Bill Would Prohibit Sale of Americans’ Personal Data to Adversarial Countries

Sen. Ron Wyden

Sen. Ron Wyden J. Scott Applewhite/AP

The proposal would establish an interagency group to categorize data, then develop a list of countries banned from importing individuals’ data that could threaten national security.

Legislation introduced this week would make it illegal for companies to export data generated by people living in the U.S. to certain countries where that data could pose a national security risk.

Federal agencies already regulate the kinds of technologies and industrial data that can be sold abroad, but a new bill introduced by Sen. Ron Wyden, D-Ore., would be the first to prohibit the sale of individuals’ data by a third party.

“Shady data brokers shouldn’t get rich selling Americans’ private data to foreign countries that could use it to threaten our national security,” Wyden said in a statement after introducing the legislation. “My bill would set up common sense rules for how and where sensitive data can be shared overseas, to make sure that foreign criminals and spies don’t get their hands on it.”

But in order to protect the data, regulators first must know exactly what they’re regulating.

The Protecting Americans’ Data from Foreign Surveillance Act would first categorize the types of personal data people generate each day, and identify which data types could be used by foreign adversaries to the detriment of the U.S. In establishing the categories, regulators would be instructed to look at data collected by commercial entities; data that has already been shared with foreign adversaries; and both identifiable and anonymized data, if the latter can be reverse engineered using other data sources.

The categorization work—spread across multiple agencies, working together—would be completed one year after the bill was enacted.

“In compiling the list of categories, the interagency process shall consider publicly available information, classified information from the intelligence community, the Committee on Foreign Investment in the United States, the categories of personal data specified under 31 CFR 800.241, input from an advisory committee established by the Commerce Department, the recommendations of independent privacy experts and First Amendment experts, and a public notice and comment period,” according to a one-sheet released by Wyden’s office.

Once those categories are established, the Commerce Department would be charged with creating “export control regulations on the export, reexport, or in-country transfer” of data under those restricted categories and develop a list of countries “for which exports will be presumptively banned, unless the potential exporter can demonstrate that the export, reexport or in-country transfer will not harm the national security of the United States.”

Conversely, the department will also be tasked with creating a list of countries where companies won’t require a license to import U.S. data, such as allies that don’t pose a risk to national security. But that list won’t be easy to get on.

“Countries can only be added or removed from this list after notifying Congress and giving Congress 180 days to object via a joint resolution of disapproval,” according to a summary breakdown of the bill.

The legislation, as written, also outlines the criteria Commerce should use in developing both lists:

  • The adequacy and enforcement of data protection, surveillance, and export control laws in foreign countries in order to determine whether such laws are sufficient to: protect personal data from accidental loss, theft, and unauthorized or unlawful processing; ensure that personal data is not exploited for intelligence purposes by foreign governments to the detriment of the national security of the United States; and prevent the reexport of personal data to third countries for which a license would be required for such data to be exported directly from the United States.
  • The circumstances under which the government of a foreign country can compel, coerce, or pay a person in or national of that country to disclose personal data.
  • Whether a foreign government has conducted hostile foreign intelligence operations, including information operations, against the United States.

None of this would apply to how people manage their own data, which individuals would still be free to export—or withhold—of their own accord.

The law would also not apply to journalism and other speech protected by the First Amendment or encrypted data, so long as the decryption keys are not exported.

The senator is currently taking feedback on the language in the legislation at  ExportControl_Feedback@wyden.senate.gov.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.