Irish GDPR Regulator Weighs In to U.S. Senators Shaping Federal Privacy Law
Ireland's data protection commissioner, who regulates the GDPR compliance of Facebook, Microsoft, Twitter and other U.S. tech companies incorporated in the EU country, shared lessons and advice on data privacy policies with senators at a hearing Wednesday.
May 02, 2019 at 03:00 AM
3 minute read
The original version of this story was published on Corporate Counsel
U.S. senators designing a possible federal data privacy law heard input from Ireland's data protection commissioner and U.S. consumer advocacy groups at a hearing Wednesday.
It's the latest in a series of congressional committee hearings in Washington, D.C., meant to shape policy ideas for the proposed law, which has gained bipartisan traction this year in the wake of numerous data breaches, the European Union's General Data Protection Regulation and the California Consumer Privacy Act.
Members of the Committee on Commerce, Science and Transportation raised their concerns with data privacy regulation on a federal level with witness Helen Dixon, the Irish data protection commissioner, whose agency oversees GDPR compliance for Facebook, Twitter, Uber and other U.S. tech companies incorporated in Ireland.
Sen. Ted Cruz, R-Texas, asked about the GDPR's impact on small- and medium-sized businesses in Europe and whether the law's implementation last May reduced employment opportunities. Irish officials are “not aware of evidence that the GDPR is effecting jobs adversely,” Dixon said.
That's in part because certain GDPR articles don't apply to smaller companies, Dixon said earlier in the hearing. The law dictates businesses implement new processes “appropriate to the risks and scale of personal data processing they're undertaking,” not a one-size-fits-all approach, she added.
Neema Singh Guliani, a hearing witness and senior legislative counsel for the American Civil Liberties Union, suggested a federal data privacy law's penalties should vary based on the size of the business.
Senators also questioned Dixon on the value of pre-emption in a U.S. federal data privacy law. Sen. Marsha Blackburn, R-Tennessee, said GDPR is an “EU-wide regime” versus a law specific to Ireland. Dixon noted GDPR is a “hybrid” state and EU-level law, with “members state flavors in terms of choices” on certain aspects of the regulation, such as the country's digital age of consent.
Guliani and James Steyer, the chief executive officer and founder of Common Sense Media, both said they would have “serious concerns” with a federal data privacy law that pre-empted state law, particularly the CCPA. Both witnesses said CCPA should be a “floor” for federal privacy regulation, not a ceiling, and would not back a nationwide law with looser consumer protections that undermined California's law.
Google, Twitter and other tech companies have pushed for a federal law that would pre-empt CCPA, which goes into effect on Jan. 1, 2020. In a September 2018 Senate Committee on Commerce, Science and Transportation hearing, Google chief privacy officer Keith Enright and Amazon.com Inc. associate general counsel Andrew DeVore said CCPA's definition of impacted personal information was unclear and backed the idea of a regulation with pre-emption.
At Wednesday's hearing, Dixon was also hit with questions on Ireland's enforcement of GDPR violations against EU versus U.S. companies by Sen. Roy Blunt, R-Missouri. Dixon said Ireland's Data Protection Commission hasn't issued any GDPR-related fines yet, but the agency is currently investigating 51 companies, 12 of which are U.S. tech companies, for violations.
Her agency plans to wrap the first wave of GDPR investigations up this summer, she said. That could include an investigation launched against Facebook in October after the Menlo Park, California-based company revealed a data breach impacting millions of users. The highest fine a company can face under the GDPR is 4% of its annual turnover, more than $1.5 billion for Facebook.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllTrending Stories
- 1Six Benefits of Taking an Opposing Medical Expert’s Deposition
- 2Ex-Prosecutor’s Trial Ends as Judge Throws Out Her Felony Indictment in Ahmaud Arbery Death Case
- 3Conversation Catalyst: Transforming Professional Advancement Through Strategic Dialogue
- 4Trump Taps McKinsey CLO Pierre Gentin for Commerce Department GC
- 5Critical Mass With Law.com's Amanda Bronstad: 700+ Residents Near Ohio Derailment File New Suit, Is the FAA to Blame For Last Month's Air Disasters?
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250