert their data privacy rights. On the surface, that makes dangerous ideas like \u201c<a href=\"https:\/\/blog.malwarebytes.com\/security-world\/privacy-security-world\/2019\/02\/will-pay-privacy-new-normal\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">pay-for-privacy\u201d schemes<\/a> much harder to enact. <\/p>\n<p>Concerning new business regulations, the Washington Privacy Act separates the types of companies it applies to into two categories: \u201ccontrollers\u201d and \u201cprocessors.\u201d The two terms, borrowed from the European Union\u2019s <a href=\"https:\/\/blog.malwarebytes.com\/security-world\/privacy-security-world\/2018\/05\/gdpr-causes-a-flood-of-new-policies\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"General Data Protection Regulation (GDPR) (opens in a new tab)\">General Data Protection Regulation (GDPR)<\/a>, have simple meanings. \u201cControllers\u201d are the types of entities that actually make the decisions about how consumer data is collected, shared, or used. So, a small business with just one employee who decides to sell data to third parties? That\u2019s a controller. A big company that decides to collect data to send targeted ads? That\u2019s a controller, too. <\/p>\n<p>Processors, on the other hand, are akin to contractors and subcontractors that perform services for controllers. So, a payment processor that simply processes e-commerce transactions and nothing more? That\u2019s a processor. <\/p>\n<p>The Washington Privacy Act\u2019s new rules focus predominantly on \u201ccontrollers\u201d\u2014the Facebooks, Amazons, Twitters, Googles, Airbnbs, and Oracles of the world. <\/p>\n<p>Controllers would have to post privacy policies that are \u201creasonably accessible, clear, and meaningful,\u201d and would include the following information: <\/p>\n<ul>\n<li>The categories of personal data processed by the controller<\/li>\n<li>The purposes for which the categories of personal data are processed<\/li>\n<li>How and where consumers may exercise their rights <\/li>\n<li>The categories of third parties, if any, with whom the controller shares personal data<\/li>\n<\/ul>\n<p>If controllers sell personal data to third parties, or process it for targeted advertising, the bill requires those controllers to clearly disclose that activity, along with instructions about how consumers can opt out of those activities. <\/p>\n<p>Separately, controllers would need to perform \u201cdata protection assessments,\u201d in which the company looks at, documents, and considers the risks of any personal data processing that involves targeted advertising, sale, and \u201cprofiling.\u201d <\/p>\n<p>The regulation of \u201cprofiling\u201d is new to data privacy bills. It\u2019s admirable. <\/p>\n<p>According to the bill, \u201cprofiling\u201d is any form of automated processing of personal data to \u201cevaluate, analyze, or predict personal aspects concerning an identified or identifiable person\u2019s economic situation, health, personal preference, interests, reliability, behavior, location, or movements.\u201d <\/p>\n<p>In today\u2019s increasingly invasive online advertising economy, profiling is omnipresent. Companies collect data and create \u201cprofiles\u201d of consumers that, yes, may not include an exact name, but still include what are considered vital predictors about that consumer\u2019s lifestyle and behavior.&nbsp; <\/p>\n<p>These new regulations make the Washington Privacy Act stand out amongst its contemporaries, said Stacey Gray, senior counsel with Future of Privacy Forum. <\/p>\n<p>\u201cThe big picture of the bill is that includes the same individual rights as the California Consumer Privacy Act\u2014of access, sale, et cetera\u2014and then more,\u201d Gray said. \u201cThe right to correct your data, to opt out of targeted advertising, and out of profiling\u2014that is further on the individual rights side.\u201d <\/p>\n<p>Gray added that the bill\u2019s business obligations also go further than those in the CCPA, naming the data risk assessments previously discussed. <\/p>\n<p>The Washington Privacy Act includes several more business obligations, all of which add up to meaningful data protections for consumers. For instance, companies would need to commit to data minimization principles, only collecting consumers\u2019 personal data that is necessary for expressed purposes. Companies would also need to obtain affirmative, opt-in consent from consumers before processing any \u201csensitive data,\u201d which is any data that could reveal race, ethnicity, religion, mental or physical health conditions or diagnoses, sexual orientations, or citizenship and immigration statuses. <\/p>\n<p>But perhaps most intriguing in the Washington Privacy Act is its regulation of facial recognition technology. <\/p>\n<h3><strong>Facial recognition provisions<\/strong><\/h3>\n<p>In 2019, Washington state lawmakers crafted a bill aimed at improving the data privacy protections of consumers. They called it\u2026 the Washington Privacy Act. <a href=\"http:\/\/lawfilesext.leg.wa.gov\/biennium\/2019-20\/Pdf\/Bills\/Senate%20Bills\/5376.pdf?q=20200131145031\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">That original bill<\/a>, which has now been substituted the 2020 version, included provisions on the commercial use of facial recognition. <\/p>\n<p>On its face, the new rules looked good: Companies that used facial recognition tech for commercial purposes would have to obtain consent from consumers \u201cprior to deploying facial recognition services.\u201d<\/p>\n<p>Unfortunately, the original bill\u2019s very next sentence made that consent almost meaningless. <\/p>\n<p>According to that bill, consumer \u201cconsent\u201d could be obtained not by actually asking the consumer about whether they agreed to having their facial data recorded, but instead, by posting a sign on a company\u2019s premises. <\/p>\n<p>As the bill stated: <\/p>\n<p>\u201cThe placement of conspicuous notice in physical premises or online that clearly conveys that facial recognition services are being used constitute a consumer&#8217;s consent to the use of such facial recognition services when that consumer enters those premises or proceeds to use the online services that have such notice, provided that there is a means by which the consumer may exercise choice as to facial recognition services.\u201d<\/p>\n<p>The length of the explainer is as broad as the exception it allows. <\/p>\n<p>This loophole upset several privacy rights advocates who, in February 2019, sent a letter to key Washington lawmakers.<\/p>\n<p>\u201c[W]hile the bill purportedly requires consumer consent to the use of facial recognition technology, it actually allows companies to substitute notification for seeking consent\u2014leaving consumers without a real opportunity to exercise choice or control,\u201d <a href=\"https:\/\/advocacy.consumerreports.org\/wp-content\/uploads\/2019\/02\/SB-5376-Privacy-Coalition-Letter-Oppose.pdf\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">the letter said<\/a>. It was signed by Consumer Reports, Common Sense, Electronic Frontier Foundation, and Privacy Rights Clearinghouse. <\/p>\n<p>The 2020 bill closes this loophole, instead requiring affirmative, opt-in consent for commercial facial recognition use, along with mandatory notifications\u2014such as signs\u2014in spaces that use facial recognition technology. The new bill also requires processors to open up their data-processing tools to outside investigation and testing, in an effort to root out what the bill calls \u201cunfair performance differences across distinct subpopulations,\u201d such as minorities, disabled individuals, and the elderly. <\/p>\n<h3><strong>Moving the Washington Privacy Act forward<\/strong><\/h3>\n<p>Despite the 2019 Washington Privacy Act gaining swift approval in the Senate two months after its January introduction, the bill ultimately failed to reach the House. Multiple factors led to the bill\u2019s failure, including the bill\u2019s definitions for certain terms, its approach to enforcement, and its treatment of facial recognition. <\/p>\n<p>Some of those same obstacles could come up for the 2020 bill, Gray said. <\/p>\n<p>\u201cIf this bill does not pass this year, that\u2019s where we might see a source of conflict\u2014is either with the facial recognition provisions, or with enforcement,\u201d Gray said. For enforcement to take hold, Gray said the Attorney General&#8217;s office\u2014tasked with regulation\u2014will need increased funding and staffing. Further, there will likely be opposition to the bill\u2019s lack of \u201cprivate right of action,\u201d which means that consumers will not be able to individually file lawsuits against companies that they allege violated the law. <a rel=\"noreferrer noopener\" aria-label=\"This issue has been a sticking point for data privacy legislation for years (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2019\/07\/what-should-a-us-federal-data-privacy-law-ideally-include\/\" target=\"_blank\">This issue has been a sticking point for data privacy legislation for years<\/a>. <\/p>\n<p>Still, Gray said, the bill shows improvement from its 2019 version, which could help push it forward. <\/p>\n<p>\u201cAll things aside,\u201d Gray said, \u201cwe\u2019re more optimistic than last year about it passing.\u201d <\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2020\/02\/washington-privacy-act-welcomed-by-corporate-and-nonprofit-actors\/\">Washington Privacy Act welcomed by corporate and nonprofit actors<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2020\/02\/washington-privacy-act-welcomed-by-corporate-and-nonprofit-actors\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: David Ruiz| Date: Tue, 04 Feb 2020 16:35:25 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/privacy-2\/2020\/02\/washington-privacy-act-welcomed-by-corporate-and-nonprofit-actors\/' title='Washington Privacy Act welcomed by corporate and nonprofit actors'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/Washington-State-Capitol-Building-in-Olympia-scaled.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>The Washington Privacy Act would extend new data rights of access, correction, and deletion to Washington residents, with new rules on facial recognition.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/privacy-2\/\" rel=\"category tag\">Privacy<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/2019-washington-privacy-act\/\" rel=\"tag\">2019 Washington Privacy Act<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/2020-washington-privacy-act\/\" rel=\"tag\">2020 Washington Privacy Act<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/california-consumer-privacy-act\/\" rel=\"tag\">California Consumer Privacy Act<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/ccpa\/\" rel=\"tag\">CCPA<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/consumer-reports\/\" rel=\"tag\">Consumer Reports<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-portability\/\" rel=\"tag\">data portability<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-privacy-law\/\" rel=\"tag\">data privacy law<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-privacy-laws\/\" rel=\"tag\">data privacy laws<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-privacy-legislation\/\" rel=\"tag\">data privacy legislation<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/facial-recognition\/\" rel=\"tag\">facial recognition<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/future-of-privacy-forum\/\" rel=\"tag\">Future of Privacy Forum<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/gdpr\/\" rel=\"tag\">gdpr<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/general-data-protection-regulation\/\" rel=\"tag\">General Data Protection Regulation<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/microsoft\/\" rel=\"tag\">microsoft<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/personal-data\/\" rel=\"tag\">personal data<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/right-to-access\/\" rel=\"tag\">right to access<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/right-to-correct\/\" rel=\"tag\">right to correct<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/right-to-delete\/\" rel=\"tag\">right to delete<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/senator-reuven-carlyle\/\" rel=\"tag\">Senator Reuven Carlyle<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/sensitive-data\/\" rel=\"tag\">sensitive data<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/washington-privacy-act\/\" rel=\"tag\">Washington Privacy Act<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/washington-privacy-act-2019\/\" rel=\"tag\">Washington Privacy Act 2019<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/washington-privacy-act-2020\/\" rel=\"tag\">Washington Privacy Act 2020<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/wpa\/\" rel=\"tag\">WPA<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/privacy-2\/2020\/02\/washington-privacy-act-welcomed-by-corporate-and-nonprofit-actors\/' title='Washington Privacy Act welcomed by corporate and nonprofit actors'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2020\/02\/washington-privacy-act-welcomed-by-corporate-and-nonprofit-actors\/\">Washington Privacy Act welcomed by corporate and nonprofit actors<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[24120,24121,21011,22462,15436,23367,21400,21178,21401,14753,24122,12116,12210,10516,14563,5897,22222,23787,23789,24123,24124,24125,24126,24127,15795],"class_list":["post-17628","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-2019-washington-privacy-act","tag-2020-washington-privacy-act","tag-california-consumer-privacy-act","tag-ccpa","tag-consumer-reports","tag-data-portability","tag-data-privacy-law","tag-data-privacy-laws","tag-data-privacy-legislation","tag-facial-recognition","tag-future-of-privacy-forum","tag-gdpr","tag-general-data-protection-regulation","tag-microsoft","tag-personal-data","tag-privacy","tag-right-to-access","tag-right-to-correct","tag-right-to-delete","tag-senator-reuven-carlyle","tag-sensitive-data","tag-washington-privacy-act","tag-washington-privacy-act-2019","tag-washington-privacy-act-2020","tag-wpa"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17628","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17628"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17628\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17628"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17628"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17628"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}