On the first anniversary of GDPR, Microsoft calls for a similar privacy law in the US that puts the burden on the companies that collect and use sensitive data
Microsoft's idea of a US privacy law would make it easier for people to protect their data. — The company's corporate vice president …
Context & Ripple Effects
Microsoft's GDPR-anniversary pitch lands after years of the company being on the wrong side of European privacy enforcement — including a French regulator's notice over Windows 10 data collection in 2016 — and after it endorsed the new EU-U.S. data transfer pact that same spring. It has also fought separately for transparency rights, suing the Justice Department for the right to tell customers about government data requests.
The call also cuts against the industry's own lobbying posture: as the New York Times reported months earlier, tech companies were pushing a federal privacy law designed to overrule California's statute and preserve wide leeway over personal data. Microsoft's burden-on-collectors framing is a notably different template.
First-order effects
- Microsoft's corporate vice president is publicly staking the company to a US law modeled on GDPR's obligations, meaning any bill built on this blueprint would directly raise compliance costs for every company collecting sensitive American consumer data.
Second-order effects
- Rival tech firms backing the weaker preemption play now face pressure to explain why their preferred federal standard shields them from state-level liability while Microsoft endorses collector-side burdens — and Microsoft can bank goodwill by honoring stricter regimes nationwide, as it later did with California's privacy law across the US.
Third-order effects
- If GDPR-style burden-shifting becomes the US template, privacy compliance hardens into a scale advantage: large cloud and platform vendors absorb the overhead more easily than smaller ad-dependent firms, and Microsoft's state-by-state push — recycling its twice-failed Washington Privacy Act into bills in Arizona, Hawaii, Illinois, and Minnesota (per Protocol) — shows the fallback strategy when federal legislation stalls.
The trend: US privacy regulation is converging toward the GDPR model of placing enforcement burdens on data collectors, with large platforms increasingly championing the rules they once resisted.