Schatz Leads Group of 15 Senators In Introducing New Bill To Help Protect People’s Personal Data Online
Data Care Act Will Stop Websites and Apps from Using Personal Data Against Users, Protect User Information from Hacks, and Hold Companies Accountable for Misuse
WASHINGTON – Today, U.S. Senator Brian Schatz (D-Hawai‘i), the top Democrat on the Senate Communications, Technology, Innovation, and the Internet Subcommittee, led a group of 15 senators in introducing new legislation to protect people’s personal data online. The Data Care Act would require websites, apps, and other online providers to take responsible steps to safeguard personal information and stop the misuse of users’ data.
“People have a basic expectation that the personal information they provide to websites and apps is well-protected and won’t be used against them. Just as doctors and lawyers are expected to protect and responsibly use the personal data they hold, online companies should be required to do the same. Our bill will help make sure that when people give online companies their information, it won’t be exploited,” said Senator Schatz.
Doctors, lawyers, and bankers are legally required to exercise special care to protect their clients and not misuse their information. While online companies also hold personal and sensitive information about the people they serve, they are not required to protect consumers’ data. This leaves users in a vulnerable position; they are expected to understand the information they give to providers and how it is being used – an unreasonable expectation for even the most tech-savvy consumer. By establishing a fiduciary duty for online providers, Americans can trust that their online data is protected and used in a responsible way.
“Online service providers should be required to act in the best interests of their customers, just like providers of other critical services,” Senator Hassan said. “Consumers should not be required to wade through and interpret pages of dense terms and conditions agreements, and it is not realistic in today’s digital world to suggest that people could simply forgo online services and websites if they object to the way their data is being used. This commonsense legislation establishes a legal obligation for online service providers to act in the best interests of consumers so that people can trust that their data is being protected and used responsibly.”
“It’s long past time we rethink how our personal data is collected, stored, and shared online,” said Senator Bennet. “Websites and apps that profit from our data should be held accountable for how they use it. The Data Care Act will ensure internet companies use our online data as we expect them to: in our best interest.”
“With major hacks or data leaks of private user information at Facebook, Marriott, Google, Equifax and Uber in just the last year or so, it’s abundantly clear that Congress must do more to protect Americans’ personal data online,” said Senator Duckworth. “Health professionals and financial advisors have long been responsible for handling personal information with the consumer’s best interests in mind, it’s time we extend this commonsense principle to websites and online providers. I’m proud to join Senator Schatz in introducing this important legislation to do just that.”
“Online platforms are collecting an enormous amount of personal data on Americans – everything from what we buy and what websites we go to, to what our emails say and where we go throughout the day. These companies are making billions off of this data and they’re keeping Americans in the dark about how it is being used. That’s wrong and it is especially alarming because it seems like every day we hear about new data breaches. It is clear that we must do more to protect consumer privacy. The Data Care Act will help by establishing a duty of care for sensitive data and by ensuring the FTC can hold companies accountable when they fall short. The digital space can’t keep operating like the Wild West at the expense of our privacy,” said Senator Klobuchar.
“As we see more and more often, consumer data is being used and abused in ways few people had imagined before. Now, it’s on Congress to ensure consumer protections keep pace with this changing reality,” Senator Murray said. “This legislation being introduced today makes clear that the companies we entrust with our personal information will not only be held to a higher standard, they will face penalties if they breach our trust.”
“Consumers understand now more than ever that their data is valuable and vulnerable to misuse. Everyone should be able to trust that their data is being protected and used properly. The Data Fiduciary Act is one significant step towards restoring that trust,” said Senator Booker.
“Everyone who uses the internet is vulnerable to the misuse of their personal data by websites, apps or third party businesses. By establishing a special fiduciary relationship between online providers and users, companies that use or sell people’s data will be held responsible for keeping consumers safe from harm, data breaches, and unnecessary invasions of privacy,” said Senator Cortez Masto. “I’m proud to support this bill, which will allow the FTC to work with State Attorneys General to ensure service providers strengthen personal data protections and protect the security of American consumers’ sensitive personal data.”
“As our daily and digital lives become increasingly intertwined, Americans expect online companies to protect the security of our sensitive data,” said Senator Heinrich. “There must be meaningful oversight of how companies are collecting and sharing personal data to ensure that Americans’ civil liberties and privacy rights are protected. I’m proud to support this legislation that will defend our personal data from improper use, violations of individual privacy, and security risks.”
“In today’s digital economy, personal data is everywhere, and those who have access to Americans’ sensitive information have a responsibility to protect that information and keep it private. It is time for Congress to enact comprehensive privacy legislation, and the Data Care Act would be an important part of that effort,” said Senator Markey.
“Protecting consumers from exploitation and holding companies that misuse data accountable should be a no-brainer for this Congress. I hope my colleagues in the Senate will help us pass this meaningful legislation without delay,” said Senator Brown.
“Far too many times, we have seen online providers fail to meet their users’ expectations about how their personal data will be collected, used and protected. The current system is skewed against consumers and we have to fix it. The Data Care Act will provide clear, reasonable rules of the road on user data, and hold companies who fail to follow them accountable,” said Senator Baldwin.
“The right to online privacy and security should be a fundamental one. Companies that profit from consumers’ online activity have a responsibility to protect personal information and make clear how they use their data. The Data Care Act is a smart first step to increase accountability in the use of private personal information,” said Senator Jones.
“In today’s era of ‘big data,’ Americans are using the internet every day without fully understanding the consequences of every click and whether that click just handed over their personal data for unwanted uses. This is simply unacceptable. Websites, apps, and other online providers should be required to protect their users personal data. This bill is a sensible step in protecting consumers’ personal data and I’m proud to join my colleagues in introducing it,” said Senator Durbin.
In addition to Schatz, the Data Care Act is co-sponsored by U.S. Senators Maggie Hassan (D-N.H.), Michael Bennet (D-Colo.), Tammy Duckworth (D-Ill.), Amy Klobuchar (D-Minn.), Patty Murray (D-Wash.), Cory Booker (D-N.J.), Catherine Cortez Masto (D-Nev.), Martin Heinrich (D-N.M.), Ed Markey (D-Mass.), Sherrod Brown (D-Ohio), Tammy Baldwin (D-Wis.), Doug Jones (D-Ala.), Joe Manchin (D-W.Va.), and Dick Durbin (D-Ill.).
The Data Care Act establishes reasonable duties that will require providers to protect user data and will prohibit providers from using user data to their detriment:
- Duty of Care – Must reasonably secure individual identifying data and promptly inform users of data breaches that involve sensitive information;
- Duty of Loyalty – May not use individual identifying data in ways that harm users;
- Duty of Confidentiality – Must ensure that the duties of care and loyalty extend to third parties when disclosing, selling, or sharing individual identifying data;
- Federal and State Enforcement – A violation of the duties will be treated as a violation of an FTC rule with fine authority. States may also bring civil enforcement actions, but the FTC can intervene.
- Rulemaking Authority – FTC is granted rulemaking authority to implement the Act.
“Free Press Action welcomes the important contributions the Data Care Act makes to a growing list of good ideas on privacy in the Senate. The bill shifts away from a notice and choice framework alone, where internet users bear all the responsibility and risk of protecting themselves, with few remedies for violations. Instead it moves towards putting the duty on companies and other data collectors where it belongs, to actually prevent such harmful exploitation and honor people's rights. It also does the right thing by empowering the FTC to make rules and impose penalties, and lets state attorneys general enforce the new protections too. We thank Senator Schatz and all the co-sponsors for putting so many ideas on the table, pushing the debate towards even more comprehensive laws,” said Sandra Fulton, Government Relations Director for Free Press Action.
“We commend Senator Schatz for tackling the difficult task of drafting privacy legislation that focuses on routine data processing practices instead of consumer data self-management. It signals an important shift in how Congress views consumer privacy issues and foreshadows a serious privacy debate in 2019,” said Michelle Richardson, Director of the Privacy and Data Project at the Center for Democracy and Technology.
“EFF thanks Senator Schatz for his leadership on protecting consumer data privacy. We generally favor legislation requiring large companies to serve as fiduciaries for their consumers' data, and to satisfy duties of loyalty, confidentiality, and care for their users. We look forward to working with the Senator to improve his bill and to advance information fiduciary protections that will meet the needs of Internet users and adequately safeguard consumer data privacy as a part of comprehensive privacy legislation,” said India McKinney, Legislative Analyst for the Electronic Frontier Foundation (EFF).