Tech giants call for national data regulations that subvert California's GDPR-style laws

Senators say that any federal law would need to be more progressive than a state's approach

Capitol Hill building

US Tech giants have said they would back a nation data regulation provided that it came into force before California's much tougher privacy legislation, in what's being seen as an attempt to avoid GDPR-style data protection laws.

During a hearing on Wednesday before the Senate Committee called 'Examining Safeguards for Consumer Data Privacy' members of Congress heard from six companies, including representatives from Google, Apple, Amazon and Twitter.

In his opening statement, the chairman of the committee, Senator John Thune said the question was no longer whether the US needed a federal law to protect consumer privacy, but rather what shape will that law take.

To replace current laws that are enforced at the state level, a countrywide privacy bill is being crafted, but senators are worried that tech companies will not like what is being put together, believing they will feel it's akin to the GDPR, which came into effect in March, or be similar to California's Consumer Privacy Act (CCPA) set to be implemented in 2020.

Instead, tech companies are working with lawmakers in an effort to avoid GDPR-style regulation that would place far greater restrictions on how and what data can be processed.

The representatives discussed three key points for a potential privacy legislation: a state law that pre-empts the California legislation; a promotion of privacy on their terms; and a block to the creation of a US version of the GDPR.

California Governor Jerry Brown signed the CCPA in June, which aims to give consumers more control over how companies collect and manage their personal information. The law, which is due to take effect in 2020, effectively replicates many of the provisions set out by GDPR inside the state of California, something which tech companies such as Alphabet Inc's Google and Amazon oppose as being too restrictive.

Referencing the GDPR, and also California's Law, AT&T senior VP of global public policy, Len Cali said: "What we're urging is a comprehensive federal law that looks at both these laws, learns from them, but does better than them."

At the hearing, Amazon VP Andrew DeVore said that California's law was hastily written and the law's definition of personal information went too far.

"The result is a law that is not only confusing and difficult to comply with, but that may actually undermine important privacy-protective practices," he said.

The drafting of tough data laws has played out simultaneously with high profile news stories such as the Cambridge Analytica scandal and the recent data breach to Equifax that affected around 145 million of its customers in the US, UK and Canada.

The tech companies are in favour of a federal law, provided it preempts California's 2020 legislation and doesn't emulate the GDPR. But the senators said that for a federal law to nullify a state law, it would have to be more progressive and robust than the state law which had already been voted for.

"I understand that from the standpoint of these companies, the holy grail is preemption," said Senator Brian Schatz. "We're not going to get 60 votes for anything and replace a progressive California Law, however flawed you may think it is, with a non-progressive federal law."

Matt Lock, director of sales engineers at Varonis said that the tech companies feared many other states would follow California's example and adopt tougher regulations.

"Tech leaders are afraid that consumer privacy laws similar to the GDPR will gain popularity among U.S. states and upend their business model, which often involves treating a person's data as a commodity to be bought and sold in exchange for a free service," he said.

"When an industry bands together to help steer the discussion in their favour it's because they fear strict laws down the road. California may be the first state to adopt GDPR-like laws, but it will not be the last."

Featured Resources

BIOS security: The next frontier for endpoint protection

Today’s threats upend traditional security measures

Download now

The role of modern storage in a multi-cloud future

Research exploring the impact of modern storage in defining cloud success

Download now

Enterprise data protection: A four-step plan

An interactive buyers’ guide and checklist

Download now

The total economic impact of Adobe Sign

Cost savings and business benefits enabled by Adobe Sign

Download now

Recommended

ICO to relax GDPR enforcement during coronavirus economic downturn
General Data Protection Regulation (GDPR)

ICO to relax GDPR enforcement during coronavirus economic downturn

16 Apr 2020
The NHS teams up with Apple and Google on coronavirus tracking app
privacy

The NHS teams up with Apple and Google on coronavirus tracking app

14 Apr 2020
Health sites are 'unlawfully' sharing medical data with Facebook and Google
data protection

Health sites are 'unlawfully' sharing medical data with Facebook and Google

7 Apr 2020
Supreme Court rules Morrisons was not liable for 2014 data breach
data protection

Supreme Court rules Morrisons was not liable for 2014 data breach

1 Apr 2020

Most Popular

16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

16 Sep 2020
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

16 Sep 2020
Nokia will replace Huawei as BT's largest 5G equipment provider
5G

Nokia will replace Huawei as BT's largest 5G equipment provider

29 Sep 2020