Mr. Speaker, I yield myself such time as I may consume. Mr. Speaker, I rise today in strong opposition to S.J. Res. 34. Today, colleagues, we are waist deep in the swamp. The American people did not…
Mr. Speaker, I yield myself such time as I may consume.
Mr. Speaker, I rise today in strong opposition to S.J. Res. 34.
Today, colleagues, we are waist deep in the swamp. The American people did not ask for this resolution.
In fact, no company will even put its name behind this effort. Instead, this resolution is the result of an explicit written request from Washington lobbyists. These lobbyists make the bogus claim that having actual protections will confuse consumers and the only way to help clear up this information is to have no rules at all.
No consumer has come forward to support this position. No consumer has said this argument even makes sense.
I challenge every Member of this body at your next townhall meeting to have a show of hands of how many people think it is a good idea to allow your internet service provider to sell their personal information without their permission.
Then after you get that show of hands, ask them how many of them would vote for you if you support allowing corporations to do that.
This resolution is of the swamp and for the swamp and no one else. The rules of this resolution would overturn rules that are simple and make common sense. They don't require much, only three things:
One, internet service providers should ask permission before selling your private internet browsing history, app usage, or other sensitive information;
Two, once they have your information, internet service providers should take reasonable measures to protect it; and
Finally, if the information gets stolen, the company should quickly let you know.
That is it. That is all that is being asked of them.
These modest rules don't stop internet service providers from using data for advertising and profiling or whatever else so long as they ask first.
ISPs have an obligation under these rules not to dive into the personal lives of Americans unless that is what those Americans want. They just need to ask first.
This is particularly true because broadband providers see literally everything you do online, every website you visit, every app, every device, every time. By analyzing your internet usage and browsing history, these companies will know more about you than members of your own family, more than you tell your doctor, more than you know about yourself. Without these rules, these companies don't have to ask before selling all of that information, and they don't have to take reasonable measures to protect that information when they collect it.
Make no mistake about this, colleagues: Anyone who votes for this bill is telling your constituents that they no longer have the freedom to decide how to control their own information. You have given that freedom away to big corporations. More importantly, there aren't rules to fall back on if Congress scraps these.
Critics of the rules argue that the Federal Trade Commission should oversee the privacy protection for broadband providers, but, under current law, they have no authority to do so, and the CRA won't do a thing to fix that. Under a Federal court of appeals case, the FTC has no authority over mobile broadband providers at all.
And to those that say the FCC can evaluate complaints on a case-by- case basis using its statutory authority, the current Chairman--your current Chairman--stated that section 222 cannot be used to protect personal information and that rules are necessary to enforce this statute.
Mr. Speaker, I include for the Record a statement by the FCC Commissioner.
Dissenting Statement of Commissioner Ajit Pai
Re TerraCom, Inc. and YourTel America, Inc., Apparent
Liability for Forfeiture, File No. EB-TCD-13-00009175.
A core principle of the American legal system is due
process. The government cannot sanction you for violating the
law unless it has told you what the law is.
In the regulatory context, due process is protected, in
part, through the fair warning rule. Specifically, the D.C.
Circuit has stated that ``[i]n the absence of notice--for
example, where the regulation is not sufficiently clear to
warn a party about what is expected of it--an agency may not
deprive a party of property.'' Thus, an agency cannot at once
invent and enforce a legal obligation.
Yet this is precisely what has happened here. In this case,
there is no pre-existing legal obligation to protect
personally identifiable information (also known as PII) or
notify customers of a PII data breach to enforce. The
Commission has never interpreted the Communications Act to
impose an enforceable duty on carriers to ``employ reasonable
data security practices to protect'' PII. The Commission has
never expounded a duty that carriers notify all consumers of
a data breach of PII. The Commission has never adopted rules
regarding the misappropriation, breach, or unlawful
disclosure of PII. The Commission never identifies in the
entire Notice of Apparent Liability a single rule that has
been violated.
Nevertheless, the Commission asserts that these companies
violated novel legal interpretations and never-adopted rules.
And it seeks to impose a substantial financial penalty. In so
doing, the Commission runs afoul of the fair warning rule. I
cannot support such ``sentence first, verdict afterward''
decision-making.
To the extent that the circumstances giving rise to today's
item merited the Commission's attention, there was a better
(and lawful) path forward. We could have opened a notice-and-
comment rulemaking. This process would have given the public
an opportunity to speak. And in turn, the agency would have
had a chance to formulate clear, well-considered rules--rules
we then could have enforced against anyone who violated them.
Instead, the Commission proposes a forfeiture today that, if
actually imposed, has little chance of surviving judicial
review.
One more thing. The Commission asserts that the base
forfeiture for these violations is nine billion dollars--
that's $9,000,000,000--which is by far the biggest in our
history. It strains credulity to think that Congress intended
such massive potential liability for ``telecommunications
carriers'' but not retailers or banks or insurance companies
or tech companies or cable operators or any of the myriad
other businesses that possess consumers' PII. Nor can I
understand how such liability can be squared with the
Enforcement Bureau's recent consent decrees with these
companies. Under those consent decrees, the companies paid
the Treasury $440,000 and $160,000 for flouting our actual
rules and draining the Universal Service Fund by seeking
Lifeline support multiple times for the same customer.
Consumer protection is a critical component of the agency's
charge to promote the public interest. But any enforcement
action we take in that regard must comport with the law. For
the reasons stated above, I dissent.
Without these protections, there will be no clear rules of the road. At a time when foreign actors like the Russians, the Chinese, and everyone else under the sun are constantly trying to steal our data and compromise our security, it would be irresponsible to roll back the only Federal safeguards we have. I want my colleagues to think long and hard before you give corporations the ability to sell your information without their permission.
Mr. Speaker, I include several articles in the Record by Free Press and the Open Technology Institute opposing the CRA, an op-ed from a current
FTC Commissioner opposing this CRA, and a memorandum from engineers at EFF opposing this CRA.
[From Free Press, May 10, 2016]
Pay-for-Privacy Schemes Put the Most Vulnerable Americans at Risk
(By Sandra Fulton)
The FCC has opened a proceeding on the rules and policies
surrounding privacy rights for broadband service. One
industry practice called into question in that proceeding
could have a devastating impact on our most vulnerable
populations.
Internet service providers charge broadband customers a ton
for Internet access. ISPs are increasingly finding new
revenue streams too, by taking part in the multibillion-
dollar market that's evolved out of selling users' personal
information to online marketers. As the debate around privacy
has heated up, ISPs have tried to placate the public's
growing interest in privacy protections while maintaining
revenues they can get when they auction off their customers'
valuable personal information.
One proposed solution that AT&T has largely ``pioneered''?
Have customers pay to preserve their privacy.
The potential harms and discriminatory implications of this
practice are obvious. It could mean that only people with the
necessary financial means could protect their privacy and
prevent their ISPs from sharing their personal information
with predatory online marketers. The FCC rulemaking
proceeding seeks comments on whether to allow such
``financial inducements'' for the surrender of private
information. If the agency decides not to ban such practices
outright, it wants to know how it should regulate them.
As our lives have moved online, ISPs have gained access to
our most sensitive personal information. Advanced
technologies allow companies to track us invisibly,
collecting and selling data on nearly every detail of what we
do online.
But ISPs don't just stop at knowing what we're doing. The
location tracking that's needed to provide mobile service to
our phones lets the ISPs know when and where we do it too.
And they can figure out the people and organizations we
associate with by looking at who we talk to and which
websites we visit.
As ISPs track their customers, they create comprehensive
dossiers containing sensitive information on each person's
finances, health, age, race, religion and ethnicity. Their
reach is so pervasive that information like a visit to a
website discussing mental health, a search on how to collect
unemployment benefits, or a visit to a church or Planned
Parenthood office could be swept up into their databases.
How do you feel about your ISP selling such a personal
glimpse into your life to online advertisers? Under a pay-
for-privacy scheme, you wouldn't need to worry about it so
long as you could afford to shell out the hush money. But
those who aren't so fortunate would have to relinquish any
control over how their personal data is spread across the
Web.
The FCC raised concerns about this dynamic when it launched
its rulemaking proceeding, noting that such pay-for-privacy
practices might disadvantage low-income people and members of
other vulnerable communities. But it didn't make any specific
recommendations or issue any proposals on how to regulate in
this space.
Long before the FCC launched this inquiry at the end of
March 2016, and even before the agency had clarified its
authority to protect broadband users in the February 2015
Open Internet Order, AT&T's GigaPower broadband service had
become one of the first pay-for-privacy plans on the market.
The AT&T deal allows customers to opt out of some information
sharing if they pay an extra $29 a month or more.
For a struggling family, that could mean choosing between
paying for privacy and paying for groceries or the public
transportation needed to get to work. And while AT&T might be
the first to launch this kind of service, an article in
Fortune notes that other companies are eager to roll out
similar plans.
Under pay-for-privacy models, consumers who are unable to
pay the higher broadband cost will likely see their ISPs
share their data with shadowy online data brokers who use
this information to tailor marketing messages. While
unregulated and unaccountable data brokers are a threat to
everyone's privacy, they're notorious for targeting low-
income communities, people of color and other vulnerable
demographics.
One particularly damning report from the Senate Commerce
Committee offered this glimpse into how these brokers
categorize and label these target audiences:
The Senate committee's report notes, for example, that the
``Hard Times'' category includes people who are ``Older,
down-scale and ethnically diverse singles typically
concentrated in inner-city apartments.''
It continues: ``This is the bottom of the socioeconomic
ladder, the poorest lifestyle segment in the nation. Hard
Times are older singles in poor city neighborhoods. Nearly
three-quarters of the adults are between the ages of 50 and
75; this is an underclass of the working poor and destitute
seniors without family support . . .''
These classifications can influence not just what kinds of
ads people see, but the interest rates they're offered or the
insurance premiums they pay. These targeted communities are
precisely the ones who can't pay extra to shield their
personal information from these dangerous companies.
There may be some argument that if big companies are going
to profit from our data anyway, it's actually good if their
customers get a share of that. The FCC's rulemaking proposal
notes that brickand-mortar stores and websites alike offer
all sorts of ``free'' services, discounts and perks in
exchange for the data they mine from their customers and
users.
But the nature of the broadband market--where users have no
real options when it comes to choosing their providers, and
no way to opt out short of staying offline--makes the
tradeoffs here especially worthy of attention. If users could
get fair value for their data, and if they got a real
discount on broadband and not just a privacy penalty, and if
they were providing truly informed consent with full
knowledge of all the pernicious uses data brokers have for
their information, then maybe we could have a conversation
about the fairness of such schemes. But those are some very
big ifs.
We need better transparency rules for marketers and easy-
to-use disclosures and opt-in mechanisms before we get there.
We also need strong baseline privacy protections guaranteed
for all, including rules that prohibit ISPs from using
discriminatory schemes that jeopardize the rights of their
most vulnerable customers.
We applaud the FCC for taking this crucial first step to
protect privacy from broadband ISPs' overreach and abuse. As
gatekeepers to the Internet, ISPs hold a wealth of
information about their customers, and the Communications Act
commands the FCC to establish strong safeguards for that
private info. But the FCC also must also remember that our
rights are not for sale--and that privacy is not a luxury for
the wealthy.
Mr. Speaker, I reserve the balance of my time.
Mr. Speaker, I would remind my friends that, under current law, the FTC has no authority to regulate ISPs and that it was your Commissioner, your current FCC Commissioner, that said that they can't do it under section 222 also, which I have submitted for the record.
Mr. Speaker, I yield 4 minutes to the gentlewoman from California (Ms. Eshoo).
Mr. Speaker, I would just remind my colleague, once again, that the FTC has no authority to regulate ISPs once this bill is implemented; and consumers will not be protected, and their current FCC Commissioner has stated that.
Mr. Speaker, I yield 1\1/2\ minutes to the gentlewoman from Colorado (Ms. DeGette).
Mr. Speaker, might I inquire as to how much time remains on both sides?
Mr. Speaker, I would remind my colleagues that, whether it is nonsensitive information or sensitive information, the ISP should ask for your permission to use it.
Mr. Speaker, I yield 5 minutes to the gentleman from New Jersey (Mr. Pallone), the ranking member of the Energy and Commerce Committee.
Mr. Speaker, I remind my friend, since he acknowledges the court decision does not allow FTC jurisdiction and that he wants to introduce a bill, perhaps the Republicans should have done that first, before scrapping the rules that leave ISPs with no rules.
Mr. Speaker, I yield 2 minutes to the gentlewoman from California (Ms. Matsui).
Mr. Speaker, I have heard about this last-minute dropping and late at night. Just for the other side's information, after a 7-month rulemaking process, this rule was adopted midday on October 26. So let's get the record straight.
Mr. Speaker, I yield 3 minutes to the gentleman from California (Mr. McNerney).
Mr. Speaker, may I inquire how much time is remaining on both sides?
Mr. Speaker, I remind the gentleman that these heavy-handed regulations that he speaks of are simply: ask permission, protect people's data, and tell them if it gets stolen.
That doesn't sound too heavy-handed to me.
Mr. Speaker, I yield 2 minutes to the gentleman from New York (Mr. Tonko).
Mr. Speaker, I remind my friends once again that this does not put us on equal footing. The FTC has no power to regulate ISPs under current law.
Mr. Speaker, I yield 3 minutes to the gentleman from Massachusetts (Mr. Capuano).
Mr. Speaker, I yield an additional 30 seconds to the gentleman from Massachusetts.
Mr. Speaker, may I inquire how much time remains on both sides?
Mr. Speaker, I just remind my friend, you can say it as many times as you want, but the fact of the matter is that, under current law, the FTC has no authority to regulate the FCC, and the FCC Commissioner has said that you cannot do this without a rule in section 222.
I yield 1 minute to the gentlewoman from California (Ms. Pelosi), our House Democratic leader, the magic minute.
Mr. Speaker, I yield 1 minute to the gentlewoman from Illinois (Ms. Schakowsky).
Mr. Speaker, I yield 1 minute to the gentleman from Rhode Island (Mr. Langevin).
Mr. Speaker, may I inquire how much time I have remaining?
Mr. Speaker, I yield 1 minute to the gentlewoman from Florida (Mrs. Demings).
Mr. Speaker, I include in the Record letters from a coalition of small ISPs, a coalition of civil rights organizations, the Consumers Union, and an article by Terrell McSweeny all opposing this CRA.
Electronic Frontier Foundation,
San Francisco, CA.
Re Oppose S.J. Res 34--Repeal of FCC Privacy Rules.
Dear U.S. Representatives: We, the undersigned founders,
executives, and employees of ISPs and networking companies,
spend our working lives ensuring that Americans have high-
quality, fast, reliable, and locally provided choices
available when they need to connect to the Internet. One of
the cornerstones of our businesses is respecting the privacy
of our customers, and it is for that primary reason that we
are writing to you today.
We urge Congress to preserve the FCC's Broadband Privacy
Rules and vote down plans to abolish them. If the rules are
repealed, large ISPs across America would resume spying on
their customers, selling their data, and denying them a
practical and informed choice in the matter.
Perhaps if there were a healthy, free, transparent, and
competitive market for Internet services in this country,
consumers could choose not to use those companies' products.
But small ISPs like ours face many structural obstacles, and
many Americans have very limited choices: a monopoly or
duopoly on the wireline side, and a highly consolidated
cellular market dominated by the same wireline firms.
Under those circumstances, the FCC's Broadband Privacy
Rules are the only way that most Americans will retain the
free market choice to browse the Web without being surveilled
by the company they pay for an Internet connection.
Signed,
Sonic, MonkeyBrains, Cruzio Internet, Etheric Networks,
Aeneas Communications, Digital Service Consultants Inc.,
Hoyos Consulting LLC, Om Networks, Motherlode Internet,
Goldrush Internet, Credo Mobile, Andrew Buker (Director of
Infrastructure Services & Research computing, University of
Nebraska at Omaha), Tim Pozar (co-founder, TwoP LLC), Andrew
Gallo (Senior Network Architect for a regional research and
education network), Jim Deleskie (co-founder, Mimir
networks), Randy Carpenter (VP, First Network Group), Kraig
Beahn (CTO, Enguity Technology Corp).
Mr. Speaker, I yield 1 minute to the gentlewoman from California (Ms. Lofgren), my colleague from the class of '94.
Mr. Speaker, I ask my colleagues to vote against this horrible resolution, and I yield back the balance of my time.
Mr. Speaker, on that I demand the yeas and nays.