On June 3, 2022, House Energy and Commerce Chair Rep. Frank Pallone (D-NJ), Ranking Member Rep. Cathy McMorris Rodgers (R-WA) and Senate Commerce, Science and Transportation Committee Ranking Member Sen. Roger Wicker (R-MS) released a new comprehensive federal privacy bill, the American Data Privacy and Protection Act (“ADPPA”).
While the ADPPA contains a number of similarities to the Consumer Online Privacy Rights Act (“COPRA”), which was previously introduced in 2019 by Senate Commerce Committee Ranking Member Maria Cantwell (WA), Senators Brian Schatz (HI), Amy Klobuchar (MN) and Ed Markey (MA), the ADPPA also contains some notable differences. We have summarized some of these similarities and differences below. Read our previous post on the COPRA.
Similar to the COPRA, the ADPPA:
- provides individuals with a number of privacy rights, including rights to access, delete and correct their data, as well as a right of data portability;
- imposes data minimization obligations, requiring covered entities to avoid collecting, processing or transferring data beyond what is reasonably necessary and proportionate;
- requires covered entities to obtain express, affirmative consent to collect, process or transfer “sensitive covered data,” which is broadly defined;
- requires covered entities to provide individuals with privacy policies detailing their data collection, processing and transfer activities, and data security practices;
- requires certain covered entities (“large data holders”) to annually certify that they maintain reasonable internal controls and reporting structures for compliance with the respective bills and obligations to implement comprehensive privacy and security programs that include training programs, reporting processes and privacy impact assessments;
- prohibits covered entities from collecting, processing or transferring data in a manner that discriminates against individuals; and
- requires covered entities to implement and maintain reasonable data security practices, which at a minimum must contain certain prescribed activities such as vulnerability assessments.
Notable differences between the COPRA and the ADPPA include the following:
- The COPRA does not address children’s privacy, however, the ADPPA contains a provision devoted to the data protections of children and minors. For example, the ADPPA prohibits covered entities from engaging in targeted advertising to individuals under the age of 17 (provided the covered entity has actual knowledge of the individual’s age). The ADPPA also prescribes restrictions on the transfer of data related to minors without affirmative express consent from the individual or the individual’s parent or guardian, if the individual is between ages of 13 and 17. The ADPPA will establish a Youth Privacy and Marketing Division at the Federal Trade Commission, responsible for addressing privacy and marketing concerns with respect to children and minors.
- The ADPPA requires covered entities to publicly disclose whether individuals’ data is made available to China, Russia, Iran or North Korea. The COPRA does not require this type of disclosure.
- The ADPPA requires certain covered entities (“Third-Party Collecting Entities”) to provide clear and conspicuous notice on their websites or mobile applications informing individuals that they are Third-Party Collecting Entities using language required by FTC regulations. The ADPPA requires the FTC to promulgate regulations requiring such entities to allow for auditing of any access to or disclosure of data processed by the entities. Third-Party Collecting Entities that process data of more than 5,000 individuals will be required to register with the FTC on an annual basis, pay a registration fee, and may be at risk of civil fines for failing to comply with these requirements. The COPRA does not contain such a requirement.
- While both bills provide a small business exception, the ADPPA provides a higher revenue threshold, and the small business must meet this threshold for a certain number of years. The ADPPA exempts businesses that for the prior three calendar years had (1) annual revenue of less than $41 million; (2) did not collect or process the data of more than 100,000 individuals; and (3) did not derive more than 50% of its revenue from transferring personal information.
- Both the ADPPA and COPRA impose a duty of loyalty on covered entities; however, the ADPPA appears to be more prescriptive. The COPRA provides a general prohibition against deceptive and harmful data practices. The ADPPA enumerates specific data practices that are prohibited (e.g., the collection, processing, or transferring of Social Security numbers, except when necessary to facilitate extensions of credit, authentication, or the payment and collection of taxes).
- Under the ADPPA, large data holders that use algorithms, solely or in part, to collect, process or transfer data must conduct and submit annual impact assessments of their algorithms to the FTC. The COPRA requires any covered entity engaging in algorithmic decision-making (or assist others in algorithmic decision-making) for certain activities, such as determining eligibility for housing, education, employment or credit opportunities, must conduct annual impact assessments and make these assessments available to the FTC upon request.
- The ADPPA proposes that the FTC conduct a study to determine the feasibility on the creation of a unified opt-out mechanism and if the FTC finds that a centralized mechanism would be feasible, it must promulgate regulations establishing such mechanisms for covered entities. The COPRA does not contain such a proposal.
- The COPRA provides whistleblower protections that prohibit a wide range of retaliatory acts against whistleblowers for reporting violations of COPRA and grants whistleblowers a private right of action. The ADPPA does not address whistleblowers.
- The COPRA preempts state laws that “directly conflict” with the COPRA and specifies that a state law that provides greater protection is not in conflict. The ADPPA preempts state laws covered by the provisions of the ADPPA; however, a number of exceptions are enumerated, including consumer protection laws of general applicability, laws that solely address facial recognition or facial recognition technologies, electronic surveillance, wiretapping or telephone monitoring, Illinois’ Biometric Information Privacy Act and the limited privacy right of action for certain security breach damages under the California Consumer Privacy Act and California Privacy Rights Act.
- Both the COPRA and ADPPA grant individuals a private right of action; however, there are a number of restrictions with respect to this right under the ADPPA that may ultimately serve as a deterrent. For example, the right is not accessible to individuals under the ADPPA until four years after the Act takes effect. The ADPPA does not permit statutory damages; instead, individuals are only permitted to seek injunctive or declaratory relief, compensatory damages and reasonable attorneys’ fees and litigation costs. Also, to bring an action, individuals must notify the FTC and the attorney general of their state of residence prior to bringing suit. These regulators subsequently have 60 days to determine whether they will independently seek to take action. Demand for monetary payments sent to the covered entity prior or after these regulators determine to take action will be considered made in bad faith and unlawful.
On June 14, 2022, the House Energy and Commerce Committee held a hearing to discuss the ADPPA.
The Hunton Andrews Kurth Blockchain Blog features opinions and legal analysis as we follow the development and use of distributed ledger technology known as the blockchain.
Search
Recent Posts
Categories
Tags
- 2019 Leaders’ Declaration
- 2020 National Strategy for Combating Terrorist and Other Illicit Financing (the 2020 Strategy)
- Advancing Innovation to Assist Law Enforcement Act
- Airdrops
- AML compliance program
- AML/CFT
- anonymity-enhanced cryptocurrencies
- Anti-Money Laundering
- Anti-Money Laundering Act of 2020 (AMLA)
- Anti-Money Laundering Compliance
- Antifraud
- Aon and Marsh
- Arizona
- Arkansas
- Artificial Intelligence
- Artificial Intelligence (AI)
- Australia
- Australian Competition and Consumer Commission (ACCC)
- Australian Securities and Investments Commission (ASIC)
- Automated Clearing House (ACH)
- Bank of England
- Bank Secrecy Act
- Bank Secrecy Act (BSA)
- Bank Term Fund Program
- Bermuda
- Biden Administration
- BIS
- Bitcoin
- Bitcoin Cash
- Bitfinex
- BitLicense
- Blockchain
- Blockchain Incubators
- Blockchain Legislation
- Blockchain Regulatory Certainty Act
- Blockchain Technology Act
- Brazil
- Breach of Contract
- Broker-Dealer
- Broker-Dealers
- BSA
- BSA Enforcement
- BTFP
- Bureau of Economic Analysis
- California
- Canada
- Captive Insurance
- CCPA
- Celebrity Endorsers
- Central Bank
- Central Bank Digital Currency (CBDC)
- Centre for Information Policy Leadership (CIPL)
- CFTC
- Chapter 15
- China
- Christopher Giancarlo
- Civil Enforcement
- Class Actions
- Clearweb
- Colorado
- Commissioner
- Commodity Exchange Act
- Commodity Exchange Act (CEA)
- Commodity Futures Trading Commission
- Complaint Bulletin
- Compliance
- Compliance Note
- Congress
- Connecticut
- Consent
- Consumer Financial Protection Bureau (CFPB)
- Consumer Protection
- Convertible Virtual Currency
- Corporate Compliance
- Corporate Governance
- Corporate Transparency Act (CTA)
- Council of Institutional Investors
- Council of the European Union
- Countering the Financing of Terrorism (CFT)
- Cross-Border Data Transfer
- crypto arbitrage trading accounts
- Crypto Assets
- crypto bank
- crypto custody
- Crypto Hackers
- Crypto Mining
- Crypto-commodity
- Crypto-currency
- Cryptoassets
- Cryptocurrency
- Cryptopia Limited
- Cryptosweep
- CVCs
- cybercrime
- Cybersecurity
- Dalia Blass
- DAO Report
- Darknet
- darknet marketplaces
- Data Privacy
- Data Protection Authority
- Davos
- decentralized finance (DeFi)
- DeFi
- Del. Michael San Nicolas
- Delaware
- Department of Business and Industry
- Department of Justice
- Department of Treasury
- DFS
- Digital Asset
- Digital Asset Securities
- Digital Assets
- Digital Commodities Consumer Protection Act of 2022
- digital currency
- digital currency ATM operators
- digital currency exchangers
- digital currency flows
- Digital Financial Assets Law (the Act)
- Digital Token Act
- digital token sales
- Digital Tokens
- Distributed Ledger
- Documentary Stamp Tax (DST)
- Dodd-Frank
- DOJ
- Economic Sanctions
- EDPB
- Eleventh Circuit
- Endorsement Guides
- Enforcement Action
- ePrivacy
- Ether
- Ether Classic
- EU General Data Protection Regulation (GDPR)
- EU Regulation
- European Central Bank
- European Commission
- Exchange Act
- Exchange Traded Fund
- FDIC
- Federal Election Commission
- Federal Reserve
- Federal Reserve Board
- Federal Trade Commission
- FedNow
- fiat currency MSBs
- Fiat-Backed
- Fight Illicit Networks and Detect Trafficking Act
- Figure Lending LLC
- Final Guidance
- Financial Action Task Force (FATF)
- Financial Crimes Enforcement Network (FinCEN)
- Financial Privacy
- Financial Stability Board
- Financial Stability Oversight Council
- Financial Stability Report
- Financial Technology Protection Act
- FinCEN
- FINRA
- FinTech
- Florida
- Foreign Corrupt Practices Act (FCPA)
- Foreign Extortion Prevention Act (FEPA)
- Form BE-12
- fractional interests
- FTC
- Gemini Dollar
- Gemini Trust Company
- Global Consortium for Digital Currency Governance
- Group of Seven
- Group of Twenty (G20) Finance Ministers
- H.R. 5635
- Hard Fork
- Heath Tarbert
- Her Majesty’s Revenue & Customs (HMRC)
- HM Revenue & Customs (HMRC)
- home equity lines of credit (HELOCs)
- Homeland Security Assessment of Terrorists’ Use of Virtual Currencies Act
- House of Representatives
- House of Representatives’ Financial Services Committee
- Howey
- Howey test
- IEO
- iFinex Inc.
- Illinois
- India
- Information Sheet 225
- Initial Chain Offering
- initial exchange offerings (IEOs)
- Insurance
- Intellectual Property
- International
- International Monetary Fund (IMF)
- Investor Protection
- IRS
- Jefferies Funding LLC
- Kenneth Blanco
- KYC/AML requirements
- Lael Brainard
- Large Platform Utility
- Legislation
- Legislature
- Liechtenstein Parliament
- liquidity
- Litecoin
- Litigation
- Louisiana
- Ltd.
- Malicious Cyber Activity
- Malicious Cyber Actor
- managed stablecoin
- Martin Act
- Maryland
- Metaverse
- model rule
- Monetary Policy
- Money Laundering
- Money Service Business
- money services businesses (MSBs)
- Mortgages
- Multi-Level Marketing Program (MLM)
- Mutual Fund
- Nakamoto
- narcotics
- NASAA
- Nebraska
- network maturity
- Nevada
- New Jersey
- New York
- New York Attorney General
- New York Department of Financial Services (DFS)
- New Zealand
- NFT (Non-Fungible Token)
- NFTs
- Non-fungible tokens
- North Dakota
- North Korea
- NY Department of Financial Services
- OFAC
- Office of Investor Education and Advocacy
- Office of the Comptroller of the Currency (OCC)
- Ohio
- Oklahoma
- Patent
- Paxos Standard
- Paxos Trust Company
- peer-to-peer exchangers
- Penalty
- Pennsylvania
- Personal Data
- Personal Information
- President’s Working Group (PWG)
- Privacy
- privacy coins
- Provenance.io
- Proxy Voting
- Public Blockchain
- rapid settlement
- real estate
- Regulation and Enforcement
- Rep. Sylvia Garcia
- Rescission
- Retail
- Ripple
- Ripple Labs
- Rule 233-1
- Russia
- Sanctions
- Sanctions Compliance Program (SHP)
- SAR lookback review
- SD8 coins
- SDN List
- SEC
- SEC crypto-securities
- SEC registration
- Securities
- Securities Act
- Securities Act of 1933
- Securities and Exchange Commission
- Securities and Exchange Commission (SEC)
- Securities Exchange Commission
- security tokens
- Self-disclosure
- Senate Committee on Banking Housing and Urban Affairs
- Shareholder
- Shareholders
- SIFI
- Signature Bank
- Silicon Valley Bank
- South Carolina
- South Dakota
- Spencer Dinwiddie
- stablecoins
- Stablecoins are Securities Act of 2019
- State-Sponsored Malicious Cyber Groups
- Suspicious Activity Report
- suspicious activity reporting (SARs)
- SVB
- SWIFT messaging system
- Swiss Financial Market Supervisory Authority (FINMA)
- Switzerland
- synthetic hegemonic currency
- Taxation
- Templum
- Tennessee
- Terrorist Financing
- Tether Limited
- Texas
- Texas Business Organizations Code (TBOC)
- Texas Senate Bill 1859
- Texas Senate Bill 1971
- The World Bank
- three-year safe harbor
- Token and TT Service Provider Act
- token developers
- token transfer limits
- tokenization
- tokenized assets
- Trademark
- Travel Rule
- Trump Administration
- TT Identifier
- TT System
- TVTG
- U.S. Virtual Currency Market and Regulatory Competitiveness Act of 2019
- UCC Article 12
- UK Tax Rules
- unhosted wallets
- Uniform Commercial Code
- United Kingdom (UK)
- United Specialty Insurance Company
- United States Bankruptcy Code
- United States Patent and Trademark Office
- US central bank digital currency (US CBDC)
- US Department of the Treasury
- US Department of the Treasury’s Office of Foreign Assets Control (OFAC)
- US dollar
- US Treasury
- USTR
- Utah
- Vermont
- Virginia
- Virtual Asset Service Providers
- Virtual currencies
- Virtual Currency
- Virtual Currency Consumer Protection Act of 2019
- Virtual Currency Exchange
- virtual currency license
- Virtual Currency Tax Fairness Act of 2020
- Virtual Markets Integrity Initiative
- Washington
- Weapons of Mass Destruction Proliferators Sanctions Regulations
- World Economic Forum
- Wyoming
- XRP
Authors
- Jimmy Bui
- Mayme Donohue
- Nicholas Drews
- Andrew Feiner
- Jason Feingertz
- Hannah Flint
- Kevin E. Gaunt
- Armin Ghiam
- Carleton Goss
- Gregory G. Hesse
- Scott H. Kimpel
- Marysia Laskowski
- Michael S. Levine
- Phyllis H. Marcus
- Lorelie S. Masters
- Patrick M. McDermott
- Uriel A. Mendieta
- Alex D. Pappas
- Daryl B. Robertson
- Natalia San Juan
- Caitlin A. Scipioni