Rep. Shelley Kloba, D-Kirkland, has introduced a privacy bill in the Legislature every year since 2021, none of which has reached the House floor due to disagreements over whether consumers should be able to sue. (Washington House Democrats Photo)

More than 20 states have now passed the “Washington model” of privacy legislation. Washington state hasn’t. 

In the years since then-state Sen. Reuven Carlyle introduced the Washington State Privacy Act in 2019, the blueprint has been adopted across the country, mandating that companies get the consent of consumers before collecting sensitive personal data, and providing consumers with the right to correct and delete their details in those databases.

In its home state, the bill stalled in negotiations between the House and Senate two years in a row. Every year since, a comprehensive privacy bill has been introduced in the Washington state Legislature but has failed to pass. 

Washington state Attorney General Nick Brown released his office’s first data privacy report Aug. 14, calling on lawmakers to pass a privacy law that would limit how much personal information companies can collect and keep in the first place.

But that proposal will face the same hurdle that has blocked efforts to pass a state privacy law for seven years: a fight over whether consumers should be able to sue companies that violate it.

Washington AG Nick Brown

“The attorney general supports greater data privacy protections for Washingtonians,” said Mike Faulk, a spokesperson for the AG’s office. “In our experience, this has proven to be a difficult subject for the Legislature to build consensus on.”

Experts say the stakes are rising as AI systems train on personal data that often falls outside Washington’s existing privacy protections. Without a baseline privacy law, they say, lawmakers also have less to build on when they try to regulate AI itself. 

Rethinking privacy

AI has rendered some parts of the Washington model moot, while making others more necessary than ever, according to policy experts. 

As states have begun to pass the first AI regulations, one of the highest priorities has been the regulation of AI-based high-risk decisions.

In Washington, for example, the state Legislature passed the Prior Authorization Transparency Act, which bars health insurers from using AI as the only basis to deny, delay or modify care. Washington state lawmakers also considered a bill to regulate the use of AI to make decisions of financial, educational, or legal consequence.

This is proving to be a much easier lift in states that passed the “Washington model,” often years before the current AI craze. That’s because Carlyle’s bill happened to include what’s now known as an automated decision-making technology (ADMT) opt-out clause, which granted residents the right to opt out of automated profiling when used for “legal or similarly significant effects.” 

Algorithmic wage and price determinations, as well as AI-based healthcare and employment technologies, could be regulated under the pre-existing privacy act, or by tweaking those laws.

“The states that have passed automated decision making laws have done so on top of existing privacy laws,” said Cobun Zweifel-Keegan, a managing director at the International Association of Privacy Professionals (IAPP). “There’s already restrictions, or at least the beginnings of restrictions, on automated decision making baked into these privacy laws. It’s a natural model to build on top of.”

Meanwhile, AI has made it more dangerous to go without a privacy law, because an absence of privacy legislation means more personal data online for AI models to access, said Kara Williams, counsel at the Electronic Privacy Information Center.

Williams said data minimization could prevent or limit companies from repurposing personal data to train AI systems. 

“It goes back to using the data for the purpose you collected it for,” Williams said. “Almost all of the data that companies have used to train AI systems or develop the algorithms that led to this moment were not collected for the purpose of training AI systems.”

Data minimization requires companies to restrict the collection and use of customer data to the service the customer requested. That often precludes secondary uses like selling it to a data broker.

The Washington attorney general’s privacy report also endorsed a data minimization standard, which the original Washington model does not include.

Carlyle said he might have written one in, if he were drafting the bill today.

“We live in an AI world with a giant vacuum in the sky, sucking up every ounce of data that exists on a person,” Carlyle said. “So I think the concept [of data minimization] makes some sense.” 

Meanwhile, experts say AI makes some elements of the Washington model irrelevant. 

Zweifel-Keegan of IAPP said those elements include the right to control, correct, and delete personal data, which was the bread and butter of Carlyle’s bill. Because LLMs are a weighted map of associated words, there is no straightforward way to selectively delete or change information once a model has been trained.  

“That’s just fundamentally how LLMs work. They’re not a table where you can go to my name and see all the other records that are associated with me,” Zweifel-Keegan said. “You can’t go in and selectively delete information.”

While states around the country that have passed the Washington model are now seeking to revise its provisions to meet the AI moment, Washington state has no comprehensive privacy law to start with.

“AI is making us rethink some of our foundational expectations of what a privacy law does,” Zweifel-Keegan said. “Washington could be the place where that happens.”

The story of the “Washington model”

In 2019, when now-retired State Sen. Carlyle introduced the Washington State Privacy Act, it passed the Senate 46-1 before dying in the House. One year later, it passed both chambers but died after a long and heated fight in conference.

Some say the bill didn’t deserve to pass after being “rewritten” by tech lobbyists. Others say the lawmakers who opposed the bill let the perfect be the enemy of the good. 

The original bill was based on an opt-out framework, also called “notice and consent,” which required a platform to present a privacy policy to users who consent to the collection of their data by continuing to use the platform. The bill’s sole enforcement mechanism was the state attorney general, and did not offer a private right of action for individuals to sue companies that violated the proposed rules. 

In 2019, Carlyle was focused on establishing a baseline notion of consumer rights — one that could be revised later, as other states ultimately did.

“At that time we didn’t have a direct understanding that consumers have a right to correct or delete their personal data, we didn’t have an understanding of what opt out meant for advertising, or an understanding of data brokers and the role that they play,” Carlyle said.  

His bill also established special protections for sensitive data and frameworks to hold corporations accountable for complying with transparency and disclosure requirements. 

“Those were pretty novel pillars that didn’t exist,” Carlyle said. “That’s why it had a big effect on other state laws.” 

By March 2021, Virginia had passed a privacy law closely modeled off of Carlyle’s template, and over the next few years, more than 20 other states did, too.

In Washington, meanwhile, no progress was made. After Microsoft endorsed the Senate bill in 2019, consumer advocacy groups and some state lawmakers said that the tech lobby’s influence had gone too far. The state House countered with a stronger privacy bill, premised on opt-in data collection frameworks and enforced by a private right of action.

Both the 2019 and 2020 legislative sessions ended in failed negotiations between the state Senate and House over their competing privacy laws. Every year since 2021, Rep. Shelley Kloba has introduced a bill that preserves the House’s stronger language. It has yet to make it to the House floor. 

A potential compromise

The sticking point for Washington negotiators in 2019 and 2020 was the enforcement mechanism. Carlyle’s bill proposed state attorney general enforcement, while the House bill, led primarily by then-Rep. Zack Hudgins, included an additional private right of action.  

Consumer advocacy groups are firm in their support for a private right of action as part of a data privacy law. 

“Attorney general enforcement alone is not sufficient to enforce privacy laws, just because of limited resources and staff and funding that attorneys general across the country face,” said Williams, the EPIC counsel. “We need a stronger enforcement mechanism, like a private right of action, that would allow consumers to vindicate their own privacy rights and to take companies to court who have violated their privacy rights.” 

For some in the tech industry, a private right of action is seen as unnecessarily harsh, stymieing innovation while AG enforcement would have sufficiently guaranteed compliance. 

“I believe that the difference is, are you looking to get companies to comply and have clear enforcement or are you looking to punish?” said Rose Feliciano, TechNet executive director of policy for the Northwest United States. TechNet is a trade association that includes tech industry giants such as Amazon and Google.

Carlyle agreed, saying his efforts failed because the trial attorneys “were not enthusiastic about giving up a right of private action against big tech.” The insistence on letting individuals sue, he said, is a case of “perfect is the enemy of the good.” 

“It’s the ultimate representation of, ‘we can’t have any regulation, any policy framework, any guidelines, any protections whatsoever, unless it’s a grand slam home run for individual lawsuits,'” he said.

The private right of action has continued to hold up privacy legislation.

Rep. Kloba’s alternative, the People’s Privacy Act, ties enforcement to the state’s Consumer Protection Act, under which a plaintiff’s private action can seek damages, attorney’s fees, and treble damages capped at $25,000. Her bill treats all violations, including failure to comply with records keeping and timely responses to consumer queries, with the same severity.

This winter, Kloba may be open to changing that. She said she’s willing to consider separating enforcement rules so that some violations would be eligible for a private right of action and others would be subject to civil penalties enforced by the attorney general’s office. 

“Over the last eight years, various laws have been put in place in different states and we’ve seen them then go back and improve them over time,” she said, “and so I think it’s time to have that conversation.”

Job Listings on GeekWork

Find more jobs on GeekWork. Employers, post a job here.