That the Senate encourages entities covered by the General Data Protection Regulation of the European Union (referred to in this resolving clause as the “GDPR”), including edge providers, broadband providers, and data brokers—
to provide the people of the United States with the privacy protections included in the GDPR in a manner consistent with existing laws and rights in the United States, including the First Amendment; and
to include in the protections described in paragraph (1)—
the requirement that—
data processors (as described in the GDPR) have a legal basis for processing the data of users;
opt-in, freely given, specific, informed, and unambiguous consent from users be a primary legal basis for purposes of clause (i);
data processors design their systems in a way that—
minimizes the processing of data to only what is necessary for the specific purpose stated to the individual; and
by default, protects personal information from being used for other purposes;
entities processing the data of children institute special protections, particularly with reference to the use of the data of children for marketing purposes;
data processors and controllers (as described in the GDPR) ensure compliance with relevant privacy rules; and
data processors implement appropriate oversight over third party data processors; and
the right of an individual—
to revoke consent for data processing at any time;
to not be subject to automated decisionmaking, including profiling, without human intervention if the decisionmaking has legal or otherwise significant effects on the individual;
to know which entities have access to the data of the individual and how that data is being used;
to correct the data of the individual if it is inaccurate or incomplete; and
to obtain and reuse the data of the individual for the purposes of the individual across other services.