I disagree with the immediate labeling of a potential consumer protection law as "rent seeking." Such an attitude totally excludes any improvement in the consumer privacy situation, unless it's an act of benevolence from adtech; which is to say that it totally excludes any privacy improvement ever.
The only sticky one is really the "right to be forgotten," which just isn't a right, and possibly has constitutional (1st amendment) problems.
IMO though, a "conservative GDPR" could get Republican backing by basically framing it as a question about property rights, which their base is all about: your data is valuable, and it's YOUR property, not Google's. Some of the other provisions could be sold as a "sunshine law" for big business.
Also resumably, given US politics, there would be plenty of exemptions for small businesses (and industries that have strong lobbying firms).
(note that I'm not a lawyer, so this may be bullshit)
A law requiring businesses and individuals to delete any personal data at the request of the data subject, as the GDPR requires, would have to be extremely narrowly written to survive constitutional muster here, I think.
If I do business with you and write down your name, the GDPR requires that I delete your name if you ask me to (and even if you don’t if our relationship ends). That wouldn’t survive a First Amendment challenge here.
In America, I don't need a reason for writing your name down. In the EU on the other hand, all personal data needs to be deleted, unless a specific government-approved exemption applies, as you said.
Quoting the US Supreme Court, in Chicago v. Mosley, 1972:
> Above all else, the First Amendment means that government has no power to restrict expression because of its message, its ideas, its subject matter, or its content. To permit the continued building of our politics and culture, and to assure self-fulfillment for each individual, our people are guaranteed the right to express any thought, free from government censorship [1]
I'm pretty sure that if the GDPR was copied and pasted into a US law, the Right to be Forgotten would be struck down as unconstitutional very quickly.
1. https://supreme.justia.com/cases/federal/us/408/92/case.html
No, it really really doesn't.
https://gdpr-info.eu/art-17-gdpr/
> The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:
> the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
> the data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing;
> the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);
> the personal data have been unlawfully processed;
> the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;
> the personal data have been collected in relation to the offer of information society services referred to in Article 8(1).
Of course, we already have a variety of limitations on free speech, plenty of laws that restrict what companies and and cannot disclose about other entities, and GDPR would be no different.
Copyright is settled law that definitely limits the kinds of speech people can engage in.
Couldn't you construct a right to privacy by first saying an individual has an automatic ownership right to certain kinds of personal data [1], and that data can't be used without an appropriately constructed license [2]?
[1] You might be able make this strong and compatible with the First Amendment, by treating machine-collected and person-collected data differently. A machine has no First Amendment right to speak about what it knows, while a person does.
[2] The "appropriately constructed license" requirements could include GDPR-like definitions of consent.
The constitution specifically calls out for a "free press."
HIPAA exists... and it doesn't prevent the press from using that information.
I'm not sure your really have a good grasp on what any of these laws actually do, let alone 'free speech'. You keep alluding to complications that don't exist and don't explain what you're talking about.
Or perhaps, that USA Today is collecting tracking data on its users and selling it secretly to 3rd parties and doesn't want to stop spying?
Plenty of other newspapers have had no problem implementing GDPR. It's as simple as not spying on your users.
For "press freedom" defined as the writing and publishing of articles, it's unaffected.
For "press freedom" defined as literally any action a member of the press takes, sure it's affected, but that's a very flawed definition. It's not like drunk driving laws are an infringement on "press freedom", even though they occasionally affect members of the press.
This information is has to be kept away from the public, including journalists, but there is no law preventing journalists from publishing information about someone's health. HIPAA doesn't cover journalists, it just prevents covered entities from giving journalists information.
It's not like information doesn't have restrictions already, those situations do not seem to have been ruled unconstitutional...
https://gdpr-info.eu/art-17-gdpr/
But then look at para 3.
> Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:
> for exercising the right of freedom of expression and information;
Example: if I want to say Brian accessed my website last Thursday.