Latest

Federal privacy bill clears committee with bipartisan support

Abstract editorial illustration of classical columns and a pediment rendered in flat slate tones

A comprehensive federal privacy bill advanced out of committee with support from members of both parties, the furthest any general privacy framework has travelled in this Congress. Two provisions that have sunk previous attempts — pre-emption of state law and a private right of action — survived in modified form.

What the bill would do

The framework sets a data-minimisation duty: a covered entity may collect and retain personal data only where it is reasonably necessary for a defined purpose. That is a meaningful departure from the notice-and-consent model, under which almost any collection is lawful if it is disclosed somewhere in a policy nobody reads.

It also creates individual rights to access, correct, delete and port personal data; requires impact assessments for algorithms used in consequential decisions; and imposes heightened duties around sensitive categories including precise location, biometric identifiers and health information.

The two provisions that always decide it

  • Pre-emption: the bill would displace most state privacy statutes while preserving carve-outs for health, financial and biometric-specific laws. States with stronger regimes object; national businesses want one rulebook.
  • Private right of action: individuals could sue for certain violations after a notice-and-cure period, with a delayed effective date. Consumer groups call the limits too tight; industry groups call the right too broad.

The committee vote suggests the compromise is holding for now. Floor time is a different question, and the calendar is the constraint every witness mentioned.

What happens if it passes

Most obligations would take effect after a transition period measured in quarters, not weeks. The immediate work for organisations is inventory: knowing what personal data is held, why, on what legal basis and for how long. Firms that completed that exercise for state or international regimes are largely prepared; firms that have not will find it the longest part of the project.

Data minimisation is the provision with real operational teeth. Access and deletion rights are process; minimisation changes what you are allowed to collect in the first place.

Newsroom analysis

Small-business exemptions are the other detail worth reading closely. The text exempts entities below revenue and data-volume thresholds from most substantive obligations, but not from the duties around sensitive data. Where those thresholds land determines whether the framework covers a few thousand organisations or a few hundred thousand, and the committee adjusted them twice during markup.

Advertising technology is treated less directly than some witnesses wanted. The bill restricts targeted advertising to minors outright and requires an opt-out for everyone else, but it does not attempt to regulate the underlying real-time bidding infrastructure, which several members said would need separate legislation to address properly.

Enforcement would sit primarily with the federal consumer-protection regulator, with state attorneys general able to bring parallel actions. The bill authorises additional staffing, which is the detail that usually determines whether a framework is enforced in practice or only on paper.

The full committee text, the amendments considered and the recorded vote are published in the congressional record. Anyone assessing what this means for their organisation should read the definitions section first: in privacy law, the scope of “covered entity” and “personal data” decides more than the rights that follow.

Elena follows privacy legislation, product-safety regulators and the research that policy is meant to rest on. She files from committee rooms and, occasionally, from mission control livestreams.

3 articles View all


Leave a Reply

Your email address will not be published. Required fields are marked *