Context: Questions from the Washington Privacy Act Hearing
On January 15, 2020, the Washington State Legislature's Senate Environment, Energy & Technology Committee held its first public hearing on the reintroduced Washington Privacy Act. The bill has bipartisan support and praise from many privacy advocates, but critics argue it doesn't adequately protect consumers.
These questions arise when legal teams evaluate state privacy bills, whether you're assessing Washington's approach or comparing it to frameworks in California, Virginia, or Colorado. They're the questions your general counsel will consider when deciding whether to prepare for a new state law or lobby for changes before it passes.
Q1: If a bill has bipartisan support, doesn't that mean it's stronger for consumers?
Not necessarily. Bipartisan support often signals political viability, but it can also mean the bill has been negotiated down to the lowest common denominator. When both parties agree, it's worth asking what compromises were made.
In Washington's case, the bill gained bipartisan backing, yet critics like Jevan Hutson and Jennifer Lee testified that it fails to protect consumers in multiple ways. The specific gaps they identified matter more than the vote count. Look at enforcement mechanisms, private rights of action, and whether the attorney general has adequate resources and authority. A bill with unanimous support but no enforcement teeth won't change how companies handle your data.
When evaluating any state privacy bill, check whether bipartisan support came at the cost of meaningful enforcement. A law that everyone can agree on might be one that doesn't require anyone to change their practices.
Q2: How should we compare the Washington Privacy Act to CCPA or GDPR?
Start with enforcement structure and consumer rights, not just the list of principles. GDPR gives supervisory authorities independent enforcement power and imposes fines up to 4% of global revenue. CCPA created a private right of action for data breaches and gave the California Attorney General rulemaking authority.
For Washington, ask: Does the bill create a private right of action? Can the attorney general issue regulations, or is enforcement limited to statutory text? What's the penalty structure, and is it tied to revenue or a flat fee? These structural differences determine whether a law changes behavior or just adds disclosure requirements.
Also, examine scope. CCPA applies to businesses meeting revenue or data-volume thresholds. GDPR applies to any controller or processor handling EU residents' data. Washington's thresholds and definitions will determine which of your vendors and partners fall under the law.
Don't compare privacy bills like a checklist of rights (access, deletion, opt-out). Compare them on whether those rights are enforceable and whether the definitions create loopholes. A right to deletion means nothing if there's no penalty for ignoring the request.
Q3: What specific protections are critics saying Washington's bill is missing?
Critics like Hutson and Lee testified the bill "fails to protect consumers in a number of ways," but specifics weren't detailed in the source article. However, typical criticisms of state bills include weak enforcement (no private right of action, underfunded attorney general office), broad exemptions (carve-outs for specific industries or data types), vague definitions (what counts as "sensitive data" or "sale"), and missing rights (no data minimization requirement, no limits on automated decision-making).
If you're evaluating the Washington Privacy Act for your organization, get the full text and compare it to CCPA and VCDPA on these dimensions. The critics' concerns likely cluster around enforcement gaps and industry exemptions.
Q4: Should we prepare for Washington's law even though it failed last year?
Yes, but calibrate your investment to the bill's momentum. The reintroduced version gained a public hearing and bipartisan support, suggesting it has a better chance than the previous attempt. However, "better chance" doesn't mean "certain passage."
Track the bill's progress through committee and floor votes. If it clears the Senate committee, assign someone to monitor amendments. State privacy bills often get altered in the amendment process, and you don't want to build compliance infrastructure for a version of the law that never gets enacted.
In the meantime, use Washington's bill as a planning tool. If your organization operates in California, Colorado, Virginia, and Connecticut, you're already managing multiple state privacy regimes. Adding Washington to your compliance matrix now (even as a draft scenario) helps you identify common requirements and state-specific gaps. You'll be ready to move quickly if the bill passes, and you won't have wasted effort because the analysis improves your understanding of state privacy law trends.
Q5: What does "comprehensive privacy reform" actually mean in the state context?
It depends on who's using the term. For lawmakers, "comprehensive" often means the bill covers multiple data practices (collection, use, disclosure) and grants multiple consumer rights (access, deletion, correction). For privacy advocates, "comprehensive" means the law creates meaningful accountability, not just disclosure obligations.
A comprehensive state privacy law should include: clear definitions of personal data and sensitive data, data minimization requirements, purpose limitations, consumer rights with enforcement mechanisms, and penalties that scale with harm or revenue. It should apply broadly (not just to the largest companies) and limit exemptions to genuinely incompatible use cases (like HIPAA-covered entities or GLBA-regulated financial data).
When you see "comprehensive privacy reform" in a bill's marketing, read the exemptions section. A law that exempts employee data, B2B data, and pseudonymous data isn't comprehensive, it's selective. A law that grants rights but provides no enforcement mechanism isn't reform, it's theater.
Q6: If Washington passes this bill, should we expect other states to copy it?
State privacy laws tend to cluster around models, but they don't copy wholesale. California's CCPA influenced Virginia's VCDPA and Colorado's CPA, but each state made different choices on thresholds, exemptions, and enforcement. If Washington passes a privacy law, other states will study it, but they'll adapt it to their political and economic contexts.
Watch for the bill's treatment of specific issues: Does it regulate automated decision-making? How does it define "sale" versus "sharing"? What does it require for sensitive data? These choices will influence later bills, especially in states with similar political compositions or industry lobbies.
For your compliance planning, don't assume Washington's approach will become the standard. Instead, track the divergence. If Washington allows opt-out for targeted advertising but Colorado requires opt-in, you'll need state-specific consent flows. If Washington's definition of "sensitive data" includes geolocation but Virginia's doesn't, your data classification needs to account for that variation.
Where to Go for More
Monitor the Washington State Legislature's bill tracking system for the Washington Privacy Act's status and amendments. Read the full text, not just the summary. Compare it to enacted laws in California, Virginia, and Colorado using a side-by-side matrix that covers scope, definitions, consumer rights, and enforcement.
If you're building a multi-state privacy program, focus on the structural differences (enforcement, thresholds, exemptions) rather than the surface similarities (access rights, deletion rights). The devil isn't in the principles, it's in the definitions and penalties.




