American Privacy Rights Act Faces Opposition from State Attorneys General Over Concerns of Diminished Authority

For years, state attorneys general (AGs) have taken the lead in regulating consumer data privacy, utilizing multistate investigations to enforce both federal and state laws addressing significant alleged violations. The proposed American Privacy Rights Act (APRA), a comprehensive consumer data privacy bill, now threatens to disrupt this established system. Its potential diminishment of AGs’ powers and the mechanisms developed through deliberate regulatory evolution has led a coalition of AGs to request Congress to reconsider the language in the bill.

To understand the potential impact of APRA, historical context is critical. In the absence of equivalent federal legislation, certain states have enacted comprehensive consumer data privacy laws, filling enforcement gaps and establishing a de facto national privacy enforcement framework that has grown sophisticated over time. States like California and Texas have created specialized regulatory enforcement groups focusing on consumer data privacy law enforcement.

Even in states lacking dedicated regulatory enforcement groups, AG offices typically employ attorneys and specialists dedicated to data privacy. These individuals are often considered leading experts in the field. The multistate enforcement ecosystem benefits from long-standing relationships among specialized attorneys, who share and pool resources, enabling AGs to operate at levels far exceeding those of other regulatory enforcers at both federal and global levels.

Given the extensive effort put into building this complex enforcement system, it is clear why AGs are reluctant to cede authority to the federal government. The primary concern lies in the preemption language in APRA, which could significantly limit AGs’ ability to bring claims under consumer protection laws that provide broad authority to pursue unique data privacy violations.

The civil investigative demand (CID)—a tool akin to a subpoena used to initiate investigations—is often predicated on an alleged violation of state consumer protection law. APRA could disrupt this practice by stating that “a violation of this Act or a regulation promulgated under this Act may not be pleaded as an element of any violation of such law.” State AGs interpret this as a prohibition against using violations of federal law as a basis for state consumer protection claims, thereby potentially crippling their investigative and enforcement authority, especially in areas where the law has yet to catch up with technological advancements.

The Federal Trade Commission (FTC) would play a primary role in shaping enforcement under APRA, creating a new bureau within the FTC for oversight and rulemaking. This could lead to industries adapting to differing standards and AGs modifying their enforcement practices. As experienced by AGs, it can take years for a new federal agency bureau to become operational and even longer to build the professional relationships necessary for high-level enforcement.

The ongoing debate underscores the tension between federal and state jurisdictions over data privacy. Comprehensive federal legislation like APRA has the potential to disrupt the status quo and alter the balance of regulation and enforcement within the United States.

For a more detailed examination of the issues, visit the original article on Bloomberg Law.