Why the Supreme Court’s Strike Down of the Chevron Case Should Matter to You

Data Privacy and Security Laws: Why the Supreme Court’s Strike Down of the Chevron Case Should Matter to You

by Stephen Toland, Shareholder/Attorney, Data Privacy & Security, CIPP/US

The U.S. Supreme Court’s Loper Bright decision striking down forty years of precedent under the Chevron doctrine in late June left federal agencies, such as the Federal Trade Commission (FTC), reeling with questions about how the ruling will impact their ability to regulate data privacy and security laws under authorizing statutes. Why? After Loper Bright, federal agency interpretations of silent or ambiguous administrative provisions will not be given weight or deference.

Under the Chevron doctrine, if Congress had not directly addressed a question at the center of a dispute, a court was required to uphold the agency’s interpretation of any silent or ambiguous provision, so long as it was reasonable. This is the deference to agency interpretation.

The Chevron doctrine, which has been cited by federal courts more than 18,000 times since 1984, is now obsolete, and courts of law – not agencies – will have the final say on silent or ambiguous provisions in federal regulations. While it remains to be seen which rules will be the focus of future challenges, we can expect an increase in industry and advocacy groups’ challenges to broad agency rules in the data privacy and security space.

Specifically, business leaders can expect more litigation around defining and implementing “appropriate [technical and security] measures,” around cyber security practices that are purposefully broad, and lengthier processes to develop and submit allegations. On the flip side, this new ruling gives companies an opportunity to challenge an agency’s interpretation in court.

 

Stepping Back for Context

While the Loper Bright decision will impact all federal agencies, the federal agency facing significant impact will be the FTC. Historically, the FTC has held substantial authority in the interpretation of laws related to the collection, sharing and protection of personal information.

For its competition mission, the FTC enforces the Sherman Act and Clayton Act. For its consumer protection mission, the FTC enforces statutes such as the Children’s Online Privacy Protection Act (COPPA), and the Fair Credit Reporting Act.

For example, under COPPA, the FTC proposed significant changes, including expansion of the definition of “personal information” to include biometric identifiers and codification of the FTC’s school consent exception policy.  While the statute allows the FTC to expand the definition of personal information, it is limited to identifiers that “permit the physical or online contacting of a specific individual.” Before Loper Bright, courts likely would have deferred to the FTC’s interpretations under Chevron, but courts now will likely determine independently whether biometric identifiers permit physical or online contact with a specific individual.

Another likely challenge could be to recent FTC revisions under the HI-TECH Act.  Recently, the FTC used its authority under the HI-TECH Act to revise its Health Breach Notification Rule. Under the Act, Congress extended broad authorization to prescribe rules that would cover “personal health records.” The FTC’s revised Rule purports to cover virtually all health apps and connected devices. Without Chevron deference, however, companies may now wish to challenge the Rule.

Similarly, the FTC and corresponding federal agencies, will likely feel Loper Bright’s impact under the Gramm-Leach-Bliley Act (GLBA). GLBA charges agency regulators with creating standards relating to the security and confidentiality of customer records and to protect against anticipated threats or hazards. Since 2022, GLBA regulators expanded their rules with an intentionally broad range of cyber incident reporting and security requirements. This broad and prescriptive approach to data security requirements from ambiguous statutes are more prone to being struck down or modified by courts after the Loper Bright decision.

 

Takeaways for Business Leaders

The strategic approach a company takes as it develops a comprehensive privacy program often requires the company to assess the risks associated with the development of each component of the program. This includes interpreting applicable data protection and security laws that are high-level in nature and generally less prescriptive to assess what that company has to do to achieve better compliance hygiene. This recent Supreme Court ruling should undoubtedly be taken into consideration when assessing those risks.

Moreover, we can expect states to take a more active role in legislative activity and enforcement activities as it relates to data privacy and security interpretations. For instance, many state court systems previously adopted Chevron-like deference in adjudicating challenges to state agency actions. It remains to be seen whether such states will retain their state Chevron counterparts or reach a decision rejecting deference to state agencies.

Furthermore, this may also put states like California and Texas in more of a leadership role on national policy making as federal activity is constrained. In addition, this likely will create greater strain in the red state/blue state dichotomy in policymaking.

While Loper Bright could lead to temporary instability in the regulatory landscape, in time it should lead to greater stability for companies subject to multiple regulatory regimes, as courts will likely give weight to judicial precedent interpreting similar statutory language, and agencies will face greater difficulty changing their interpretations of statutes from administration to administration.

LinkedIn
Previous
Next

Related Posts

Cory D. Eden discusses how artificial intelligence is transforming legal practice by improving efficiency while preserving attorney judgment and strategic legal advice.
AI Isn’t Replacing Lawyers. It’s Redefining Where Lawyers Deliver Value
Read More
Common-Contractual-Clauses-From-a-Litigation-Perspective
Common Contractual Clauses From a Litigation Perspective
Read More
image
Discovery, Doctrine, and Decision-Makers: Civil vs. Common Law in Action
Read More