FT : Big tech changes tack on US privacy regulation

Big tech changes tack on US privacy regulation
Federal data protection rules would be good for consumers, not just the industry


For years, the world’s biggest technology companies lobbied politicians to leave them alone. In a striking change of approach, executives from Google, Amazon, Twitter and others asked a Senate committee last week for regulation. After the EU’s General Data Protection Regulation and, more significantly, new California privacy rules that establish broad definitions for personal information, impose restrictions on selling data to third parties, and fine companies for data breaches, big tech has decided it wants US politicians to impose a national privacy law.

One motive is to avoid internet regulation splintering along US state lines. Regulatory fragmentation and arbitrage is already happening internationally, as the US, Europe and China move in different directions on issues such as privacy, personal data rights and competition. In an ideal world, there would be a single international regulatory regime for technology, given that no industry is more borderless than big tech. We do not live in that world.

Another reason the tech sector is pushing for a single national policy in lieu of state rules is a concern that stricter states will end up setting the de facto regulations for the rest of the country — in the same way that the EU’s GDPR is now becoming a global standard for many multinational companies. The California rules, set to go into effect in 2020, are in some ways even tougher than the EU’s. Customers can, for example, explicitly ask firms not to share a broad range of data, rather than a more blanket “opt in” and “opt out” clause. Massachusetts has passed a bill strengthening protections for consumers suffering data breaches. Illinois has a law restricting collection of biometric data that Google and Facebook are pushing back against.

Certainly, the US should try to avoid fragmentation of regulation at the state level. But it should also avoid watering down regulation in order to come up with a national standard. As recent Senate commerce committee hearings made clear, there is still plenty of opacity in how the largest platform tech companies define data, and sell it to third parties. Provisions for what happens to users whose data are compromised, meanwhile, are not strict enough. At the moment, the burden of proof is on users themselves. If the California regulation is copied, it will be on the companies to prove that they have taken the right steps to avoid hacking.

What is clear is that the current model of “self-regulation” is not working. The technology sector, like the financial sector before it, has long argued that the complexity of its business model could not be well understood by politicians or the public at large; protecting the public from the downside of technology should therefore be left to technologists. If the past few years have shown us anything, it is the folly of that argument.

The complexity and systemic importance of technology in fact argues for a tougher approach to regulation. Ideally, Congress would convene a diverse body of experts to look at the economic, political, and social ramifications of the rise of platform tech companies. Policy could then be shaped to ensure the transition to the digital economy is both safe for users, and not a zero-sum economic game. Co-ordination is essential, since many of the tech-related policies adopted by the administration so far — from the rollback of net neutrality to increased interest in antitrust regulation — are being crafted in silos. Sadly, co-ordination is not a strength of this administration. It is up to Congress to err on the side of regulatory safety with a national data privacy policy that is good for the public, as well as the industry.