Two Think Minimum
Two Think Minimum

Jane Horvath on Privacy Policy

Jane Horvath joins Two Think Minimum to chat about privacy policy. She shares the serendipitous way she became a privacy expert in the early days at a technology start up. She also discusses the need for a baseline omnibus privacy law in the US. Jane recently became a partner at Gibson Dunn, where s

Featured Speakers

Technology Policy Institute HostJane Horvath Guest

Topics Discussed

Episode Summary

Executive Summary: Jane Horvath discussed the evolution of privacy from an ad hoc legal issue into a core product, engineering, and regulatory concern. She argued the U.S. needs a baseline federal privacy law to replace inconsistent state rules, emphasized privacy-by-design and risk-based approaches, and distinguished commercial privacy from government surveillance rules.

Main Topics: Evolution of privacy law and practice (Priority: 5/5): Horvath traced privacy from the early AOL era, when privacy policies were newly invented, to today’s more formal profession shaped by global regulation and technical design choices. Why the U.S. needs a federal privacy law (Priority: 5/5): She argued that a patchwork of inconsistent state laws creates uncertainty and inefficiency, and that the U.S. should adopt an omnibus baseline privacy statute similar in effect to Europe’s uniform regime. Europe, innovation, and regulatory comparisons (Priority: 4/5): Horvath rejected the idea that Europe’s privacy rules explain its weaker tech sector, noting that companies can innovate through encryption, on-device processing, and other privacy-friendly technologies. Privacy engineering and privacy by design (Priority: 5/5): A major theme was the importance of privacy engineers and technical solutions that go beyond legal minimums, including sampling, on-device processing, and reducing unnecessary data collection. Notice, consent, and risk-based approaches (Priority: 4/5): She questioned whether notice-and-consent remains workable in practice, but said transparency and choice still matter, especially when combined with a risk-based framework that treats sensitive data differently. Commercial privacy vs. government surveillance (Priority: 4/5): Horvath distinguished consumer-data regulation from government data collection, arguing that the government needs its own privacy/surveillance framework alongside a separate commercial privacy law. Company culture at Google and Apple (Priority: 3/5): She contrasted Google’s experimental, beta-heavy culture with Apple’s secrecy and product discipline, while noting that privacy was a core value at both firms.

Key Arguments: The U.S. is increasingly an outlier because many countries now have baseline privacy laws; China, Japan, and Korea are cited as examples. A patchwork of state laws is economically inefficient and can leave residents with uneven protections depending on where they live. Privacy regulation can coexist with innovation; companies can design products using encryption, device identifiers, and on-device processing. Legal rules should be a floor, not a ceiling; firms can and should go beyond compliance when privacy engineers identify better designs. Consent alone is imperfect, but transparency remains necessary; a principles-based, risk-based law would be more workable than exhaustive, unreadable notices. Commercial privacy and government surveillance should be regulated differently because enforcement, choice, and remedies differ substantially. The FTC may issue privacy rules, but its authority likely would not substitute for a comprehensive federal statute.

Data Points: EU first privacy law: 1995 - Horvath cited the European Privacy Directive as the first major privacy law. Privacy law gap in states: Close to 50 state data breach laws - She used breach-notification law as an example of how state-by-state regulation proliferates and becomes inconsistent. Federal legislation momentum: Closest attempt was in summer 2022 - She said privacy advocates and lawmakers came closest to a deal recently, but it fell apart over preemption and private right of action. Nine/11 impact: 2001 - She linked 9/11 and the Patriot Act to increased privacy-related government structures and negotiations with Europe. Umbrella Agreement negotiation length: 7 years - She said the U.S.-EU law enforcement data-sharing arrangement took seven years to finalize. Apple tenure: 2011 to 2022 - Her Apple career framed her remarks on privacy engineering and product design. Google tenure relative timing: Over 12 years ago - She noted her Google experience was long ago and may not reflect the company today.

Pivotal Quotes: "I think the secret sauce is privacy engineers." — Jane Horvath: She explained why legal compliance alone is insufficient and why technical design matters. "I think we are at that point in the US, where Europe was with inconsistent regulations." — Jane Horvath: She compared the U.S. state-law patchwork to Europe before its move from a directive to a regulation. "I really don't agree with it. I think that that's been an excuse for a long time." — Jane Horvath: She rejected the claim that Europe’s privacy rules explain the relative dominance of U.S. tech firms.

Implications: Listeners should expect more pressure for a federal privacy law, continued FTC activity, and greater use of privacy-by-design and risk-based rules. Companies should prepare for state-law complexity, while policymakers should separate commercial privacy from government surveillance.

🔓 Sign Up for Unlimited Episode Search

About Two Think Minimum

Podcast of the Technology Policy Institute of Was…

View all episodes from Two Think Minimum