Recent Bills
- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
Committees
- AdministrationU.S. House
- AgricultureU.S. House
- Agriculture, Nutrition, And ForestryU.S. House
- AppropriationsU.S. House
- Armed ServicesU.S. House
- Banking, Housing, And Urban AffairsU.S. House
- BudgetU.S. House
- Commerce, Science, And TransportationU.S. House
- Education and WorkforceU.S. House
- Energy And CommerceU.S. House
- Energy And Natural ResourcesU.S. House
- Environment And Public WorksU.S. House
- EthicsU.S. House
- FinanceU.S. House
- Financial ServicesU.S. House
- Foreign AffairsU.S. House
- Foreign RelationsU.S. House
- Health, Education, Labor, And PensionsU.S. House
- Homeland SecurityU.S. House
- Homeland Security And Governmental Affa…U.S. House
- Indian AffairsU.S. House
- Indian and Insular AffairsU.S. House
- IntelligenceU.S. House
- JudiciaryU.S. House
- Natural ResourcesU.S. House
- Oversight And Government ReformU.S. House
- Permanent Select IntelligenceU.S. House
- RulesU.S. House
- Rules And AdministrationU.S. House
- Science, Space, And TechnologyU.S. House
- Select IntelligenceU.S. Senate
- Small BusinessU.S. House
- Small Business And EntrepreneurshipU.S. House
- Subcommittee on AviationU.S. House
- Subcommittee on Border Security and Enf…U.S. House
- Subcommittee on Coast Guard and Maritim…U.S. House
- Subcommittee on Commodity Markets, Digi…U.S. House
- Subcommittee on Conservation, Research,…U.S. House
- Subcommittee on Counterterrorism and In…U.S. House
- Subcommittee on Cybersecurity and Infra…U.S. House
- Subcommittee on Disability Assistance a…U.S. House
- Subcommittee on Economic Development, P…U.S. House
- Subcommittee on Economic OpportunityU.S. House
- Subcommittee on Emergency Management an…U.S. House
- Subcommittee on Energy and Mineral Reso…U.S. House
- Subcommittee on Federal LandsU.S. House
- Subcommittee on Forestry and Horticultu…U.S. House
- Subcommittee on General Farm Commoditie…U.S. House
- Subcommittee on HealthU.S. House
- Subcommittee on Highways and TransitU.S. House
- Subcommittee on Livestock, Dairy, and P…U.S. House
- Subcommittee on Nutrition and Foreign A…U.S. House
- Subcommittee on Oversight and Investiga…U.S. House
- Subcommittee on Oversight, Investigatio…U.S. House
- Subcommittee on Railroads, Pipelines, a…U.S. House
- Subcommittee on Transportation and Mari…U.S. House
- Subcommittee on Water Resources and Env…U.S. House
- Subcommittee on Water, Wildlife and Fis…U.S. House
- Transportation And InfrastructureU.S. House
- Veterans' AffairsU.S. House
- Ways And MeansU.S. House

Hearings to examine protecting and safeguarding Americans' online data.
Meeting•Senate Judiciary Subcommittee on Privacy, Technology, and the Law•Jul 30, 2025 · 2:30 PM
Summary
Senate Judiciary Subcommittee on Privacy, Technology, and the Law held a meeting on Jul 30, 2025 at 2:30 PM in Dirksen Senate Office Building, Room 226.
Record
The meeting has its transcript on the record.
Transcript
The transcript runs to 1,850 lines and 99,365 characters, as the Government Publishing Office printed it.
senate-hearing-61893.txt1[Senate Hearing 119-205]2[From the U.S. Government Publishing Office]34 S. Hrg. 119-20556 PROTECTING THE VIRTUAL YOU:7 SAFEGUARDING AMERICANS' ONLINE DATA89=======================================================================1011 HEARING1213 BEFORE THE1415 SUBCOMMITTEE ON PRIVACY,16 TECHNOLOGY, AND THE LAW1718 OF THE1920 COMMITTEE ON THE JUDICIARY21 UNITED STATES SENATE2223 ONE HUNDRED NINETEENTH CONGRESS2425 FIRST SESSION2627 __________2829 JULY 30, 20253031 __________3233 Serial No. J-119-353435 __________3637 Printed for the use of the Committee on the Judiciary3839[GRAPHIC NOT AVAILABLE IN TIFF FORMAT]4041 www.judiciary.senate.gov42 www.govinfo.gov4344 __________4546 U.S. GOVERNMENT PUBLISHING OFFICE4761-893 WASHINGTON : 20264849-----------------------------------------------------------------------------------5051 COMMITTEE ON THE JUDICIARY5253 CHARLES E. GRASSLEY, Iowa, Chairman54LINDSEY O. GRAHAM, South Carolina RICHARD J. DURBIN, Illinois,55JOHN CORNYN, Texas Ranking Member56MICHAEL S. LEE, Utah SHELDON WHITEHOUSE, Rhode Island57TED CRUZ, Texas AMY KLOBUCHAR, Minnesota58JOSH HAWLEY, Missouri CHRISTOPHER A. COONS, Delaware59THOM TILLIS, North Carolina RICHARD BLUMENTHAL, Connecticut60JOHN KENNEDY, Louisiana MAZIE K. HIRONO, Hawaii61MARSHA BLACKBURN, Tennessee CORY A. BOOKER, New Jersey62ERIC SCHMITT, Missouri ALEX PADILLA, California63KATIE BOYD BRITT, Alabama PETER WELCH, Vermont64ASHLEY MOODY, Florida ADAM B. SCHIFF, California6566 Kolan Davis, Chief Counsel and Staff Director67 Joe Zogby, Democratic Chief Counsel and Staff Director6869 Subcommittee on Privacy, Technology, and the Law7071 MARSHA BLACKBURN, Tennessee, Chair72LINDSEY O. GRAHAM, South Carolina AMY KLOBUCHAR, Minnesota,73JOHN CORNYN, Texas Ranking Member74JOSH HAWLEY, Missouri CHRISTOPHER A. COONS, Delaware75JOHN KENNEDY, Louisiana RICHARD BLUMENTHAL, Connecticut76ASHLEY MOODY, Florida ALEX PADILLA, California77 ADAM B. SCHIFF, California7879 Ben Blackmon, Republican Chief Counsel80 Dan Goldberg, Democratic Chief Counsel8182 C O N T E N T S8384 ----------8586 OPENING STATEMENTS8788 Page8990Blackburn, Hon. Marsha........................................... 191Klobuchar, Hon. Amy.............................................. 29293 WITNESSES9495Butler, Alan..................................................... 1096 Prepared statement........................................... 3297Goodloe, Kate.................................................... 598 Prepared statement........................................... 3399 Responses to written questions............................... 76100Levine, Samuel................................................... 12101 Prepared statement........................................... 48102Martino, Paul.................................................... 8103 Prepared statement........................................... 56104 Responses to written questions............................... 80105Thayer, Joel..................................................... 7106 Prepared statement........................................... 72107 Responses to written questions............................... 84108109 APPENDIX110111Items submitted for the record................................... 91112113 PROTECTING THE VIRTUAL YOU:114 SAFEGUARDING AMERICANS' ONLINE DATA115116 ----------117118 WEDNESDAY, JULY 30, 2025119120 United States Senate,121 Subcommittee on Privacy, Technology,122 and the Law,123 Committee on the Judiciary,124 Washington, DC.125 The Subcommittee met, pursuant to notice at 2:47 p.m., in126Room 226, Dirksen Senate Office Building, Hon. Marsha127Blackburn, Chair of the Subcommittee, presiding.128 Present: Senators Blackburn [presiding], Klobuchar, and129Schiff.130131 OPENING STATEMENT OF HON. MARSHA BLACKBURN,132 A U.S. SENATOR FROM THE STATE OF TENNESSEE133134 Chair Blackburn. The Subcommittee on Privacy, Technology,135and the Law will come to order. And Senator Klobuchar is on her136way. She'll be here in a couple of minutes, but we will go137ahead and begin since we do have five witnesses. And we thank138each of you for giving your time and being here today.139 Today, we are going to put our attention on what I think is140one of the most consequential issues up for discussion when we141talk about the virtual space, and that is how does each and142every individual American preserve their privacy and their143personal data in the virtual space? The title of the hearing,144Protecting the Virtual You: Safeguarding American's Online145Data.146 This speaks to what is becoming a growing connection147between you, and the physical space, and what you are doing148each and every day in your transactional life, in the virtual149space, or the digital version of your yourself. And this comes150through how companies collect, track, and monetize your data.151And every single bit of that is done without your consent or152your knowledge.153 In today's economy, data is currency. Everything from your154shopping habits to your health information, your children's155online activity, to your political views can be identified,156sold, and resold, often with little transparency or recourse.157Meanwhile, consumers are left to decipher lengthy privacy158policies and click ``agree'' at the bottom of the page even159before they can begin to access any online service.160 The absence of a comprehensive national data privacy161framework has left millions of Americans vulnerable. While162numerous States have enacted privacy laws, the result has been163a patchwork that fails to provide the clarity, consistency, and164confidence that consumers and responsible businesses need and165deserve. For years now, I have been clear we need a national166privacy standard that is comprehensive and enforceable, one167that empowers consumers, promotes innovation, and ensures168accountability. It should prioritize transparency, minimize169data collection, and provide meaningful consent, not just a box170to check.171 We have a panel of witnesses here this afternoon who all172agree that there is an urgent need for a comprehensive bill.173Now, there's probably going to be some disagreement about how174we get to that national standard, but we can agree on one175thing; it is past time for Congress to take up this issue, to176take action to pass a bill and see that bill signed into law.177 We should also acknowledge how closely this issue is tied178to the safety of our children online. Senator Blumenthal and I179have worked diligently on the Kids Online Safety Act, which180would require platforms to design their product for children's181well-being in mind, not just for their bottom line. We've seen182time and again how data-driven algorithms target kids with183addictive content and expose them to harmful material. Business184models that profit from children's vulnerabilities must be185reined in.186 It is absolutely disgusting that our children are the187product when they are online. And through the Open App Market188Act that I introduced with Senator Klobuchar, I have worked to189increase competition and consumer choice in the digital190marketplace. Whether it's protecting your personal data, your191right to download the apps you want, or your ability to access192services, the common thread is this; users not tech giants193should be in control of the individual users' life.194 Today's hearing will explore core principles that should go195into a national data privacy framework that reflect American196values. We'll ask what categories of personal data deserve197background protection? How can we give consumers real control198over how their data is used, and how do we ensure that AI199systems which are only growing more powerful or accessing and200using consumer's data and information in a responsible way?201 As artificial intelligence becomes increasingly embedded in202everyday life from how we shop to how we work, communicate, and203make decisions, Americans deserve to know when, where, and how204their data's being used to shape their online experiences. We205have an opportunity and a responsibility to get this right, and206I am looking forward to your testimony today, and to the207questions that we will have as we move forward.208 Senator Klobuchar, you're recognized.209210 OPENING STATEMENT OF HON. AMY KLOBUCHAR,211 A U.S. SENATOR FROM THE STATE OF MINNESOTA212213 Senator Klobuchar. Well, thank you very, Chair Blackburn,214and thank you to all of our witnesses. And I'm really grateful215for your leadership on these issues, Madam Chair, and your216willingness to work with me, and Senator Blumenthal, and many217others.218 We all know new technologies have made it easier for people219to monitor their health, collaborate with colleagues,220communicate with loved ones, and more, but Federal law doesn't221do enough, as we all know, to address the privacy that come222with these innovations, the privacy concerns. Technology223companies collect an enormous amount of personal information224about our daily lives. They know what we buy, who our friends225are, where we live, where we work and travel, even how much we226would be willing to pay for something.227 Yet, for too long the Big Tech companies, many of which228dominate the market that they operate in, have been telling229American consumers, ``Just trust us,'' even though their230business models are designed to collect personal information231and to use it for profit. The bottom line is that we are the232product, we are and that's how many tech companies make their233money, and a lot of it.234 In 2024, Google and Meta earned a combined $420 billion in235advertising revenues alone, and they made a lot more money236because Americans lack privacy protections. And American's data237earned Meta $68 in a single quarter last year. Think about238that. All these people who don't realize that they're being239tracked. But a European Facebook user with a comprehensive240privacy protection only generated $23. And that money can be241used for a lot of other things that people need right now.242 And it seems like every day we hear a new story about243companies playing fast and loose with data and taking advantage244of customers. Earlier this year, a whistleblower from Facebook,245now Meta, testified to another Subcommittee about how the246company would track users so closely that it could identify247when teenage girls felt emotionally vulnerable and then target248them with ads exploiting these emotions. For example, when a249teenage girl would delete a selfie, Facebook might serve her an250ad for diet products.251 Criminals also view huge troves of data as attractive252targets for hacking. We've seen major data breaches ranging253from the 2017 Equifax data breach that exposed sensitive254financial information from more than 140 million individuals,255to the hack of Change Healthcare affecting 190 million people256and causing more than 100 electronic systems vital to the U.S.257healthcare system to be shut down.258 On my way here, I was on the phone with the mayor of St.259Paul, Minnesota, because they, like so many other260jurisdictions, are responding to a targeted cyberattack on261their IT infrastructure, which has shut down some of the city's262digital services and may have compromised city employee data.263 Once in the hands of criminals, data can be used for264everything from identity theft to more serious crimes and we265all learned too tragically with the horrific murders in my266State of my good friend Melissa Hortman, the former speaker of267the House and her husband, Mark, how accessible personal data268is including people's addresses because the murderer only269killed the people and went to the houses, the people whose270addresses he had.271 Businesses are also using personal data collected across272the internet in novel ways such as to set individualized prices273designed to increase costs for consumers. Should a person--and274this is a question we have to ask as Senators really have to275submit to this kind of intrusive data collection just to send a276message to a friend online, or to book a flight, or to order277some diapers. I don't think so.278 That's why more than 20 States have stepped in. I suspect279today we'll hear from some of our witnesses about the patchwork280of State laws. I agree it's a problem, but I believe we should281have passed privacy legislation many, many years ago. I282advocated for it back then. We tried, and in fact, in 2019, I283introduced a comprehensive privacy bill. I was a co-sponsor of284Senator Cantwell, and Kathy, McMorris Rogers, a former285Republican House Member.286 The bill would've required companies to collect only the287information necessary to provide the goods and services that288consumers sought. Insured consumers consented before their289personal data was shared with third parties and put consumers290in control of their data by allowing them to access, correct,291and even delete personal data.292 But many of the businesses that today complain about the293burden of complying with the patchwork of State laws, I have294the advantage of having been there then even before Maria295Cantwell's bill was introduced when the companies were lobbying296against a Federal privacy law, and now they're back complaining297about the patchwork of laws. And I would like to change that,298but I do think it's important to know that's why we're in the299position that we are and to understand why some of these States300are looking at this going, ``Wait a minute.''301 The need for Federal privacy reform is even more urgent as302AI continues to expand its role into our lives. Data is both303the gasoline and the engine for AI models. That means that304demand for our data is skyrocketing. So, it is critical that we305set guardrails to ensure the data that powers AI is responsibly306sourced, and used for legitimate means, and protected when you307want to have it protected.308 Luckily, there is a bipartisan agreement that Congress309needs to act. The Commerce Committee on which Chair Blackburn310and I also sit has seen a strong bipartisan, bicameral proposal311for Federal privacy reform. Not everyone agrees with all of312them, but there has been some start out of that Committee, and313I look forward to hearing from our witnesses about why we need314these guardrails now.315 Thank you, Senator Blackburn.316 Chair Blackburn. I thank you and our witnesses. Ms. Kate317Goodloe is managing director at the Business Software Alliance,318where she develops policies on privacy, AI, and law enforcement319access. She also taught AI law at the GW Law School. Prior to320her time at BSA, Ms. Goodloe was a senior associate at321Covington & Burling focusing on privacy and cybersecurity. She322earned her JD from the New York University School of Law. We323welcome you.324 Mr. Joel Thayer is the president of the Digital Progress325Institute and founder of Thayer, PLLC. He has represented326clients before the FCC, FTC, and Federal courts on issues327relating to telecom law, data privacy, cybersecurity, and328competition policy.329 Before that, he has held positions at the App Association,330the FCC, the FTC, and the U.S. House of Representatives. Since331earning his JD from American University Washington College of332Law, he has been recognized as a Super Lawyers Rising Star for333his work in communications law and digital policy.334 Mr. Paul Martino is a partner at Hunton Andrews Kurth, LLP.335He has nearly 25 years of experience in public policy and336government relations specializing in privacy, data security,337AI, e-commerce, and tech. Mr. Martino is the founder and338general counsel of the Main Street Privacy Coalition.339 Before joining Hunton, he served as VP and senior policy340counsel for the National Retail Federation and co-chaired the341Privacy and Data Security Task Force at Alston and Byrd. After342earning his JD from the University of California, Berkeley343School of Law, he served as Majority counsel on the Senate344Commerce Committee for, then Chairman, John McCain.345 Alan Butler is the executive director and president of the346Electronic Privacy Information Center. Before his role as347executive director, he managed EPIC's litigation and amicus348program where he filed briefs before the U.S. Supreme Court and349other appellate courts in privacy and civil liberties cases.350After earning his JD from UCLA School of Law, he was admitted351to the DC Bar and the State Bar of California.352 Samuel Levine is a senior fellow at the Berkeley Center for353Consumer Law and Economic Justice. He previously served as354director of the Federal Trade Commission's Bureau of Consumer355Protection. Prior to his role at the FTC, Mr. Levine served as356an attorney advisor to Commissioner Chopra as an attorney in357the FTC's Midwest Regional Office, and as an assistant attorney358general in Illinois. After earning his JD from Harvard Law, he359clerked on the U.S. District Court for the Northern District of360Illinois.361 We welcome each of you for being here. Now, I'm going to362ask you to rise and raise your right hand.363 [Witnesses are sworn in.]364 Chair Blackburn. And we will note that everyone has365answered in the affirmative. Okay. Ms. Goodloe, you are366recognized for 5 minutes, and we'll go right down the line.367368STATEMENT OF KATE GOODLOE, MANAGING DIRECTOR, BUSINESS SOFTWARE369 ALLIANCE, WASHINGTON, DC370371 Ms. Goodloe. Good afternoon, Chair Blackburn, Ranking372Member Klobuchar, and Members of the Subcommittee. My name is373Kate Goodloe, I'm managing director at the Business Software374Alliance, or BSA.375 BSA members create the business-to-business technologies376used by companies across industries. Privacy and security are377core to our members' operations. I commend the Subcommittee for378convening today's hearing, and I thank you for the opportunity379to testify. The United States needs a strong, clear,380comprehensive consumer privacy law. BSA has been a longtime381supporter of adopting a Federal privacy law.382 Americans share their personal information online every383day, whether we shop online, use apps to track our workouts,384take ride shares, or host video calls with friends and family,385we provide personal information to a broad range of companies.386Consumers deserve to know their data is used responsibly.387 In our view, a Federal privacy law should achieve three388goals. First, it should require companies to handle consumers'389personal data responsibly, and assign obligations to companies390based on their role in handling that data. Second, it should391give consumers new rights. And third, it should create strong392consistent enforcement.393 I want to focus on that first goal. To create the right set394of obligations, a privacy law must recognize different types of395companies handle consumers data. Those companies must all adopt396strong but different safeguards to effectively protect397consumers. Most importantly, not all companies are consumer-398facing.399 BSA represents the business-to-business technology400providers that work for companies across the economy. An online401store that sells clothing for example, will rely on a series of402business-to-business technology providers. It may use one to403manage customer service inquiries, another to track deliveries,404and a third to protect its data against cybersecurity threats.405 Each company must protect the personal data it handles, but406companies need to take different actions to effectively protect407consumers because they play different roles in handling their408data. Laws should not create a one-size-fits-all obligation.409Treating an online store and its cybersecurity vendor alike410doing so actually creates new privacy and security risks for411consumers.412 Now, this is something that States get right. Twenty413States, both red and blue, have adopted comprehensive consumer414privacy laws and those laws are remarkably consistent. All 20415reflect a fundamental distinction between two types of416companies that handle consumer's data and assign strong but417different obligations to each.418 The first are controllers. These companies decide how and419why to collect a consumer's personal data, and State laws give420them obligations about those decisions, including; telling421consumers how and why they process data, responding to consumer422rights requests, asking for consent to process sensitive423personal data, and minimizing the collection and use of data in424the first place.425 The second type are processors. These companies have a role426of handling data on behalf of a controller, and State laws give427them a common set of obligations, too. Those include;428processing data pursuant to the controller's instructions,429entering into a contract with a controller, handling the data430confidentially, and giving controller the information it needs431to conduct privacy assessments.432 These roles reflect the modern economy. They're not unique433to State laws and they're not new. The distinction between434controllers and processors dates back more than 40 years, and435it underpins privacy laws worldwide. It must be part of any436Federal privacy law.437 In addition to putting obligations on companies, the438Federal privacy law should create new rights for consumers and439strong consistent enforcement. Here, too, you can look to440States. There is widespread agreement on consumer rights. All44120 States give consumers rights to access, delete, and port442their personal data. Nineteen, also give a right to correct443inaccurate data. States also create similar enforcement444mechanisms, with all 20 giving a leading role to the attorney445general to enforce privacy violations.446 I look forward to discussing consistent aspects of these447State laws, but I want to say that consistency may not last.448This year, we've seen a striking interest in amending existing449laws to revise, expand, and change their protections and new450obligations coming through rulemakings.451 A Federal law is needed to bring consistency to existing452protections and to create broad long-lasting protections for453consumers. A Federal law should not weaken protections already454provided by the States, but extend those protections to455consumers nationwide.456 There is significant common ground between industry and457civil society stakeholders on comprehensive Federal privacy458protections. We look forward to working with Congress on these459issues.460 Thank you, and I look forward to your questions.461 [The prepared statement of Ms. Goodloe appears as a462submission for the record.]463 Chair Blackburn. And well done right at 5 minutes. You get464a gold star on that. Mr. Thayer.465466 STATEMENT OF JOEL THAYER, PRESIDENT,467 DIGITAL PROGRESS INSTITUTE, WASHINGTON, DC468469 Mr. Thayer. I'll try to emulate it. Thank you, Chairwoman470Blackburn, Ranking Member Klobuchar and esteem Members of this471Committee for inviting me to testify and holding this important472hearing. My name is Joel Thayer, and I'm the president of the473Digital Progress Institute.474 It's a think tank based in Washington, DC, focused on475promoting bipartisan policies in the tech and telecom space.476 Ensuring privacy for all is a founding principle of the477institute. And as such, I very much appreciate the Committee's478commitment to building out a privacy framework that further479assures that the integrity and ownership of our digital selves480remains in our domain, not by a company with a domain name.481 Although our privacy from our Government is well482established, that is unfortunately not the case with respect to483companies. With the allure free services, we provide details484about our most intimate selves to trillion-dollar tech485companies who in turn make enormous profit off the data they486collect. They know everything about us; what we like to eat,487when we sleep, where we live, where we are, our beliefs, and488even our fears. Curiously, though they claim our age confounds489them, but let's set that aside for now.490 A recent Pew study shows that 73 percent of Americans feel491they have limited to no control over how companies use their492personal information. And the reality is they don't. We sign493privacy policies that are filled with so much legal jargon that494it may as well be unintelligible to the average person, and495presto, our data is now their data.496 The problem is not just they sell our data to third party497advertisers, but also to those who use our data to create fake498images, curate bias newsfeeds, conduct elaborate scams, and499even engage in espionage campaigns. In short, we are not in500control, and Americans are right to be concerned. And with the501advent of AI, this trend is only going to increase. It's no502wonder why 85 percent of people want more privacy protections.503 We need government intervention here. The good news is that504protecting privacy is a bipartisan issue. Indeed, 20 States505across the political spectrum have passed privacy laws, and as506evidenced by this hearing, Congress appears poised to address507this issue again. We welcome this much needed development.508 With that in mind, here are a few high-level suggestions as509the Committee evaluates paths forward. First, it's important to510define your goals and keep the framework targeted at511accomplishing its goals. One of the primary issues with512previous attempts at passing meaningful privacy laws has been513that bills attempt to do too much all at once. We have seen the514most success in legislation that has clearly articulated goals515with targeted solutions.516 It's why the institute has supported targeted bipartisan517measures such as the Protecting Americans from Foreign518Adversary Controlled Applications Act--that's a mouthful--the519TAKE IT DOWN Act, the Kids Online Safety Act, the App Store520Accountability Act, and Oama just to name a few.521 As we have seen in the EU's GDPR, overly sweeping privacy522laws have the unintended consequence of entrenching incumbents.523The GDPR should be a cautionary tale for the U.S. because it524clearly shows that privacy regulations without market525guardrails can seriously exacerbate today's competition issues526we have with Big Tech.527 Second, enforcement matters. In our experience, agency528actions or attorney general enforcement are the most effective,529whereas a private right of action alone may act more as a530carrot as opposed to a stick given these companies' seemingly531endless teams of lawyers and budgets.532 For instance, the Texas attorney general recently secured a533$1.4 billion settlement against Google for violating its534privacy law, whereas when consumers sued Apple under535California's privacy law, in part for sharing recorded536conversations that included personal health information with537their physician to medical ad companies, they were only538entitled to a meager $95 million. Worse, consumers won't see539about a third of that because that's reserved for their540lawyers.541 Third, the broader the Federal statute, the more important542preemption will become. That's because targeted legislation is543less likely to run into differing State privacy regimes. Any544preemption framework should be clear on what it is preempting545and should reserve rights for State attorney general546enforcement.547 Key areas though ripe for preemption are addressing basic548definitions like; what does personal information mean, the549creation of data rights. It seems to be unanimous amongst all550State privacy laws, and of course, be specific with what data551management practice we seek to prohibit. In some, the reality552is that if these Big Tech companies cared about user privacy,553they would protect it. Frankly, it's in their interest not to.554Congress needs to act. Once again, I would like to thank the555Subcommittee for allowing me to testify, and I welcome any556questions you may have. Two seconds on this one.557 [The prepared statement of Mr. Thayer appears as a558submission for the record.]559 Chair Blackburn. There you go. Well done. Mr. Martino, the560pressure is on.561 [Laughter.]562563 STATEMENT OF PAUL MARTINO, GENERAL COUNSEL,564 MAIN STREET PRIVACY COALITION, WASHINGTON, DC565566 Mr. Martino. Thank you, Chair Blackburn, and Ranking Member567Klobuchar, for the invitation to be here today. I am Paul568Martino, a partner at Hunton Andrews Kurth, here in Washington,569and I serve as the general counsel for the Main Street Privacy570Coalition.571 Our coalition members represent a broad array of companies572that line America's main streets. They interact with consumers573each day. They're found in every town, city, and State,574providing jobs, supporting our economy, and serving Americans575as a vital part of their communities.576 Collectively, Main Street businesses directly employ577approximately 34 million Americans, and contribute $4.5578trillion to our Nation's GDP. Since 2019, the coalition has579supported Federal privacy legislation that would establish a580single nationwide law to protect the privacy of all Americans.581 Where we sit here on Capitol Hill today, we can travel to582two States in 20 minutes by car or metro. Just like many583Americans who live in tri-State areas or near State lines,584should Americans privacy rights change as they drive from DC585into Maryland or Virginia? They do right now, but many don't586know that Americans expect their privacy to be protected the587same everywhere.588 Our coalition members share a strong conviction that a589preemptive Federal privacy law will benefit consumers and Main590Street businesses alike. It would give consumers confidence591that their data will be uniformly protected across America592regardless of where they live or choose to do business. And it593would provide the certainty Main Street businesses need to594lawfully and responsibly use data to better serve their595customers online or across State lines.596 Establishing a uniform national law that extends consumer597privacy rights and consistent privacy rules to all consumers598and businesses in America is a core principle for Main Street.599I will highlight two more. First, a Federal privacy law should600protect consumers comprehensively with equivalent standards for601all businesses. A privacy law should empower consumers to602control their personal data used by businesses regardless of603business type. Likewise, businesses must be permitted to604lawfully use data consumers share with them.605 To better serve customer needs. To meet these goals, we606recommend a Federal privacy law that creates equivalent privacy607obligations for all businesses handling consumer data. This608would be a change from past Federal privacy bills that narrowed609obligations for service providers in Big Tech, telecom, cable,610and financial industries, relieving them from the same611obligations that apply to Main Street businesses.612 For privacy laws to succeed for consumers, it is critical613for all entities handling consumer data to secure that data and614protect the privacy rights. This is true regardless of the615terms used in privacy laws that blur the reality of who616actually controls the data. The label ``controller'' which is617applied to every Main Street business that directly serves a618customer, can create a false impression about the power of Main619Street businesses as they interact with Big Tech service620providers.621 Main Street companies control their relationship to622customers, a responsibility they value, but very few can623control how nationwide service providers operate and do624business. Powerful Big Tech and ISP service providers require625Main Street businesses to sign ``take it or leave it''626contracts that dictate the terms of their service. The myth627that Big Tech processors merely follow the instructions of the628typical Main Street business is not credible. Privacy laws629should not permit any industry sector to shift its630responsibilities onto another.631 Ensuring equivalent data privacy obligations across632industry sectors is also inherently pro-consumer. Consumers633have the right to expect privacy rules. They can understand,634predict, and support that meet their expectations. Congress can635pass a law to ensure that all businesses protect consumer's636privacy, and processors cannot hide behind labels that make it637appear they have no control at all.638 Finally, Federal privacy laws should hold accountable all639entities handling personal data with the same enforcement640mechanisms. This creates an even playing field with proper641incentives across industry. The law should encourage compliance642to protect consumers more effectively than gotcha lawsuits that643threaten Main Street businesses driving to be in compliance.644This is why State privacy laws thoughtfully couple government645notice with the opportunity to quickly correct or cure646mistakes.647 Thank you, and I welcome your questions.648 [The prepared statement of Mr. Martino appears as a649submission for the record.]650 Chair Blackburn. And you came in with a few seconds on the651clock. You're in the lead. All right, Mr. Butler, we're going652to see what you can do here.653654 STATEMENT OF ALAN BUTLER, EXECUTIVE DIRECTOR AND PRESIDENT,655 ELECTRONIC PRIVACY INFORMATION CENTER, WASHINGTON, DC656657 Mr. Butler. Thank you, Chair Blackburn, and Ranking Member658Klobuchar, and Members of the Subcommittee for the opportunity659to testify today about the need to better safeguard American's660online data.661 My name is Alan Butler and I'm the executive director at662the Electronic Privacy Information Center. EPIC is an663independent, nonprofit research organization established in6641994 to secure the right to privacy in the digital age for all665people.666 Twenty-five years ago, the Federal Trade Commission issued667a report to Congress based on its research of privacy risks in668the online marketplace. The takeaway was clear self-regulation669does not work, and we need legislation to ensure adequate670protection for Americans online.671 In the decades since that report, we have seen our digital672world expand and develop in amazing ways, but without strong673privacy protections. We have seen an alarming expansion of674surveillance and data abuses online that threaten our rights675and subvert our most fundamental values of autonomy and676freedom.677 The status quo is untenable. If the law allows a company to678scrape images of all of us to build a universal facial679recognition data base, while another company tracks every site680we visit to build invasive profiles, and yet another company681buys and sells our logs of daily movements, do we have privacy682protection at all? I believe any reasonable person would say683no, and would demand that our lawmakers step in to fix this684broken system.685 In my testimony today, I will describe the current state of686State privacy law and identify the areas where Federal687leadership would be most impactful. Privacy is a fundamental688right and Americans deserve a law that actually protects our689data. In the absence of action by Congress, States have stepped690in to advance digital rights in the information age. This has691been an important catalyst for change, but there's more work692ahead to establish robust privacy standards.693 There is significant bipartisan agreement across party and694State lines about the need for privacy protection in the core695principles that should shape the law. So, our attention at the696Federal level should be on establishing clear rules of the road697to make our digital world safer and more secure. What we cannot698do is pass a weak Federal standard that prevents States from699responding to new challenges and emerging threats in the700future.701 A Federal privacy law should set a consistent and robust702standard for protection while preserving flexibility for States703in the future. Over the past 7 years, 19 States have passed704comprehensive data privacy laws and many States have also705passed bills aimed at preventing specific privacy harms. Most706of these State laws follow a common framework, and have many of707the key components of any modern privacy law.708 But unfortunately, these laws do very little to actually709limit abusive data practices and to protect privacy. In a710recent report, EPIC analyzed these laws in detail and graded711each of them. Eight received Fs, and none received an A.712 So, what went wrong? The tech industry has invested heavily713in State lobbying to water down the substantive protections,714narrow their scope and add exceptions that swallow the rules.715But over the last 2 years, we have seen stronger State716proposals building off the bipartisan framework that Congress717created in 2019 and 2021.718 The Maryland Online Data Privacy Act, for example, passed719last year, it builds on existing State laws and incorporates720strong data minimization protections, and a ban on the sale of721sensitive data. Inspired by Maryland's success, 10 States have722introduced bills with strong data minimization rules this year.723Several States that originally passed weak privacy laws have724revisited and amended their laws to strengthen their725protection.726 Any Federal privacy proposal should have a strong data727minimization rule, include heightened protections for sensitive728data, and establish robust enforcement mechanisms. Data729minimization offers a practical solution to our broken internet730ecosystem. Instead of allowing data collectors to dictate731privacy terms, data minimization rules set clear standards to732limit the processing of our data. Companies can collect the733data they need to provide the services we want. This standard734better aligns business' conduct with what consumers expect and735stops abusive data practices like third-party tracking and736profiling.737 Enhanced protections can also ensure that our most738sensitive data remains confidential and secure. So, much739information about us that has traditionally remained private is740now captured in digital form; our health records, our741movements, our biometrics, and genetic markers, even the data742about our children. These records are frequently targeted by743hackers and scammers, and should be locked down and secure.744 Strong privacy standards should also be backed up by robust745enforcement, including the three-tiered approach that we saw in746the Federal bill. And while State and Federal enforcement is747essential, the scope of data collection online is simply too748vast for any one entity to regulate, and that is why private749rights of action with enforceable court orders are so750important.751 EPIC has been calling on Congress to pass a strong privacy752law to protect all Americans for the past 25 years. We are753grateful that the Subcommittee is turning its attention to this754important issue, and we urge Federal lawmakers to learn from755State's experience.756 I thank you for the opportunity to testify today, and I757look forward to your questions.758 [The prepared statement of Mr. Martino appears as a759submission for the record.]760 Chair Blackburn. And Mr. Levine, you're recognized.761762 STATEMENT OF SAMUEL LEVINE, SENIOR FELLOW, UC BERKELEY CENTER763 FOR CONSUMER LAW & ECONOMIC JUSTICE, NEW YORK, NEW YORK764765 Mr. Levine. Thank you, Senator. My name is Sam Levine, and766I'm a senior fellow at Berkeley Center for Consumer Law and767Economic Justice. Until January, I led the FTC's Bureau of768Consumer Protection.769 Today, protecting Americans' personal information is about770much more than privacy. It's about whether we can afford771essential goods, whether we can be profiled based on our772political or religious beliefs, and whether the next generation773will grow up addicted to screens. I'll be focusing on three774real-world threats that unchecked privacy abuses are fueling775threats to economic fairness, democratic freedoms, and the776safety of kids and teens.777 Let's start with economic fairness. On a recent earnings778call, Delta Airlines executives boasted they could soon raise779prices on plane tickets, not by adding value, but through a new780formula; stop matching competitors' prices, unbundle basic781services and charge each passenger the most they're willing to782pay.783 Investors cheered the news calling this the Holy Grail, but784we should call it what it is; personalized price gouging. And785it's only possible because weak privacy protections are786allowing companies to track our behavior and predict how much787we can be pushed to pay.788 This practice, also known as surveillance pricing, is789spreading. More and more businesses are looking to price790everyday goods from groceries to hardware the way airlines are791pricing tickets. And let's be clear, their goal is not to lower792prices, it's to charge each person as much as possible and the793people hit hardest will be those with the fewest options; a794parent buying baby formula, a senior filling a prescription, or795family booking last minute travel to a funeral.796 Unchecked data collection is moving us from a world of one797product, one price, to one person, one price. And if we don't798act, the shift will be costly. Uncheck data collection is also799putting our democratic freedoms at risk. Last year, the Federal800Government alleged that an entity was tracking American's801movements and profiling them into categories like Wisconsin802Christian churchgoers, likely Republican voters, and restaurant803visitor during COVID quarantine.804 This was not a foreign adversary. This was a U.S. data805broker. The FTC sued to halt these practices. That lawsuit806should be a wakeup call. No American should be profiled based807on their politics, their religion, or their stance on COVID808lockdowns. Yet, without strong data protections, that's exactly809what brokers are doing. Political and religious freedom cannot810thrive in a society where our movements, beliefs, and behaviors811are tracked, recorded, and then sold to the highest bidder.812 We need to act. We also need to act to protect our next813generation. Over the past two decades, Big Tech has been814running a massive experiment on our children; what excites815them, what enrages them, and what holds their attention? The816result is a youth mental health crisis.817 Weak data privacy is powering these harms. Social media818companies collect personal data to power their ad-driven819business models. More screen time means more revenue, and more820insights into how to keep kids hooked. It's a dangerous821feedback loop that profits from addiction and it's getting822worse.823 Today, companies are building AI chatbots engineered to824earn kids' trust and keep them engaged. And that means serving825up content that's provocative, obscene, and sometimes826dangerous. One bot reportedly told a teen that self-harm feels827good. Another offered lesson on how kids can hide drugs and828alcohol, and how to set the mood for sex with an adult.829 You might expect these incidents to prompt a pause, but the830opposite is happening. The same tech giants that have been831putting kids at risk for years are now racing to roll out AI832chatbots, and respectfully, they are doing so because Congress833is not telling them they need to stop. That must change across834each of these threats.835 The common thread is weak data protection, but we can fight836back. Strong privacy laws can stop companies from using837personal data to set individualized prices, ban the profiling838of Americans based on sensitive information, and end the839surveillance that's fueling an endless cycle of harm to kids840and teens.841 Thank you for holding this important hearing today, and I842look forward to taking your questions.843 [The prepared statement of Mr. Levine appears as a844submission for the record.]845 Chair Blackburn. And you win the gold medal.846 Mr. Levine. Thank you.847 Chair Blackburn. Yes. I think it was 23 seconds left. We're848going to move to questions, and Senator Klobuchar, I will let849you begin.850 Senator Klobuchar. Okay, very good. Thank you very much.851So, as I discussed earlier, there've been a number of852bipartisan proposals for Federal data privacy law that have853been introduced over the years, including the American Privacy854Rights Act, and the American Data Privacy and Protection Act.855 I guess, Mr. Butler, I will start with you. Why is it so856essential that we put reforms like these in place for consumers857across the country?858 Mr. Butler. Well, thank you for the question, Senator859Klobuchar. I mean, we've seen what happens without Federal860leadership on privacy. Surveillance tools have become embedded861in every website and app that we visit. And without a Federal862standard, companies really don't have the incentive to innovate863on privacy protection and a few Big Tech firms dominate the864marketplace.865 So, we're fueling harms to individuals, we're fueling harms866to the market, and we're just allowing ourselves to be867inundated by these surveillance and abusive data collection868practices.869 Senator Klobuchar. Thank you. And Ms. Goodloe, in your870testimony, you highlight that there's broad consensus on many871privacy principles across the 20 States that have them both872Democratic-and Republican-led. I think Mr. Butler was873mentioning how some of the early laws were weaker. There have874been some improvements. What are the significant areas of875bipartisan consensus that should be at the core of Federal876privacy legislation?877 Ms. Goodloe. Thank you for the question. We see a lot of878consensus on the right set of rights to give to consumers both879affirmative rights like the ability to access, correct, and880delete their information, and on giving them rights to opt out881of certain activities, including the sale of their data882profiling and targeted advertising. I think there is consensus883among many most of these State privacy laws on that set of884important issues.885 There's also a core set of obligations on companies for886controllers. It's things like asking for consent to process887sensitive data. We have 17 States that require companies that888are processing sensitive data to conduct privacy assessments,889looking at the sensitive issues arising from that processing.890 And when it comes to processors, there is broad consensus891that they have a separate set of rights to handle data on892behalf of a controller pursuant to their instructions and to do893so confidentially.894 Senator Klobuchar. Okay, thank you. Mr. Levine, while at895the FTC, you prosecuted unfair and deceptive acts and practices896related to data privacy, as well as other privacy laws like897those intended to pre protect young children.898 Despite your efforts to use every legal tool at your899disposal to protect privacy, what gaps exist that are the most900critical for Congress to fill through a comprehensive data901privacy bill?902 Mr. Levine. Well, thank you for the question, Senator. And903as you alluded to in your remarks, we currently live under a904privacy regime where companies have taken the position that905they can basically do whatever they want so long as they906disclose it in their privacy policy.907 Over the last 4 years, the FTC, we took a number of steps908to try to push back against that. We told GoodRx they couldn't909share sensitive medication information with Facebook even if910consumers clicked ``Yes.'' We told Better Health they couldn't911share with advertisers what mental health treatments people912were seeking. We told Amazon Ring that its employees couldn't913spy on people who were using their security cameras.914 But I can tell you, Senator, that every case we brought,915when I would meet with counsel for those companies, they would916tell us the same thing, ``Well, we put it in our privacy917policy, so it's legal.''918 I think our enforcement, the FTC's enforcement, and State919enforcement, and privacy enforcement would be far more920effective with bright-line rules on what companies can collect,921how they can use it, and with whom they can be shared. Without922that, you're going to continue to see a whack-a-mole approach923that doesn't do enough to protect Americans' privacy.924 Senator Klobuchar. Thank you. Very good. Mr. Thayer, I've925long advocated for common-sense rules to require the platforms926to allow competing businesses the same access to the platform927that they give themselves. Senator Blackburn has advocated for928similar reforms in app store markets, but as you mentioned in929your testimony, dominant platforms use privacy concerns as a930pretext to avoid opening up their platforms to fair931competition.932 How can interoperability requirements be implemented933without putting user privacy at risk?934 Mr. Thayer. Thank you for the question, Senator, and also935thank you for your work that you do on this. And also, Senator936Blackburn, you guys have been real champions on this issue, and937I think it really does highlight the significant aspects in the938concentration that this market involves, where we have939basically four players, maybe three in some markets, or maybe940even two in others, particularly an app store where you really941have--you're at the behest of or at the whim of whatever these942companies want you to do. So, you're basically stuck with943whatever privacy policies that they decide on.944 And so, a good example of this is the software we're seeing945at the DOJ, with AG Gail Slater at the helm, where she's been946arguing on the remedies case. And the first argument that you947got from Google was like, ``Hey, you can't do this sharing948arrangement because it'll violate privacy.'' But in reality,949what they really care about is scale. They want to harbor the950data. They don't really care about the privacy at all. It's951really all a ruse.952 Senator Klobuchar. And how can a strong Federal privacy law953help ensure that interoperability opens up digital markets to954competition?955 Mr. Thayer. So, I really point to the idea of a general956statute versus a specific statute. And as you know, Senator,957the antitrust laws are pretty broad, and so are Section 5 of958the FTC Act. Being able to designate exactly what we're959interested in and target the actual acts that we're concerned960with will help regulators down the road.961 And this is precisely what Mr. Levine was alluding to when962bringing that broader framework out. If we say interop is963something that we all believe is something that could equal out964or balance out the scales, then it gives the regulator the965ability to assess it in that way instead of using vague966statutes.967 Senator Klobuchar. Okay. Last question, Mr. Martino. As you968know, I was close friends of John McCain, and miss him very969much. In your written testimony, you say that businesses should970not be responsible for the data privacy practices of other971entities whose actions they cannot control, including the Big972Tech platforms on which we know many businesses now have to973rely to reach consumers.974 How can Congress ensure that responsibility is aligned975properly with the entities best suited to protect consumer976privacy?977 Mr. Martino. Thank you, Senator Klobuchar. Well, I think978the core principle we have here is that businesses need to have979equivalent requirements, equivalent standards to protect data.980There's a chart in my testimony that----981 Senator Klobuchar. You like charts, huh?982 Mr. Martino. Yes, I like charts [holds up documents]. I983didn't make it real big though, [laughter]. Sorry. But it's it984shows some of the State law requirements for the Big Tech985service providers. And you'll notice there are a couple red Xs986here on things that I think consumers would expect and987businesses like Main Street businesses would expect their988service providers to do which is provide data security.989 The State laws for the most part, except for Colorado, I990believe, don't require the Big Tech service providers to991actually secure the data they're processing on behalf of992businesses. They're only required to assist the controllers in993their own data security and if they have their own breach, but994there's a lack of parity there.995 Another place that I'll mention where there's a red X and996again, you know, only I think Colorado and Connecticut have997done this, but processors use lots of subprocessors or998subcontractors, and they have requirements that any999subprocessors they share the data with has to meet the same1000standards as the processor.1001 But, you know, they don't give the Main Street business an1002opportunity to object to those subprocessors, to those1003subcontractors. Only in two States that I'm aware of. And that1004is a big difference between, for example, what happens in1005Europe and what happens in the U.S. And so, if you have a1006processor that you don't want to downstream pass on data to--1007you know, think of some of the past breaches and privacy1008violations we've seen before, you know, the Main Street1009business should have the ability to object to that. So, we ask1010for the similar requirements that Main Street businesses have1011to live by.1012 Senator Klobuchar. Okay. Thanks. And thank you. Sorry to go1013over.1014 Chair Blackburn. No, thank you. It is perfectly fine that1015you went over. This is the first of our hearings that are going1016to look at this virtual space. And as you all know, Senator1017Klobuchar, and I've done a lot of work and trying to secure the1018American citizens' privacy in the virtual space.1019 And as we work through this on this Committee, I think that1020foundational to the conversations is who owns an internet1021user's data and what is the scope of that ownership? Where does1022it begin? Where does it end? And let's just go down the line,1023Ms. Goodloe, starting with you, and everybody keep it under a1024minute and answer that question so that we've got that for the1025record.1026 Ms. Goodloe. Thank you for the question. Our companies1027provide business-to-business technologies to other companies.1028In many cases, their business customers own the data that they1029store with business-to-business providers, and yet there may be1030personal data that individuals own as well.1031 And those individuals should have rights like to access,1032correct, and delete that information no matter whether it's1033stored with a consumer-facing company or the business-to-1034business provider processing it on behalf of that consumer-1035facing company.1036 Chair Blackburn. Okay. Mr. Thayer?1037 Mr. Thayer. Given the lack of appropriate consent to1038regimes, I would say that the user owns that data, because I1039don't think that the way we have things set up right now the1040data subject, doesn't even know that they've given over some of1041that data.1042 And so, at the end of the day, I think the reality is that1043we have to have privacy regimes in place to ensure that the1044ownership to outline those particular contours. But it is 1001045percent you own your data, and it shouldn't be the other way1046around.1047 Chair Blackburn. Okay.1048 Mr. Martino. Thank you, Senator, for your question. It's a1049very good question. There are some nuances here I think that1050are important. First, Main Street businesses understand it's1051the user's data and the user has the right to correct it,1052delete it, remove it from their system. But there are some1053kinds of data that is considered shared.1054 And so, for example, if you make a purchase in a store,1055well, the store needs to keep a record of that purchase if you1056want to do a return or an exchange for their inventory. So, is1057it the consumers'--that this consumer made this purchase on1058this date? Is that personal information? Yes. Is it also1059information the business needs and can't just get rid of? Yes.1060 And so, I think when it comes down to ownership, we just1061have to understand that in modern commerce and e-commerce, some1062information will need to be retained, but only for as long as1063it's necessary to retain it. And I think hopefully that answers1064the question.1065 Chair Blackburn. Okay.1066 Mr. Butler. Thank you for the question, Chair Blackburn. We1067believe that we all have a fundamental right to control when1068our data is used and how it is collected. But individual1069mechanisms of consent and control don't provide a complete1070solution to this problem, and that's why we feel that it is so1071important to have rules of the road that protect people's1072privacy by default and align business collection and use data1073practices with what consumers reasonably expect.1074 Chair Blackburn. Okay.1075 Mr. Levine. Thank you, Senator. I very much agree with Mr.1076Butler. Data about people should be owned by people, but at the1077same time, as Alan said, we don't want a world in which people1078are solely responsible for protecting their own privacy. That's1079why we need strong Federal protections that don't put the onus1080on people, but put the onus on companies to make sure they're1081not abusing people's privacy.1082 Chair Blackburn. Yes. It was over a decade ago that now1083Senator Welch and I were in the House at Energy and Commerce1084Committee--I know Mr. Martino remembers all of this--and we had1085bipartisan legislation to establish a data privacy framework.1086And of course, Big Tech fought it just all the way to today. We1087still don't have it into law.1088 So, Mr. Thayer, talk for a minute about why Big Tech has1089found it so vitally important to kill any effort to have1090Federal online privacy?1091 Mr. Thayer. Because it's against their financial interest1092to actually be regulated. I mean, that's the basic--that's the1093obvious answer, but in reality, what you're pointing out, and I1094think everyone on this Subcommittee has experienced, it doesn't1095matter how tailored you make your legislation, it doesn't1096matter how measured. They will find some reason and put1097something forward.1098 If you want to do any trust reform, for instance, they'll1099say there's a privacy violation. If you say there's privacy,1100then we don't have to worry about competition. It's always this1101game of Whack-a-Mole. And so, at the end of the day, they like1102the way things are because it benefits them. The market is1103basically created for them.1104 And so, I think this is exactly why we have strong1105advocates fighting for things like the Kids' Online Safety Act,1106where you have parents begging Congress to do something, and1107we're seeing the harms play out right in front of us. I think1108at this point, we've recognized that Big Tech is in the1109``emperor has no pants'' moment and we are all starting to see1110that; that we absolutely need the reforms.1111 And so, things like the Open App Markets Act are going to1112be very helpful to quell any of those privacy concerns. The1113Kids Online Safety Act, I think will do really do a lot to1114measure targeted approaches that will ultimately help kids. But1115again, I think that the waves are changing, and I think that1116there--I'm very hopeful, and things that I'm seeing at the DOJ,1117especially from the Trump administration to the Biden1118administration out the gate to the new Trump administration, it1119seems as if everyone has identified that these companies are1120bad actors and they should not be trusted.1121 So, I hope whatever advocacy I can provide would be to1122outline that this really just don't fall for the red herrings.1123Ultimately, the side of right is to protect consumers, and Big1124Tech has no interest in doing that.1125 Chair Blackburn. Ms. Goodloe, I want to come back to you.1126In your testimony, you talked about State laws and the1127importance of some of those State laws. I want you to define a1128couple of the common elements that you have seen in the State1129laws that could be transferred into a Federal law that should1130be broadly supported and accepted.1131 Ms. Goodloe. Thank you for the question. I think the States1132provide a lot of common ground for Congress to look to as it1133works toward Federal privacy legislation. That common ground1134exists on things like the consumer rights that we've talked1135about today, rights to access, correct, delete, and port your1136data to another service, rights to opt out of the sale of your1137data, targeted advertising, certain types of profiling.1138 And States are unanimous on recognizing there are different1139types of companies that handle consumers' data. One set of1140obligations should be assigned to controllers who decide how1141and why to collect a consumer's data, how to use it. And one1142set of obligations should be put on the processors that handle1143the data on behalf of controllers.1144 I also want to take a moment to respond to something that1145Mr. Martino brought up about what those processors do when they1146employ other subprocessors. Because in many cases, what1147processors do is they collect a series of other subprocessors,1148package it together, and are able to provide it to business1149customers at scale so that their small businesses can enjoy the1150economies of scale at being able to use cutting edge1151technologies.1152 That means you are providing the same service to hundreds1153or thousands of business customers. And letting one object to a1154package of subprocessor doesn't work. That's why we haven't1155seen the majority of States adopt that, which could actually1156increase security risk to consumers when one of those1157subprocessors has a breach and they have to go and ask1158permission to change over the data.1159 But I think we do see broad agreement among the States1160about the right set of consumer rights and obligations on1161businesses to safeguard consumers' data, and to do so1162effectively along with a common enforcement system that is a1163regulatory-led enforcement system to ensure we have consistent1164expectations for companies that want to comply with privacy and1165security obligations.1166 Chair Blackburn. Mr. Martino, you wanted to respond?1167 Mr. Martino. Yes. Just on the point. And one thing to keep1168in mind with the ADPPA, that was the predecessor to the APRA.1169The way the definitions worked, a subprocessor was also defined1170as a processor. So, once it got to a processor, there could be1171this endless train of data sharing that the mainstream business1172has no control over.1173 Well, that might be great for efficiencies of the services1174that the main processor is providing. You know there's no check1175on the downstream. And so, that's why all that we've been1176pushing for was a simple notice to the Main Street business of1177the subprocessor you are using and the right to object. It's1178not like an opt-in that they can't go to them and they can't1179provide these efficiencies.1180 So, that's just a--I mean, it's an ``in the weeds'' point.1181But I think it's an important point because it's the Main1182Street businesses that will be held liable under most of these1183constructs because the same requirements aren't applying to the1184processors and the same enforcement mechanisms aren't applying.1185 I'll make one last point. In the APRA, the private right of1186action largely applied only to what are called the1187``controllers'', but of course, these Main Street businesses1188that can't really control the Big Tech companies. And it hardly1189applied to the processors and it didn't apply at all to the1190third parties.1191 So, I think we have to look at not just that these State1192laws have requirements, but who's subject to them and who's1193liable for those violations.1194 Chair Blackburn. Okay. You had additional questions?1195 Senator Klobuchar. Yes.1196 Chair Blackburn. Go ahead.1197 Senator Klobuchar. It's really an extraordinary panel, so1198thank you. I guess I would start with you again, Mr. Butler.1199Over time we've seen that these data privacy frameworks move1200away from a notice and consent regime to focus on data1201minimization and transparency, consumer control opt-out rights.1202Why is notice and consent insufficient for protecting user1203privacy?1204 Mr. Butler. Thank you for the question, Senator Klobuchar.1205I think, notice and consent really takes us back to that self-1206regulation point that was made in the FTC report 25 years ago,1207because that's essentially what it is, right? It's a rule set1208that says so long as you disclose in general terms what you're1209doing, then the law permits it.1210 And of course, the incentives there are clear, you put in1211your disclosure everything you could ever potentially----1212 Senator Klobuchar. That I never read.1213 Mr. Butler [continuing]. Do with that data----1214 Senator Klobuchar. Says the Senator who decided every1215morning this week I'm going to spend 5 minutes pushing1216``unsubscribe'' on my email, and I am still getting--I cut it1217in half what I'm getting. Yes, it's a nightmare.1218 Mr. Butler. And it doesn't shift business practices.1219 Senator Klobuchar. I know, but it's just really sad. Okay.1220Continue on, Mr. Butler.1221 Mr. Butler. And it doesn't shift business practices, and it1222doesn't change anything about the surveillance that surrounds1223us and the data collection that pervades, which is why a data1224set of data minimization rules that better align the business1225practices with the expectations of the users, and link the1226collection and use of data to what the services that people are1227actually requesting, I think better aligns with those reasons,1228and is much a much easier way to solve the problem.1229 Then, as I mentioned earlier, the individual control1230concept, which then requires us to all make thousands of1231choices every second of every day and face popups and questions1232in detailed settings.1233 Senator Klobuchar. Right. And then you pop the wrong one,1234suddenly you're in something else.1235 Mr. Butler. Exactly.1236 Senator Klobuchar. Mr. Levine what barriers does today's1237notice and consent, a regime that I was just talking to Mr.1238Butler about for data privacy, create for enforcers who are1239trying to protect consumers?1240 Mr. Levine. That's a great question, Senator, and I alluded1241to it earlier. It's not only are data privacy cases, but so1242many of the enforcement actions we brought at the FTC over the1243last 4 years, we said, ``Look, you surprised consumers. You1244misled consumers. You abused their data. You shared what1245medication they were taking with Facebook.'' And the company1246says, ``Hold up. We put it all in our privacy policy, and the1247consumer clicked, `I accept,' before proceeding to use the1248service.'' This is a total fiction. It's a total fantasy that1249consumers can protect themselves by reading privacy policies.1250 And to Mr. Thayer's excellent point, we can draw a direct1251line between Congress', in my opinion, inability to pass1252privacy laws and Big Tech lobbying. This is the most valuable1253industry in the history of the planet, and they have built1254their revenue not by selling cars, not by selling oil, but by1255collecting our data and predicting our behaviors. That's how1256they've built their valuations. They don't want restrictions in1257what they can collect, and that's why I think it's so important1258Congress defy what they want and actually pass a strong bill.1259 Senator Klobuchar. Very good. Mr. Martino, in your written1260testimony, you say that businesses should not be responsible1261for the data practices. We already went over that, but I guess1262my second question about that is just when you look at the1263differences between--as we look at how we craft this Federal1264law, and the States, and what's stopped us before, well, how do1265you think we're going to get around that to get to a place1266where we can get something done?1267 Mr. Martino. That's a great question. Thank you, Senator. I1268do think that we start with where the strong consensus of State1269laws have been. They have outlined, as Ms. Goodloe pointed out,1270a set of requirements. Our issue has really been with who gets1271exemptions, who's subject to the liability for violations, and1272is the law taking care of it?1273 I would say one of the things you can take from the State1274laws is that they realize there is this imbalance in1275negotiating power between smaller Main Street businesses and1276large Big Tech companies. So, they have taken the route of1277putting statutory requirements in.1278 We're just asking that you build on that framework and add1279a few more. One of the key issues on the APRA and the ADPPA1280before it was--that on there was a big debate over data1281minimization standards. And when the bill was originally1282drafted, the ADPPA, it was applying to both covered entities1283which are like the controllers or Main Street businesses as1284well as the processors.1285 But processors and Big Tech did not support that bill until1286that data minimization standard was changed to apply only to1287covered entities or controllers, and that is a fundamental1288difference.1289 I think while there are very good requirements in State1290levels. And most of the States from the same place it is not1291the case that everyone in the marketplace is handling data and1292protecting data for consumers and honoring their rights to the1293same level that is being put on the consumer-facing businesses.1294And we think Americans expect that their privacy is the same1295everywhere, as I said in my testimony. And we should have1296requirements that make that happen.1297 In terms of the politics, you know, if Big Tech's been1298fighting some of the previous bills that weren't so heavy on1299them, it's going to be more challenging if bills are more1300fairly and have equivalent standards more fairly balanced so1301but.1302 Senator Klobuchar. One of our best arguments as we look at1303the politics of this is on both sides is affordability. And Mr.1304Levine, I know you did this study on how the collection of this1305data can affect affordability. So, I look at some of the fresh,1306new arguments we can make to convince our colleagues, which is1307always fun to do, but we're doing better and better. Could you1308tell us about that?1309 Mr. Levine. Well, I think it is a new argument, Senator,1310because it's a new practice. We're seeing more and more1311companies using--some people think of privacy as a discrete1312issue; I have nothing to hide, you have nothing to hide.1313Privacy is much deeper than that. And what we are finding and1314what the FTC study found is that companies are using these1315reams of data as they've collected. And they've historically1316used to target people with advertisements.1317 We know that's been very profitable, but they're suddenly1318realizing they could target people with individual prices. And1319they go around and they tell Members of Congress and State1320houses, ``Oh, we're just doing this because we want to lower1321prices and send people discounts.''1322 This is ridiculous. They are paying companies like1323McKinsey, high pricing consultants, to use AI optimization and1324reams of consumer data to set individual prices. And they're1325not doing it to lower their profits. They're not doing it to1326lower their prices. They're doing it so that they can raise1327prices on the Americans who are most desperate for goods and1328services.1329 We have always seen that pricing abuses can start in the1330airline industry. That is what we are seeing now with Delta,1331and I have a lot of concern this is going to spread throughout1332the economy, and the early results of our FTC study show that1333it already is.1334 Senator Klobuchar. And we've seen the same thing with rent,1335by the way----1336 Mr. Levine. Absolutely.1337 Senator Klobuchar [continuing]. Collecting of data on rent.1338 Chair Blackburn. Let me jump in on this, because we really1339appreciate having all of you here. On surveillance pricing.1340Just a show of hands, do you think surveillance pricing should1341be banned?1342 [Hands raised.]1343 Mr. Levine. Yes.1344 Chair Blackburn. Okay.1345 Mr. Thayer. How would you define surveillance pricing?1346 Chair Blackburn. I know, I know. I just wanted a response.1347Mr. Martino?1348 Mr. Martino. For the record, my hand was not up, it was1349down--asking a question as to what you meant, but yes.1350 Chair Blackburn. I want you to talk then a little bit about1351shared data, order, history, loyalty programs, and then how1352long you keep that, and how you incent that keeping of the data1353because that's a choice that somebody makes to enter into that1354loyalty program.1355 Mr. Martino. Absolutely, Senator, and in doing so, let me1356just first address what Mr. Levine said. I know there's the1357concern that what pricing may happen in one industry, or the1358way those practices go, it may come down to retail.1359 I think there's a very significant difference between the1360retail industry and let's say some other industries. And it's1361really comes down to competition where you have robust1362competition like you do in the retail industry and very low1363profit margins. The goal on retail is volume. It's business.1364It's attracting new customers. It's growing the business1365because you have very little profit on each item.1366 And what that leads to is, I think, a market constraint.1367So, almost like a defacto regulation in terms of having such1368severe competition that your competitor is one click or tap1369away on an app or one stop away. And so, what's the mindset of1370retailers and Main Street businesses is how do I attract more1371customers? How do I do that?1372 Well, you have to do that with excellent customer service.1373I mean, the only way to really differentiate yourself is to do1374that. And so, loyalty plans are one way that is done. There's a1375report that I cited to in the testimony called the Bond Brand1376Loyalty Report. They do it every year. They've been doing it1377the last 14 or 15 years.1378 They survey consumers, consumers say that 85 percent of1379them will continue to shop at a brand if they have a great, or,1380or yes, will continue to buy products from a brand that has a1381great loyalty program. So, yes, loyalty programs are one of1382those very important features.1383 And also, it's important to note, it's also inherently1384privacy, protective of loyalty plan in the sense that they're1385not foisted on consumers without their choice. You have to opt1386in to avoid a loyalty program. You have to be delivered the1387deal and decide whether you want to do that or not. And the1388State laws recognize this as well.1389 The only protections for loyalty plans are based on1390bonafide loyalty plans where a consumer has voluntarily opted1391into participate in it. So, I think there are ways that, you1392know, one of our principles is that businesses and consumers1393should be able to freely develop a business relationship.1394 And if businesses on Main Street can develop those1395relationships, whether it's a very small business offering a1396buy one get two free, or buy five cups of coffee, get the six1397one free, they should be able to have those kinds of1398relationships as long as they're privacy protective. And we1399think they are in terms of making sure they're voluntary.1400 And it's important to also note that the loyalty programs1401are subject in the State laws to every other requirement in the1402law. So, whether it's a right to opt out or a right to delete,1403the consumers have those rights. So, we think there are good1404business ways to do it.1405 And loyalty is something that's been around in the retail1406industry for centuries. And we could go to general store1407examples and things from 1890, but the same thing applied back1408then that applies now.1409 Chair Blackburn. Okay. Mr. Levine?1410 Mr. Levine. Well, thank you, Senator. You know, it's one1411thing to join a loyalty program and say you can track my1412purchase history in exchange for getting coupons, fine, but1413what the FTC study showed is that these consultants are telling1414companies; look at what consumers are Googling, look at what1415they're searching online, look at their location, look at how1416they're sorting products.1417 A bunch of California law enforcers actually sued Target1418for increasing in-app prices while consumers were inside a1419Target store. So, they didn't know that they could pay lower1420prices when they're not at the store.1421 Briefly, with respect to loyalty programs, again, I think1422if consumers voluntarily turn over information, that's fine.1423But what we saw in this Delta earnings call is what Delta said1424is we can stop matching prices because of our brand strength,1425because of our customers' loyalty.1426 And in a world of surveillance pricing, my fear is that1427companies are going to prey on the consumers who are going to1428pay the most. You might say they're the most loyal, rather than1429giving them discounts. That's what we're already seeing in the1430airline industry.1431 Chair Blackburn. All right. Mr. Martino, come back?1432 Mr. Martino. I'll keep it to a 10-second response. What1433applies to Delta doesn't apply to Main Street businesses. You1434have to look at the size of the market, the competition in the1435market. Airline industry is notorious for being very few1436competitors, not millions of businesses across America.1437 Chair Blackburn. Years ago, as we were starting in on this1438debate, I would have people take out their key chain and look1439at their fobs that were on there, and those are programs they1440were choosing to share information with because of the1441incentive that would come back to them.1442 Those times have changed. I want to go to the issue of AI1443because we are looking at these AI models that are collecting1444more and more personal data. They are doing tracking search1445history monitoring. And as we look at the prevalence of AI, and1446we've had a hearing on the NO FAKES Act to protect name, image,1447likeness, and voice of individuals, and that in essence is a1448form of privacy.1449 But one of the questions that will come before us as we1450look at developing a Federal privacy standard is how you hit1451that sweet spot of being strict enough to have that preemptive1452Federal enforcement, but yet, flexible enough to allow the1453innovation of new technologies that we see, things that are1454going to run on quantum rails, things that are going to be AI1455applications.1456 So, Ms. Goodloe, let me come to you on that, and then I'd1457like Mr. Thayer for you to give me a response also.1458 Ms. Goodloe. This is such an important question, and thank1459you for asking that. I think there are a couple of different1460ways to look at the need for a Federal privacy law and its1461intersection with AI technologies. I think the first thing to1462look at is a recognition that AI can involve many different1463types of data. Some of that data may be personal if an AI1464system is using personal data that relates to consumers. But a1465lot of the data used to train AI systems is not personal data.1466For example, AI systems may be trained to detect weather1467patterns based on data that's just about the weather and not1468about people. But when it comes to AI systems that may be1469processing personal data, that's where a Federal privacy law is1470very important to create the right set of safeguards so that1471consumers know their data will be handled responsibly in,1472trustworthy ways.1473 One key issue is exactly what you pointed out, the need to1474make sure that a law is flexible enough to allow those products1475to continue to innovate over time. And I think this is one of1476the struggles that we've seen as the conversation about data1477minimization has evolved. That is such an important1478conversation, but you have to get it right because a standard1479needs to allow for technologies to get better over time. I1480expect all of the technology that I use today to be better next1481year and even better the year after that. And so, it is1482important as you look at these protections to make sure they're1483flexible over time and to think through the uses that you want1484to apply to create the right set of safeguards.1485 Chair Blackburn. Okay. Mr. Thayer?1486 Mr. Thayer. Thank you, Senator. And I think Kate put it1487very well. There is that nuance when it comes to AI, right? You1488do have that anonymized data, but there also is the question of1489what the consumer expected when they gave that data over. And I1490failed to remember exactly who said it, but it really is like1491big that data is the new oil and what runs the machine.1492 The AI machine is data. So, the question is where are they1493getting it and how are they using it? So, I think at the front1494end, the consumer has to know how is this data going to be1495used? Is it going to be used to train an AI system? Are there1496elements of transparency in terms of how this this this data is1497going to be used down the road?1498 That comes down to really being upfront with the consumer1499on where the data is going. And I think that's when it goes1500back to my testimony when I said that we just feel like it's1501out of control. We don't feel like we know exactly what happens1502when we put the data into any application or any use of search.1503So, a big part of this is going to be transparency, and1504specifically, what data these AI systems are training on. Are1505they training on PII, are they training on anonymized data?1506Where are they pulling it?1507 And Senator, as you well know, there are ancillary issues1508like intellectual property that are also included into all of1509this as well. So, the big question really comes down to, with1510respect to privacy, is what rights do citizens have when it1511comes to protecting their data on the front end? So, that way,1512it's not used on the back end to do all the parade of horribles1513that we've already heard about today.1514 So, that's how I see it in most cases. I think at the end1515of the day, the consumer has to know exactly what their data is1516going to be used, and whether or not it--and also on the AI1517system, what are they training their data on?1518 Chair Blackburn. So, you're looking for specificity in that1519utilization?1520 Mr. Thayer. Specificity, and at the very least, being able1521to have the consumer be empowered to say, I do not want my data1522to be used for X, Y, and Z. So, it's both.1523 Chair Blackburn. Opt-in, opt-out.1524 Mr. Thayer. Yes.1525 Chair Blackburn. All right. Do you have any other----1526 Senator Klobuchar. Oh, I'll just--I think Senator Schiff is1527coming. I thought maybe, you know, since we have a glass1528ceiling for only women asking questions here.1529 Chair Blackburn. We kind of like that.1530 Senator Klobuchar. I mean, Hawley came by, Blumenthal.1531They've all had other hearings. They're great, and been really1532helpful to us. Maybe I'll just ask two more and see if he can1533make it.1534 Chair Blackburn. Okay. Go ahead.1535 Senator Klobuchar. So, Mr. Thayer, in your written1536testimony you referenced a European study that found that after1537the passage of GDPR, the General Data Protection Regulation----1538 Chair Blackburn. I'm going to have to jump in here because1539they need me to go to VA to vote.1540 Senator Klobuchar. That's where he is.1541 Chair Blackburn. Yes, that's where Senator Blumenthal is.1542So, I will say my thank yous to you-all, in case I don't get1543back before this closes, and remind you all that we're going to1544have questions for the record.1545 As you can see, we have lots of questions, and we are ever1546so grateful that you-all have come before us. I'll go vote.1547 Senator Klobuchar [presiding]. Okay. Thank you very much.1548And thank you, again, for putting together this hearing.1549 So, I was talking about the GDPR. We know we don't like1550everything that Europeans are doing on tech, but there are some1551good examples of some good things they've done. What about1552GDPR? Were Big Tech platforms able to take advantage of to1553entrench their position, and how can we avoid doing the same in1554the U.S., and how can we design data privacy standards that1555reign in abuses? What's the good things we can get out of that?1556I know there's things we could simply do here that they agreed1557to in Europe that we're still fighting out over here.1558 Mr. Thayer. So, it's a fantastic question, and I think it1559really comes down to defining your goals. That was like the1560first big issue. But in terms of what happened with the GDPR,1561and to be clear, there are elements of the GDPR that I think a1562lot of States have latched onto, particularly Texas, where they1563pull this analytical framework between data controllers and1564data processors. Being able to articulate exactly who has the1565responsibility is a big part of it.1566 Senator Klobuchar. I just want to have the record reflect1567the Texas used the European model, but keep going.1568 [Laughter.]1569 Mr. Thayer. I fell right into it. But I think where things1570went a little bit awry, where there was this weird1571responsibility that the controllers basically had with respect1572to contractual regulation. I think it's Article 24 of the GDPR1573where the controller basically has to dictate specifically.1574Well first whether or not they have to make the assessment of1575whether or not the processor is even GDPR compliant. And that1576gives the controller a lot of authority over what that smaller1577company most likely can do and can't do. I think that's one1578area we may want to stay away from.1579 But my overall point was that you need privacy and strong1580antitrust enforcement in competition enforcement. I think the1581both two things go hand in hand. And so, I think what Congress1582is currently looking at and I think is very important is that1583it seems like you guys want to walk and chew gum which I very1584much appreciate where you have these competition reform bills1585that are currently being discussed.1586 You are a sponsor of that, Senator, which is the Open App1587Markets Act. I think that goes a long way in quelling some of1588those concerns. But one of the things I would caution against1589is creating an overly generalized authority and allowing the1590controller to have the pure mandate or at least the pure1591control of what the smaller companies are doing. I think that's1592one way you can avoid some of the pitfalls.1593 Senator Klobuchar. Okay. Last two questions, Mr. Martino,1594and they're related, and then I'll turn to Senator Schiff.1595We're very excited you're here. Yes, thank you. Mr. Martino,1596you can followup on that, but could you talk about the1597challenges small businesses have operating across State lines,1598quickly, because I want to give Senator Schiff a chance here.1599 Mr. Martino. Certainly, Senator. First, let me just1600followup real quickly. I wanted to add a point to what Mr.1601Thayer was saying. It's just that there are some things that1602are problematic in the GDPR. And some of the expectations put1603on controllers envision a construct where the controller is the1604big company and they're getting these smaller processors to do1605what they want. And that's not what's developed here in the1606U.S. where you have very few almost monopolistic Big Tech1607companies who are doing the vast majority of the processing1608consumers need----1609 Senator Klobuchar. Understand.1610 Mr. Martino [continuing]. Including transmission, including1611broadband, and cable.1612 And think about how a main street business might only have1613a choice of one broadband provider and imagine trying to1614negotiate that contract. I mean they don't do as--they do the1615same as we do when we try to argue about a cable bill or a1616broadband bill. So, we've all had that experience.1617 In terms of the multi-state operations, it's sort of a1618sense that I know I put in my original testimony. Many of us1619live in areas that are tri-state or multiple States are close1620by. There is travel across State lines. There's shopping, and1621then certainly online, you know, if there's a boutique store in1622Minnesota that while you're here in Washington doing your job1623here, you want to make a purchase from there. You are engaging1624in interstate commerce.1625 And so, it's really important and these privacy laws tend1626to be set up to apply to the location where the consumer is.1627So, if you're in DC and you don't have a privacy law, are they1628complying with privacy law there? So, what these small1629businesses need to do is they have to--I mean, there's a1630defacto national standard because they have to comply with all1631these different States, but they're constantly changing. New1632laws are coming online. So, Congress can do a really helpful1633job by passing a uniform national standard.1634 Senator Klobuchar. Yes. And last question here, Mr. Butler.1635You've advocated for Federal privacy law as well, what you1636want, one that sets a floor. Obviously, this is all going to be1637political negotiations, but could you talk about why you would1638take that approach?1639 Mr. Butler. Sure. Thank you for the question, Senator1640Klobuchar. You know, as Mr. Martino alluded, I think from the1641vast majority of businesses in this country, they just want to1642know what the rules are. And Congress's traditional role in1643privacy laws has been to set the baseline standard, but allow1644States to address new challenges and threats as they emerge.1645And that's been true. And I have the list here, I could rattle1646off the list of acronyms, but if you look at Federal privacy1647statutes, by and large, they don't set a ceiling on the level1648of protection that States can provide.1649 But what's really essential here is for the Federal1650Congress to step in and say, ``Here's what the consistent1651standard is.'' And I think if they do that, then we'll have a1652consistent standard. Companies will know what to comply with,1653and States still have the flexibility in the future to address1654new issues.1655 Senator Klobuchar. Thank you. Senator Schiff.1656 Senator Schiff. Thank you. Thank you for----1657 Senator Klobuchar. The filibuster [off mic].1658 Senator Schiff [continuing.] Too. I understand that you1659did, and I'm grateful for that and for all your leadership on1660this issue.1661 Nearly, a decade ago, California became the first State in1662the Nation to adopt a comprehensive consumer privacy law, the1663California Consumer Privacy Act. This was shortly followed by1664the establishment of the California Privacy Protection Agency,1665which has served Californians for the last 5 years by1666implementing and enforcing the State's privacy laws.1667 Other States have looked at California and our example, and1668followed our lead, especially as new technologies have emerged,1669AI facial recognition, algorithmic targeting, each posing more1670sophisticated threats to Americans privacy. At the end of the1671day, California has proven you can be the fourth largest1672economy in the world and be home to the most innovative1673technology companies on the planet. And you can still protect1674consumers' fundamental right to privacy.1675 To this end, I'd like to enter into the record a letter1676from the California Privacy Protection Agency on the importance1677of a Federal privacy law that creates robust baseline1678protections while allowing States like California to continue1679to adopt stronger protections and respond to the rapidly1680changing technologies being built in our own backyard. May that1681letter be entered in the record?1682 Senator Klobuchar. Of course, it will. Yes. We just have,1683you know, procedural things.1684 Senator Schiff. Yes, thank you. The horrific political1685assassinations last month targeting Minnesota lawmakers that I1686know Ranking Member Klobuchar has already referenced were1687aided, in part, by a data broker and website the shooter used1688to look up politicians' addresses.1689 A recent investigation also revealed that a data broker1690owned and operated by at least nine major U.S. airlines1691secretly sold Americans' information collected through flight1692records to U.S. Customs and Border Protection, and U.S.1693Immigration and Customs Enforcement.1694 Starting on January 1, 2026, 40 million Californians will1695be able to go to a single webpage hosted by the California1696Privacy Protection Agency and request that their data be1697deleted from over 500 data brokers if they choose. Federal1698legislation that preempts California's Delete Act without1699meaningful consideration of State level protections, could mean1700that Californians will lose this touch-of-a-button ability to1701know how their data is being used and have a voice in it.1702 Mr. Butler, and Mr. Levine, how can a Federal privacy law1703include better regulation of data brokers, including their1704registration and central clearinghouse, and allow Americans to1705prevent the personal information from being sold to outside1706entities like we have done in California with a soon to be1707implemented Delete Act?1708 Mr. Butler. Thank you, Senator Schiff, for the question. I1709think that California really has taken the lead here on1710tackling the problems of data brokers in this specific context.1711And I think both the requirements of registering, given that1712the average consumer has no way really to know what data1713brokerage exists and who might have access to their1714information, and also providing a centralized mechanism to1715allow for deletion of data held by these entities are really1716important protections, especially because this is a massive1717problem that requires scaled solutions, right?1718 This isn't a situation where an individual consumer can be1719expected to go to every single one of hundreds or thousands of1720data brokers and submit individualized requests. So, I think1721both of those are really important protections that have been1722developed in California.1723 Senator Schiff. Mr. Levine? Am I pronouncing your name1724correctly?1725 Mr. Levine. You are. Thank you, Senator. I fully agree with1726Mr. Butler on the need for a floor rather than a ceiling1727consistent with other Federal privacy laws. You know, I'll make1728a quick point. I started my career at a State attorney general1729in the run up to the financial crisis. It was State AGs1730desperately trying to stop subprime mortgages, the innovative1731products of the day. And it was Federal banking regulators1732cheered on by big banks that were actively trying to stop them.1733 So, as I hear today, Big Tech companies go around1734Washington saying we need to hit delete at all of these1735important State laws, like the one you referenced, Senator. I1736recall that similar conversations two decades ago, and I1737recall, well, what happened in our country as a result. Two1738quick points specifically on data brokers. You know, the first1739is that we brought a series of enforcement actions under chair1740Khan at the FTC. And what we required data brokers to do, we1741banned them from sharing sensitive location data, and we1742prohibited them from building profiles of consumers based on1743sensitive geolocation data. I think that's a really important1744precedent.1745 I think Congress also acted, I think, in the last Congress1746with the--I'm going to get this wrong--Protecting American Data1747from Foreign Adversaries Act, PAFACA. Given the FTC enforcement1748authority, I think it's regrettable that 6 months into this1749administration, we've not seen a single enforcement action. I1750hope that changes.1751 Senator Schiff. Madam Chair, do I have time for one more?1752 Senator Klobuchar. Oh, yes.1753 Senator Schiff. Okay. Thank you. Over the past few months,1754I've led a number of letters along with my colleagues to the1755Trump administration in response to alarming reports that1756various agency officials have ordered States to hand over the1757personal data of millions of Medicaid enrollees, as well as1758SNAP recipients, and applicants to the Department of Homeland1759Security. These actions are remarkable departure from1760established Federal privacy protections and should alarm1761everyone. I've demanded the administration reverse these1762actions, which likely violate several Federal and State privacy1763laws, including the Privacy Act of 1974, HIPAA, and the Social1764Security Act.1765 Mr. Levine, what precedent does it set when Federal1766agencies under the administration simply bypass established1767privacy laws that have protected Americans for decades and1768demand that States hand over their residents' most sensitive1769information with little or no explanation? And how does this1770compare to privacy protections in other democratic nations? Are1771we seeing the U.S. now fall behind international standards for1772protecting citizens' data?1773 Mr. Levine. Thank you, Senator. I think we have the right1774standards here, at least with respect to government. It's not1775clear whether government officials are following them, and that1776makes me very worried. One of my consistent messages as an1777enforcer to Big Tech companies and to everyone, is you need to1778follow privacy laws. And if you don't, they're going to be1779consequences.1780 And when you have reports, and I've not verified them1781myself, but when you have reports of Federal officials and1782Federal agencies brazenly violating hard-won privacy1783protections around Federal data, resulting in potential loss of1784healthcare, loss of jobs, loss of housing for Americans, I1785think that's deeply disturbing. And it raises a real question1786of how Congress is going to pass a privacy law to bind the1787private sector when the Federal Government isn't following its1788own rules.1789 So, I completely share your concern, and I hope to see1790changes in that from this administration.1791 Senator Schiff. And, finally, if I could very quickly, Mr.1792Butler, you mentioned that there were a list of other privacy1793laws where Congress had set a floor, not a ceiling. Can you1794share a few of those with us?1795 Mr. Butler. Absolutely. And I'm happy to supplement the1796record with that as well.1797 Mr. Butler. But just to note that basically every major1798Federal privacy law sets either a floor or a conflict1799preemption standard. And that includes the Electronic1800Communications Privacy Act, the right to Financial Privacy Act,1801the Cable Communications Privacy Act, the Video Privacy1802Protection Act, the Employee Polygraph Protection Act, the1803Telephone Consumer Protection Act, the Driver's Privacy1804Protection Act, the Gramm-Leach-Bliley Act, and the Fair Credit1805Reporting Act.1806 These are not ceiling preemptions. They don't limit State's1807abilities to adapt, and evolve, and protect their citizens1808more.1809 Senator Schiff. Oh, thank you. Thank you, Ranking Member. I1810appreciate it.1811 Senator Klobuchar. Okay. Very good. Well, thank you. And1812this is a lot of great testimony and answers. I just can't tell1813you how inspired I am from this work and Marsha's willingness1814to put this panel together, the good questions, and just, you1815know, I always think maybe we can do this. Maybe we can1816actually get a privacy standard and then, you know, I get1817excited and then it's hard.1818 But as this gets more and more important, and with the1819advent of AI, and just the patchwork, and maybe we can get some1820more incentives going to try to get to a better place on this,1821despite what everything would seem. And what gives me hope is1822just the people that are involved in this Subcommittee, people1823we work with on commerce, and their ability to kind of take1824risks in terms of what the everyone wants them to do, and try1825to find some common ground on this issue, which we have done1826several times.1827 So, I just want to thank all of you for the testimony, and1828the hearing record will remain open for one for 1 week. And the1829hearing is adjourned.1830 [Whereupon, at 4:22 p.m., the hearing was adjourned.]1831 [Additional material submitted for the record follows.]1832 [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]18331834 A P P E N D I X18351836The following submissions are available at:18371838 https://www.govinfo.gov/content/pkg/CHRG-119shrg61893/pdf/CHRG-1839 119shrg1840 61893-add1.pdf18411842Submitted by Chair Blackburn:18431844 Consumer Technology Association (CTA), letter................... 218451846Submitted by Senator Schiff:18471848 California Privacy Protection Agency (CPPA), letter.............. 418491850 [all]