On Saturday the 28th, Japan time, the U.S. White House released its draft Consumer Privacy Bill of Rights Act [1]. This turns the previously announced Consumer Privacy Bill of Rights into actual draft legislation.
A distinguishing feature is that it adheres to a context-based approach rather than regulating according to data type. I think this is the better approach. Structurally, definitions appear in SEC. 4; SEC. 101 through 107 set out the Consumer Privacy Bill of Rights; SEC. 201 through 203 concern enforcement; SEC. 301 provides a safe harbor for enforceable codes of conduct; SEC. 401 provides that this Act preempts other laws; SEC. 402 makes clear that it does not affect the FTC’s authority; and SEC. 403 makes clear that the Act does not create a Private Right of Action.
If there is time, I hope to discuss these points at today’s OpenID BizDay #8 as well.
I plan to expand this article when I find time, or write a separate article.
I had no time at all this weekend because there were 5 deadlines for ISO/IEC comments. I will write something after today’s BizDay.
See you!
[1] http://www.whitehouse.gov/sites/default/files/omb/legislative/letters/cpbr-act-of-2015-discussion-draft.pdf
Related posts

President Signs the U.S. Consumer Privacy Bill of Rights
On February 23, 2012 U.S. time, President Barack Obama signed the administration white paper “Consumer Data Privacy in a Networked World”. The paper sets out a…

UK Digital Markets, Competition and Consumers Act Enacted
The Digital Markets, Competition and Consumers Act has received Royal Assent and become law. Under this Act, the following will apply: * UK competition regulators receive…
U.S. “Kids Online Safety Act” (KOSA) Passes Senate Amid Divided Opinions
On July 30, for the first time since 1998, the U.S. Senate passed a law aimed at protecting children online. In 1998, social networks did not…
