Cybersecurity, Privacy, & AI

Trending Now
CUI, FOCI, Quantum, and CMMC: The Federal Government Issues a Wave of Proposed Rules to Safeguard Government Information • 10 Questions Every Organization Should Ask a Potential AI Vendor • VA Software Management Woes Linked in Part to CIO Vacancy, Watchdog Says • FedRAMP and Identity Security: Why Federal Organizations Are Consolidating Identity Security Platforms • NIST Announces Funding Opportunity for 14 MEP Centers to Advance Small and Medium-Sized U.S. Manufacturers

Why a Privacy Law Like GDPR Would Be a Tough Sell in the U.S.

Derek Hawkins of The Wall Street Journal‘s “Cybersecurity 202” argues that although there is no reason the United States couldn’t enact privacy standards similar to the EU’s new General Data Protection Regulation, and many are calling for it, it’s unlikely to happen. He cites three reasons:

1. There’s no agency to carry it out.

EU member states have their own data privacy authorities to enforce the GDPR. The closest US equivalent is the Federal Trade Commission, but its powers are thin compared to its European counterparts, and it has little to no oversight over a range of businesses and industries.

2. Congress won’t go for it.

It’s challenging enough to pass simple legislation in a gridlocked Congress. Privacy legislation far less sweeping has stalled over and over in recent years, and rallying support around those measures and others would be a struggle.

3. There’s probably not enough public demand.  

The Cambridge Analytica scandal has spurred a national debate about data privacy and brought federal law enforcement investigations. But change such as this takes a kind of shock akin to the 2008 financial collapse to make it happen.

More at The Washington Post

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–Saturday — Subscribe here.