Marc Rotenberg, director of the Electronic Privacy Information Center, told lawmakers this week that the Federal Trade Commission's recent report on online privacy practices left out nearly everything Congress needed to know. Testifying on S. 809, the Online Privacy Protection Act of 1999, Rotenberg argued that years of industry self-policing have produced little more than cosmetic notices, while consumers remain largely unprotected against the collection and resale of their personal data.
EPIC, which helped lead the fight against the Clipper chip encryption scheme in the 1990s and published one of the earliest comprehensive studies of internet privacy policies, has spent years tracking how commercial websites handle personal information. Rotenberg's own 1997 survey of the hundred most visited sites found that only a small fraction posted any privacy policy at all, and none met a basic standard of fair information practice. For readers trying to understand how their data moves once it leaves a browser, it helps to know the same logic applies to the tools people now use to protect themselves; even something as technical as what a VPN config file contains reveals the kind of granular detail - servers, encryption parameters, authentication keys - that determines whether a privacy tool actually works as advertised, rather than merely claiming to.
That distinction between appearance and substance sits at the center of Rotenberg's critique. The FTC's report relied heavily on an industry-funded survey conducted by Georgetown University, commissioned by trade groups with a direct financial stake in avoiding legislation. The survey found that fewer than one in ten websites described even a rudimentary set of privacy principles, and offered no evidence that any site actually followed the policies it published. The FTC characterized this as progress. Rotenberg called it an admission of failure dressed up as reassurance.
Seal Programs Under Scrutiny
Much of the testimony focused on seal programs such as Truste, which certify participating websites as privacy-compliant in exchange for a fee and a pledge to follow disclosed practices. The FTC's report described these programs in terms lifted almost verbatim from their own marketing materials, according to Rotenberg, without independently verifying whether complaints were investigated or penalties ever imposed. He pointed to the widely reported case in which Microsoft was found to have "compromised consumer trust and privacy" through a tracking identifier scheme, yet Truste determined no violation of its licensing agreement had occurred. No audit followed. No penalty was imposed beyond a written rebuke.
Rotenberg also noted that a federal agency had quietly abandoned plans to adopt a Truste seal after questions arose about whether the program complied with the Privacy Act, and that Truste had awarded its seal to a company later found selling user income and occupation data to marketers in direct violation of its own stated policy. These episodes, he argued, illustrate a structural flaw: voluntary certification programs are financially dependent on the companies they are meant to police.
Why Legislation Matters Beyond American Borders
The stakes extend past domestic consumer protection. European governments have already rejected the American self-regulatory model as inadequate under their own data protection framework, a development the FTC's report did not mention despite its direct bearing on transatlantic electronic commerce. Rotenberg suggested that a strengthened version of S. 809 could resolve this standoff, giving European regulators grounds to deem American protections sufficient, at least for internet-based services. Without that legal foundation, he warned, disputes over data transfers could disrupt the digital economy far more broadly than any single privacy complaint.
He closed by urging the Committee to look beyond this one bill, proposing a dedicated federal privacy office, continued investment in privacy-enhancing technologies, and sustained enforcement of fair information practices already recognized internationally. The alternative, he suggested, is an internet where disclosure replaces protection and consumers are left to decipher fine print instead of relying on enforceable rights.