House Democrat Introduces Legislation to Strengthen Children’s Online Privacy

Feb 11, 2020

Reading Time : 4 min

The Kids PRIVCY Act would amend COPPA in a number of ways, including by:

Establishing protections for children 13–17 years old

The bill would amend COPPA to require companies to obtain opt-in consent for all individuals under the age of 18 prior to collecting, retaining or sharing users’ personal information. The measure proposes establishing a new class of “young consumers” ages 13-17 and providing them with specific protections. Currently, COPPA provides protections related to data collected from children under 13.

Expanding the enumerated types of personal information covered under COPPA

The Kids PRIVCY Act would expand the enumerated types of information covered under COPPA to include a number of additional categories, including biometric information, health information, geolocation information and search history. COPPA currently defines “personal information” as “individually identifiable information about an individual collected online” and provides examples of personal information, including first and last name, home address, telephone number and Social Security number. The bill would significantly expand upon this list of codified examples.

Expanding upon access and deletion rights provided under COPPA and establishing the right to correct personal information

Similar to other privacy proposals in the 116th Congress, the Kids PRIVCY Act would establish access, correction and deletion rights for users and require privacy policies to describe how users can exercise these rights in plain language. COPPA regulations require operators to provide parents and guardians the “opportunity at any time to refuse to permit the operator’s further use or future online collection of personal information from that child, and to direct the operator to delete the child’s personal information.” They also require operators to provide a parent, upon request, a “means of reviewing any personal information collected from the child.”

The Kids PRIVCY Act would expand upon these rights by requiring covered entities to provide access to additional information, including all covered information pertaining to a child or young consumer and the names of each third party to which the covered entity has disclosed such information. The Act would also require covered entities to provide a mechanism by which a parent or young consumer could request that personal information be corrected.

Prohibiting operators from terminating services because a parent, guardian or young consumer has exercised their access, deletion or correction rights

The Kids PRIVCY Act would prohibit covered entities from refusing to provide a service, or discontinuing provision of a service, if a young consumer, parent or guardian exercises their rights to access, deletion or correction. Under current law, operators are permitted to terminate services to a child whose parent or guardian has directed the operator to delete the child’s personal information, provided that operators cannot condition a child’s participation in an activity on the child disclosing more personal information than is reasonably necessary.

Adding a number of specific data security requirements

COPPA currently requires operations to “establish and maintain reasonable procedures to protect the confidentiality, security, and integrity of personal information collected from children.” The Kids PRIVCY Act would require covered entities to include certain elements in their data security policies and procedures, including information regarding data retention and breach response. The legislation also contains language that would require companies to establish concrete procedures to mitigate vulnerabilities, as well as a designated data security officer.

Repealing the COPPA safe harbor provisions

COPPA includes provisions that allow industry groups to develop self-regulatory guidelines that implement COPPA protections and seek FTC approval for their use. The FTC has approved seven safe harbor programs under these provisions. The Kids PRIVCY Act would repeal COPPA’s safe harbor program due to concerns that the program facilitates non-compliance.

Providing for increased civil penalties, punitive damages and a private right of action

Regarding enforcement, the Kids PRIVCY Act would increase the maximum allowable civil penalty per violation by 50 percent and allow the FTC to pursue punitive damages. The measure would also grant parents the ability to bring civil actions.

The FTC is in the process of reviewing its regulations implementing COPPA. It recently concluded collecting public comments regarding, among other topics, potential updates to the parental right to review or delete children’s information and factors that should be used to determine whether an online service is directed to children.

The House Energy and Commerce Committee is also currently reviewing feedback in response to a staff-level discussion draft of comprehensive federal privacy legislation. This proposal, released to the public in December, would create an online privacy bureau within the FTC and prohibit discriminatory uses of personal data. While the initial draft did not contain legislative language on controversial provisions such as preemption and a private right of action, staff left these areas in brackets for stakeholder input.

Recent proposals to amend COPPA are likely to play a significant role in the larger privacy debate in the House. Rep. Jan Schakowsky (D-IL), Chair of the Energy and Commerce Committee’s Subcommittee on Consumer Protection and Commerce, has indicated that the Committee will likely combine provisions from various bills, including the Kids PRIVCY Act, in its final product. We continue to monitor the Committee’s process on this broader House proposal.

Share This Insight

Previous Entries

Data Dive

November 19, 2024

The European Union’s AI Office published the inaugural General-Purpose AI Code of Practice on November 14, 2024. The Code is intended to assist providers of AI models in their preparations for compliance with the forthcoming EU AI Act, to be enforced from August 2, 2025. The Code is designed to be both forward-thinking and globally applicable, addressing the areas of transparency, risk evaluation, technical safeguards and governance. While adherence to the Code is not mandatory, it is anticipated to serve as a means of demonstrating compliance with the obligations under the EU AI Act. Following a consultation period that garnered approximately 430 responses, the AI Office will be empowered to apply these rules, with penalties for nonconformity potentially reaching 3% of worldwide turnover or €15 million. Three additional iterations of the Code are anticipated to be produced within the coming five months.

...

Read More

Data Dive

November 15, 2024

On October 29, 2024, the DOJ issued a proposed rule prohibiting and restricting certain transactions that could allow persons from countries of concern, such as China, access to bulk sensitive personal data of U.S. citizens or to U.S. government-related data (regardless of volume).

...

Read More

Data Dive

October 17, 2024

During the course of any lending transaction, lenders will conduct a due diligence review of the borrower, including reviewing any relevant “know-your-customer” information.

...

Read More

Data Dive

September 17, 2024

Following the publication of the European Union’s Artificial Intelligence Act (AI Act or Act) on 12 July 2024, there are now a series of steps that various EU bodies need to take towards implementation. One of the first key steps is in relation to the establishment of codes of practice to “contribute to the proper application” of the AI Act.

...

Read More

Data Dive

August 6, 2024

On July 30, 2024, the Senate passed the Kids Online Safety and Privacy Act (S. 2073) via an overwhelmingly bipartisan vote of 91-3 shortly before departing for the August recess.

...

Read More

Data Dive

July 18, 2024

On 12 July 2024, the European Union Artificial Intelligence Act (AI Act or Act) was published in the Official Journal of the European Union (EU), marking the final step in the AI Act’s legislative journey. Its publication triggers the timeline for the entry into force of the myriad obligations under the AI Act, along with the deadlines we set out below. The requirement to ensure a sufficient level of AI literacy of staff dealing with the operation and use of AI systems will, for example, apply to all providers and deployers on 2 February 2025.

...

Read More

Data Dive

July 18, 2024

On June 18, 2024, the United States Securities and Exchange Commission (SEC) announced a settlement with R.R. Donnelley & Sons Company (RRD) for alleged internal control and disclosure failures following a ransomware attack in 2021. Without admitting or denying the SEC’s findings, the business communications and marketing services provider agreed to pay a civil penalty of over $2.1 million to settle charges alleging violations of Section 13(b)(2)(B) of the Securities Exchange Act of 1934 (Exchange Act) and Exchange Act Rule 13a-15(a).1

...

Read More

Data Dive

June 11, 2024

In May, the National Institute of Standards and Technology (NIST) issued updated recommendations for security controls for controlled unclassified information (CUI) that is processed, stored or transmitted by nonfederal organizations using nonfederal systems, (NIST Special Publication 800-171 (SP 800-171), Revision 3). These security requirements are “intended for use by federal agencies in contractual vehicles or other agreements that are established between those agencies and nonfederal organizations.”1 While these new controls are only applicable to nonfederal entities that agree to comply with the new issuance, Revision 3 signals the next phase of expected security for government contractors.

...

Read More

© 2024 Akin Gump Strauss Hauer & Feld LLP. All rights reserved. Attorney advertising. This document is distributed for informational use only; it does not constitute legal advice and should not be used as such. Prior results do not guarantee a similar outcome. Akin is the practicing name of Akin Gump LLP, a New York limited liability partnership authorized and regulated by the Solicitors Regulation Authority under number 267321. A list of the partners is available for inspection at Eighth Floor, Ten Bishops Square, London E1 6EG. For more information about Akin Gump LLP, Akin Gump Strauss Hauer & Feld LLP and other associated entities under which the Akin Gump network operates worldwide, please see our Legal Notices page.