The American Data Privacy and Protection Act (ADPPA), currently under congressional review, would be the first piece of American legislation explicitly concerning data protection. Eighty-one percent of consumers say the potential risks they face from data collection by companies outweigh the benefits. Additionally, sixty-two percent of Americans don’t believe that it’s possible to go through their daily life without companies collecting data on them. These statistics paint a worrying picture of personal privacy in the United States, but these challenges don’t exist independently from one’s social identity. It is clear that U.S. citizens hold genuine concern about data security, which the ADPPA appears to address. With that said, the proposed bill makes monumental strides in regulation that would directly protect marginalized groups from companies harvesting user data.
If enacted, The American Data Privacy and Protection Act would apply to any organization and business that operates in the United States. The act would institute clear limits to the methods that institutions use to collect and store the data of individuals in ways that the average consumer can easily interact with. Section 202 notes that each institution would be legally required to outline their respective privacy policies and data collection methods and include how individuals can exercise their rights under the act. These policies must be provided in all languages, highlighting an overarching goal of equity and inclusivity in data protection. Regarding data ownership and control, Section 203 outlines that individuals would also have the right to access, correct, or delete covered data in a readily accessible and portable format. Finally, the act would also implement policy concerning corporate accountability, ensuring institutional compliance. Section 303 enforces that the CEO’s (or equivalent) and privacy officers at large data holders must annually certify that their company maintains reasonable internal controls and reporting structures for compliance with the act. Moreover, this certification must be based on a review conducted by the certifying officers within ninety days of submission.
Perhaps most notable of its countless and landmark regulations is Section 207, regarding civil rights and algorithms. This provision establishes that any entity or service providers, “may not collect, process, or transfer covered data in a manner that discriminates in or otherwise makes unavailable the equal enjoyment of goods or services on the basis of race, color, national origin, sex, or disability.” American companies and businesses would have to follow strict guidelines of evaluation for any computational processing technique before it is incorporated into interstate commerce. These guidelines would evaluate the data inputs, strutcute, and overall design of an online model. Mayor Brown, one of the largest international law firms, notes that the ADPPA would also require these assessments, labeled as “algorithm design evaluations,” to be externally and independently audited by qualified auditors or algorithm reasearchers. Finally, the bill also requires data holders to write detailed descriptions of steps to mitigate “potential harms” within algorithms. The bill specifically identifies potential harms related to disparate impact on individuals based on race, color, religion, national origin, sex, or disability status as areas of concern for lawmakers.
The notion of a discriminatory algorithm is not one the United States hasn’t encountered before. In 2019, Ziad Obermeyer, a University of California, Berkeley graduate for public health, identified a then-prominent algorithm in the healthcare industry, which used a patient’s health care spending history to estimate the amount of healthcare that they show need for, as one possessing racial bias. Among the examined high-risk patients for one hospital, those who identified as black spent a similar amount of medical bills as a self-identifying white patient who was in greater health. The researchers noted that this could be due to the fact that marginalized races are more likely to have reduced access to health services or not have the means to pay for a service. The algorithm did not account for the fact that black patients were far less likely to be flagged as in need of high-risk hospital care despite their actual conditions. Moreover, around eight of the top U.S. insurance companies utilized the alrogithm, which effectively gave black patients a lower risk score than white patients because it placed so much weight on medical spending history. In short, as they instill consumer distrust toward companies that collect and interpret data and target marginalized groups who have the weakest defenses, discriminatory computational processes are a real problem that won’t end without legislative action.
The ADPPA not only sets a precedent for algorithm evaluation in the name of civil rights but also outlines strict enforcement guidelines for possible violations. There is a clear need for the legislation in Section 207 concerning algorithm assessment, particularly for historically marginalized groups. While it is still unclear whether the bill will be passed and to what extent its implementation would be successful, it is a much needed start for data protection policy in the United States.