The FTC, LabMD, and the state of US privacy law
I published some thoughts on the U.S. Court of Appeals decision in the latest saga between LabMD and the FTC. While very narrow, the ruling does present obstacles for future FTC enforcement in the privacy and data security space. More than anything, it demonstrates the need for U.S. privacy and data security legislation. The FTC continues to operate in this space against an unconventional legal backdrop, merely 14 words in Section 5 of the FTC Act, which dates back to 1914 (“unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful”). Compare this to the 55,000 words in the European General Data Protection Regulation of 2018 and you can clearly see why the agency must chart its own path.
It's also a good opportunity to revisit research we've produced at the IAPP Westin Center. In September 2014, IAPP Westin Fellow Patricia Bailin published a study titled What FTC Enforcement Actions Teach Us About the Features of Reasonable Privacy and Data Security Practices. In it, she sought to “reverse engineer” the FTC’s implied standard for privacy and data security, exactly the standard the Court found lacking in the LabMD decision. Reading between the lines of numerous cases where the FTC articulated why certain practices were unreasonable, the Westin Center tried to delineate the zone of activity that the agency would consider to be reasonable. Perhaps this helps respond to some of the criticism of the agency's actions. In addition, we now present an updated piece, written by IAPP Westin Fellow Müge Fazlioglu, What FTC Enforcement Actions Teach Us About the Features of Reasonable Privacy and Data Security Practices: A Follow Up Study. In it, Fazlioglu adds new categories to and updates Bailin's report with the numerous FTC privacy and security cases between 2014 and 2018.
My conclusion in the piece is that with states rushing in to fill the legislative void in Washington - Vermont legislating against data brokers, Illinois restricting biometric information and California weighing a sweeping privacy ballot initiative - businesses may soon be clamoring for a uniform, national privacy law, overseen by a responsible agency like the FTC.
Please share your comments/thoughts!