1. The bill dramatically strengthens the FTC, including by elevating privacy and security to its own bureau.
2. The bill incentivizes independent researchers to investigate company practices.
3. The bill protects internal whistleblowers.
4. The bill requires internal governance structures such as a consumer IRB and annual certification of compliance by the CEO personally.
5. The bill provides for a private cause of action while preserving mini-FTC acts (though not consumer privacy laws 😩)
But most importantly imo:
6. The bill makes it clear that *the mere act of violating the statute* is an actual, cognizable harm without more.
This is important in two ways (a) getting over the standing hurdle and (b) dispensing with cost-benefit under the unfairness doctrine.
(The privacy harm exceptionalism we have seen to date has been surreal to me. How can we improve privacy when many courts and some regulators pretend privacy harms aren't real harms? https://ctlj.colorado.edu/wp-content/uploads/2014/11/Calo-website-final.pdf)
You can follow @rcalo.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled: