This bill requires the Department of Veterans Affairs (VA) to display clear warnings on all public-facing VA websites and online tools about predatory practices. Specifically, it mandates that VA websites warn veterans not to share their account login credentials or bank account information (like usernames/passwords) with anyone. The law amends existing VA procedures to add this security warning as a standard message during website logins. The Chief Veterans Experience Officer will implement these changes, effective 180 days after the bill's enactment. The policy directly affects veterans using VA online services by strengthening protections against fraudulent agents targeting their personal information.
This bill protects personal information for Members of Congress, their immediate family members living in their households, and congressional staff identified as security threats. It requires government agencies and data brokers to remove specific sensitive details - including home addresses, phone numbers, school locations, and precise location data - from public records upon request. Agencies must act within 72 hours to remove such information, while data brokers are prohibited from selling or sharing covered data without consent. Exceptions include news reporting on public concerns and information voluntarily shared by the individual.
This bill codifies the Federal Trade Commission's existing "negative option" rule into law, making it permanently binding as of July 7, 2025. It requires companies to get explicit customer consent before automatically renewing subscriptions or services, rather than assuming consent through inaction. The rule directly affects consumers who use recurring payment services (like streaming, software, or memberships) and the businesses that offer them. This change prevents companies from charging customers for continued service without clear, affirmative action from the user to renew.
HR 2612, the DELETE Act, creates a system allowing individuals to request deletion of their personal data from data brokers through a single online portal. Data brokers must register annually with the FTC and implement a centralized deletion system, requiring them to delete personal information within 31 days of a request (with limited exceptions for legal requirements or research). The FTC enforces compliance through annual audits, mandatory reporting on deletion completion rates, and penalties for violations. This directly affects companies that collect personal information without a direct customer relationship and sell or share it with third parties.
This bill bans online platforms from conducting market research on children under 13 and requires parental permission for such research on teens aged 13-17. It applies to social media and apps that let users create profiles, share content, and use features like auto-play or notifications to keep users engaged. Platforms must stop collecting data about minors' behavior without consent, with enforcement led by the Federal Trade Commission. States can also sue platforms that violate these rules.
This bill requires the Comptroller General to conduct a security audit of Social Security Administration systems accessed by the U.S. DOGE Service or affiliated entities, focusing on vulnerabilities and potential violations of privacy laws like the Privacy Act of 1974. The audit must identify security flaws in software used by these entities and assess compliance with federal data privacy rules. The Comptroller General must submit a report to Congress and the Social Security Commissioner within one year, detailing findings and recommendations. The Social Security Commissioner then has 90 days to fix identified issues and report back to Congress on progress. The bill directly affects Social Security Administration systems handling sensitive data, primarily impacting seniors whose information is processed through these systems.
This bill prohibits companies from using automated systems to set prices or wages based on surveillance data about consumers or workers. It bans "surveillance-based price setting" (personalized pricing based on consumer tracking) and "surveillance-based wage setting" (using personal data to determine worker pay), with limited exceptions for standard discounts like student or senior citizen rates when properly disclosed. Companies must publish clear procedures about how their automated systems work, including how data is used and how consumers/workers can challenge inaccuracies. The Federal Trade Commission and Equal Employment Opportunity Commission will enforce the law, and individuals can file lawsuits to challenge violations. The bill also prohibits pre-dispute arbitration agreements that would prevent class action lawsuits.
This bill restricts access to Treasury payment systems (including the Bureau of the Fiscal Service) to only Treasury employees with a "fully successful" performance rating and at least one year of civil service, or contractors/outsiders with security clearances, required privacy/cybersecurity training, ethics agreements, and no conflicts of interest. It treats non-government users accessing these systems as government employees for ethics rules and defines specific actions (like stopping payments) as "personal and substantial participation" in government matters. The Treasury Inspector General must investigate any unauthorized access within 30 days and report to Congress, detailing the breach, security risks, and any halted payments. The bill directly affects Treasury staff, contractors, and any external entities accessing federal payment systems.
The REMOTE Act requires federal agencies to collect and retain data on teleworking employees' digital activity, including login frequency, connection duration, and data usage, for at least three years. Agencies must report this data in budget documents, comparing telework patterns to in-office work while protecting personal information. Managers must also document reasons for revoking telework privileges, including employee details and circumstances, to improve oversight of telework programs. This bill directly affects all Executive departments and their teleworking staff, including contract workers.
S 3097, the Health Information Privacy Reform Act, updates privacy rules for health data by requiring new federal regulations that harmonize with existing HIPAA and HITECH standards. It directly affects healthcare providers, insurers, and technology companies handling health information by mandating clearer privacy rules, stricter breach notifications, and new requirements for patient access to records. Key provisions include requiring written consent for selling health data, banning HIPAA protections for wellness app data (like step counts), and clarifying when health data can be shared without patient permission. The bill also establishes standardized rules for de-identifying health data and requires companies to notify patients if their health data is no longer protected under HIPAA. These changes aim to strengthen patient control over health information while aligning with modern data practices.