Episode Summary
Executive Summary: The episode examines the prospects for U.S. federal privacy legislation in 2019 and the FTC’s existing role in privacy enforcement. The guests argue the environment is unusually favorable for reform, but emphasize tensions around civil penalties, consent decrees, preemption, transparency, and whether the U.S. should follow GDPR or California-style models without sacrificing innovation, uniformity, and consumer benefits.
Main Topics: Prospects for federal privacy legislation (Priority: 5/5): Both guests say this is the strongest political environment they have seen for federal privacy and data security legislation, driven by GDPR, California, and rising public concern, but final passage remains uncertain. FTC authority and enforcement model (Priority: 5/5): Maureen Ohlhausen explains the FTC’s Section 5 deception and unfairness powers, how it has brought more than 500 privacy and data security cases, and why its current framework is substantial but not unlimited. Civil penalties, remedies, and consent decrees (Priority: 5/5): The speakers debate whether the FTC should get first-instance civil penalty authority and whether 20-year consent decrees are too burdensome or necessary for deterrence and compliance. Comparison with GDPR and European enforcement (Priority: 4/5): They contrast the FTC’s harm-based approach with GDPR-style regulation, criticizing the EU model as broad, bureaucratic, and potentially draconian, while acknowledging its transparency benefits. Role of transparency and guidance (Priority: 4/5): The discussion stresses that companies and consumers need clearer guidance on notice, consent, legitimate interest, and privacy practices, rather than enforcement that relies on vague standards or 'gotcha' tactics. Preemption and state-level fragmentation (Priority: 5/5): Both argue that a national privacy framework should significantly preempt state laws to avoid a balkanized compliance regime, though states may still play a role in enforcing federal standards. Benefits of data use and advertising-supported services (Priority: 4/5): The speakers caution that privacy reform should preserve the economic and consumer benefits of data-driven innovation, targeted advertising, and uniform standards across the U.S. market.
Key Arguments: Federal privacy legislation has its best chance in years, but the major unresolved issues are preemption, remedies, and how broad the rules should be. The FTC already has meaningful tools under deception and unfairness authority and has used them extensively in more than 500 cases. Civil penalties are more persuasive for data breaches than for privacy generally, because breach harms are real but often hard to trace to a specific incident. Consent decrees lasting 20 years can be overly burdensome and may justify reform of FTC remedial practice. The FTC’s approach is more harm-based than the GDPR, which can impose penalties for many technical violations without clear injury. Public concern over privacy has grown because of Snowden, large breaches, and election manipulation through social media, which have blurred privacy, security, and national-security debates. A federal privacy law should avoid fragmenting the national market; California-style state leadership could create de facto national standards without adequate uniformity. Transparency and disclosure should be emphasized more, because consumers and even many companies do not fully understand data flows and ad-tech ecosystems. Companies should better explain the benefits of data use, including innovation and free/ad-supported services, rather than appearing to hide monetization practices. A privacy framework should include guidance or safe-harbor mechanisms, similar to COPPA, so firms can comply without guessing what regulators will later deem acceptable. Private rights of action may encourage class-action litigation more than genuine consumer protection. State AGs can still enforce a federal standard, preserving local involvement while maintaining national consistency.
Data Points: FTC privacy and data security cases: more than 500 - Maureen Ohlhausen describes the FTC’s enforcement record under Section 5 and related authorities. Largest previous FTC fine: $22.5 million - Referenced as the largest FTC-imposed fine prior to discussion of potential Facebook penalties. Largest European fine mentioned: 50 million euros (about $57 million) - Alan Rawl cites the French CNIL penalty against Google as the then-largest European GDPR fine. GDPR penalty ceiling: up to 4% of annual revenue - Used to illustrate the scale of European enforcement authority compared with the FTC. FTC consent decree duration: 20 years - Described as the common length of FTC decrees that can burden companies for decades.
Pivotal Quotes: "I would say it's the best chances that I've seen during my time." — Maureen Ohlhausen: On whether 2019 could produce federal privacy legislation. "They'd like to be the FTC on steroids." — Alan Rawl: On how European data protection authorities view their role under GDPR. "We want privacy and prosperity. Both values are important to American consumers." — Maureen Ohlhausen: On balancing consumer protection with innovation and economic benefits in any federal privacy law.
Implications: Listeners should expect continued momentum for privacy reform, but also intense fights over preemption, penalties, guidance, and state versus federal authority. The most durable policy is likely to be a national framework that preserves innovation while tightening transparency and enforcement.
About Two Think Minimum
Podcast of the Technology Policy Institute of Was…