Rep. Bobby Rush (D-Ill.) unveiled a privacy bill on Monday that would require companies to obtain people's opt-in consent before disclosing their personal information to third parties in some circumstances.
A version of the bill seen by Online Media Daily appears to be similar to a draft measure floated in May by Rep. Rick Boucher (D-Va.), chairman of the Subcommittee on Communications, Technology and the Internet, but with some key differences.
Both bills follow a notice-and-choice framework, and both require users' consent for online behavioral advertising, or tracking users across sites in order to serve targeted ads. Both also allow companies to obtain opt-out consent rather than opt-in, but under slightly different circumstances.
Rush's measure would require Web sites to obtain users' explicit permission before sharing their personal information with third parties, unless those companies participate in a "universal opt-out" program operated by industry groups, like the Network Advertising Initiative, and overseen by the Federal Trade Commission.
Boucher's draft proposal, by contrast, would require ad networks that track people and collect personal information for ad purposes to obtain users' opt-in consent, unless the networks provide prominent notice through an icon and also allow people to view and edit their profiles.
Rush's bill also defines third-party broadly, saying that companies are considered third parties to each other if consumers would not expect reasonably them to be related. For instance, a publisher that owns an unbranded network of blogs could be considered a third party to those blogs.
Rush's measure also tasks the FTC with further defining "third party" within 18 months.
Like Boucher's proposal, Rush's bill would apply to data that is traditionally considered "personally identifiable" -- such as names and addresses -- as well as information sometimes deemed "anonymous," like marketing profiles associated with particular computers.
Rush's bill provides that IP addresses would be covered if used to create marketing profiles, but not when used to send ads dynamically. As with the definition of third party, Rush delegates to the FTC the task of further defining personal information.
Also similar to Boucher's measure, Rush's bill requires companies to obtain users' affirmative consent before collecting or sharing sensitive information -- but provides a more sweeping definition of that term. Rush says that sensitive data includes information about people's medical history or health, race or ethnicity, religious beliefs and affiliation, sexual orientation or sexual behavior, as well as certain financial data. Precise geolocation information would be considered "sensitive" if associated with other data like names or profiles. Rush also says FTC may modify the definition of sensitive information through a rulemaking.
Boucher, by contrast, defined sensitive information as medical records, race or ethnicity, religious beliefs, sexual orientation, financial records and precise geolocation information.
One key area that differs from Boucher's proposal involves consumers' ability to sue. Rush would allow individuals to sue companies that don't follow the measure for up to $1,000 per violation. Boucher's bill would completely bar consumers from bringing private lawsuits.
Rush, chairman of the House Energy and Commerce Subcommittee on Commerce, Trade and Consumer Protection, did not have a co-sponsor for the bill as of Monday afternoon. A hearing on Rush's proposal is slated for Thursday.
Some consumer advocates reacted more favorably to Rush's proposal than to Boucher's. Privacy advocate Jeff Chester, executive director of the Center for Digital Democracy, said Rush's proposal "significantly advances the privacy debate in Congress."
Chester added, "By empowering the FTC to engage in additional rule-makings on privacy, it creates a framework to better address consumer privacy concerns -- online and off."
Leslie Harris, president of the digital rights group Center for Democracy & Technology, said Rush's bill "establishes a forward looking and flexible framework for protecting consumer privacy."
Harris is expected to testify at a hearing on Thursday addressing privacy legislation.