Across the United States, evolving data collection and processing practices and advances in artificial intelligence are driving new digital services, technologies, and socially beneficial research – while also raising new opportunities, risks, and questions for individuals and communities. In response, state and federal policymakers are considering new legislative and regulatory frameworks on three interconnected fronts: comprehensive consumer privacy laws that establish baseline rights and protections for personal data across the economy; frameworks that target specific sectors and practices such as automated decisionmaking, biometric identification, companion chatbots, data-driven pricing, data brokerage, frontier AI model safety, genetic data, and health data; and youth-specific privacy and online safety laws that set distinct rules for minors. These three tracks rarely stay in their lanes: a comprehensive privacy law may include AI provisions, an AI safety bill may carve out rules for minors, a youth online safety law may hinge on biometric age verification. Understanding the landscape requires understanding both the individual pieces and how they fit together.
FPF’s U.S. Legislation team provides expert, independent, pragmatic analysis of state and federal legislative and regulatory approaches to privacy, AI, and youth online safety – three distinct but increasingly intertwined issue areas. The team tracks emerging proposals, compares new laws against existing frameworks, analyzes implementation and compliance implications, and helps policymakers and stakeholders understand how legal requirements interact with current technologies, business practices, and data uses.
Through reports, blog posts, legislative and policy analyses, webinars, in-person and virtual peer-to-peer gatherings, and educational programs, FPF helps the broader technology policy and governance community understand the mechanisms and strategies available to protect privacy, promote responsible AI development and deployment, and advance youth online safety. FPF does not typically support or oppose particular bills. Instead, the U.S. Legislation team focuses on explaining the practical and legal implications of proposals – individually and as they interact with one another. This work helps ensure that privacy, AI, and youth safety compliance and policy strategies remain future-looking, adaptable, and workable for the continued, beneficial use of data and AI.
FPF’s U.S. Legislation team is led by Tatiana Rice, Senior Director.
Featured
Navigating Preemption through the Lens of Existing State Privacy Laws
This post is the second of two posts on federal preemption and enforcement in United States federal privacy legislation. See Preemption in US Privacy Laws (June 14, 2021). In drafting a federal baseline privacy law in the United States, lawmakers must decide to what extent the law will override state and local privacy laws. In […]
Manipulative Design: Defining Areas of Focus for Consumer Privacy
In consumer privacy, the phrase “dark patterns” is everywhere. Emerging from a wide range of technical and academic literature, it now appears in at least two US privacy laws: the California Privacy Rights Act and the Colorado Privacy Act (which, if signed by the Governor, will come into effect in 2025). Under both laws, companies […]
Preemption in US Federal Privacy Laws
As federal lawmakers consider proposals for a federal baseline privacy law in the United States, one of the most complex challenges is federal preemption, or the extent to which a federal law should nullify the state laws on the books and the emerging laws addressing the collection and use of personal information. Many recognize the […]
Colorado Privacy Act Passes Legislature: Growing Inconsistencies Ramp Up Pressure for Federal Privacy Law
Today, the Colorado Senate approved the House version of the Colorado Privacy Act (SB21-190) that passed yesterday, on June 7. If approved by Governor Jared Polis, Colorado will follow Virginia and California as the third U.S. state to establish baseline legal protections for consumer privacy. “Although the Colorado Privacy Act contains notable advances that build […]
Privacy Trends: Four State Bills to Watch that Diverge from California and Washington Models
During 2021, state lawmakers have proposed a range of models to regulate consumer privacy and data protection. As the first state to pass consumer privacy legislation in 2018, California established a highly influential model with the California Consumer Privacy Act. In the years since, other states have introduced dozens of nearly identical CCPA-like state bills. […]
Automated Decision-Making Systems: Considerations for State Policymakers
In legislatures across the United States, state lawmakers are introducing proposals to govern the uses of automated decision-making systems (ADS) in record numbers. In contrast to comprehensive privacy bills that would regulate collection and use of personal information, automated decision-making system (ADS) bills in 2021 specifically seek to address increasing concerns about racial bias or […]
U.S. Department of Education Opens an Investigation into Pasco County’s Predictive Policing Program
This post was originally released on studentprivacycompass.org, and can be found here. On Friday, the U.S. Department of Education opened an investigation into the data-sharing practices between Florida’s Pasco County sheriff’s office and school district. First uncovered in November 2020 by reporting by the Tampa Bay Times, the Department will be investigating the school district’s […]
FPF Testifies on Automated Decision System Legislation in California
Last week, on April 8, 2021, FPF’s Dr. Sara Jordan testified before the California House Committee on Privacy and Consumer Protection on AB-13 (Public contracts: automated decision systems). The legislation passed out of committee (9 Ayes, 0 Noes) and was re-referred to the Committee on Appropriations. The bill would regulate state procurement, use, and development […]
Supporting Responsible Research and Data Protection
Scientific research is often dependent on access to personal information, whether collected directly from individuals or collected for a real-world use and then accessed for research. For research to be trusted, processing of personal information must be lawful, ethical and subject to privacy and security protections. Supporting responsible research is a priority for FPF: Data […]
Manipulative UX Design & the Role of Regulation: Event Highlights
On March 24, the FPF hosted “Dark Patterns:” Manipulative UX Design and the Role of Regulation. So-called “dark patterns” are user interface design choices that benefit an online service by coercing, manipulative, or deceiving users into making unintended or potentially harmful decisions. The event provided a critical examination of the ways in which manipulative interfaces can […]