The federal government's blueprint for online privacy has arrived, and it carries a blunt message for industry: voluntary restraint alone has not worked. In a report unveiled Thursday, the Commerce Department called for a new federal office dedicated to privacy policy and a baseline set of consumer protections it is calling a Privacy Bill of Rights - a framework that would govern how companies collect, store and use personal data gathered online.
The proposal, described by officials as a "green paper" rather than a finished policy, reflects growing unease in Washington over how little oversight currently exists for the vast troves of behavioral and personal data flowing through browsers, apps and cloud services. For consumers trying to manage their own exposure in the meantime, tools such as the BuyBestVPN service offer a practical way to limit tracking and encrypt web traffic while regulators sort out longer-term rules. That gap between individual self-protection and institutional oversight is precisely what the Commerce Department says it wants to close. the BuyBestVPN service
Why Self-Regulation Fell Short
Commerce Secretary Gary Locke was direct about the limits of the current approach, telling reporters that "self regulation without stronger enforcement is not enough." For more than a decade, companies handling consumer data online have operated under a patchwork of voluntary commitments, industry codes and case-by-case enforcement actions from the Federal Trade Commission. Critics, including Senate Commerce Committee Chairman Jay Rockefeller, argue that model has failed to keep pace with how aggressively data is now collected, shared and monetized.
The new Privacy Policy Office, as envisioned, would not replace the FTC's enforcement role but would instead serve as a convening body - bringing together companies, advocacy groups and regulators to hash out enforceable data-handling standards. Officials described this as a "bully pulpit" function: an office that can pressure industry toward compliance before heavier-handed regulation becomes necessary. The FTC would remain, as the report puts it, the lead enforcement agency, though the document pointedly asks whether that agency should gain expanded rulemaking authority if industry efforts stall.
Unresolved Questions and Pushback
Not everyone welcomed the proposal. Jeff Chester of the Center for Digital Democracy argued that housing a privacy office inside the Commerce Department - an agency whose mission includes promoting business interests - risks putting data collectors in charge of consumer protection. That tension between industry facilitation and consumer advocacy is likely to shape debate as the green paper moves toward a final version.
The report also leaves significant territory unmapped. It does not take a position on updating the Electronic Communications Privacy Act, the 1986 law that still determines how law enforcement accesses e-mail and other data stored on remote servers - despite acknowledging that stakeholders are pressing for reform. Nor does it explicitly endorse "Do Not Track" mechanisms, the browser-based opt-out system the FTC floated weeks earlier, leaving that question for the proposed office to help resolve. What is clear is that Washington now has two competing drafts on the table, and reconciling them will determine whether Americans eventually get an enforceable, uniform standard for how their data is used.