Tech giants call for national data regulations that subvert California's GDPR-style laws

Senators say that any federal law would need to be more progressive than a state's approach

Capitol Hill building

US Tech giants have said they would back a nation data regulation provided that it came into force before California's much tougher privacy legislation, in what's being seen as an attempt to avoid GDPR-style data protection laws.

During a hearing on Wednesday before the Senate Committee called 'Examining Safeguards for Consumer Data Privacy' members of Congress heard from six companies, including representatives from Google, Apple, Amazon and Twitter.

Advertisement - Article continues below

In his opening statement, the chairman of the committee, Senator John Thune said the question was no longer whether the US needed a federal law to protect consumer privacy, but rather what shape will that law take.

To replace current laws that are enforced at the state level, a countrywide privacy bill is being crafted, but senators are worried that tech companies will not like what is being put together, believing they will feel it's akin to the GDPR, which came into effect in March, or be similar to California's Consumer Privacy Act (CCPA) set to be implemented in 2020.

Instead, tech companies are working with lawmakers in an effort to avoid GDPR-style regulation that would place far greater restrictions on how and what data can be processed.

The representatives discussed three key points for a potential privacy legislation: a state law that pre-empts the California legislation; a promotion of privacy on their terms; and a block to the creation of a US version of the GDPR.

Advertisement - Article continues below
Advertisement - Article continues below

California Governor Jerry Brown signed the CCPA in June, which aims to give consumers more control over how companies collect and manage their personal information. The law, which is due to take effect in 2020, effectively replicates many of the provisions set out by GDPR inside the state of California, something which tech companies such as Alphabet Inc's Google and Amazon oppose as being too restrictive.

Referencing the GDPR, and also California's Law, AT&T senior VP of global public policy, Len Cali said: "What we're urging is a comprehensive federal law that looks at both these laws, learns from them, but does better than them."

At the hearing, Amazon VP Andrew DeVore said that California's law was hastily written and the law's definition of personal information went too far.

"The result is a law that is not only confusing and difficult to comply with, but that may actually undermine important privacy-protective practices," he said.

Advertisement - Article continues below

The drafting of tough data laws has played out simultaneously with high profile news stories such as the Cambridge Analytica scandal and the recent data breach to Equifax that affected around 145 million of its customers in the US, UK and Canada.

The tech companies are in favour of a federal law, provided it preempts California's 2020 legislation and doesn't emulate the GDPR. But the senators said that for a federal law to nullify a state law, it would have to be more progressive and robust than the state law which had already been voted for.

"I understand that from the standpoint of these companies, the holy grail is preemption," said Senator Brian Schatz. "We're not going to get 60 votes for anything and replace a progressive California Law, however flawed you may think it is, with a non-progressive federal law."

Matt Lock, director of sales engineers at Varonis said that the tech companies feared many other states would follow California's example and adopt tougher regulations.

Advertisement - Article continues below

"Tech leaders are afraid that consumer privacy laws similar to the GDPR will gain popularity among U.S. states and upend their business model, which often involves treating a person's data as a commodity to be bought and sold in exchange for a free service," he said.

"When an industry bands together to help steer the discussion in their favour it's because they fear strict laws down the road. California may be the first state to adopt GDPR-like laws, but it will not be the last."

Featured Resources

Preparing for long-term remote working after COVID-19

Learn how to safely and securely enable your remote workforce

Download now

Cloud vs on-premise storage: What’s right for you?

Key considerations driving document storage decisions for businesses

Download now

Staying ahead of the game in the world of data

Create successful marketing campaigns by understanding your customers better

Download now

Transforming productivity

Solutions that facilitate work at full speed

Download now


General Data Protection Regulation (GDPR)

ICO to relax GDPR enforcement during coronavirus economic downturn

16 Apr 2020

The NHS teams up with Apple and Google on coronavirus tracking app

14 Apr 2020
data protection

Health sites are 'unlawfully' sharing medical data with Facebook and Google

7 Apr 2020
data protection

Supreme Court rules Morrisons was not liable for 2014 data breach

1 Apr 2020

Most Popular

Business operations

Nvidia overtakes Intel as most valuable US chipmaker

9 Jul 2020

How to find RAM speed, size and type

24 Jun 2020

The best server solution for your SMB

26 Jun 2020