This article was featured in Tech Policy Press.
The COVID-19 pandemic relegated data privacy to the backburner on the public policy agenda. But discussions of a federal data privacy law — which, to date, the U.S. lacks — have resumed in Congress. Proponents argue it would provide much-needed protections for citizens whose personal information continues to be excessively harvested by internet platforms like Google and Facebook.
But a federal data privacy law would likely accomplish another goal: curbing the impact of online disinformation.
Events of the past four years have crystallized the dangers of online disinformation. In 2016, Cambridge Analytica harvested data from eighty-seven million Facebook profiles to target individual US voters with political advertisements. In 2017, members of the Myanmar military relied on Facebook's data repositories to identify and target the country's Muslim Rohingya minority, precipitating a genocide. And throughout the pandemic, foreign actors have sought to spread disinformation about COVID-19, sowing doubt in vaccines and fanning partisan divide.
A data privacy law wouldn't rid the digital universe of these bad actors. But it would render them less effective: without detailed data on users' political beliefs, search history, consumption habits, and location, disinformation campaigns become weapons without a target.
Europe's General Data Protection Regulation (GDPR), which went into effect in May 2018, is considered the gold standard in privacy regulation globally. A report by the Internet Policy Review found that GDPR has reduced unlawful political micro-targeting, and proven to be an effective tool for limiting disinformation and political manipulation. A well-crafted federal privacy bill that mirrored GDPR would allow the U.S. to reap similar benefits.
Three Core Provisions
The key for federal policymakers is to produce a bill that includes the provisions that have made GDPR successful. Specifically, a federal data privacy bill must address three core issues: consent, purpose limitation, and accessibility.
First, the law should require the biggest technology companies to receive explicit consent to collect user data. Currently, Facebook and Google automatically opt in users to data collection. Federal law should require companies to make opt out their default privacy setting, allowing users to make an informed decision about how much personal information they want to share.
Second, the bill should include a purpose limitation provision that limits the information the largest tech platforms are entitled to sell to third parties. Facebook and Google should be barred from sharing users' political views, private messages, photos and facial recognition data. Establishing commonsense guardrails will make it harder for bad actors to access sensitive information.
Third, big tech companies should be required to maintain documentation of the user data they collect, including the metadata that drives their advertising business. Users should be able to access this information at any time, and request to have it erased.
Enforcement Matters
Without strong enforcement, a federal data privacy law is unlikely to be effective. A 2011 consent decree with the FTC bars Facebook from sharing user data without obtaining explicit consent — and yet, the company routinely continues this practice.
Therefore, the Senate should also pass the Data Protection Act, introduced by Senator Kirsten Gillibrand (D-NY), which proposes creating a U.S. federal data protection agency. If this sounds like a pipedream, consider recent history: Elizabeth Warren's proposal for a Consumer Financial Protection Bureau materialized within months of Obama's presidency and has since returned $12 billion to 29 million Americans who fell victim to financial wrongdoing.
Mark Zuckerberg, Sundar Pichai and other Silicon Valley executives have argued against a comprehensive federal privacy bill, claiming that unchecked data collection helps small-and-medium sized enterprises as much as it helps the largest platforms. But such arguments don't hold up to scrutiny. In the two years since GDPR was passed, 90% of EU citizens have opted in to online data collection — suggesting that if consumers find targeted advertising useful, they will choose to opt in regardless.
A federal data privacy bill has notable limitations. Facebook and Google have done their best to sidestep GDPR compliance. But unlike content moderation proposals — which raise difficult First Amendment questions and require platforms to make inherently subjective editorial decisions — a data privacy law restricts the supply of data that makes disinformation so potent, without touching speech itself. That makes it both more targeted and more durable as a policy tool.
