Reps. Davidson, Eshoo Introduce The Protecting Americans’ Data from Foreign Surveillance Act
June 14, 2023
Wyden, Lummis, Whitehouse, Hagerty, Heinrich and Rubio Introduce Bipartisan Senate Companion Bill to Protect Americans’ Data from Unfriendly Foreign Nations
Washington, D.C. – Reps. Warren Davidson (R-OH) and Anna Eshoo (D-CA) today introduced legislation to protect Americans’ data from being exploited by unfriendly foreign nations, and apply tough criminal and civil penalties to prevent employees of foreign corporations like TikTok from accessing U.S. data from abroad. The Protecting Americans’ Data from Foreign Surveillance Act of 2023 was also introduced in the Senate today by Sen. Ron Wyden and Sen. Cynthia Lummis, along with co-sponsors Sen. Sheldon Whitehouse, Sen. Bill Hagerty, Sen. Martin Heinrich, and Sen. Marco Rubio…
In April 2021, Director of National Intelligence Avril Haines warned of the threat posed by unrestricted commercial data sales: “There’s a concern about foreign adversaries getting commercially-acquired information as well, and [I] am absolutely committed to trying to do everything we can to reduce that possibility.”
The Protecting Americans’ Data From Foreign Surveillance Act of 2023 updates the previously introduced bill to include new protections against foreign-owned companies like TikTok accessing U.S. data from abroad, or sending data to unfriendly foreign nations. This bill:
- Directs the Secretary of Commerce, in consultation with other key agencies, to identify categories of personal data that, if exported, could harm U.S. national security.
- Directs the Secretary of Commerce to compile a list of low-risk countries, where data can be shared without restrictions, a list of high-risk countries where exports of sensitive data will be blocked, and create a system to issue licenses for data exports to nations not on either list. The risk status of countries will be determined based on:
- the adequacy and enforcement of the country’s privacy and export control laws
- the circumstances under which the foreign government can compel, coerce, or pay a person in that country to disclose personal data
- whether that foreign government has conducted hostile foreign intelligence operations against the United States.
- In addition to regulating bulk exports, the bill also regulates all exports of personal data by data brokers and firms like TikTok directly to restricted foreign governments, to parent companies in restricted foreign countries and to persons designated on the Bureau of Industry and Security’s Entity List.
- Exempts from the new export rules data encrypted with NIST-approved technology.
- Ensures the export rules do not apply to journalism and other First Amendment protected speech.
- Applies export control penalties to senior executives who knew or should have known that employees below them were directed to illegally export Americans’ personal data.
The bill has been endorsed by the Electronic Privacy Information Center, the R Street Institute and Justin Sherman, senior fellow and data brokerage research lead, and David Hoffman, professor of cybersecurity policy, Duke University Sanford School of Public Policy, experts on the sale and exploitation of Americans’ data.