House seal

House · Hearing transcript

Examining Legislation to Establish a Federal Comprehensive Privacy and Data Security Law

Wednesday, June 3, 2026

Summary

  • Rep. Bilirakis touted the Secure Data Act as a uniform national privacy standard protecting consumers while giving businesses regulatory certainty nationwide.
  • Caitriona Fitzgerald (Deputy Director and Policy Director, EPIC) condemned the Secure Data Act as weaker than state laws with unenforceable rights and expansive preemption.
  • Rep. Pallone pressed Fitzgerald on data minimization, enforcement, surveillance pricing, and preemption, and she called the bill data maximization without recourse.
  • Rep. Guthrie praised the Kentucky-modeled bill for balancing innovation and protection while Rep. Castor condemned it as betraying Americans and gutting kids’ safeguards.
  • Small businesses face costly state patchwork compliance, and supporters urged advancing the Secure Data Act to provide one clear federal privacy rule.

Morning digest

Get hearings like this in your inbox

Free weekday email. Unsubscribe anytime.

Hearing Details

Witnesses

Members Who Spoke

View on Congress.gov

Transcript

Rep. Bilirakis (FL-12)13:54 – 13:54

can we get a

Rep. Obernolte (CA-23)13:54 – 13:55

still good

Rep. Bilirakis (FL-12)14:34 – 16:55

Good morning. The chairman recognizes himself for five minutes for an opening statement. Good morning, and welcome to today's legislative hearing on federal comprehensive privacy reform. After years of debate, I'm pleased to see us return to the critical issue and discuss the secure data act. Legislation, I believe, will establish a national standard that protects American consumers and provides much needed certainty to businesses across the country. Whether it's your favorite restaurant, your hometown newspaper, or the corner gas station, Every business, no matter the size, uses digital technology these days. These innovations bring enormous benefits to everyday Americans and help ensure that our country remains dynamic and competitive in an increasingly digital world. But today, when Americans ask if their personal data is protected, the answer depends entirely uh on which state they're in. Unfortunately, for the millions of Americans that live in states without a comprehensive privacy law the answer is no. This is unacceptable as far as I'm concerned, not only for consumers but for the small and mainstream businesses navigating confusing patchwork of state mandates. The Secure Data Act takes the best ideas of the state privacy laws and incorporates many of the ideas developed over the past several years. It seeks to establish meaningful consumer protections while creating a uniform national standard that promotes innovation, economic growth, and regulatory certainty. I would like to thank Doctor Joyce for leading the committee's privacy working group and all the working group members and their staff for their efforts today. This group, I think Doctor Joyce did an outstanding job, personally. This group was tasked with finding consensus on a difficult subject while balancing consumer protections with business certainty.

Rep. Pallone (NJ-6)16:53 – 16:55

Oh, I can't. I just can't.

Rep. Bilirakis (FL-12)16:55 – 17:38

Their work has laid an important foundation for today's discussion. I look forward to working with you, our colleagues across the aisle, and the stakeholders so that we work to advance the strong the strongest bill possible. So I wanna thank everyone here on the panel, and I will yield back the balance of my time. And I'll uh recognize the ranking member, Miss Schakowsky, for her five minutes for an opening statement. Thank you. You know,

Rep. Schakowsky (IL-9)17:42 – 18:09

Until now, Democrats and Republicans have worked together, um, and on privacy and these important issues. But right now, Democrats have really not been included, which is very distressing to to to me. um but uh the

Rep. Mullin (CA-15)18:10 – 18:12

corporations over consumers

Rep. Schakowsky (IL-9)18:13 – 18:25

yeah corporations cannot be over consumers right now and um the

Rep. Mullin (CA-15)18:28 – 18:29

you're too back more

Rep. Schakowsky (IL-9)18:29 – 18:29

hmm

Rep. Mullin (CA-15)18:30 – 18:31

you're too back more

Rep. Schakowsky (IL-9)18:32 – 18:38

so i wanna i'm gonna yield right now to rep Malam for his comments.

Rep. Mullin (CA-15)18:42 – 20:28

Thank you, ranking member Schakowsky. Americans overwhelmingly feel powerless over how their information is collected, used and shared. And the evidence suggests they have good reason to feel this way. Information on whether someone has been to an abortion clinic, or search for information about addiction treatment can be easily bought and sold. Cars are transmitting driver location data to insurers. Gig work platforms are using nurses' personal financial data to set individualized pay, offering lower wages to those who appear most in need of work. Foreign adversaries have legally purchased location data that can be used to track active duty US service members. We know how to address these problems. My home state of California, enacted the nation's first comprehensive consumer privacy law in twenty eighteen and has continued to strengthen those protections, giving consumers greater transparency and control over how their personal information uh is collected, used and shared. And in recent congresses, this committee has also proposed strong bipartisan privacy legislation. Unfortunately, this secure data act is not that. The legislation before us today moves in the opposite direction. It protects companies that profit from personal data, places the burden on consumers to fight for control over their own information, and undermines stronger state-level protections already in place. So I urge my Republican colleagues to work in a bipartisan basis on meaningful privacy protections that put consumers in control of their personal information and with that, I yield back to the ranking member.

Rep. Bilirakis (FL-12)20:31 – 20:32

Does the ranking member yield back?

Rep. Schakowsky (IL-9)20:33 – 20:35

Well, and I yield back.

Rep. Bilirakis (FL-12)20:35 – 20:43

Okay, thank you very much. Now uh I'll recognize the Chairman of the full committee, Mister Guthrie, for his five minutes for an opening statement.

Rep. Guthrie (KY-2)20:43 – 21:49

Thank you very much. I want to thank my good friend. Uh, thank you, Chairman, for having us. My good friend Ashley Watts, CEO of the Kentucky Chamber of Commerce, for being here. And this can be a bipartisan bill. Matter of fact, the model of this bill is what happened in our Commonwealth. where we have a uh very prominent Democrat governor and a super majority Republican legislature that put a bill together that's very similar to what we're doing that does protect individuals and also ensures that we can still be competitive in the world we're not competing with Europe to regulate, we're competing with with China to innovate. We have to innovate and also protect uh protect individuals' data. So it's a crucial time and I'm glad that we're here. I believe the Secure Dat- Secure Data Act does. protect individuals' data and allows us to flourish and to to make sure we're the world leaders. Doctor Joyce has really led this this effort. Doctor Joyce, when uh we first started this, Congress was chair was Vice Chair of the full committee and took this on. He has done a fantastic job with the staff and I would like to yield the remainder of my time to Doctor Joyce for talk about and and and thank you for the great job that you've done.

Rep. Joyce (PA-13)21:50 – 24:05

Thank you, Chairman Guthrie, and thank you, Chairman Bill Raucous. At the start of this Congress, you gave the privacy working group a tall order. Find a path forward on federal privacy reform. It protects consumers, enables beneficial use of data, gives businesses the certainty that they need, and can earn consensus among committee Republicans. As we saw in the one hundred eighteenth Congress, reaching agreement on comprehensive privacy legislation is not easy, even among members on the same side of the aisle. We cannot and will not take that consensus as for granted. The Secure Data Act is a result of fifteen months of the working group's efforts. Reaching this consensus was only possible with strong collaboration between members of the working group who are all original co-sponsors of this legislation. Thank you for your partnership, and thank you to your dedicated staff who spent countless hours on this issue, reviewing more than two hundred fifty RFI responses, taking hundreds of meetings with stakeholders and working through difficult policy questions to reach agreement on legislative's task, is no small task to the stakeholders who engaged with the working group. Thank you for your thoughtful contributions. Many stakeholders have already expressed support of the Secure Data Act, and I'm grateful for this support as we work to move this bill through regular order to the House floor. To my colleagues on both sides of the aisle, I look forward to engaging with you to advance the Secure Data Act and produce the strongest bill that is possible. This legislation is built on the foundations laid by more than twenty states, red states, blue states, and purple states. The states have sketched a path forward for us that protects consumers, provides certainty for businesses, and offers a strong foundation for bipartisan federal privacy legislation. All of these issues are significant components of the secure data act. I look forward to today's subcommittee discussion as we work to advance this legislation. And again, thank you, Chairman Villaraquist, and I yield back to Chairman Guthrie.

Rep. Bilirakis (FL-12)24:07 – 24:22

Thank you. Thank you, Mr. Chairman. Uh, give a job to Doctor Joyce and he gets it done. So, uh, next we'll recognize, uh, the Chairman of the full committee, ex- actually the ranking member of the full committee. I think the assumed. mr. polon for five minutes for an opening statement

Rep. Pallone (NJ-6)24:22 – 28:39

thank you chairman biliragas when it comes to data privacy it's clear what americans need they need a national privacy law that puts the focus on companies to collect and use data responsibly they need their sensitive data used only for limited purposes that they control they should have the ability to easily opt out across all data brokers and websites selling their data or using it for invasive targeted ads rather than opting out one by one And they need to know that their data will be kept safe from data breaches and misuse, and that they can pursue legal remedies if it's not. They need protections to ensure their data won't be used to discriminate against them. And our nation's kids and teens need the strongest possible protections for their data. Now, the Republican bill before us today does not meet that mark. The partisan secure data act is not the strong and forcible standard its sponsors describe. Instead, this bill locks in the failed notice and consent status quo, and then compounds loophole upon loophole to water down its provisions. And then to make matters worse, it adds expansive preemption that will leave many Americans with fewer privacy protections than they have today. Rather than taking the strongest consumer protections from the existing state privacy laws, this bill is assembled from industry-friendly state privacy laws that have been pushed by big tech. It's therefore no surprise that this bill allows big tech and others to continue their ongoing privacy violations. And unfortunately, these intrusions will only get worse as they push to insert artificial intelligence into every corner of our lives, supercharging both incentives to gather every bit of personal data and the potential harm that could result. A future with AI chatbots that can tailor personalized recommendations to our unconscious wants and algorithms that can set prices based on intimate details, demand strong privacy guarantees for all Americans. And in fact, these privacy guarantees are more important than ever. Now, I have fought for years for data minimization standards to shift the burden of protecting Americans' privacy from consumers to the companies that profit off of their data. But the Secure Data Act, the so-called data minimization provisions, those provisions allow companies to collect and use data however they choose, as long as it's disclosed in the fine print. So this is just another notice and consent by a different name. It continues to impose unreasonable burdens on consumers. They should not be forced to become privacy policy experts every time they visit a web site or download an app. The sweeping preemptions in this bill would not only eliminate hard-won privacy protections that millions of Americans currently enjoy, but would also invalidate any state law that relates to the bill. The legislation would prevent Maryland, for example from continuing to protect its residents by ensuring their sensitive information is not sold. It would prevent Californians from being able to delete their data from all data brokers in one step. And it would invalidate state laws on wiretapping, on robocalls, data breach notifications, civil rights and kids' online safety. Not only are these existing laws preempted, but states will be forever barred from addressing the future privacy harms that emerge with new technologies like AI. So I've long supported bipartisan national comprehensive privacy legislation. But previous bipartisan compromises, like the American Privacy Rights Act, the American Data Privacy and Protection Act, they recognize that a federal privacy law must succeed the strongest protections of any state and not set a weak ceiling. These compromises also put consumers in control of their personal information, prioritized data minimization, protected kids and teens, and included algorithmic accountability measures. And all of this was paired with strong enforcement to make these protections meaningful for consumers. Such a compromise remains, in my opinion, the only path forward to truly protect American privacy. And I want to stress, uh, Mister Chairman, that, you know, a- a- although I'm being very critical of this bill, I do I still think that we can come to a compromise similar to what we've done in the past. But this is not it. And and so I have to criticize uh what's here today and and hope that we can work uh for a better bill. And with that I yield back, Mister Chairman.

Rep. Bilirakis (FL-12)28:40 – 29:24

I thank the ranking member. Thanks so very much for your comments and we will work together. Uh, today our witnesses are uh Miss Kate Goodlow, Managing Director, Business Software Alliance, uh Miss Ashley Watts, President, CEO of Kentucky Kentucky uh Chamber of Commerce, Miss Katrina Fitzgerald, Deputy Director of electronic privacy information center and mister tyler r breitigan i hope i said that right uh partner of the uh bon dickinson so let's start let's begin with uh miss goodloe you're recognized for five minutes thank you

Kate Goodloe (Witness)29:25 – 29:29

good morning chair bilirakis ranking member schakowsky chair guthrie

Rep. Bilirakis (FL-12)29:26 – 29:26

good morning

Kate Goodloe (Witness)29:29 – 34:28

and ranking member polon and members of the subcommittee My name is Kate Goodlow, and I'm Managing Director at the Business Software Alliance, or BSA. BSA represents the business-to-business technology providers that support companies in every sector of the economy. Privacy and security are core issues for our members, which is why we are deeply engaged on privacy legislation in the United States, including across the state capitals and worldwide. Companies of all sizes and in all industries, including manufacturers, automakers, hotel chains, and energy companies rely on AI-driven business-to-business tools, like cloud computing, collaboration software, customer service platforms, and cyber security services. BSA members provide these technologies so that other companies can focus on what they do best, making products and serving customers. The United States needs a national privacy law that is built for the modern economy. one that pairs strong consumer protections with clear rules that limit how companies can collect and use consumers' data. We welcome your focus on these issues, and I thank you for the opportunity to testify. This committee has led Congress's work to protect consumer privacy. We urge you to continue that work and to leverage progress made by the States in recent years. In July, twenty twenty-two, this committee approved a comprehensive consumer privacy bill. At that time, just one state had a comprehensive consumer privacy law in force. Two years later, in April twenty twenty four, leaders of this committee released a discussion draft of an updated federal privacy bill. At that time, five state laws had entered force. Now, two more years have passed and twenty-two states have acted. Past efforts to draft comprehensive federal privacy legislation started from a blank slate. But the landscape of American privacy laws is no longer blank. Twenty-two states, both red and blue, have enacted comprehensive consumer privacy laws. Those laws are remarkably consistent because twenty-one share the same core structure with a common approach to definitions rights and obligations. But this core structure risks unraveling as at least thirty different amendments have revised expanded and changed state laws, making it hard for companies and consumers to keep up. The Secure Data Act adopts the right structure for protecting consumer privacy nationwide because it is grounded in the laws already passed by states. This is a key difference from prior federal bills. The Secure Data Act uses the same structure of privacy legislation that underpins twenty-one of the twenty-two state laws. It includes a core set of rights for consumers. based on the clear consensus that consumers should have the ability to access, correct, delete, and port their data, and rights to opt-out of activities like the sale of their data, targeted advertising, and certain profiling. It also adopts the long-standing, wide-spread distinction between controllers and processors. This ensures its obligations fit companies across the modern supply chain, in which one company relies on many others to serve customers. I want to emphasize this last point, because every company that handles consumers' personal data should be required to do so responsibly, in a way that fits their role. Grounding federal privacy legislation in the structure already used by state laws is a critical step, and we urge you to continue this important work. Why is it good for businesses? Well, companies should not have to track fifty moving goal posts to do business in the United States. We need a single, clear set of rules. that limits how companies collect and use consumers' data, so consumers' trust it is used responsibly. Why is it good for consumers? They need rights that do not depend on whether they live in one of the twenty-two states that has already acted. Consumers' data should also be used responsibly and kept securely no matter where they live. Of course, for any federal privacy bill to pass into law, it will need to have bipartisan support. As this bill moves through the process, We hope that the text can become a bipartisan product. Privacy has always been a bipartisan issue. In the States, ten Democratic governors and eleven Republican governors have signed privacy bills with this structure into law. We look forward to working with both sides of the aisle as this bill moves forward. We appreciate the subcommittee's leadership on federal privacy legislation, and we urge you to move the Secure Data Act through the legislative process. to promote technology adoption across the economy and protect American consumers nationwide. Thank you, and I look forward to your questions.

Rep. Bilirakis (FL-12)34:29 – 34:34

Thank you. Thank you for your testimony. Now I'll recognize Miss Watts. Uh, you're recognized for five minutes.

Ashli Watts (Witness)34:35 – 34:38

Yes, thank you. Thank you, good morning Chairman Guthrie,

Rep. Bilirakis (FL-12)34:37 – 34:38

Good morning.

Ashli Watts (Witness)34:38 – 39:26

Chairman Bilkeres, Ranking Member Polon, Ranking Member Schakowsky, and members of the subcommittee. Thank you for the opportunity to be here today. I'm Ashley Watts and I am the President and CEO of the Kentucky Chamber of Commerce. which is the Commonwealth's largest business advocacy association. We represent employers of every size and every sector who collectively employ hundreds of thousands of Kentuckians. I also serve as chair of the US Chambers Committee of One Hundred, comprised of the chief executives of America's largest state and metropolitan chambers of commerce. Through that role, we have brought together more than one hundred and twenty state and local chambers in unified support of the Secure Data Act, including the Kentucky Chamber. In two thousand and twenty-four, the Kentucky Chamber played an important role as a convener throughout the state-level conversation on data privacy. We brought together stakeholders from across industry sectors, business organizations, retailers, and privacy, security and technology experts to negotiate a balanced, workable solution. The result was House Bill fifteen, Kentucky's comprehensive consumer data Now, like Chairman Guthrie said, Kentucky is a bit of a unique state. We have a super majority of Republican legislature and a Democratic governor. House Bill fifteen, which is very similar to the Secure Act, passed unanimously with strong bipartisan support and was signed into law by Governor Andy Beshear. And it is a law that the Kentucky chamber is pr- proud of leaving leading the way. The goal was straightforward. protect consumers' data and privacy, while maintaining an environment where Kentucky businesses can operate and compete. The Secure Data Act asked Congress to extend to all Americans what Kentucky and nineteen other states have already put into law. We believe that federal action is urgent, because when every state writes its own law, even good policy creates a patchwork. The majority of our businesses at the Kentucky Chamber are small businesses, and no business large or small can realistically navigate fifty state legal strategy to comply with privacy expectations. Small businesses in particular often lacked in-house legal teams, chief privacy officers, or large compliance budgets. The US Chamber's empowering small business report found that nearly two-thirds of small businesses are worried that complying with different state laws will expose them to higher compliance and litigation costs. a number that jumped fourteen percentage points in just a single year. A fragmented privacy landscape is estimated to cost the U S. economy as much as one trillion dollars, with two hundred billion of that burden falling on small businesses. It is important to note that strong consumer privacy protections and economic growth are not competing goals. They reinforce each other. When customers' trust of their information is being handled responsibly, they are more willing to engage, to transact, and participate in the digital marketplace. And clear rules help build that trust. The Secure Data Act is built on bipartisan state laws, just like the one we passed in Kentucky. It provides consumers with strong privacy protections, the right to access, correct, delete, and port their data, opt-out rights, and opt-in requirements, for sensitive information. It has a reasonable data minimization standard. And it establishes a national standard without a private right of action. Every state that has passed this type of legislation has made that same choice, because it produces consistent, meaningful outcomes for consumers. This framework has been signed by nine Democratic governors and eleven Republican governors. More than two thousand five hundred state lawmakers, both Democrats and Republicans, have voted for it. More than one hundred and thirty-five million Americans are already protected by it. This is not just a technology policy issue. It is a competitiveness issue. Kentucky's businesses and all American businesses, especially small businesses, need one clear set of rules of which they can build around. The Secure Data Act provides just that. The model is proven and the consensus exists across party lines. What remains is for Congress to act. On behalf of the business community, I urge this subcommittee and the full Congress to pass the Secure Data Act. The Kentucky Chamber of Commerce, the US Chamber of Commerce, and our more than one hundred and twenty state and local chamber partners, stand ready to support you in this effort. Thank you and I look forward to your questions.

Rep. Bilirakis (FL-12)39:27 – 39:35

I tell you what, that was excellent testimony. I appreciate it. Uh, Miss Fitzgerald, you're recognized for five minutes.

Caitriona Fitzgerald (Witness)39:35 – 44:37

Chairs Guthrie and Bilirakis, Ranking Members, Pallone and Schakowsky, members of the subcommittee, thank you for the opportunity to testify today. My name is Katrina Fitzgerald, and I'm Deputy Director of the Electronic Privacy Information Center, or EPIC. EPIC is an independent nonprofit established in nineteen ninety four to secure the fundamental right to privacy in the digital age for all people. And we have been deeply involved in the debate in the States over privacy legislation. We believe privacy is a fundamental human right. There's broad bipartisan agreement that Americans need stronger privacy protections. Poll after poll shows that consumers are fed up with the status quo. They don't want surveillance pricing at the grocery store, they don't want their car cars broadcasting their driving habits to their insurance companies, and they certainly don't want US troops put at risk in war zones because online pri- online advertising is a privacy nightmare. America needs a strong data privacy law. But the Secure Data Act is not the right approach. This committee previously approved bipartisan bills that meaningfully protected privacy. In those negotiations, both sides worked to craft a federal bill that was stronger than the strongest state law. Those bills included meaningful data minimization, heightened protections for sensitive data, limits on data discrimination, and robust enforcement. The Secure Data Act does the opposite. It sets a national standard that is weaker than the weakest state law. We shouldn't be making the floor the ceiling. You've heard today that this framework has been successful in the States, but it hasn't been successful for the people in those States. What makes it so weak? A core weakness of the Secure Data Act is its lack of a real data minimization rule. Right? The Secure Data Act allows businesses to continue collecting and using data, however they please, As long as they disclose it in a privacy policy that we know few consumers read, and no consumer has the power to change. Data minimization only works if it actually limits how much data companies can collect and how they can use it. You know, my eight year old is a huge soccer fan, but every team he joins requires me to download a new app to get the schedule and and talk to the coach. Um, if I don't like the app's terms, there's no disagree but download the app anyway button. There's, you know, I have to accept it Or not download the app. Am I supposed to tell my son he can't play soccer because his mom doesn't want her data used to train AI systems? Congress shouldn't be passing a privacy law that bakes this unfair system where companies get to dictate the terms into law. The Secure Data Act also fails to adequately protect our most sensitive data, like our location data. Sensitive data should have stronger protection than beyond simply consent, because in practice that just leads to endless pop-ups that consumers grow numb to. Another significant weakness of the Secure Data Act is that despite its focus on individual consumer rights it lacks a private right of action. If a company ignores my request to delete my data or opt out, there's just no recourse. It's essentially unenforceable. The FTC and state AGs don't take on individual cases. This bill has many more weaknesses than I have time to detail in my testimony today, but the fatal flaw is the combination of these weak rules with the most expansive preemption option available to the federal government. This bill would wipe out decades of state laws causing chaos in our legal system. My testimony includes a list of the hundreds of laws Epic believes could be preempted, including those on robocalls, civil rights, kids' online safety, and even long-standing privacy torts. This bill would also make it harder to hold big tech accountable in court. Just last week, Meta, Snap, YouTube, and TikTok agree to a twenty-seven million dollar settlement with a Kentucky school district where platforms' addictive designs harmed students' mental health. Many of the claims in that case relate to rules in this bill, so there's no way of knowing whether similar cases could move forward. The weak bu- b- weak rules in this bill paired with its extreme preemption provision would be a disaster for Americans. I want to emphasize that. This bi- the passage of this bill would be a worse outcome for Americans than no federal data privacy law at all. The trends in the US are clear. Companies are abusing increasing amounts of our personal data, AI is turbo-charging that abuse, and Americans want more protections from big tech. Yet this committee is proposing weaker legislation than it overwhelmingly approved in previous sessions. Congress should not pass a privacy law that fails to address the very real data abuses and privacy harms that Americans are asking them to fix and it certainly should not strip Americans of privacy rights they already have. We know what's needed. Strong data minimization, heightened protections for sensitive data, limits on data discrimination, and robust enforcement. The Secure Data Act unfortunately doesn't meet the moment, but the solutions do exist, and I urge the subcommittee to consider other approaches that give Americans the privacy they want and deserve. Thank you for the opportunity to testify today, and I look forward to your questions.

Rep. Bilirakis (FL-12)44:38 – 44:44

Thank you. Uh, now I'll recognize Mister Breitigan, uh, for your five minutes. Appreciate it.

Tyler R. Bridegan (Witness)44:47 – 49:33

Ranking member Pilon, and Schakowsky, members of the subcommittee, my name is Tyler Breitigan. As as a brief housekeeping matter, um I'm here in my personal capacity today not on behalf of any company organization or client. Um, I I wanna s- uh, one I wanna sar- say thank you members for picking up this effort again. You know, I I think we all are in agreement that it is a it's essential um priority to get a federal privacy law passed in the United States. Um, I wanna give you guys start uh with a bit of my background, so you can understand the sort of lens that I am viewing uh the Secure Data Act. Um, at the end of uh up until the end of last year, I was serving as the Director of Privacy and Tech Enforcement for the Texas Attorney General's office. There I was in uh headed up our efforts to implement and enforce all of the recently passed um Texas privacy laws that included comprehensive privacy. data broker laws, children's privacy and s- online safety laws. Um, as as part of that, you know, we took a very, um, intentional approach to looking at sort of what harms exist, um, in the United States. Many of our our cases were very high profile. Um, they involved looking into the entire auto ma- manufacture industry, um, several social media companies, and several of our investigations ultimately led to litigation. Um, also as part of my role, I have the opportunity to get to know, uh, my counterparts in other states. It was a incredible experience getting to hear what so many states are doing on the privacy front, both, um, advising their legislatures on what is working and what isn't in their privacy laws, as well as figuring out ways to appropriately enforce their law and dedicate resources. Um, at the end of last year I, I returned back to private practice at the law firm Juan Bobon Dickinson. there our our firm has a very broad client base you know we have our origins in the southeast um and then we've since expanded you know across the united states as part of that we have clients of all sizes um in that are in every industry from your brick and mortar to defense um you know to giant on-line retailers um it is been extremely educational for myself um to see what all of these different companies in different sectors care about with respect to privacy. Um, but enough about enough about my background, um, on the Secured Data Act front, I I wanna cover, you know, sort of four key points with you guys today. Um, first, you know, there is a widespread support and I think that's been echoed by all the other witnesses that Americans want a privacy law passed. Companies' practices are unclear to c- consumers, they um, our learning of new ways their data is being used, it is time to protect those consumers. In Texas, as part of our privacy law, we had to create a consumer privacy complaint database. Um, it it took, it went online July first, by July second, we had our first ten consumer complaints, um, coming from corners of Texas you would not expect. Someone from Laredo, um, filed a complaint, uh, asking for a, uh, a um, oh my gosh, fast food chain to update their privacy policy cuz it didn't have a right for them to, an option for them to delete. Um, not the first company I probably would have looked into. Um, you know, you think th- all to say there's widespread support on that front. Um, now, uh, second point, we now know mu- much more tangible harms. You know, I think several of our cases focus on how data was particularly sensitive data types. were ultimately being used to monetize or um affect consumers. Um third, we now know more. You know, when the last time Congress pushed forward with this effort, most of the state laws were not in effect, and there has definitely not been enforcement that it occurred yet. We now have had the opportunity to see which provisions in the laws sort of co- protect from those key consumer harms particularly the tang- the tangible harms that we're seeing emerge. Um and then fourth um I think that passing a federal privacy law is crucial. You know, right now over half the states don't have sensitive data protections, meaning by default companies can collect and use those that data however they please. Trillions of data points are being generated about Americans every single day that still go unregulated. All that to say, you know, I am extremely excited for this effort to be moving forward. Um, I think, you know, we're actually pretty close on um a lot of provisions which is exciting when i was reviewing this law um that is it for me and i'm happy to answer any questions

Rep. Bilirakis (FL-12)49:34 – 50:25

uh thank you gentlemen uh now i'll begin questioning and recognize myself for five minutes uh i share the concerns of many americans the companies are collecting more of a uh personal data than is uh really needed uh at the same time uh we've seen how overly restrictive privacy laws like the like europe's general data protection regulation uh throttle privacy uh again private industry and innovation so uh mister goodlaw how do the secure data acts restrictions on data collection work and how do they differ from europe's uh law and past proposals before the committee uh mister bradigan uh if you wanna add something uh after mister goodlaw

Kate Goodloe (Witness)50:34 – 51:23

alright thank you for the question uh the secure data act builds on the experience of state laws to create a core right core set of rights for consumers and a core set of obligations on companies importantly those obligations extend across the modern supply chain and they create rules for both controllers which are the companies that decide how and why to collect consumers' data and for processors which are the companies that handle data on behalf of other companies pursuant to their instructions that is a critical difference from prior federal laws and it ensures that the obligations created by this act carry across the modern economy i think it is important that congress pass a law that creates one set of rules for companies to collect and use data so that consumers know it is used responsibly

Rep. Bilirakis (FL-12)51:24 – 51:27

Thank you. Mister Brattigan, would you like to uh add to that?

Tyler R. Bridegan (Witness)51:27 – 52:29

Yeah. Um, you know, compared to the GDPR, i- it's actually conceptually similar. There're - there're similar restrictions in the GDPR about sensitive data and using consent in order to collect and use that data. That - that is present in the Secure Data Act. There's a long history. Illinois' Biometric Information Privacy Act, Washington State's most recent My Health My Data Act. Texas's similar biometric and genetic privacy act. That that principle is a is strong. It has led to several of the largest settlements in history in the United States. I'd also say GDPR takes a more high level approach, um, without being too prescriptive. And that's similar to things we've seen in other contexts in the United States like the NIST cyber controls. Right? It's it's tell- explaining what types of controls you need and what sort of practices, you know, ultimately lead to, um, stronger protections. um without being so pres- prescriptive as to require companies to implement or include many specific requirements in a privacy policy for example

Rep. Bilirakis (FL-12)52:29 – 53:22

thank you next question uh there's a view in washington as was some states that more mandates on business means uh more protections for americans right now we have twenty two comprehensive uh consumer privacy laws in this country which uh may become twenty four Uh, in short order, it's uh governors of Louisiana and Vermont signed the bills on their desks. Uh, and I know you alluded to this uh uh earlier, but uh these uh laws uh set alongside existing federal requirements for different sectors, such as health care and finance and FTC, the FTC Act. So uh, Mr. Rydigan, uh, is the status quo effectively protecting consumers, are more state by state laws better than a uniform federal framework.

Tyler R. Bridegan (Witness)53:24 – 54:05

You know, I I think there has been a a good mmm movement at the state level to increase enforcement that said you at the end of the day the f- fifty states having a uniform law to enforce and create precedent around is plus being able to team up with the Federal Trade Commission will create very clear market shifts in privacy practices around the country. Most companies want to, good faith, comply with the law. But at the end of the day, the there's a real effect for the when there's a heightened risk of enforcement from several entities I think a federal law would create that heightened risk for um enforcement and ultimately um encourage companies to prioritize complying with the letter of the law.

Rep. Bilirakis (FL-12)54:06 – 54:10

I have a little more time. Uh, Miss Goodloe and uh Miss Watts, would you like to add anything?

Kate Goodloe (Witness)54:12 – 54:36

i will add that the important piece of a national law is it will it will protect consumers nationwide right now consumers are protected in twenty-two states with different state laws and we need a clear set of national rules that companies can build strong compliance programs toward i think that will make sure that consumer protections are extended nationwide and that companies know what to do and what to focus on to better protect consumers

Rep. Bilirakis (FL-12)54:37 – 54:37

Ms. Watts?

Ashli Watts (Witness)54:38 – 55:11

yes thank you Yes, thank you, Chairman, and I would echo my colleagues' answers on that. We in Kentucky really did kind of question whether we should continue to advocate for a federal law or work on a state law. After several years of no action by Congress, we decided that we needed to take matters a little bit into our own hands and pass a law in Kentucky but we absolutely believe that a federal law is the way to go. I'm proud to speak on the majority of my my members of the chamber of commerce for small businesses they want one clear set of standards to be able to comply with. and this is what this would bill would do instead of a patchwork of all the various states.

Rep. Bilirakis (FL-12)55:11 – 55:20

Very good, thank you. I yield back the balance of my time and I'll recognize the ranking member of this subcommittee Miss Schakowsky for five minutes of questioning.

Rep. Schakowsky (IL-9)55:25 – 55:54

Hmm? Miss Fid Let's see. Am I getting here? Okay. Miss Fitzgerald, I wanted to um ask you, where are you? There you are. Um, how, um, what is it? Yeah, how does this bill benefit corporations rather than the American people?

Caitriona Fitzgerald (Witness)55:55 – 58:15

Thank you so much for that question, Ranking Member Schakowsky, because I think it's really important for members to understand a bit of the history of where these twenty-two state laws came from. Privacy and consumer rights and civil rights groups have opposed those laws in the States. Those bills originated from a draft that was written by tech giants in Washington State. It ultimately did not pass in Washington State. But, um, they took it to Virginia first and passed it in twenty twenty one, and then brought it to, you know, uh, these these now twenty-two states, or twenty-one, I guess, cuz California followed a simil- uh, a different path um and pushed their weak model with the hopes of getting exactly to this moment, coming to Congress and saying this is the consensus in the States, please pass this at the federal level, and preempt States from doing anything for all of time on privacy. Those state laws are far too weak to adequately protect privacy, and Congress should not be emulating that model, right? Privacy laws should not be written by the very entities they seek to regulate. Um This bill also contains about five pages of exemptions and loopholes, uh corporate carve-outs. It makes you wonder what uh who the weak rules in the bill will even apply to in the end. Uh so that's something we really want to be careful of when we're looking at at bills as well and and who they're protecting. Um yeah well I'll say as as a privacy advocacy advocate in the States when it's disappointing to see how quickly the conversation turns to a focus entirely on business compliance. And consumers are almost you know, they're hardly mentioned in the end. You c- you almost would forget that you're working on a consumer protection bill in the end, as opposed to a business compliance bill. So I'd say so much work was done on previous bipartisan proposals to come up with a framework that protected Americans and allowed businesses to thrive and innovate. Uh, and it's disappointing that the Secure Data Act throws all that out and starts over, and I hope that we can come back to the table and come to a bipartisan agreement on a bill that works for both the American people and our businesses.

Rep. Schakowsky (IL-9)58:16 – 58:22

Are there other things that we should be doing to make sure that consumers are uh benefited?

Caitriona Fitzgerald (Witness)58:24 – 59:20

I think the key with the privacy law is to make sure that the onus of protecting privacy is not entirely on the consumer, And rather the businesses that are collecting, using, profiting off of our data have obligations on the f- foreign front to limit the amount of data they're collecting and using, right? It's it's there's just such a power imbalance that if companies can just write these policies and say take it or leave it, uh that that just doesn't doesn't protect privacy. They need, you know, I I realize that we're trying to put things back in the box because we didn't act on privacy um early on. EPIC has been asking Congress to pass a privacy law for thirty years. Um but that doesn't mean that we should just allow the status quo to continue. We need consumers need adequate protections online, and I really do think that the solutions exist to do that in a way that would allow our businesses to thrive but adequately protect consumers.

Rep. Schakowsky (IL-9)59:20 – 59:26

What are the things that we need to do to make sure that consumers are un- empowered?

Caitriona Fitzgerald (Witness)59:27 – 59:54

We need a strong data minimization rule that limits data collection and use. It says to company, you know, uh, the ADP PA and APRA, limited data collection used to what was necessary for the product or service the consumer is asking for. So that means that companies have to better align their data practices with what consumers expect. I don't expect my flashlight app to collect my location data. I expect my weather app to collect my location data, but I don't expect

Rep. Schakowsky (IL-9)1:00:07 – 1:00:10

Thank you. Appreciate that very much.

Rep. Bilirakis (FL-12)1:00:13 – 1:00:21

General Lady yields back. I now recognize the uh the Chairman of the full committee, Mister Guthrie, for his five minutes of questioning.

Rep. Guthrie (KY-2)1:00:21 – 1:02:00

Thank you very much, and uh the process by writing this bill that as for Sheryl described, absolutely was not the process in writing this bill. It was uh, Doctor Joyce will speak for himself, but we met with hundreds of different people, different groups, and everybody on here wants people's data data to be secure and to have their privacy and have uh security. As I said, we're not um looking to compete with Europe to regulate. We're looking against to compete against China to innovate, and we don't wanna be China either. We certainly don't wanna be Europe. Uh, and so the question is can you find a balance, and that's what we've worked hard to find a balance, and we think that we strongly believe that we have. You know, European United States had the same economy twenty years ago. The same economy twenty years ago, the European economy, and there's a lot of reasons, our energy policy can't dismiss uh that Europe, that Britain has pulled out, but our economy is twice the size of Europe today, in fifteen years. Twice the size. So now you gotta look at the reverse. What if our economy today was half the size that it is today. Talk about unemployment, you talk about affordability, you talk about all these, so these things matter, and things just don't happen in a think tank. Things just happen in academia, things happen in the real world, and so people's data's being being collected in the real world and people are trying to innovate and grow their companies in the real world. And so how do we strike that balance? That's what we're looking at. So Miss Watts, we heard a lot about big tech. I know in Kentucky we have a lot of small businesses and you mentioned it in your remarks. Could you kinda going a little further on how con- typical Kentucky small businesses are affected by this and why they, and I don't believe Governor Beshear was out looking for big tech and for businesses.

Ashli Watts (Witness)1:02:00 – 1:02:00

Yeah.

Rep. Guthrie (KY-2)1:02:00 – 1:02:14

I'm thinking he's trying to make Kentucky a business state. I'm not saying he was anti, but I don't think he was how can we give everything to big tech. I don't think he had that that at all. And he, and it didn't just come from the General Assembly, cuz he's been known to veto a lot of bills.

Ashli Watts (Witness)1:02:14 – 1:02:15

Mm-hmm.

Rep. Guthrie (KY-2)1:02:15 – 1:02:25

And they get overwritten, but he vetoes a lot of them. So I would have it to have to think that he had a hand in doing this too, and so I don't think he's out there trying to to protect big tech at the expense of the consumer, it's been insinuated.

Ashli Watts (Witness)1:02:26 – 1:03:22

Absolutely, thank you Chairman Guthrie for that question. You know, we are really proud of our small businesses in Kentucky, they are the backbone of our economy, as you know in your district, and I always say, you know, I've been at the Kentucky chamber now for fourteen years, lead leading their advocacy, I feel like I'm pretty good at my job, but it's still really hard to pass a bill unanimously through the Kentucky General Assembly and have it signed into law, by a democratic governor. I think that shows the power of our convening and the power of the consensus that we built around this. It was not just big tech. Of course we had tech at the table. We needed to have their voice be heard. But we also had small businesses. We had retail. We had restaurant. We had consumers. We had everyone kind of at this table, really working together for a consensus-based solution. And that's exactly what we did in Kentucky, that is really mirrored here with the secure act. And so I think just speaking for it wasn't only bipartisan, it was unanimous in Kentucky's General Assembly and then signed into law by Governor Andrews.

Rep. Guthrie (KY-2)1:03:22 – 1:03:26

Because every business, no matter what size, if they have a credit card portal is affected by this.

Ashli Watts (Witness)1:03:26 – 1:03:27

Exactly, and I

Rep. Guthrie (KY-2)1:03:26 – 1:03:35

So if you're a lone person with a store, your family runs your store, you're the and you have a credit card portal which everybody has to have now, then you're affected by this bill.

Ashli Watts (Witness)1:03:35 – 1:03:37

Absolutely, and I think you know small business

Rep. Guthrie (KY-2)1:03:36 – 1:03:38

For any proposal that we do.

Ashli Watts (Witness)1:03:38 – 1:03:50

Exactly, small businesses in our in in your district and throughout the Commonwealth want to be a nationwide marketplace. We do a lot of our shopping online. You want that ease and you want your small businesses in the Commonwealth to grow.

Rep. Guthrie (KY-2)1:03:49 – 1:03:54

And and I was in the General Assembly, so being a product of the General Assembly, you do get a lot more grassroots input.

Rep. Bilirakis (FL-12)1:03:54 – 1:03:55

Yes.

Rep. Guthrie (KY-2)1:03:55 – 1:04:14

So my guess is you had a lot of consumers and you had a lot of businesses around the table as opposed to consumer groups that represent the interest of consumers. Not out there as kind of their think tanks and uh you always gotta wonder who's hired the think tank. And the second thing is and then big tech. So not in Kentucky, you didn't have probably the four or five big titans of

Ashli Watts (Witness)1:04:32 – 1:05:01

I would absolutely agree, and I would say if small businesses were upset with a law that was passed in Kentucky two years ago, I absolutely guarantee you that law would not have been passed unanimously by the Kentucky General Assembly and signed into law by Governor Andy Beshear. Small businesses in Kentucky supported this bill. Local chambers of commerce all across the Commonwealth supported this bill. And that bill has then has now been mirrored a lot in the secure act. I think we're a great example to show the convening power and the consensus building that we built around data privacy in the Commonwealth.

Rep. Guthrie (KY-2)1:05:02 – 1:05:08

And it's typical of state governments to have those kind of grassroots input. Thank you and my time, I don't have time to ask another question, I'll yield back.

Rep. Bilirakis (FL-12)1:05:09 – 1:05:18

You're welcome to ask another question, Mr. Chairman. Alright. The gentleman yields back. Now I will recognize the ranking member of the full committee. Mr. Palon, please.

Rep. Pallone (NJ-6)1:05:19 – 1:06:15

Thank you, Chairman Bilirakis. I've long said that the core of any comprehensive uh privacy standard has to begin with strong data minimization but if the secure data act contains a provision that claims to offer data minimization it actually allows companies to do anything they want uh with consumer data with notice and consent. So my question to Ms. Fitzgerald, and I actually have four, so I'm gonna ask you like to answer them in a minute or so if you could. So the first one is, how does the standard for data minimization in the secure data act compare to the data minimization offered by prior bipartisan federal privacy proposals like the American Data uh Privacy Act and and the prote- American well there are two bills, American Data Privacy and Protection Act and the American Privacy Rights Act. Um and does it provide, the secure act, any meaningful difference for consumer privacy compared to the status quo. In a minute.

Caitriona Fitzgerald (Witness)1:06:16 – 1:07:13

Thank you, Member Pallone, Epic views data minimization as the most important substantive rule in any privacy bill and I would hesitate to call what's in the Secure Data Act data minimization, I know that section is titled that way, but it's really data maximization, right? Companies are incentivized to write their privacy policy as broadly as possible, list as many purposes as possible, because the only thing the count as a violation is not disclosing. So they'll just say, you know, we collect your data for marketing purposes, that allows them to do anything, doesn't tell anything to consumers. And in fact, it's basically restating current consumer protection laws, so it's not giving them any additional protections because unfair and deceptive trade practices laws already require companies to be truthful in their privacy policies. Um, whereas previous bipartisan proposals, like you said, limited, required companies to limit their data collection and use, to purposes that um the the consumer expected that were reasonably necessary for the product or service they asked for.

Rep. Pallone (NJ-6)1:07:13 – 1:07:38

Alright, thanks. So the second thing is about enforcement, because meaningful consumer protection is only as effective as its enforcement, and that includes cases involving individual consumers who have been uniquely harmed. So the question is how will the lack of a private right of action in the Secure Dat- Data Act impact the law's effectiveness? Will the right to cure further impact the the law's uh effectiveness, and in what way.

Caitriona Fitzgerald (Witness)1:07:39 – 1:08:26

Yes, thank you. We've seen in the States that um uh the lack of a private right of action, that without it there's really little incentive for companies to comply with the law because they know the risk of government enforcement is so low. And that's only uh made worse by the inclusion of a right to cure in the Secure Data Act because companies know they'll get a jail uh uh get out of jail free card uh if government enforcers do come knocking at their door. you know they can just fix the problem and the there can't be any enforcement. Consumers lose in all these situations because they can't enforce their own rights, and then if uh a gover- a government agency, a state AG or the FTC does try to enforce, companies can just fix the problem after the fact, even though you know the harm is already done, your data's already out there, uh your privacy rights have already been violated, and there's no getting that back.

Rep. Pallone (NJ-6)1:08:27 – 1:08:32

Alright. And then the third uh thing, I recently began an inquiry into surveillance

Caitriona Fitzgerald (Witness)1:08:52 – 1:08:59

No, secure data act does nothing to address it surveillance pricing um companies could just say in their privacy policy that they were using your personal data,

Rep. Pallone (NJ-6)1:08:56 – 1:08:56

Mm.

Caitriona Fitzgerald (Witness)1:08:59 – 1:09:17

to offer personalized pricing. And what that will look like for the consumer is they sign up for a loyalty program in the hopes of saving money and then their personal data is used to determine just how much they'll tolerate paying for eggs um which could be a different price than their neighbor and the Secure Data Act would do nothing to stop that harmful practice.

Rep. Pallone (NJ-6)1:09:17 – 1:09:39

Alright, and then the last thing is about preemption. The Secure Data Act contains very broad preemption language. It goes beyond what we saw in APRA and ADPPA and clearly preempts more than state comprehensive data privacy laws so the question is, Under the Secure Data Act, what is the potential scope of state preemption and how might this affect consumers in states that already have strong protections in the law?

Caitriona Fitzgerald (Witness)1:09:40 – 1:10:39

Yes, the Secure Data Act includes the broadest preemption option available to the federal government, um, preempting anything that relates to the provisions in the bill. And the Supreme Court has described this form of preemption as deliberately expansive. I attached a list of the hundreds of laws that EPIC believes could be preempted. Uh to my testimony, that's even a representative list, there could be many more. Uh it's hard to overstate the chaos this will cause in our legal system. Uh you know, it goes so far beyond just preempting the comprehensive privacy laws that it attempts to mirror. Um it would preempt long-standing privacy torts, it would preempt a lot of kids' online safety laws like age appropriate design codes, um laws about robo-calls that we all, no one wants robo-calls back. Um and data breach notification laws. So, the preemption provision was just written, um, so expansively that everything from, you know, uh, kids' online safety to robocalls is at risk.

Rep. Pallone (NJ-6)1:10:39 – 1:10:42

I thank you so much. Thank you, Mister Chairman.

Rep. Bilirakis (FL-12)1:10:42 – 1:10:43

I appreciate it.

Caitriona Fitzgerald (Witness)1:10:42 – 1:10:43

Thank you.

Rep. Bilirakis (FL-12)1:10:43 – 1:10:52

The gentleman, uh, yields back. Now I'll recognize the the gentleman from, uh, the great state of California, Mister Albanelti, for his five minutes of questioning.

Rep. Obernolte (CA-23)1:10:53 – 1:12:40

Thank you, Mister Chairman. Let me begin by saying how delighted I am that we are finally having this hearing. This has been a long road. Uh, it's been an honor for me to serve on the data privacy working group under the leadership of Congressman Joyce. And uh, let me emphasize some of the points that have b- uh been already been made here. This legislation has been over a year in drafting, and we tried to correct some of the mistakes that have been made in previous efforts by broadly engaging all corners of the stakeholder community. We sat down with hundreds of different groups representing different Uh, and I want to sh- give a shout out to uh all of our individual staff and the committee staff because this has been a herculean effort to get to this point. Uh, one of the things that I think we need to spend more time talking about is how burdensome it is on small businesses to have this complex regulatory landscape of potentially fifty different state laws currently twenty-two, but potentially fifty different state laws, as a technology entrepreneur myself. I can tell you that a landscape like that is a barrier to entry to people trying to start new t- businesses in technology because what it does, is it advantages big tech. Because those are the companies, not to pick on them, but those are the companies that have buildings full of lawyers, and the the sophistication to deal with a regulatory landscape like that. So if you're a Google, you're a Microsoft, you can do it. If you're two people in a garage somewhere trying to start the next Google or the next Microsoft, you can't. And uh, and this is the, the big challenge that we're trying to solve with one unified federal standard. So, uh, Miss Goodloe, could you, you, you have many small businesses as part of your organization. Can you talk about just how challenging it is to navigate this landscape of currently twenty-two different state regulations?

Kate Goodloe (Witness)1:12:42 – 1:13:33

Thank you for the question. BSA represents the business-to-business technology providers that power companies across every sector of the economy, and those are companies of all sizes. When you have to comply with laws on a state-by-state approach, companies are forced to track fifty moving goal posts. We have twenty-two state laws already enacted, several more awaiting action by governors, and amendments that continue to go through the legislative process every day. It is a complicated landscape no matter what size your company is. I can only speak for the business-to-business part of the technology industry, But we think one standard is needed so that companies of all sizes know the rules and know how to comply with the goal of protecting consumer privacy so that consumers trust that their data is used responsibly.

Rep. Obernolte (CA-23)1:13:34 – 1:14:54

Right, well, uh, obviously, uh, I would very much agree with you. Um, Miss Fitzgerald, uh, we could agree to disagree on, uh, some of these issues. You said a couple of things that I found to be kind of inflammatory and I wanted to, uh, talk about them and give you the opportunity to respond. Uh, one of the things you said is that the goal of this process of creating one federal standard should be to create a standard that's strongest, of, uh, stronger than any of the individual state standards. And I very much disagree with that because we tried very hard to take a consensus approach where we took the best of what everything, every state had to offer. And that would mean, you know, being somewhere in the middle, not the strongest, not the weakest, but, but looking at what worked. The other thing that you said that I take issue with a little bit is you said that uh this bill is weaker than the weakest state standard and that we would be better off to have no federal standard at all, than to pass this bill. And I do take exception to that because first of all, the weakest state standard right now is no state standard. We have twenty-two different state standards. That means the majority of states have zero protections for consumers when it comes to digital data privacy. How can you say that having no bill is better than the protections in this bill even if we agree to disagree on how strong those protections should be.

Caitriona Fitzgerald (Witness)1:14:56 – 1:15:19

Thank you, Representative, and, you know, thank you for the the opportunity to elaborate on this. You know, um, we believe at EPIC, especially where there's a broad preemption provision in this bill, that if the federal law does not exceed the protections in the strongest state law, then Congress is taking away privacy rights from Americans that they already depend on.

Rep. Obernolte (CA-23)1:15:18 – 1:15:28

Yeah, but but half the states don't have they have no privacy rights in half those states. So, uh, even if that's true, uh, you're giving privacy rights to consumers that right now have none.

Caitriona Fitzgerald (Witness)1:15:30 – 1:15:55

But privacy rights that are not necessarily meaningful. And in practice, most businesses are now offering these consumer rights of access, correction and deletion to residents of fifty states because uh so many states have uh the state privacy laws that include these consumer rights. So in practice, you know, the enactment of this bill is going to give Americans, even in states without privacy laws, very few rights that they don't already have today.

Rep. Obernolte (CA-23)1:15:55 – 1:16:18

Well, I mean, the the that's the whole goal here is to create one federal standard that gives everyone the same rights that we all believe that we should have. And I'm hopeful, Mister Chairman, I see my time's expired, I'm hopeful that we can get to a place of bipartisan agreement on this. Obviously, for this to be a lawmaking exercise, we have to get there eventually. Uh, so uh I I hope that we can still uh continue having this discussion as the bill moves forward. Are you back?

Caitriona Fitzgerald (Witness)1:16:19 – 1:16:20

Good enough.

Rep. Bilirakis (FL-12)1:16:20 – 1:16:24

Good enough. I now recognize uh Miss Castor for her five minutes of questioning.

Rep. Castor (FL-14)1:16:25 – 1:17:22

Uh, well, Mister Chairman, I'm not gonna mince words. I think this bill is an appalling betrayal of hardworking Americans, their ability to safeguard their personal uh information. It's a violation would just allow violation of their privacy to continue. It wipes away laws across the country that protect privacy. It will lead to higher costs for consumers. Uh, it will further unleash insidious AI surveillance pricing. It will end state laws, uh, relating to unwanted robo-calls and spam, uh, text messages, and it will gut long-line privacy protections for kids. Uh, Miss Fitzgerald, you have an entire section in your testimony about how the GOP anti-privacy bill will make minors less safe online. Uh, we've debated this a lot in this committee. Will you expand and elaborate on that?

Caitriona Fitzgerald (Witness)1:17:23 – 1:18:22

Yeah sure, thank you for the question. You know, states have passed dozens of laws giving kids and teens stronger privacy protections online, um, both as part of comprehensive privacy laws and in age-appropriate design codes and other kids' online safety rules. Um, and this bill will take those protections away without really, you know, meaningfully replacing them. So it's an example of why I did say that I I do think the passage of this bill would be a worse outcome for Americans, because, you know, we know how this works. If this privacy bill passes, uh, you know, Congress will have checked the box on dealing with privacy for decades to come, and these rules will be cemented into law, technology is changing, we're already, you know, seeing the harms that um kids are suffering, especially kids are suffering online due to harmful business practices of big tech. And I just don't think that Congress should be passing a federal privacy law that fails to address those harms.

Rep. Castor (FL-14)1:18:21 – 1:18:36

And it would weaken enforcement of those laws, kind of gut um gut those enforcement mechanisms. In fact there are many lawsuits right now uh that parents and families have brought against the tech companies. What would the impact be uh legally?

Caitriona Fitzgerald (Witness)1:18:36 – 1:19:01

Yeah, the broad preemption provision in this bill would really cause chaos for those lawsuits, because um you know, t- you're talking about school districts and parents and others going against the most powerful companies in the world. And so if those companies have an out to to argue in court that, you know, their claims are preempted by this bill and that they disclosed in their privacy policy what they were doing, there's a question about whether they'll take this in court.

Rep. Castor (FL-14)1:19:00 – 1:19:30

I think that is so wrong. That is so wrong to rip the rug out from under. the families and kids. I mean the evidence of harm to children online is is very apparent after many years. Um, and I know they're, they wanna, I hear the argument, they wanna hang their hat on, okay we wanna con, we want one set of rules nationwide, but if you have a very weak uh federal standard, that's no protection at all for people's privacy, is it?

Caitriona Fitzgerald (Witness)1:19:31 – 1:19:39

No, it's not. I agree that we need a federal data privacy law, and EPIC has been asking that for thirty years, but um we need that rule to be strong.

Rep. Castor (FL-14)1:19:39 – 1:21:09

In fact, we had a we had a good bipartisan compromise that we had hammered out here, and it's I think it that Americans deserve better. They really do deserve to be able to safeguard their personal private data. Some of it is very sensitive, their personal health data, uh as well, and this would just I think unleash uh the big tech company's ability to mine that data, make us the the product uh with no recourse, it's kind of on theme for what this committee has done. If folks don't know what this committee has done, this session they passed out of this committee uh a complete ban on any AI regulation at all at all, federally or for the states at all. Uh they've also gutted our kids online safety act that is very bipartisan in the senate also the kids uh online privacy protection act is passed unanimously by unanimous consent in the senate and here uh i don't know why the tech companies have greater influence they have gutted that uh weakened that uh it just seems like it's another gift to the big tech companies it's unfortunate that that's the tact of this committee but i want folks to know what what is going on here we i just think people deserve better they deserve to to have their privacy protected and not constantly mined and surveilled and then sold um and i'll i'll end it there thank you very much

Rep. Bilirakis (FL-12)1:21:12 – 1:21:17

general lady yields back uh we will recognize mister bentz for five minutes of questioning

Rep. Bentz (OR-2)1:21:17 – 1:22:00

thank you mr. chair yeah mister ridge again i'm uh just to start with you and this is just a question i've had for years And and it it you say on page four of your testimony, um, consent is generally defined as a clear affirmative act that signifies the customer's freely given specific informed unambiguous agreement to process their personal data. I don't know how many times I've quickly gone through the twenty-six pages, or fifty-six pages of the consent in other situations and, you know, gone to the bottom box and checked yes. I'm just curious how the, how you or anybody would ever suggest that w- that we're gonna get this kind of unders- understood consent from anybody in these kind of situations.

Tyler R. Bridegan (Witness)1:22:00 – 1:23:07

Yeah, I, and thank you for the question. I wou- I would like to clarify a couple, respectfully, a couple misunderstandings on, um, how consent works, uh, i- in these privacy laws. So, Texas has a very similar, um, comprehensive privacy law as the the Secure Data Act, particularly around consent insensitive data. Um, Texas is also the only state in the United States that has recovered over a billion dollars multiple times using laws that are based on consent. There's no other state that has ever recovered more than a billion dollars from a l- company. Um, so consent in these scenarios is not something as simple as a click-through you know when you see a banner at the bottom of the screen, and you say accept all to privacy policies. It needs to be specific and informed. Um, Texas precedent has uh, Texas courts have done a great job on explaining that each one of these adjectives has a meaning and a company needs to satisfy those specific meanings. So at a minimum you're going to be able to you're going to need to be able to demonstrate that a com- that the company disclosed the pro- the what they were collecting the data for and how they were using that data.

Rep. Bentz (OR-2)1:23:07 – 1:23:14

So if if if I may, I I understand the desire to achieve that type of understanding, but what are the odds of that actually happening?

Tyler R. Bridegan (Witness)1:23:16 – 1:23:29

If if companies will part of that relates to the enforcement mechanisms, right? So, uh if there's actually the risk of enforcement, companies are going to take a close look at um what they are disclosing and telling consumers and how they're obtaining consent.

Rep. Bentz (OR-2)1:23:29 – 1:23:54

So let's say if I if I may, the the the way this works, the you harvest this data from millions of people. And so to to suggest that these companies are gonna go to millions of people and uh to ascertain that each one has reached that level of consent seems um highly unlikely. So I'm just trying to say, can you explain to me how we're going to reach that level of consent in any meaningful form?

Tyler R. Bridegan (Witness)1:23:54 – 1:24:24

So, it it would be on a going forward basis obviously, but um you would, I mean a company would need to, say if it was just a web site that wanted to collect sensitive data, that's going to need, our position is al- was always that it needed to be a separate disclosure, and a short disclosure, not something that is, you know, mixed into a giant privacy policy that nobody reads. It needs to be something that is very clearly informing the consumer um and so you know that's like a you can condense that down to two sentences but it does need to specifically state like we're collecting your

Rep. Bentz (OR-2)1:24:23 – 1:24:28

So so again if if again if if I may I'm I don't wanna be too mean to my state of Oregon but

Tyler R. Bridegan (Witness)1:24:24 – 1:24:25

geolocation data.

Rep. Bentz (OR-2)1:24:29 – 1:25:00

our reading uh comprehensive test scores are abysmal so I wonder how anybody is going to read these kinds of things in my state of Oregon uh and actually understand them but I wanna set that aside because it it but it's a typically important question Because w- the whole uh system now seems to be run on LLMs, and that means all kinds of data. And what you're basically saying is there's gonna have to be a opt-in from an educated person who actually gets it. And I don't see that happening.

Tyler R. Bridegan (Witness)1:25:01 – 1:25:24

I mean, the burden is on uh under the law, the burden's on the company to demonstrate that they um actually obtained specific informed consent so they're going to have to be you know, adversely arguing that with the regulator. So that is a uh burden shifting it's not as simple as a notice um provision but that that ultimately will fall on that burden to demonstrate that will be on the company

Rep. Bentz (OR-2)1:25:24 – 1:25:47

hmm uh ms. watts uh a state by state regime rewards whoever has the biggest legal and compliance budget and that's uh rarely a new entrant this this goes back to comments already made by previous uh folks uh so my question is does the privacy patchwork entrench the largest incumbents at the expense of smaller competitors Seems to be the answer is obviously yes, but go ahead and tell me.

Ashli Watts (Witness)1:25:47 – 1:26:05

Yeah, uh, we we absolutely be agree that a federal framework is really the way to go for small businesses. As we have discussed several times throughout this committee testimony, the uh the compliance up for small businesses and the navigation is really cumbersome and burdensome so we do believe the national framework will help small businesses.

Rep. Bentz (OR-2)1:26:05 – 1:26:11

Mm. Thank you, and uh I just wanna thank the panel of the extraordinarily interesting conversation, appreciate it very much, yield back.

Rep. Bilirakis (FL-12)1:26:12 – 1:26:16

Uh, thank you, appreciate it. And now I'll recognize Mister Mullen for five minutes of questioning.

Rep. Mullin (CA-15)1:26:18 – 1:27:21

Thank you, Mister Chair, and thank you all for your testimony today. As I mentioned earlier, I am concerned that the legislation before us today moves us in the wrong direction on data privacy. Not only does it set a remarkably low ceiling for privacy protections, it also overrides the good work that the states have been doing in this arena. As I noted, uh, California has enacted some of the strongest privacy protections in the country. giving consumers rights over how their personal data is collected, used and shared. These laws are now actively being used by Californians to exercise control over their data. Uh, for example, California also recently enacted the Delete Act, which allows consumers to submit a single request directing registered data brokers to delete their personal information. Hundreds of thousands of Californians have already used this service, and Connecticut adopted similar legislation just last week as i understand it uh miss fitzgerald can you discuss how the legislation before us today would affect existing privacy protections for californians

Caitriona Fitzgerald (Witness)1:27:22 – 1:28:41

yes it would completely um wipe out the protections in the california consumer um protection act the privacy act i'm sorry uh the delete act the california age appropriate design code you know there may be uh the california consumer privacy act does cover employees that might be the only piece that's left since this doesn't cover um the employment situation but uh all of the provisions in those laws relate to provisions in this bill so billions of Californians would be left with fewer privacy rights than they have today and that they have had on the books for you know eight years now um and in our federalist system Congress's role should not be stripping privacy rights, um eviscerating hard-fought rights that their state legislators have decided they should have. Uh, the Delete Act has been wildly popular. It's only been, you know, uh effective since January first, and I think something like three hundred thousand Californians have already taken advantage of that, to have that centralized deletion mechanism, um, because we don't know who data brokers are as consumers, so it's great that they have a, you know, one place to go where they can say, I don't want my information sold by data brokers, and and that is conveyed to those companies. Um, And this would just it would leave Californians in a worse place than they are today.

Rep. Mullin (CA-15)1:28:43 – 1:30:00

Thank you for that. I uh also wanna walk through a real world example that our witnesses are familiar with. Uh Texas recently led a suit against an insurance company that used third-party apps to collect trillions of miles worth of location data from over forty-five million consumers nationwide and use that information to build what has been described as the world's largest driving behavior database. According to the allegations, insurers then use that data when setting or renewing consumers' insurance premiums. Under the Secure Data Act, even if those allegations are true, the company would have forty-five days to remedy the issue without any penalty, even though the data has already been collected, shared, and sold. So, uh, Mister Bright again, uh, you just mentioned Texas Texas's biometric privacy law and the recovery of billions of dollars for consumers. Um, as I understand it, uh, that law and others hold bad actors accountable, even if they later fix, uh, any violations. However, the secure act would give bad actors forty-five days to rectify any violations with no penalty, if they do. But fixing the problem, uh, going forward doesn't undo the harm that the data, uh, has already been collected, already been sold, and consumers can't get it back. So why would we want to preempt state legislation with such a provision?

Tyler R. Bridegan (Witness)1:30:01 – 1:31:43

Thank you for that question. I I think that case is actually an very fascinating example of how narrow a cure period really is. Um, Texas has a thirty day cure period that was not curable conduct under Texas's privacy law. There's actually very few, we've we've had to do a lot of thinking on what really is curable. So if you collect data about a person without their consent, how do you fix, you can't really unc- how do you cure that? Do you delete it? But I would say you already did the harm by their data without their consent deleting it doesn't do it if you go back and get their consent but arguably you still violated that initial provision of the law there's not really a way to walk that back a lot of these data ecosystems are also extremely complex in pursuant to very complex contractual agreements that are negotiated with sophisticated law firms and parties those have mechanisms that can't really be completed in a thirty to forty five day window you you say you're you know up uh uh you're counter party to the agreement big company how do you and you've sold that data to them how do you can't suddenly void that sale of data and if that company went on and used that data that would also be another layer of arguably incurable conduct i kind of i have viewed the cure period as really something that goes for for more of the facial violations so not including um the right language and a privacy policy not having your um uh the ability for consumers to exercise their rights working properly. There are and even that one might get you know into incurable conduct, but ultimately you know the that case was a very good illustration of sort of how limited um the cure period really is ultimately.

Rep. Mullin (CA-15)1:31:44 – 1:31:48

Well thank you for that, I remain skeptical of the approach before us today and and with that I yield back, thank you all.

Rep. Bilirakis (FL-12)1:31:49 – 1:31:56

Gentleman yields back, I recognize Miss Lee from the great state of Florida, my fellow for Florida Gator, you're recognized for five minutes of questioning.

Rep. Lee (FL-15)1:31:57 – 1:33:53

Thank you, Mister Chairman. What we are doing here today is so important. Americans should not have to surrender their privacy in order to participate in modern life. And parents should not have to wonder whether a child's personal information is being collected, shared, or sold without their knowledge. The reality is that technology has changed dramatically, but many of the laws governing how we address personal information have not kept pace. I have worked along with many of my colleagues on this committee to modernize COPPA because the internet children use today looks nothing like the internet that Congress attempted to regulate in nineteen ninety eight. As we consider a national privacy framework, we should reject the false choice between protecting consumers and promoting innovation. We can do both, and I appreciate all of you for sharing your insight about the pathway toward doing that here today. States like my home state of Florida have already shown that strong consumer protections and economic growth can go hand in hand. We should build on those lessons by giving families meaningful control over their children's data, strengthening safeguards for sensitive information, and establishing clear rules that consumers and businesses alike can trust. Mister Bright, again, I want to come back to you. One of the major differences between the Secure Data Act and some of the existing privacy frameworks that we've been discussing here today is its requirement that companies obtain affirmative consent before processing sensitive information such as health information, biometric data, or precise geolocation data. During your time enforcing Texas privacy laws, what types of sensitive data abuses concerned you most, And how does an affirmative consent requirement help us prevent those abuses?

Tyler R. Bridegan (Witness)1:33:54 – 1:34:59

Thank you for the question, representative Lee. When I when I started as um heading enforcement, privacy enforcement for Texas, I did not come in expecting to be focused so heavily on geolocation data. Um, around that time the New York Times had reported that several car manufacturers were collecting data from people's vehicles directly and ultimately um scoring them and and sending it on to insurance companies for insurance companies to charge varying rates. Um, you know, that, that I think was sort of a novel use in some ways of geolocation data, and it sort of to me underscores the importance of having a law that has those tried and true um mechanisms like consent um that enforcers can apply to different situations as more data types and uses emerge over time. You know, a data ecosystem is incredibly complex, but you know, there needs to be enough flexibility um a and sort of reliance on those mechanisms that we've seen work in the enforcement context. Children's data I think is extremely um will will emer- has emerged and will continue to emerge as um an area that requires heightened attention.

Rep. Lee (FL-15)1:34:59 – 1:35:14

What is your perspective on the biggest privacy risks facing children and teens today and how does requiring parental consent help get to ensuring that that minor's personal information can be kept safe and parents can stay stay in control?

Tyler R. Bridegan (Witness)1:35:15 – 1:36:09

There is data being collected by children now that I I think will stay with them for the next seventy years, longer. Um, it it is unpredictable how that data will ultimately be used, um, i- it throughout their lives. You know, I I think there has not been a enough of a focus on sort of ensuring that going from that age of minority to majority that there's some sort of clear line about what needs to happen with that data. Um, on the ver- uh, age verification front, you know, Texas has been a leader in passing um children's online safety and privacy laws. Um those all come back to age verification. I know Congress is pushing forward with um an additional children's privacy and online safety package which I think is a a great effort because there is continues to be sort of a a blind spot um for parents, and then um ma- and arguably sometimes intentionally blind spot by um companies on as to what is happening on these platforms.

Rep. Lee (FL-15)1:36:10 – 1:36:20

And do you believe that parental consent, in addition to those age verifications verifications, uh, plays an important role? And if so, uh, tell us, tell us more about that.

Tyler R. Bridegan (Witness)1:36:20 – 1:37:00

Yes, I I think it's, it is key for parents to be in the loop on what is happening, um, what is being u- what their children's data is being used for, and what, um, are, are, what features are allowed for children. You know, in the social media context there, there's a lot of, uh, there was a lot of focus from our office on sort of what um different users could um how they could interact with minors. And there needs to be some sort of stop gap there because there there there's just has not been sort of a required um demarcation of you know preventing certain interactions from like adults and minors or minors to minors um in in several of those spaces.

Rep. Lee (FL-15)1:37:00 – 1:37:01

Thank you. Mister Chairman, uh you're back.

Rep. Bilirakis (FL-12)1:37:02 – 1:37:10

I thank the General Lady, I recognize Mister Vici for his five minutes of question. Oh Miss Clark is back. Okay, we'll recognize Miss Clark, you're recognized.

Rep. Clarke (NY-9)1:37:11 – 1:40:59

Thank you, Mister Chairman, and good morning to both you and Ranking Member Chikowsky, my colleagues, and thank you to our panelists of witnesses for joining us today. Anyone familiar with the work in history of this subcommittee knows that for years I've been stressing the importance of a comprehensive federal privacy framework. While I can appreciate the title of today's hearing, I must address the fact that legislate the legislation before us today is a non-starter for comprehensive privacy and data security. In front of us is a piecemeal attempt at protecting Americans online. And to be clear, naming a bill the Secure Data Act by no means qualifies it as a comprehensive privacy bill. A privacy bill should actually protect privacy. To s- to level set today's hearing, we must acknowledge that my colleagues on the right have not only been unserious about Americans' on-line safety, they have been actively working against it. Let me remind, let me remind us all that the party backing this legislation is the same one who has tried to illegally fire the Democratic FTC commissioners, is insistently promoting sweeping preemption, of state AI laws and continues to prioritize big tech over people. Sorry, but I don't trust this proposal as a good faith attempt. It wasn't too long ago that House Democrats and Republicans were able to come together and form the bipartisan AI task force that produced a comprehensive report with the intention that it would be guide the one nineteenth Congress on the necessary next steps. at regulating AI. My colleagues and I have worked to advocate for the inclusion of civil rights priorities in the bipartisan report. And while it could have gone further, I was proud to see that the task force report emphasized the different biases that AI can hold and how that may affect consequential decisions that AI occasionally is employed to make. I'm beyond disappointed to see that the secure data act has not only walked back on any effort to protect American civil rights online, but has gone as far as to narrow the scope of protections, watered down the definition of consequential decision making, and preempt state civil rights laws. When Congress works to stymie or dumb down privacy protections and technology and technology safeguards it is working against the public interest. This bill maintains the status quo. Big tech, data brokers will carry on business as usual, collecting and using people's data, whether they know it or not. Now, more than ever, we should be holding companies responsible for failing to keep us from harm when we go online, to live up to their promises when they say they care about our privacy, and to hold them to their commitments to ensure that AI systems they create are safe. I implore my colleagues to recognize that this bill is just not not it. This bill will do nothing to prevent or mitigate harm caused when the data collected and used by company drives discriminatory decisions, and will only further harm black and brown Americans who will continue to have their data used against them. I move to enter into the record this letter from the Leadership Conference on Civil and Human Rights into the record.

Rep. Bilirakis (FL-12)1:40:59 – 1:41:01

Without objection, so ordered.

Rep. Clarke (NY-9)1:41:01 – 1:41:04

Well, I thank you, Mister Chairman, and with that, I yield back.

Rep. Bilirakis (FL-12)1:41:06 – 1:41:12

Now I recognize uh Mister Falter, the Vice-Chairman of the Subcommittee, for his five minutes of questioning.

Rep. Obernolte (CA-23)1:41:13 – 1:42:55

Thank you, Mister Chairman. The purpose of the secure act is to provide consumers more control over their personal data and create a uniform national framework. The bill does not include a private right of action. And we've seen downsides of litigation abuse in the privacy space in other cases historically. Currently, all protesting law firms have filed over forty-six hundred suits nationwide, claiming that ordinary internet activities, the use of cookies and pixels and bots and analytical tools, constitute wiretapping under various state laws. It's been more than three thousand of these suits have been filed just in California alone. So I'm gonna just fast-forward here, but um we've got a situation where one plaintiff has filed thirty lawsuits claiming wiretapping by roofers plumbers general contractors HVAC employees, and so on. Another one has filed thirty-eight uh lawsuits against Rocket Mortgage, Marri Marriott, HP, Frontier, and Williams Sonoma. There's many more examples like that, but you get the the picture of of the the issue I'm trying to bring up here. A question for Miss, Miss Watts. Um, in your written testimony you mentioned that private rights of actions are used to target small businesses who are incentivized to settle cases as opposed to engaging in the costly l- litigation Do you think that if the secure act did not contain federal preemption that we'll see a growth in lit- in litigation in privacy suits and just more generically What are your thoughts of the ramifications if the secure act did not have a federal preemption?

Ashli Watts (Witness)1:42:56 – 1:44:23

Yeah, thank you for that question. I think it's important to note that twenty-two states have not had private right of action in their legislation. It wasn't even taken out of the legislation. It was never it was never included in the first place. We hear stories from small businesses all the time, from other states, where they are being targeted by the trial bar. And instead of going through a costly legal system, they are settling for ten thousand, fifteen thousand dollars Because it's easier to do that than to fight that that lengthy that lengthy court system. I think it's also important to note that there is recourse in this bill. And actually in Kentucky, that would be strengthened. Right now in Kentucky, our recourse is to go to our state's Attorney General, Russell Coleman, uh who absolutely has been very communicative with business and with consumers as well, on how to, if there is an issue, to complain to his office. Uh he is a former US Attorney, he is a former FBI agent. He very much wants to protect consumers and especially children, as it has been mentioned throughout this testimony. I also think it's really important that we make sure that this bill, it's clear that it is not go- it is not going to protect bad actors. In addition to states going through their attorney generals, there is also the recourse of going to the FTC as well. For a state like Kentucky that has passed a state law, right now our recourse, kind of our our way of our pathway would be to go to the state's attorney general. Now, uh, consumers could go to the Attorney General, but also the FTC as well. So I think it actually strengthens the protections of the the states that already have these bills in place.

Rep. Obernolte (CA-23)1:44:24 – 1:45:11

Thank you for that. I I appreciate your comments. Mister Brattigan, when professional plaintiffs file lawsuits and there's no demonstrable harm, what's the impact of that? And I I I wanna just preface my question by uh by just sharing that I worked in the tech sector before this portion of my life. And as a matter of course, when an officer of of of the company would would sell stock, whether it was in the um, uh, window of time where that was allowed or not, there would just be a a flurry of lawsuits that got filed automatically. And so, there truly are professional plaintiffs out there, but when those lawsuits are filed and there's no demonstrable harm, what's the impact of that?

Tyler R. Bridegan (Witness)1:45:11 – 1:46:25

Yeah, thank you for the question. Ba- back in private practice we we've had to deal with this a a lot, and it comes in waves and I think underscores both the risk of a private right of action, but also the risk of not having a uniform standard. So, you know, using wiretap litigation as an example, that is um legal theories crafted by the plaintiff's bar to essentially um claim that someone's privacy rights are are violated. You know, it's a it's a unfortunate model where many of them um, and and this happens in the ADA website, compliance, and TCPA litigation as well, where they will price this opening offer settlement so low that it is um, more but it's more than, or I'm sorry, it is it the opening settlement offer is less than what it would take for a cl- a company to retain a law firm to respond to the lawsuit. So they're getting these five, ten, fifteen thousand dollars on behalf of single consumers over and over and over. um from you know oftentimes several companies will have multiple filed against them in any one time. Um I think it's very distressing for particularly small I mean the targets of those are, as Ms. Watts explained oftentimes small medium sized businesses that do not have the resources to um retain and fight those lawsuits.

Rep. Bilirakis (FL-12)1:46:26 – 1:46:31

Thank you for that. Mister Chairman yield back. Gentleman yields back. I'll recognize Mister Vici for his five minutes of questioning.

Tyler R. Bridegan (Witness)1:46:32 – 1:46:33

Uh thank you Mister Chairman um

Rep. Pallone (NJ-6)1:46:34 – 1:47:01

Obviously there are a lot of things about this bill that really, you know, worry me. Obviously we need to do something about data and privacy. I think that everybody agrees on that. Uh, but uh, but again there are just some worrisome language in this bill, and I just specifically wanted to ask if Mr. if Mr. Fitzgerald could answer this question. I know this bill explicitly bars the FTC from enforcing its own civil rights provision and can only pass complaints to other agencies I was wondering that if a company is

Caitriona Fitzgerald (Witness)1:47:14 – 1:47:45

Yes, that is um of every problematic um provision in this bill, one of many. Um and it's unclear who uh a consumer would go to if they are discriminated against online. Um you know, there are it points to other agencies um that the FTC would refer those cases to. Um but the FTC has historically had that authority um to protect consumers when when data is used in ways that discriminate against it.

Rep. Pallone (NJ-6)1:47:45 – 1:48:15

Yeah, yeah, that that's really interesting. If a company is caught misusing data to discriminate based on someone's race or religion or politics to give them a job, I know that the bill gives them a forty-five day uh grace period to uh try and and cure uh exactly uh what's going on uh so they can say that it's fixed no matter how serious the violation may be and i was wondering why is it important for a company to get a free pass just because they promise not to do it again

Caitriona Fitzgerald (Witness)1:48:17 – 1:49:13

yes the right to cure in this bill is mandatory um many states that have included rights to cure have either sunsetted them after a couple of years after the bill comes into effect so that you know companies have a a chance to catch up on compliance, um, for the first couple of years and then it goes, you know, it sunsets, or they make the right to cure discretionary so that enforcement authorities, you know, can look at a specific case and see that it's curable, um, or decide, you know, not to move forward that if the violation rises to that level. So I think that those are options that were, you know, not included in this bill and that could have been, and something else that's missing from the secure act is the strong civil rights protections that were included in the American Data Privacy and Protection Act and American Privacy Rights Act, that prohibited personal data from being used in ways that discriminate against Americans, um, it wou- in many ways.

Rep. Pallone (NJ-6)1:49:13 – 1:49:27

Yeah, I was wondering from some of the other panelists, does it bother you that there is no language in there to to um to help in those areas of civil rights? You just jump in, I would be curious. I mean to me this all seems very problematic.

Kate Goodloe (Witness)1:49:27 – 1:49:57

We agree this is a really important issue, and in the past the Business Software Alliance has called for legislation that addresses um AI related issues including this one. We have though deferred to Congress on whether to combine that with privacy legislation or to address it through stand alone legislation. We know it is difficult to pass a federal comprehensive privacy law, and we want to see progress on that, so it is something where we have really looked to to leaders in Congress to decide how best to move these issues forward.

Rep. Pallone (NJ-6)1:49:57 – 1:50:17

OK. Well, thank you very much. Um, you know, speaking of, that sort of puts the burden on individual consumers to request the deletion of their data, uh, particularly if someone had no idea that their data is being used to profile them and deny services, um, how would someone be able to make that kind of request on their data?

Caitriona Fitzgerald (Witness)1:50:22 – 1:50:23

Darsha, um,

Rep. Pallone (NJ-6)1:50:22 – 1:50:23

Yeah, please.

Caitriona Fitzgerald (Witness)1:50:24 – 1:51:04

yeah, so, um, companies in their privacy policy will are required to explain to consumers how to exercise their privacy rights. So if it's a company that they interact with directly, a social media company or a retailer's website, um they would go to the website and either, you know, submit a form or or email the company to ask to delete their data. The problem is that there are so many companies that most consumers have never even heard of, um that are gathering our data on a every minute of every day and so they don't have uh they don't know that those companies exist to go to them and ask to delete their data.

Rep. Pallone (NJ-6)1:51:04 – 1:51:39

yeah yeah and uh my my my last question is it problematic that people will sometimes just click on the box to give people consent? cause i'm worried about that it's almost like when people clicked on boxes before and they didn't know they were waving their right to go to trial is that a problem that people are just basically you know clicking this box to give consent, little pop-up box so they can sorta keep moving along without knowing exactly what they're clicking on, uh and does that uh is is is that uh a fair and transparent way to help consumers.

Caitriona Fitzgerald (Witness)1:51:40 – 1:51:46

I don't think so, because even if they know what they're agreeing to, there's no choice not to agree. Usually the proceed button is grayed out

Rep. Pallone (NJ-6)1:51:45 – 1:51:45

Yeah.

Caitriona Fitzgerald (Witness)1:51:46 – 1:51:49

until you check the box saying I agree to these terms.

Rep. Pallone (NJ-6)1:51:48 – 1:51:49

Yeah. Yeah.

Caitriona Fitzgerald (Witness)1:51:49 – 1:51:51

So that is not a real choice at all.

Rep. Pallone (NJ-6)1:51:51 – 1:51:52

Yeah. Oh, thank you very much.

Rep. Goldman (TX-12)1:51:53 – 1:51:54

Thank you, Mr. Chairman.

Rep. Obernolte (CA-23)1:51:54 – 1:51:57

Thank you. The chair recognizes Mr. Goldman for five minutes, please.

Rep. Goldman (TX-12)1:51:58 – 1:52:37

Thank you, Mr. Chairman. Uh, first let me thank my desk mate today, Dr. Joyce. Thank you so much for your leadership on this. Um, for those of you who don't know, Dr. Joyce and his staff have put insane amount of hours into this, and I just wanna thank you, it's been an honor to work with you on this. Uh, as a member of the privacy working group, I'm proud to cosponsor the secure data act. which is based on consensus privacy laws like those in my home state of Texas. Mister Breit, again, thank you for being here. Uh, great to see a fellow Texan. Uh, thank you for your work on data privacy and security. If the Secure Data Act becomes law, would Texas still be able to hold bad actors accountable?

Tyler R. Bridegan (Witness)1:52:38 – 1:53:46

Yes, I I think to Mister Fitzgerald's point, the the consent mechanisms, at the end of the day, that shifts the burden to companies to demonstrate to the government. If they can't do that, it's somewhat uh a a side note whether the consumer understood or not what was contained in that consent provision, it is the it shift fundamentally shifts the onus on two companies to be able to demonstrate that to the government. Compare that to California which is the only state of every state that has passed a privacy law that does not require consent they this was alluded to earlier, it it they as Fr- Fitzgerald's point in California by default as long as a company includes notice of what they're doing with their privacy law, uh, or I'm sorry, with sensitive data in their privacy policy, they are allowed to collect, use, process, sell, whatever with that sensitive data. It is a, sort of, I would say arguably, um, lowest standard for sensitive data of any privacy law in, in the world at this point. Um, every other state strengthened that requirement with consent. You know, some states have taken it further to go to a full-on ban, but that is, um, you know, I would say that even goes further than the GDPR, um, on that front.

Rep. Goldman (TX-12)1:53:47 – 1:53:59

Super. And based on your experience leading privacy enforcement in Texas, can you explain why state attorneys generals and their federal trade commission would be better equipped than private trial lawyers to enforce federal privacy laws?

Tyler R. Bridegan (Witness)1:53:59 – 1:55:15

Yeah. I I alluded to this earlier, the the wiretap litigation is a really good example of how there's this sort of different interpretation of privacy laws that is inconsistent with, say, Cal- s- take the California wiretap law compared to California's privacy law. Those provision, if you comply with California's comprehensive privacy law that does not does not immunize you from suit by private plaintiffs um so there's companies that were having to divert resources to um limited resource dollars for privacy compliance to focusing on these class action private litigation as opposed to um implementing requirements that would be required under California's privacy law um these laws also give government regulators an immense amount of discretion you know should a if say a company doesn't include specific language in a privacy should they now be hauled into court and sued by individual plaintiffs. I I would argue that's not really protecting privacy and not in taking dollars away from actually making sure compliance programs are up to snuff. Um, alternatively, because of the cure period, because these are highly technical laws, those are much more sort of attuned to government interpretation, um, in sort of the the injunctive nature that comes along with government enforcement as opposed to a a more a larger focus on obtaining a monetary settlement.

Rep. Goldman (TX-12)1:55:15 – 1:55:33

Alright, thank you. Miss Watts, uh, thank you very much for coming. Throughout your testimony you explained the small businesses are increasingly dependent on data technology and on-line commerce to compare, compete and grow. Can you explain why the Secure Data Act is important for the success of many small businesses both in my district and Texas and around the nation?

Ashli Watts (Witness)1:55:33 – 1:56:41

Yes, thank you for that question. As I said, most of our members of the Kentucky Chamber of Commerce are small businesses, and they want to grow their businesses. They wanna take those businesses outside of the commonwealth and get consumers and customers from all over the nation. And so having a patchwork of laws is very cumbersome and burdensome to them. So really what we have been saying is the twenty-two states that have these comprehensive data protection laws, it really, we don't need to reinvent the wheel. We can use what we've done in twenty-two states that have protected consumers first, but also had businesses have a clear set of guidelines to follow nationwide. I think it's really important for small businesses in particular, to be able to grow their business, and as we know, we are a digital world. i know myself as a working mom of two i do most of my shopping on my phone uh that is really important to businesses we had a small business member that is a member of the us chamber of commerce say that if all of the data was gone and kind of this technology ceased to exist it would be another pandemic for him so i think we cannot um underestimate the power of technology and data for our small businesses to really grow and flourish like we all want them to do thank you very much i appreciate i do want to thank everyone

Rep. Goldman (TX-12)1:56:38 – 1:56:42

thank you very much i appreciate i do want to thank everyone for being here it's always

Ashli Watts (Witness)1:56:41 – 1:56:42

for being here it's always

Rep. Goldman (TX-12)1:56:42 – 1:57:01

great to have uh a full house and the the general public here attending this hearing. I specifically wanna point out we have two young Americans, they've been sitting here on the front row the entire hearing, without their phones, without playing games. I just wanna thank y'all for being you've been paying attention the entire hearing, so thank y'all very much for being here especially. Thank you, Mr. Chairman. I go back.

Rep. Obernolte (CA-23)1:57:01 – 1:57:07

Thank you, we can all take a lesson from that. Chair and I recognize as the representative from Illinois, Miss Kelly, please.

Rep. Kelly (IL-2)1:57:09 – 1:58:06

Thank you, Chair Bill Arachas, and Ranking Member Schakowsky for holding this morning's hearings, and thank you to our witnesses for participating. As has been said, Americans want a strong privacy act, but the Secure Data Act does not quite meet the mark and preempts the stronger protections already in place in the States. This piece of legislation keeps a notice of consent model in place, where a company can collect and use data for almost any purpose, as long as it lists that purpose somewhere in a privacy policy. Almost no one reads those policies, and the few who do cannot reasonably understand them in many clay cases. This is not true consent. Miss Fitzgerald, you stated that under this legislation, a company can bundle a necessary purpose like processing a payment with an unnecessary one like selling data into a single set of terms. When a consumer clicks accept, do they have any real way to know what they just agreed to?

Caitriona Fitzgerald (Witness)1:58:08 – 1:59:38

Um, you know, I think it is difficult for consumers to you know, I'm a privacy advocate, I still don't read all the privacy policies, you would do nothing else with your time if you read all the privacy policies for everything uh you used. Um, so while consent is an important piece of consumer protection, it shouldn't be the only thing standing between consumers and the collection and use of their data. There should be obligations on companies to limit how much data they're collecting and how they're using it because if the only protection is at the end of a long privacy policy there's a checkbox for accept and I have to check it in order to use the web site or app that's not a meaningful protection that leaves me with no choice um in modern day society um there's just so many apps that we have to use um and also I wanna highlight that uh there are protections in many state laws in terms of what consent means that were not included in this bill. Mm-hmm. Uh, the protections that Mr. Bridgen mentioned about um making sure that consent isn't just acceptance of broad terms and conditions, or prohibitions on dark patterns. There's nothing in this bill prohibiting dark patterns. So that means that a company can just have one big brightly colored accept button and then d- you know disagrees in small fonts, Mm-hmm. and requires toggling a dozen buttons. So um we want to make sure that when you are using consent, uh, it's meaningful and that it's not the only protection for consumers.

Rep. Kelly (IL-2)1:59:38 – 2:00:02

Thank you. Miss Goodloe, your members write the privacy policies and consent screens consumers every day. And your testimony says a federal law should help people trust their data is used responsibly. That trust depends on people understanding what they agree to. What standard would your members support to make sure consumers actually understand what they're they are agreeing to.

Kate Goodloe (Witness)2:00:03 – 2:01:56

Thank you for the question. And before I respond, I want to clarify, I represent the business to business part of the technology industry. I know we've talked about the technology industry more broadly. I represent BSA members who are a very specific part, providing business to business technologies to companies of all sizes across every industry sector. Things like cloud computing, software that can track inventory and keep track of customer service inquiries, these sort of back-end functions that everyday businesses across the economy Very often it is those other companies, the consumer-facing companies, who are creating this sort of privacy policy to tell consumers what they're going to collect from the consumer how they're going to use that information. I think the bill that is before this committee today reflects both of those roles by being anchored in this long-standing distinction between controllers who decide how and why to collect data and processors who handle it on their behalf. When we step back and look at the consent requirements that apply to those controllers, the ones who are deciding why do I collect a consumer's data, how am I going to use it, I think that is a long-standing and very important topic in the broader conversation about privacy legislation and the right set of safeguards that are put on how companies collect and use consumers' data and I think there has been a concern that consumers are sort of bombarded by consent requests and that ends up in the situation where they're unable to read all of them. At the same time, consent is an important guardrail, and consumers do want to know when companies are collecting very sensitive types of data and know how companies intend to use that data and be offered that choice. This bill requires consent to collect sensitive data, as some of the other witnesses have mentioned, that is stronger than the law right now in California. But I think the goal of privacy legislation is to make sure that that consent is meaningful and consumers actually have a choice about the things that matter most to them.

Rep. Kelly (IL-2)2:01:57 – 2:02:00

Thank you so much and thank you to all the witnesses. I yield back.

Rep. Obernolte (CA-23)2:02:01 – 2:02:04

Thank you and the chair recognizes Representative Fry for five minutes, please.

Rep. Pallone (NJ-6)2:02:05 – 2:02:59

Thank you, Mr. Chairman. Um, you know, I've I've found myself in this working group just kind of really interested in diving into the the legalese of what states are doing, how they operate, the lessons learned. Um, you know, I served in the state legislature and we often borrowed good ideas from other states, and we shunned ones that were not successful in other states. And this was I think no different uh when you're looking at this. Um Miss Watts, what is what was imp- what do you think is important here? In uh what are the competing interests, excuse me, what are the competing interests uh that exist when you were in the uh debating this in the Kentucky legislature? It seems to me that the competing interests are privacy, right, citizens' right to their data maybe, um but also innovation uh small business entrepreneurship that that seems to be kind of the rub right between the two sides is that fair to say roughly

Ashli Watts (Witness)2:02:59 – 2:03:32

yeah thank you uh representative frye for that question you know we passed this bill back in two thousand twenty four and you as a former state legislator know that sometimes it does take a couple years to get the right bill uh we worked for several years with a broad coalition and often say i know many of you work with your local or state chambers of commerce if the chamber of commerce had one superpower it's the ability to convene and find consensus we bring groups of all different shapes, sizes, and sectors to the table to really find a feasible path forward. And that's exactly what we did with House Bill fifteen back in two thousand twenty four.

Rep. Pallone (NJ-6)2:03:32 – 2:03:41

So you guys, you worked with stakeholders, right, with different ideas on what is acceptable and what is unacceptable, and they were not always aligned. Is that correct?

Ashli Watts (Witness)2:03:41 – 2:03:59

That is correct. I mean, I I said earlier, I've been doing uh this job for fourteen years and very rarely have I ever passed a bill unanimously through the Kentucky General Assembly. But this was one of them. So you're exactly right. It was the balance of consumer protection, but also business innovation and making sure businesses can flourish.

Rep. Pallone (NJ-6)2:03:57 – 2:04:15

Isn't that the balance that we have? Isn't that the balance that we have right now, Miss Goodloe, right? I mean, uh, to to to your point, you have multiple states that have done this. California's model seems to be modeled after the European model more than it does the uh some other states would you characterize it that way, Miss Goodloe?

Kate Goodloe (Witness)2:04:16 – 2:04:48

Thank you for the question. I think California has a different approach than the other. twenty-one state consumer privacy laws. And California took the important step of adopting the state's of of adopting the United States' first state-level comprehensive privacy law back in twenty eighteen but we haven't seen anyone copy it since. The model that has been widespread throughout the states where it's had uh you know common agreement is this model that has a core set of rights, a core set of obligations for companies um to make sure that their data is used responsibly and it's regulatory

Rep. Pallone (NJ-6)2:04:51 – 2:05:03

Do you know what happened in Europe after they passed the GDPR model? What happened to investment in Europe in in tech? Do you know? Miss Watts, do you would you care to guess?

Ashli Watts (Witness)2:05:03 – 2:05:18

Yeah, I would like to comment on that. The uh recently the European Commission has said that the over-regulation has harmed their econom- their economy. And when every day we talk to our consumers, our businesses about affordability, I do think it's a great concern to be going down the path of what Europe did

Rep. Pallone (NJ-6)2:05:18 – 2:05:50

Yeah, in fact there was a National Bureau of Economic Research found that the GDPR took, it took effect in twenty eighteen, um, has seen technology start-ups decline in Europe. And so when we talk about competing interests, right? When we talk about this in a global economy that we have, uh, what Europe did might have been an overreaction to a, a problem, and maybe what California did was an overreaction to a problem. So states like Kentucky seem to be trying to find the right balance. Is that fair to say?

Ashli Watts (Witness)2:05:51 – 2:06:02

I think it's absolutely fair to say, and like Miss Goodloe said, I think it's very important to note that California, no other states have passed the California model. We're pretty proud that many states have passed the Kentucky model,

Rep. Pallone (NJ-6)2:06:02 – 2:06:03

So they were the first,

Ashli Watts (Witness)2:06:02 – 2:06:03

or the Virginia model.

Rep. Pallone (NJ-6)2:06:03 – 2:06:05

but everyone said, we don't want any part of that.

Ashli Watts (Witness)2:06:05 – 2:06:06

It doesn't work for business.

Rep. Pallone (NJ-6)2:06:06 – 2:06:06

We don't want that.

Ashli Watts (Witness)2:06:06 – 2:06:09

It doesn't balance those rights of consumers as well as let

Rep. Pallone (NJ-6)2:06:07 – 2:06:08

Correct.

Ashli Watts (Witness)2:06:09 – 2:06:12

business flourish and innovate which is what we want them to do.

Rep. Pallone (NJ-6)2:06:12 – 2:06:20

Miss Watts, why do you think it's important, um, that this bill, the federal bill, uh, have, uh, a strong preemption on privacy laws.

Ashli Watts (Witness)2:06:21 – 2:06:43

I think it's important that businesses know what rules to follow. And like we've mentioned before, large businesses have teams of attorneys and privacy officers, and they can usually navigate the complexity of various state laws. I represent mostly small businesses who do not have that. They are dealing with workforce issues, with inflation and affordability, and all the things that small businesses deal with every single day.

Rep. Pallone (NJ-6)2:06:43 – 2:06:45

So if you're a big, big tech company

Ashli Watts (Witness)2:06:43 – 2:06:44

So

Rep. Pallone (NJ-6)2:06:45 – 2:06:50

You've got the lawyers to be able to navigate a fifty state patchwork of laws, right?

Ashli Watts (Witness)2:06:50 – 2:06:52

Yeah, of course. They have the footage to have to do that.

Rep. Pallone (NJ-6)2:06:51 – 2:06:57

But if you if you if you you and I decided to put a hundred bucks into the into the, a collection plate and start up our own tech company,

Ashli Watts (Witness)2:06:57 – 2:06:58

Yeah.

Rep. Pallone (NJ-6)2:06:58 – 2:07:02

would we have those same financial resources to navigate fifty state laws?

Ashli Watts (Witness)2:07:02 – 2:07:03

Absolutely not.

Rep. Pallone (NJ-6)2:07:03 – 2:07:06

So we stifle innovation if we don't do something about this.

Ashli Watts (Witness)2:07:06 – 2:07:06

Correct.

Rep. Pallone (NJ-6)2:07:06 – 2:07:08

Thank you for that, Mr. Chairman. I yield back.

Rep. Obernolte (CA-23)2:07:09 – 2:07:14

Thank you. The chair recognizes the uh gentlelady from Washington. Ms. Schreier, please.

Kate Goodloe (Witness)2:07:16 – 2:10:29

Thank you, Mr. Chairman. Uh, Congress has talked for years about passing comprehensive privacy legislation to give consumers the ability to keep their data private and secure. And so I'm really glad we're holding this hearing today to discuss policy that uh were long overdue in passing and I apre appreciate all of your comments. Um, the internet basically runs on your data. Um, there's the old adage, uh, if something is free, then you are the product. And I think we should all keep that in mind. Just about every app, every site, every interaction online is collecting personal data that companies can use and sell to their financial benefit and not necessarily or not at all comparably to yours. Um and it is almost impossible to track uh exactly when your data is being collected, and certainly impossible to track when it is where it goes afterwards and for what purpose. who's getting a hold of it. And that's why an enforceable right to privacy is so important. Um, but a national standard, although I understand the importance of preemption, um, it's useless if it's weak, and it doesn't actually give consumers control over their own data. And in fact, a national s- standard can be actually uh actively harmful if it overrides or fails to adequately replace the protections that have been passed already, in dozens of states. Um that would certainly be true for Washington State which passed the My Health, My Data Act into law in twenty twenty three. And this law protects Washington residents' health data beyond the limits of HIPAA. Uh HIPAA protects uh patients by preventing health care providers from sharing or selling your data. But it doesn't prevent other companies from tracking, analyzing, selling your health data that they collect in other ways. Um like HIPAA doesn't cover health tracking apps or wearable devices that are collecting unprecedented amounts of your biometric data, doesn't cover companies using your data to infer health conditions, uh from your purchasing history. I think we all remember uh people getting advertisements for cribs when they started buying prenatal uh vitamins at a certain large retailer. Um but the My Health My Data Act does, and it's been an enormous step toward giving Washington residents privacy when it comes to their health. It has strict data minimization standards and assures that companies have to gain explicit authorization to collect and sell personal health data and specifically that authorization cannot be part of a broad terms of use agreement, or through any kind of hidden or deceptive means. So um that means it can't be buried in just a long legalistic notice that no one ever reads or hidden behind a complicated menu of options. But the Secure Data Act would override this state law, and its health protections are not nearly as robust as Washington's states. So I fear that this would be a net loss for my constituents, and this would happen in a patchwork of states across the country. Um, Ms. Fitzgerald, thank you for all of your comments. Can you speak to the kinds of robust protections, uh, and data minimization standards that you would like to see for health data, specifically?

Caitriona Fitzgerald (Witness)2:10:30 – 2:11:19

Yes, thank you for the question. You know, just a discussion of whether GDPR and California overreacted to the problem, I think it's important that we also don't under-react to the problem. People are being harmed by these data practices every minute of every day and health data is a really good example of that so any federal privacy law should require that the companies collecting that data, limit it to what's necessary, you know, line it up with what the consumers expect, And then make sure not also that not only that the collection is limited, but also those uses, cuz often it's the secondary uses of our data where the harms really happen. You know, we expect our our fitness tracker to collect our health data and and provide those services but if they're selling it to third parties that's where the harm really really happens.

Kate Goodloe (Witness)2:11:19 – 2:12:14

That's right. And we've seen this with uh ability to get life insurance, health insurance, the ability to get car insurance when our data gets sold. without our authorization. Um, some of what concerns me about the Secure Data Act is that it places so much of the burden on consumers to navigate all these different opt-out um options to protect their their uh their data and the the functionality and the ease of use is really gonna make the difference here I think more burden should be put on the companies that have been profiting off this data pert to protect this data. And I really um ap- appreciate that the Bill commissions a study on universal opt-out. mechanisms, um but I think we need to take more action than just a study. And the reality is that Congress is playing catch up right now uh to the States, and I'm glad we're having this discussion, um but as Miss Fitzgerald you noted, in twenty twenty two we had a stronger bill.

Caitriona Fitzgerald (Witness)2:12:14 – 2:12:14

Mm-hmm.

Kate Goodloe (Witness)2:12:14 – 2:12:19

And I think it's time to return to that. We can do better, we should do better, and uh I yield back.

Rep. Obernolte (CA-23)2:12:20 – 2:12:24

Thank you. Chair recognizes Representative Kammack for five minutes please.

Rep. Cammack (FL-3)2:12:24 – 2:12:43

Thank you, Mister Chairman, thank you to our witnesses and all our guests here today. It's nice to see the committee room packed full. I'm gonna start with you, Miss Goodloe. In your testimony uh testimony you state that the Secure Data Act reflects the modern economy by recognizing different roles and responsibilities with respect to data especially differences between controllers and processors.

Kate Goodloe (Witness)2:12:43 – 2:12:44

Mm-hmm.

Rep. Cammack (FL-3)2:12:44 – 2:12:52

Can you discuss how the Secure Data Act distinguishes between these roles and responsibilities, why it's important to do so, and for folks watching at home, the difference between the two.

Kate Goodloe (Witness)2:12:53 – 2:13:33

Yes, thank you very much for the question. This is a core issue. for our members who are the business-to-business technology providers that are competing to provide privacy protective and security protective services to other companies. The distinction between controllers and processors is long-standing, widespread, found in every state privacy law, and it underpins modern privacy laws worldwide. It matters because if you conflate controllers and processors, you end up creating privacy risks for consumers. And it's important to know that controllers are the companies that decide how and why to use a consumer's data. Processors are the companies that handle that data on behalf of another company.

Rep. Cammack (FL-3)2:13:33 – 2:13:33

Mm-hmm.

Kate Goodloe (Witness)2:13:33 – 2:13:39

So one example is, if you join a gym and the gym keeps your data in the cloud cuz it's not gonna keep it in a file cabinet,

Rep. Cammack (FL-3)2:13:40 – 2:13:40

Mm-hmm.

Kate Goodloe (Witness)2:13:40 – 2:14:19

um the gym is deciding how to collect your data, why it's going to use that data, and it's giving it to the cloud storage company to handle it as the gym says on its behalf. So, the cloud storage company as a processor here. If we conflate these roles and the privacy law starts assigning the wrong obligations to the wrong type of company, what we've seen is it can require that cloud storage company to start looking at all the membership data that Jim stores with it. And we don't want that. The goal of a privacy law should be to minimize how companies review data and not require them to start looking at data that they otherwise would not. That can happen when we conflate these roles, that really goes against the goal of privacy legislation.

Rep. Cammack (FL-3)2:14:20 – 2:15:03

Excellent. Thank you for that. That's a perfect dovetail into my next question. So I'm gonna start with, I'm a very proud Floridian. Go Gators. Proud to represent the real Gator nation. And so many people on this committee know that I'm always talking about my Gators. So I am very pleased that this legislation, the secure data act, is building on existing state privacy and data security frameworks, like those that we have across the country, but in particular the sunshine state. So less than half the country has comprehensive privacy laws in place, and I believe that every American should benefit from the rights and protections that Floridians enjoy every day. So I'm gonna start with you. I'm gonna mess up your last name, so I'm gonna try really hard. Britegon? Ugh,

Tyler R. Bridegan (Witness)2:15:04 – 2:15:04

Yeah.

Rep. Cammack (FL-3)2:15:04 – 2:15:14

sorry. Can you share more about the consumer protections and rights that are laid out in the Secure Data Act, and why it's important that we have a uniform federal framework?

Tyler R. Bridegan (Witness)2:15:15 – 2:15:23

Yeah, you know, I I think the data minimization point is a really interesting one, and and harkening harkening back to the consent piece that we've been talking about.

Rep. Cammack (FL-3)2:15:23 – 2:15:24

Mm-hmm.

Tyler R. Bridegan (Witness)2:15:24 – 2:16:05

Because of consent, that that, although it's a somewhat amorphous standard, we know what it doesn't look like. I think we had some great examples of it does not look like that disclosure at the end of a privacy policy that requires to click a box. Um, again, it it and it consent interacts with data minimization in a really interesting way, which we saw um sort of from in from the enforcement lens, it um, does it, data minimization is somewhat not needed in a uh in for sensitive data because, um, it only, because you have to have consent, unless a co- unless a company is um, act- actively able to get that consent, if they collected that data they're, without that consent they're in violation of the law, it doesn't matter whether they needed it or not.

Rep. Cammack (FL-3)2:16:03 – 2:16:04

Exactly.

Tyler R. Bridegan (Witness)2:16:05 – 2:16:31

Um, so that that is a a sort of a a point to um, ju- just to keep in mind that the- these provisions are all interacting with each other. Also, data minimization is a - a frankly more difficult provision to enforce. Um, it is also a somewhat amorphous standard and sometimes, uh, you know, it - Har- harkening back to consent again, if someone violated the consent provisions, I would rely on that,

Rep. Cammack (FL-3)2:16:31 – 2:16:31

Mm-hmm.

Tyler R. Bridegan (Witness)2:16:31 – 2:16:52

um, as an enforcer to point to that they violated the law. I would not necessarily need to. I could add on a violation of data minimization, which is what California recently did. be- because California does not have consent protections for sensitive data, in the recent settlement with a, um, vehicle manufacturer a couple of weeks ago, they had to rely on their data minimization violation.

Rep. Cammack (FL-3)2:16:52 – 2:17:11

Well, and I know you wanna finish that thought, so I'm gonna ask you to finish that thought in writing, cuz I wanna do a quick rapid fire across the whole panel. When we're talking about data and data privacy, when it comes to a consumer, should they have the option to opt in or out when they are signing up for a service? and i'm just gonna start with you and we'll go down the line opt in or opt out

Tyler R. Bridegan (Witness)2:17:13 – 2:17:16

for for both dated for sensitive and non-sensitive

Rep. Cammack (FL-3)2:17:17 – 2:17:19

let's just go broadly and say non-sensitive

Tyler R. Bridegan (Witness)2:17:19 – 2:17:21

non-sensitive uh that would be an opt out

Rep. Cammack (FL-3)2:17:21 – 2:17:21

k

Caitriona Fitzgerald (Witness)2:17:23 – 2:17:26

the company should have to limit what they're collecting and using it should not be on the consumer

Rep. Cammack (FL-3)2:17:26 – 2:17:29

so they should be forced to so consumers should opt in

Caitriona Fitzgerald (Witness)2:17:30 – 2:17:35

they should not be presented with constant pop-ups that will make their internet experience unusable

Rep. Cammack (FL-3)2:17:35 – 2:17:35

ok

Ashli Watts (Witness)2:17:36 – 2:17:37

our bill in Kentucky would be opt in

Rep. Cammack (FL-3)2:17:37 – 2:17:38

ok

Kate Goodloe (Witness)2:17:38 – 2:17:46

For n- nonsensitive data, I think opt-out has been the standard in part to avoid having too many consent requests going to consumers.

Rep. Cammack (FL-3)2:17:46 – 2:17:57

Okay, I'm gonna say, Miss Watts, I'm with you on this one. I think there should be a blatant opt-in in order for people's data to be shared. But I have a final question. I'll submit it for the record. I appreciate y'all's prompt responses. Thank you. I yield.

Rep. Obernolte (CA-23)2:17:58 – 2:18:02

Thank you, the chair, and I recognize the gentleman from Florida, please. Mr. Soto, five minutes.

Rep. Soto (FL-9)2:18:03 – 2:21:50

Thank you, Mr. Chairman. You know, Americans are desperate to take back our privacy rights. For generations people conducted transactions without a trail of their personal data left behind. Imagine when I was a kid going to major retail stores or to the mall or all these other places and they didn't get your biometric mat- data they didn't get your religion, they didn't get so many different things that now uh we have to protect. Uh but now that we're online, every transaction leaves a long trail of bread crumbs and it uh has fundamentally changed uh the dynamic between consumers and uh and businesses. Americans wanna own their own personal data. We wanna more control over, we wanna protect it from misuse, uh that's why we have so many people here today sharing those same values, and we especially wanna protect our kids. Uh the personal data that is recognized as uh sensitive is a good list, I I do agree with it. Health and DNA data, geolocation, calendar, children's data, religion, immigration, status, ethnicity and others, these are things that people uh should be able to protect if they want to. Uh yet the enforcement is is lacking. Uh rules without a strong enforcement is like a tiger without teeth. Uh no cause of action means we can't have strong uh we can't have a strong cause of action without we need a strong cause of action and preemption together that's reasonable. If you do one without the other, you could actually have really unintended consequences. So if you have strong preemption but then you block state causes of action, and you have no federal relief, then you've actually just shut the door on a lot of these states we've heard from both Kentucky and Texas today um on their on their uh regimes that they have. And then when you look at what the FTC can do, it it they really can't take meaningful action in this bill. They they uh can't address civil rights issues or protect personal data, they can refer it to attorney generals. And uh and this is where I get deeply concerned about the bill. Uh if you leave this all to state attorney generals, you're gonna have different enforcement by different attorney generals by how aggressive they wanna be, and how much they wanna deal with thousands and thousands of complaints. So you go from a patchwork of laws in the states to a patchwork of enforcement. depending what the uh the uh the attorney general wants to do. You know I know a lot of states, they've done these privacy laws, but have not included a private cause of action. My own state of Florida, although there are three common law privacy claims that you can make, like appropriation, intrusion, and public disclosure of private facts. Um but I noticed Kentucky and Texas, no cause of action either, right? And so we're giving a lot of work to the state attorney generals and uh And I worry that whether they're gonna be equipped to handle this kind of volume. Uh, my opinion, you know, we at least have to have injunctive relief and a and attorney's fees available, so that most people can't afford to hire an attorney just to do some personal data violation that they have. Uh, and you need to make sure you could take down the information that you wanna take down. And so we could argue about anything beyond there, about proper compensation, whether we have it or not, but injunctive relief and the ability to make sure you can hire an attorney is absolutely critical. if we're gonna have stronger preemption provisions on the federal level. And I get it, this is interstate commerce, it's the internet, it's in flowing through different states. Uh, and so, uh, first, Miss Fitzgerald, um, what happens when consumers face violations of their privacy but they can't go to court to fix it? What is traditionally what are you seeing across the states right now? What how quickly can get they get their data off-line?

Caitriona Fitzgerald (Witness)2:21:50 – 2:22:37

Yeah, unfortunately, without a private right of action, there's little they can do. Um, and I think, you know, it's really important when we're talking about a private right of action to recognize that it's not an all or nothing proposition, you know, if it We can talk about small business carve outs for a private right of action. The bipartisan bill that passed this committee on a vote of fifty-three to two, included a compromised private right of action that focused on injunctive relief and and actual damages to avoid some of the issues that were raised earlier. So you know, I think if if uh both sides come to the table and we can come up with a compromise, there are ways where individuals would have the ability to enforce their privacy rights as opposed to you know what's in this bill right now which is they're kind, they're left without a remedy.

Rep. Soto (FL-9)2:22:37 – 2:22:55

I'm glad you mentioned the small business exceptions. So we're not talking about someone with one little web site that makes a mistake, they're one of your local barbershops or general stores or or other uh restaurants or retail establishments. So where do you think the small business exceptions should fit in? Cuz that's very important.

Caitriona Fitzgerald (Witness)2:22:56 – 2:23:35

Yeah, states have been, you know, considering um private rights of action, you know, it it has struggled to get across the finish line, but um one option is, you know, set a revenue threshold or set a threshold of companies that only collect over X amount of of personal data, and only have the private reaction r right of action applied to them. Because as you mentioned, state attorney generals are under-resourced, overworked, um, and if you're talking about cases against some of the biggest companies in the world, and they have two or three Assistant Attorney Generals in a privacy division, you're talking about five years of those people's time. And that's gonna be, you know, taking up their entire workload and not being able to enforce.

Rep. Obernolte (CA-23)2:23:34 – 2:23:42

Time's expired. Thank you. And the uh, Chair recognizes the gentleman from Ohio, Mister Balderson, for five minutes, please.

Rep. Balderson (OH-12)2:23:42 – 2:24:23

Thank you, Mister Chairman, and thank you all for being here today. Uh, my first question is for Mrs. Watts. Um, good afternoon. Um. Last Congress, this committee considered data processing rules or data minimization standards that were equivalent to Europe's burdensome general data protection regulation. According to economic analysis, if the US were to adopt European style data standards, like some are proposing, it could cost the US up to one hundred and twenty-three billion dollars and cost up to three hundred and forty thousand jobs. Can you discuss the impact that strict European style data standards would have on businesses, especially small and main street?

Ashli Watts (Witness)2:24:24 – 2:24:30

Absolutely. Thank you for that question. Representing small businesses in Kentucky, which obviously borders your great state.

Rep. Balderson (OH-12)2:24:30 – 2:24:30

Yes.

Ashli Watts (Witness)2:24:30 – 2:25:05

Uh, we're really proud to make sure to protect small businesses in our state law in Kentucky. We know that the European Commission has now said that the over-regulation has actually harmed their economy. And I know much like you, which borders our state, we are dealing with affordability. and the cost of small business to just uh keep their businesses open every day, and we really can't risk that. So we definitely do not need to go down the path of having a European style model. They have now been on record of saying the overburden some regulations have harmed our economy you quote it yourself it could cost up to three hundred and forty thousand jobs. We absolutely do not need that in the United States.

Rep. Balderson (OH-12)2:25:05 – 2:25:34

Thank you very much, Mrs. Walsh. I appreciate that answer and we love Kentucky, Ohioans do. Uh, my next question uh is for Mr. Breitigan. Uh, thank you for being here, sir, also. Um, some advocates s argue that these European style data standards are necessary to protect consumers. In your opinion, as a former privacy and technology enforcement official, what affects what adopting those stricter European style rules have on consumers and their privacy?

Tyler R. Bridegan (Witness)2:25:35 – 2:26:50

Yeah, I I think, you know, as I as alluded to in the my opening, we have now learned a lot about sort of emerging privacy harms and which protections actually can help consumers and help regulators to go after um those privacy harms, and which can't, you know, including additional language in a privacy policy that's prescriptive, there's not necessarily an any tangible benefit because they're the consumer, you know, and all of us don't tend to read those privacy policies. So there's a there's a balance that, you know, I think needs to be struck of what is prescriptive in the sense that it's actually getting to those core privacy harms, and I've harped a lot about sensitive data, you know, that is just one category that is an area where there needs to be heightened protections. We have seen that on a bipartisan basis. Illinois, Washington, Texas all have heightened data standards for sensitive data types. Um, and several of them have stand-alone privacy laws for just those sensitive data types. And so, I think it's important to keep in mind and really think through which requirements are actually protecting consumers from privacy harms. And I I think there's a California has a long list of uh a long law a lot of regulations that i would struggle to see how a violation of many of those actually resulted in a tangible privacy harm

Rep. Balderson (OH-12)2:26:50 – 2:27:17

ok thank you very much for that detailed answer i appreciate that uh my next question uh is for miss goodloe um thank you for being here ma'am small businesses that sell products online may interact with customers in all fifty states even though they're often run out of a single storefront or a garage how does this how does the existing patchwork of privacy requirements complicate day-to-day operations for those businesses and i'll have a follow-up for you

Kate Goodloe (Witness)2:27:18 – 2:27:22

right i think thank you for the question right now companies are required

Rep. Balderson (OH-12)2:27:20 – 2:27:20

mmm

Kate Goodloe (Witness)2:27:22 – 2:27:47

to track fifty moving goal posts to do business in the united states as long as they are serving customers in more than one state they need to keep track not only of the twenty-two states that have already enacted laws but of the many states that are already revising and amending those laws and by my count to thirty amendments. We need a clear national standard that sets one set of rules so that companies can operate nationwide and know how to protect consumers' privacy.

Rep. Balderson (OH-12)2:27:47 – 2:28:00

Thank you. Uh, my follow-up then, uh, and we have about a minute left. In contrast, how would establishing a single national standard under the secure data act make it easier for them to serve customers across state lines?

Kate Goodloe (Witness)2:28:01 – 2:28:26

I think it tells them what to do. Our companies as business-to-business technology providers are in the business of competing to provide privacy protective and security protective services, they want to comply with strong privacy laws because their customers demand it. When they know the rules, when there's a single clear rule, and regulatory-led enforcement, it helps them know what to do to focus on core protections for consumers and providing one standard can do that.

Rep. Balderson (OH-12)2:28:26 – 2:28:28

Thank you very much. Mr. Chairman, I yield back.

Rep. Obernolte (CA-23)2:28:29 – 2:28:31

Thank you. Chair recognizes Representative Trahan for five minutes.

Rep. Trahan (MA-3)2:28:34 – 2:29:53

Well, I thought I was I thought I was ready here. Thank you, Mr. Chair. Um, I wanna thank the uh panel uh as well. You know, a federal consumer privacy law is certainly long overdue. Uh, there's broad agreement on that, but I do worry that this Congress is going to again fail to make progress uh on it. I appreciate Representative Joyce uh and the committee's work on the Secure Data Act. But I'm concerned that it falls short in a few ways, and I'm gonna use my time to identify one of them. Uh, and that's the unique harms that data brokers perpetuate and advanced artificial intelligence exacerbates. Today, AI can be used to correlate data from acro- across data sets, meaning anyone with access to an AI model can purchase your data from a broker and paint a very intimate picture of your life, from your location to your browsing data and your purchases. Ad actors can infer your sexual orientation, how much money you earn, and where you work, study, or worship. Miss Fitzgerald, how can AI now draw these kinds of inferences about people who never knew that their data was collected, and never consented to it? And what are the privacy risks of advanced AI systems built on data acquired from data brokers?

Caitriona Fitzgerald (Witness)2:29:54 – 2:30:25

Yes, thank you for that question. AI is turbo-charging the ability for companies to make inferences about consumers, and that's leading to data discrimination, um and you know, surveillance pricing is another harm that consumers really can't stand, um that is being being uh turbocharged by AI, and strong data privacy legislation is a really critis critical baseline protection um to protect Americans from the harms of AI. It doesn't do everything, but it's a really important first step.

Rep. Trahan (MA-3)2:30:25 – 2:30:56

Thank you. Uh that that as you mentioned it's so critical that data privacy legislation provides Ameri- Americans a meaningful way to prevent their data from being collected, stored, or sold by data brokers. While the bill requires data brokers to allow Americans to opt out, this must be repeated for every data broker, meaning that you might have to opt out of hundreds if not thousands of times. I have a bill, the Delete Act, which would give Americans control over their own data by allowing them

Caitriona Fitzgerald (Witness)2:31:13 – 2:31:13

Yes,

Rep. Trahan (MA-3)2:31:13 – 2:31:13

Hmm.

Caitriona Fitzgerald (Witness)2:31:13 – 2:31:24

uh, a centralized deletion mechanism is especially important when we're talking about data brokers, because these are companies that consumers don't know, have their data, don't even know exist, for the most part.

Rep. Trahan (MA-3)2:31:23 – 2:31:23

Yep.

Caitriona Fitzgerald (Witness)2:31:24 – 2:31:33

I don't think many Americans could name a data broker for you. Um and they've never interacted with these companies, so they um don't know who to go to to ask to delete their data.

Rep. Trahan (MA-3)2:31:32 – 2:31:32

Yep.

Caitriona Fitzgerald (Witness)2:31:33 – 2:33:20

So the centralized deletion mechanisms are really important. There's a reason it's been incredibly popular in California in just the five months since it went into effect three hundred thousand Californians have taken advantage of it um and I think that shows the desire Americans have to protect their information from data brokers. But even a universal opt-out has a loophole here. Uh, the bill bars Americans from Yeah, thank you for that question. Cuz it highlights something that hasn't been raised yet, today. Um, there's an exemption in this bill for de-identified and synonymous data, as you mentioned, and uh synonymous data in particular is problematic because it includes things like our advertising ID and our IP address. These are identifiers that companies are using to track us across the internet, and by exempting them from the consumer rights in this bill, from exempting them from the opt-out, it, you know, it almost makes the opt-out meaningless because they're not, you know, often identifying it with my name, they're identifying it with my advertising ID. Um So uh The FTC has long held a position that um pseudonymizing identifiers or uh, th- it does not render data anonymous. So that is not something that should be exempted. And then in the case of de-identified data, yes, there has been, there have been many cases where de-identified data has been able to be um, re-identified back to the original consumer.

Rep. Trahan (MA-3)2:33:21 – 2:33:38

Thank you. Look, I think, I believe there's agreement across the aisle that Congress must act to protect Americans' privacy as a number of states have already done the recent advancements with AI make this issue even more urgent but this bill as written fails to meet the moment so I look forward to working with my colleagues, and I yield back. Thank you.

Rep. Obernolte (CA-23)2:33:38 – 2:33:42

Thank you. The chair recognizes the gentleman from Colorado. Mister Evans, please, for five minutes.

Rep. Evans (CO-8)2:33:43 – 2:35:10

Thank you, chair, of course, to the ranking member for this hearing and to the witnesses for coming today. Um. secure data secure uh excuse me strong data security is essential for protecting consumers in today's digital economy. The FBI's internet crime complaint center showed that consumers lost more than twenty billion dollars in fraud just last year. Uh in Colorado there was a total financial lost of three hundred and fifty five million dollars statewide and that's an increase of more than two hundred and fifty percent, since twenty twenty. Colorado's got one of the fastest aging um populations in the nation and we see scammers and fraudsters are explicitly targeting seniors with complex schemes and fishing traps i saw it during the ten years that i spent as a cop in the denver metro area and unfortunately colorado has the third worst rate in the nation for senior fraud we've got malicious cyber actors weak data security uh these are some of the reasons um that americans are facing a fraud epidemic and it's why pleased to see the secure data act requiring companies to adopt some common sense data security measures to protect constituents like mine from these fraud impacts. And so, Miss Guedelow, first question uh to you, since you're here from the Business Software Alliance, can you share how the secure data act's data security requirements work in practice and how the industry can integrate them with existing policies?

Kate Goodloe (Witness)2:35:10 – 2:35:50

Yes, thank you for the question. I think this is a very important issue when we think about the privacy legislation. The Secure Data Act requires controllers to adopt reasonable security measures, to make sure that data is kept uh secure and confidential. What that means in practice is that companies have to establish, implement, and maintain data security practices. And we see this requirement already across state laws, and it needs to apply nationwide. The Secure Data Act also tells companies how to do this because it creates a rebuttable presumption that they satisfy this obligation if they use leading tools like cyber security risk management frameworks that have set the gold standard globally

Rep. Evans (CO-8)2:35:52 – 2:36:49

thank you so much the the next uh question will be to mister breitigan uh we know prevention is the first step in making sure that people's data stays safe from fraud and from these malicious actors but we still need to be able to go and prosecute the bad guys when they because they sit around all day long and try to figure out how to hack and bypass these uh security protocols uh you know security isn't static So when you have malicious actors that still work overtime to go out and do bad things, defraud Americans, we gotta have the ability to go get those guys. And so I'm pleased to see that the National Insurance Crime Bureau has sent a letter supporting the Secure Data Act, um, because this, uh, helps us not only detect, prevent, and deter deter insurance, um, fraud and financial crimes and related crimes, it also helps us work with law enforcement to be able to go and get the bad guys. So can you talk a little bit about how the Secure Data Act works with law enforcement to protect Americans?

Tyler R. Bridegan (Witness)2:36:49 – 2:37:28

Yeah, I think in general, the more cyber requirements that companies are required to implement, the more the greater the chance that law enforcement can do its job, because the more protections you have on the front end, you're collecting more information about those threat actors. Um, and ultimately you can coordinate with law enforcement to help go after them. We recently recovered on behalf of a client that was defra- a financial institution that was defrauded of six figure amount, um, go after the fraudsters civilly because of our work with law enforcement who was able to do go after them criminally. Um, so it's an incredibly complex scheme, but it is permeating throughout the United States, as you alluded to.

Rep. Evans (CO-8)2:37:29 – 2:38:06

And then my final question, and this is unfortunately a just a tragically horrifying statistic. Colorado's got two percent of the nation's population, but we're ten percent of the human trafficking in the nation. And lot of these are kids uh that are being subject to this, and we know that when you have human trafficking, there's money transactions, there's a lot of digital footprint that's involved here. And so again, we want data privacy for Americans, but we also have to be able to interrupt not just the financial crime space, but we have to be able to trace that back and untangle that to horrific crimes like human trafficking and human trafficking of minors. So can you talk in my remaining

Tyler R. Bridegan (Witness)2:38:18 – 2:38:47

Yeah, you know, again, it it's this bill helps create that um information flow between law enforcement and the private sector. The FBI has done a great job um over the past decade or so holding itself out as a partner to companies that are um you know, either observing crime or, um, the target of fraud. And so, you know, there has been that palpable shift over the past decade to really encourage that coordination which I think is so key to sort of getting out the core issues here.

Rep. Evans (CO-8)2:38:48 – 2:38:49

Thank you so much, and I'm out of time. You're back.

Rep. Obernolte (CA-23)2:38:49 – 2:38:53

Thank you. The chair recognizes a ranking member for one minute, please. Ms. Schakowsky.

Rep. Schakowsky (IL-9)2:38:55 – 2:39:15

I'm, I'm cons- I am concerned that this bill right now protects companies and not people. And that what we really need to do is protect our everyday people. And that's not happening right now.

Rep. Obernolte (CA-23)2:39:17 – 2:39:20

Thank you. The chair recognizes the gentleman from Ohio, Mister Joyce, for five minutes.

Rep. Joyce (PA-13)2:39:21 – 2:39:25

Uh, from Pennsylvania, the other Joyce, but uh it's g- it's good to be with you. Thank you.

Rep. Obernolte (CA-23)2:39:25 – 2:39:26

My apologies about this. Sorry.

Rep. Joyce (PA-13)2:39:26 – 2:41:54

Thank you. Uh, thank you for our witnesses for being here. Thank you for participating. in this candid conversation. To start, I'd like to rebut a shallow attack on the Secure Data Act that the sh- the Secure Data Act's consensus approach is flawed because it's based on over twenty states, blue, red, and purple states. To that end, Mister Chairman, I'd like to enter into the record a May eleventh, twenty twenty-two press release from the well-known consumer advocacy uh group Consumer Reports, that's entitled Connecticut governor signs comprehensive bill into law that explicitly states, this year we saw giant tech companies push weak bills at the state level. So we are especially pleased to see Connecticut sign a strong law that will extend real privacy protections to its citizens. In May, twenty twenty two, a Connecticut law that was modeled on Virginia, modeled on Colorado, and modeled on Utah laws, was dubbed by consumer advocates as extending real privacy protections, protections to consumers and not the product of giant tech companies. Yet today, a federal law that is modeled and centered on those exact laws, and extends privacy protections to all Americans is somehow in retrospect all just part of a some multi-year multi-dimensional scheme by big tech to ultimately create a federal standard. This is a clear example of how consumer groups will move the goalposts not based on what is working for the consumers but rather on a desire to hamper legitimate uses of data that benefit American consumers and American workers. For far too long, consensus on federal privacy reform has been elusive. And a lack of that consensus has pled le has plagued legislation in multiple Congresses. As I shared at the beginning of this hearing hours ago, I'm committed to working with my colleagues on both sides of the aisle, as well as stakeholders, to advance the strongest possible bill out of this committee and onto the House floor. Miss Watts, why do you believe that the consensus state approach to comprehensive privacy and data security offers the best pathway forward to consensus from the federal level.

Ashli Watts (Witness)2:41:55 – 2:42:05

Yes, thank you for that question. Thank you for all of your work uh on this bill. We are really proud in Kentucky to have had a consensus-based bill that passed unanimously through our General Assembly and was signed into law.

Rep. Joyce (PA-13)2:42:05 – 2:42:06

How's it working?

Ashli Watts (Witness)2:42:06 – 2:42:15

Uh, it's working great so far. It just went into effect in January, so it passed in during the General Assembly of two thousand and twenty-four. It is now full effect. We actually just checked with our Attorney General.

Rep. Joyce (PA-13)2:42:15 – 2:42:16

You worked hard to get that.

Ashli Watts (Witness)2:42:16 – 2:42:24

We worked very hard and I will say for a couple of years we really wanted a federal bill. We wanted kind of you all to take that step so that there was not gonna be a patchwork.

Rep. Joyce (PA-13)2:42:25 – 2:42:26

This passed unanimously, you said earlier?

Ashli Watts (Witness)2:42:26 – 2:42:29

It passed unanimously and we are a super majority.

Rep. Joyce (PA-13)2:42:29 – 2:42:31

And it was a super majority of which side?

Ashli Watts (Witness)2:42:31 – 2:42:32

Republicans, uh

Rep. Joyce (PA-13)2:42:32 – 2:42:33

And who signed it into law? A

Ashli Watts (Witness)2:42:34 – 2:42:35

Democratic governor, I think this year.

Rep. Joyce (PA-13)2:42:34 – 2:42:39

And this shows that this is a bipartisan concern and we and the US House of

Ashli Watts (Witness)2:42:38 – 2:42:38

Completely.

Rep. Joyce (PA-13)2:42:39 – 2:42:57

Representatives understand that and can work in a bipartisan lev manner to make this effective. Um, Miss Miss uh Godot, can you please talk to us about comprehensive privacy and data legislation from a whole economy regulation because you deal business to business,

Ashli Watts (Witness)2:42:58 – 2:42:58

Mm-hmm.

Rep. Joyce (PA-13)2:42:58 – 2:43:15

and you understand the entire economy s from the tech sector, and that the Secured Data Act will grant consumer rights and protections across all industries from life sciences to real estate to manufacturing. Talk to me how that will affect that business to business relationship.

Kate Goodloe (Witness)2:43:16 – 2:43:56

So we think um well I should start by saying thank you for all of your work with the working group to work on pushing forward comprehensive federal privacy legislation. We deeply appreciate that because this matters to BSA member companies. We have long supported federal comprehensive privacy legislation because it is important to the national economy. Companies of all sizes and in all industries rely on technology. BSA BSA represents the business to business technology providers that power uh businesses in every sector. And so what we see is a need for a single standard that sets the right level of consumer protections for companies nationwide and across sectors.

Rep. Joyce (PA-13)2:43:57 – 2:45:04

That US digital economy that supports all sectors, supports over twenty eight million American jobs, which means that the stakes are serious for so many Americans. We need to get privacy right. And we've seen in Europe that embracing impractical and burdensome approaches to privacy results in stagnation and results in job losses. The Secure Data Act is a result of a consensus framework. I think it was Justin Brandeis who said eighty or ninety years ago, that the states are the laboratories of democracy. We took that very seriously. We looked at the twenty plus states that have privacy acts. This is our opportunity to bring consensus-based legislation that protects consumers first and foremost and gives certainty to American businesses to stop moving the goalposts. Once again, I look forward to working with all of my colleagues on both sides of the aisle to advance the Secure Data Act. Again, I thank you for being here with us on this long morning, and, Mister Chairman, I yield back.

Rep. Obernolte (CA-23)2:45:04 – 2:45:09

Thank you, and the uh Chairman appreciates the good gentleman from Pennsylvania.

Rep. Joyce (PA-13)2:45:08 – 2:45:09

No.

Rep. Obernolte (CA-23)2:45:11 – 2:45:36

Ask unanimous consent that the documents in the staff document list be submitted for the record, without objection, so ordered. Like to thank our witnesses for being here today. Members may have additional written questions for you. I'll remind members they have ten business days to submit questions for the record and ask the witnesses to respond to the questions promptly. Members should submit their questions by the close of business June seventeenth. Without objection, subcommittee is adjourned.

Morning digest

Start every morning briefed on yesterday’s hearings

A free weekday email covering yesterday’s hearings and transcripts newly unlocked in the archive.

Free weekday email. Unsubscribe anytime.