Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Washington state pioneered a privacy model for the nation — when will it finally pass the law at home?

24 August 2026 at 13:07
Rep. Shelley Kloba, D-Kirkland, has introduced a privacy bill in the Legislature every year since 2021, none of which has reached the House floor due to disagreements over whether consumers should be able to sue. (Washington House Democrats Photo)

More than 20 states have now passed the “Washington model” of privacy legislation. Washington state hasn’t. 

In the years since then-state Sen. Reuven Carlyle introduced the Washington State Privacy Act in 2019, the blueprint has been adopted across the country, mandating that companies get the consent of consumers before collecting sensitive personal data, and providing consumers with the right to correct and delete their details in those databases.

In its home state, the bill stalled in negotiations between the House and Senate two years in a row. Every year since, a comprehensive privacy bill has been introduced in the Washington state Legislature but has failed to pass. 

Washington state Attorney General Nick Brown released his office’s first data privacy report Aug. 14, calling on lawmakers to pass a privacy law that would limit how much personal information companies can collect and keep in the first place.

But that proposal will face the same hurdle that has blocked efforts to pass a state privacy law for seven years: a fight over whether consumers should be able to sue companies that violate it.

Washington AG Nick Brown

“The attorney general supports greater data privacy protections for Washingtonians,” said Mike Faulk, a spokesperson for the AG’s office. “In our experience, this has proven to be a difficult subject for the Legislature to build consensus on.”

Experts say the stakes are rising as AI systems train on personal data that often falls outside Washington’s existing privacy protections. Without a baseline privacy law, they say, lawmakers also have less to build on when they try to regulate AI itself. 

Rethinking privacy

AI has rendered some parts of the Washington model moot, while making others more necessary than ever, according to policy experts. 

As states have begun to pass the first AI regulations, one of the highest priorities has been the regulation of AI-based high-risk decisions.

In Washington, for example, the state Legislature passed the Prior Authorization Transparency Act, which bars health insurers from using AI as the only basis to deny, delay or modify care. Washington state lawmakers also considered a bill to regulate the use of AI to make decisions of financial, educational, or legal consequence.

This is proving to be a much easier lift in states that passed the “Washington model,” often years before the current AI craze. That’s because Carlyle’s bill happened to include what’s now known as an automated decision-making technology (ADMT) opt-out clause, which granted residents the right to opt out of automated profiling when used for “legal or similarly significant effects.” 

Algorithmic wage and price determinations, as well as AI-based healthcare and employment technologies, could be regulated under the pre-existing privacy act, or by tweaking those laws.

“The states that have passed automated decision making laws have done so on top of existing privacy laws,” said Cobun Zweifel-Keegan, a managing director at the International Association of Privacy Professionals (IAPP). “There’s already restrictions, or at least the beginnings of restrictions, on automated decision making baked into these privacy laws. It’s a natural model to build on top of.”

Meanwhile, AI has made it more dangerous to go without a privacy law, because an absence of privacy legislation means more personal data online for AI models to access, said Kara Williams, counsel at the Electronic Privacy Information Center.

Williams said data minimization could prevent or limit companies from repurposing personal data to train AI systems. 

“It goes back to using the data for the purpose you collected it for,” Williams said. “Almost all of the data that companies have used to train AI systems or develop the algorithms that led to this moment were not collected for the purpose of training AI systems.”

Data minimization requires companies to restrict the collection and use of customer data to the service the customer requested. That often precludes secondary uses like selling it to a data broker.

The Washington attorney general’s privacy report also endorsed a data minimization standard, which the original Washington model does not include.

Carlyle said he might have written one in, if he were drafting the bill today.

“We live in an AI world with a giant vacuum in the sky, sucking up every ounce of data that exists on a person,” Carlyle said. “So I think the concept [of data minimization] makes some sense.” 

Meanwhile, experts say AI makes some elements of the Washington model irrelevant. 

Zweifel-Keegan of IAPP said those elements include the right to control, correct, and delete personal data, which was the bread and butter of Carlyle’s bill. Because LLMs are a weighted map of associated words, there is no straightforward way to selectively delete or change information once a model has been trained.  

“That’s just fundamentally how LLMs work. They’re not a table where you can go to my name and see all the other records that are associated with me,” Zweifel-Keegan said. “You can’t go in and selectively delete information.”

While states around the country that have passed the Washington model are now seeking to revise its provisions to meet the AI moment, Washington state has no comprehensive privacy law to start with.

“AI is making us rethink some of our foundational expectations of what a privacy law does,” Zweifel-Keegan said. “Washington could be the place where that happens.”

The story of the “Washington model”

In 2019, when now-retired State Sen. Carlyle introduced the Washington State Privacy Act, it passed the Senate 46-1 before dying in the House. One year later, it passed both chambers but died after a long and heated fight in conference.

Some say the bill didn’t deserve to pass after being “rewritten” by tech lobbyists. Others say the lawmakers who opposed the bill let the perfect be the enemy of the good. 

The original bill was based on an opt-out framework, also called “notice and consent,” which required a platform to present a privacy policy to users who consent to the collection of their data by continuing to use the platform. The bill’s sole enforcement mechanism was the state attorney general, and did not offer a private right of action for individuals to sue companies that violated the proposed rules. 

In 2019, Carlyle was focused on establishing a baseline notion of consumer rights — one that could be revised later, as other states ultimately did.

“At that time we didn’t have a direct understanding that consumers have a right to correct or delete their personal data, we didn’t have an understanding of what opt out meant for advertising, or an understanding of data brokers and the role that they play,” Carlyle said.  

His bill also established special protections for sensitive data and frameworks to hold corporations accountable for complying with transparency and disclosure requirements. 

“Those were pretty novel pillars that didn’t exist,” Carlyle said. “That’s why it had a big effect on other state laws.” 

By March 2021, Virginia had passed a privacy law closely modeled off of Carlyle’s template, and over the next few years, more than 20 other states did, too.

In Washington, meanwhile, no progress was made. After Microsoft endorsed the Senate bill in 2019, consumer advocacy groups and some state lawmakers said that the tech lobby’s influence had gone too far. The state House countered with a stronger privacy bill, premised on opt-in data collection frameworks and enforced by a private right of action.

Both the 2019 and 2020 legislative sessions ended in failed negotiations between the state Senate and House over their competing privacy laws. Every year since 2021, Rep. Shelley Kloba has introduced a bill that preserves the House’s stronger language. It has yet to make it to the House floor. 

A potential compromise

The sticking point for Washington negotiators in 2019 and 2020 was the enforcement mechanism. Carlyle’s bill proposed state attorney general enforcement, while the House bill, led primarily by then-Rep. Zack Hudgins, included an additional private right of action.  

Consumer advocacy groups are firm in their support for a private right of action as part of a data privacy law. 

“Attorney general enforcement alone is not sufficient to enforce privacy laws, just because of limited resources and staff and funding that attorneys general across the country face,” said Williams, the EPIC counsel. “We need a stronger enforcement mechanism, like a private right of action, that would allow consumers to vindicate their own privacy rights and to take companies to court who have violated their privacy rights.” 

For some in the tech industry, a private right of action is seen as unnecessarily harsh, stymieing innovation while AG enforcement would have sufficiently guaranteed compliance. 

“I believe that the difference is, are you looking to get companies to comply and have clear enforcement or are you looking to punish?” said Rose Feliciano, TechNet executive director of policy for the Northwest United States. TechNet is a trade association that includes tech industry giants such as Amazon and Google.

Carlyle agreed, saying his efforts failed because the trial attorneys “were not enthusiastic about giving up a right of private action against big tech.” The insistence on letting individuals sue, he said, is a case of “perfect is the enemy of the good.” 

“It’s the ultimate representation of, ‘we can’t have any regulation, any policy framework, any guidelines, any protections whatsoever, unless it’s a grand slam home run for individual lawsuits,'” he said.

The private right of action has continued to hold up privacy legislation.

Rep. Kloba’s alternative, the People’s Privacy Act, ties enforcement to the state’s Consumer Protection Act, under which a plaintiff’s private action can seek damages, attorney’s fees, and treble damages capped at $25,000. Her bill treats all violations, including failure to comply with records keeping and timely responses to consumer queries, with the same severity.

This winter, Kloba may be open to changing that. She said she’s willing to consider separating enforcement rules so that some violations would be eligible for a private right of action and others would be subject to civil penalties enforced by the attorney general’s office. 

“Over the last eight years, various laws have been put in place in different states and we’ve seen them then go back and improve them over time,” she said, “and so I think it’s time to have that conversation.”

Seattle weighs ban on ‘surveillance pricing’ at grocery stores, but will it save shoppers money?

20 August 2026 at 13:04
A sale price at a Seattle grocery store. A proposed city ordinance would bar grocers from setting different prices for individual shoppers based on their personal data. (GeekWire Photo / Todd Bishop)

Seattle is in the final stages of becoming the first city in the country to ban so-called “surveillance pricing” in grocery stores. Experts disagree about whether it will actually save consumers money. 

The proposed Fair Pricing and Transparency Ordinance would ban grocers from setting variable prices for individual consumers based on their personal data, both in-store and online.

This was one of Mayor Katie Wilson’s biggest campaign promises, and it comes after Maryland, Connecticut, and New Jersey passed the first state-level surveillance pricing regulations this spring. The City Council will hold a public meeting this Friday, Aug. 21, to hear amendments to the proposed ordinance.

The bill has received fierce criticism from tech and grocery industry representatives who say the ordinance would prohibit personalized discounts that benefit customers.

A City Council Central Staff Memo, which was first circulated last Thursday and will be presented at Friday’s meeting, raises some of those same concerns. Despite opposition from one councilmember and requests for major amendments from another, the bill seems well on its way to getting the requisite votes.

Impact on consumers

At the heart of the controversy is a disagreement about whether personalized pricing harms or benefits consumers. 

The use of algorithmic pricing by Instacart last December met with so much backlash that the platform stopped using it. A 2025 Consumer Reports investigation had found that Instacart varied the total cost of the same cart at a Seattle-area Safeway by roughly $10, with only 8% of shoppers getting the lowest price. Those were randomized experiments to test price sensitivity rather than prices set from individual profiles, and Instacart stopped offering the technology behind them in December after the investigation was published. 

In brick-and-mortar stores, electronic shelf labels have not yet been shown to offer individualized list prices. Instead, grocers such as Krogers and Albertsons personalize the effective price through the distribution of individualized digital coupons to loyalty club members. 

The federal government is moving to regulate those. The FTC on Wednesday proposed an enforcement policy that would treat undisclosed personalized pricing, including discounts, as a violation of federal law, and opened it for public comment. 

Amanda Dalton, who represents the Northwest Grocery Retail Association, said personalized discounts make groceries cheaper overall. Her organization was involved in drafting the bill but ultimately testified against it out of concern that it would prohibit those deals.  

“We support what the council is trying to do as it relates to using personal information to drive higher prices,” Dalton told GeekWire. “Where we diverge is the need and ability to continue what we call pro-consumer common practices that are happening in grocery stores every day, like discount programs, coupons, fuel rewards, student discounts, and volume based deals.” 

Contrary to messaging from some industry advocates, the current bill does allow some discounts. Loyalty programs, volume-based discounts, third-party manufacturer coupons, and discounts based on a broad identity, such as students or seniors, are all explicitly permitted. 

Industry groups predict, however, that the liability exposure will make it too risky for stores to continue to offer those deals.

“There will be hoops that companies need to jump through to deliver those discounts, and a lot of legal exposure to liability,” Drew Ambrogi, a policy manager at Chamber of Progress, said.

As a solution, industry groups including Chamber of Progress, TechNet, and NWGRA have suggested that the bill be amended so that algorithmic pricing is prohibited for raising prices but is permitted for lowering them.

Advocates on the other side worry that would gut the bill entirely. 

“That creates an incentive for retailers to inflate the list price and offer personalized discounts to each person based on their individual willingness to pay,” said Grace Gedye, a policy analyst for Consumer Reports. 

UFCW 3000, which represents workers at major grocery chains, has also endorsed the bill, opposing individualized pricing regardless of whether it raises or lowers prices. 

“It’s easy to figure out when your neighbors are getting a different price,” said union member J’Nee DeLancey, who works at Ballard Town and Country. “We grocery workers will have to handle the fallout of angry, confused customers.”

Loyalty programs

One Kroger and Albertsons-funded group called Protect Seattle Savings has claimed, online and in mass text blasts to Seattleites, that the proposed ordinance “puts your loyalty rewards program on the chopping block” — a claim that is not backed up by the bill itself. 

In fact, the bill does exactly the opposite: it includes a carve-out for loyalty programs that allows retailers to use a customer’s purchase history to determine pricing so long as that customer has opted into a loyalty program and the criteria for the discount are disclosed. 

That exception has drawn criticism from the NWGRA, which warns it may unintentionally penalize consumers who can’t afford to join the loyalty program. On DoorDash, for example, users have to pay $10 a month to be a “DashPass” loyalty rewards member. If DoorDash is only allowed to offer discounts to those members, then the bill may unintentionally make orders more affordable only for customers who can afford the membership fee.

NWGRA is calling on the city to expand the carve-out so that a retailer can offer purchase history-based discounts to non-loyalty members as well. The Central Staff Memo circulated last week highlighted the push from industry to preserve the use of purchase history for all customers, but wrote that it is “difficult to ascertain whether the limitations on personalized discounts would result in a net cost increase for consumers,” since consumer data could be used to raise prices as well as lower them. 

Input from industry

Supporters of the regulation say they’ve already made significant compromises with industry. Councilmember Alexis Mercedes Rinck, who sponsored the bill, initially planned to ban electronic shelf labels, as New Jersey did, but dropped the provision after grocery workers said the new labels made their jobs easier. Now, the Seattle bill simply prohibits a store from using electronic shelf labels to display a price that has been determined using algorithmic pricing.

Another compromise was the narrowing of the regulation to exempt small grocers and convenience stores. The bill will apply only to grocers with 20 or more retail locations globally, as well as mixed-use retailers that sell groceries, like Costco; and delivery services, like Instacart and DoorDash. 

Councilmember Rinck said the bill is the product of engagement with retailers, and that she hopes to keep them on board.

“We were at the table with grocers, and the proposal changed in response to their business concerns,” Rinck said. “We will be watching what folks in industry have to say about the legislation and amendments this Friday.” 

Private right of action

The last major sticking point is the proposed enforcement mechanism, which industry representatives criticize for being overly aggressive. 

The bill splits enforcement between the City Attorney’s Office and consumers. Both avenues allow civil penalties of up to $3,000 for a first violation and $10,000 for subsequent offenses, plus damages. The private right of action can only be pursued against stores with 25 or more locations instate, and civil penalties for a single collective action are capped at $1 million.

“The private right of action will have a chilling effect on the offering of discounts altogether,” Ambrogi said. “What is not explicitly banned by the bill may be presumptively banned because a business’s compliance department doesn’t think it’s worth exposing them to ambiguity.”

Dalton also opposes the private right of action for being too broad. Customers can seek damages for being offered an individual price, even if they did not buy the product in question. 

“Our argument has been for clarity and simplicity,” Dalton said. “Now you’ve got a $1 million class action threat on every single product in your grocery cart.”

Consumer advocacy groups say the expansive private right of action is what gives the bill teeth, pointing to the similar clause in New Jersey’s surveillance pricing ban.

“If it was only public enforcement, there are practical limits on how frequent enforcement could be,” Gedye said. “Compliance might not be as rigorous as it would be if any consumer who thinks they’ve really been harmed by this practice can start looking into it and potentially initiate a case.” 

City Attorney enforcement

The Central Staff Memo warned that the City Attorney’s Office may not be up for enforcing this law, either. Stores will be required to retain records on prices and discounts for three years. The bill charges the CAO with the task of auditing stores and ensuring compliance with the record keeping requirements. 

Unlike the law that passed last year regulating algorithmic rent-fixing in Seattle, this bill does not enlist a city agency to help the CAO with enforcement. The regulation also applies to a far larger potential pool of complainants, and it does not arrange for additional funding in its fiscal note. 

“The CAO may have to develop new systems and procedures to handle intakes directly and may not have capacity to conduct thorough investigations that would involve analyzing large volumes of data,” the memo said. 

In response, a CAO spokesperson told GeekWire their office does not share the memo’s concerns  and is in “full support” of the proposed ordinance.

“The City expects that grocery retailers will voluntarily comply with the legislation once it’s adopted, which includes a 1-year phase-in while the City will inform and educate retailers about the bill’s provisions,” a CAO spokesperson told GeekWire. “We anticipate the expected level of work can be managed using existing resources and funds recovered through litigation.”

The council will vote on the bill in September after they return from recess. But first, Friday’s committee meeting will reveal which councilmembers are in support of the legislation and what kinds of amendments will be considered. 

Councilmember Rinck said she “feels good” about getting the bill passed, and looks forward to making Seattle the first city to regulate algorithmic pricing on groceries. 

“Government gets a bad rap for being reactive,” Rinck said. “This is an opportunity for us to be proactive in trying to regulate this kind of practice before it really takes hold in our city.”

❌
❌