The TLDR Act requires major online platforms (excluding small businesses) to provide simplified, accessible summaries of their terms of service. These summaries must appear at the top of terms pages and include key details like categories of user data processed, legal liabilities (e.g., arbitration clauses), historical terms changes, recent data breaches, and estimated reading time. Platforms must also display interactive data flow diagrams showing how user data is shared with third parties and provide full terms in an interactive format. Enforcement will be handled by the Federal Trade Commission under existing FTC Act provisions, with states allowed to pursue cases affecting 1,000+ residents.
HR 7124 prohibits the use of specific mobile biometric apps (Mobile Fortify and Mobile Identify) outside U.S. ports of entry, restricting them solely for border identification. It requires Homeland Security to remove these apps from all non-Department devices, ban sharing with other agencies, and destroy U.S. citizens' captured biometric data (photos/fingerprints) within 12 hours of collection at ports of entry. The bill directly affects U.S. citizens whose biometric data is collected during border processing. Key mechanisms include mandatory app removal, remote deactivation of unauthorized installations, and strict data destruction timelines.
HR 6117, the Patient Device Data Access Act of 2025, requires medical device manufacturers to share patient-specific data recorded or transmitted by covered devices (like pacemakers or remote monitors) when a patient requests it. The bill mandates that manufacturers provide this data in understandable formats, publish device-specific data policies on their websites, and notify patients about how to access their information. It directly affects patients using covered devices and device manufacturers, while exempting data stored in inaccessible closed systems. The law focuses on enabling patient access to their own health data without requiring device redesigns or disclosing proprietary information.
HR 3693 prohibits all federal agencies from creating or maintaining databases that store biometric data used for verifying U.S. citizens' identities. The bill specifically bans databases containing information like fingerprints, facial recognition, or iris patterns collected through biometric identity verification systems. It applies directly to every federal agency, preventing them from using such technology for citizen identification purposes. This is a clear policy change restricting federal data collection practices related to biometric identification.
This bill prohibits grocery stores from charging unreasonably high prices (defined as 120% or more of a product’s average price over the prior six months) unless they prove the increase stems from uncontrollable costs like supply chain issues. It bans using personal data - such as facial recognition or purchase history - to set different prices for individual shoppers and requires clear signage about facial recognition use at store entrances. Large grocery stores (over 10,000 sq ft) must replace electronic shelf labels with physical price tags. The Federal Trade Commission enforces these rules, allowing states and consumers to seek $3,000 per violation in court for price gouging or data misuse.
The DELETE Act creates a federal system allowing individuals to request deletion of their personal data from data brokers. It requires data brokers (entities collecting personal information without a direct customer relationship) to register with the FTC annually and implement a centralized deletion system. Individuals can submit one request to delete all their data across registered brokers within 31 days, with limited exceptions for research or legal compliance. Data brokers must pay an annual fee (capped at 1% of system costs) to maintain the system, and the FTC enforces the rules under existing privacy laws. The law preempts conflicting state privacy laws but allows states to offer stronger protections.
This bill establishes a federal campaign to improve public understanding of artificial intelligence (AI) in daily life. It requires the Secretary of Commerce to create educational materials explaining AI's prevalence (e.g., in apps, recommendations, and services), how to detect AI-generated content like deepfakes, and how to protect personal data - with targeted outreach for vulnerable groups like seniors. The campaign must measure success through audience reach, engagement, and adoption of best practices, and will be updated annually to reflect new AI developments. The program runs for five years with no new funding, ending automatically after enactment.
This bill requires the Federal Trade Commission (FTC) to conduct a one-year study on neural data privacy and governance, including risks of behavioral manipulation and gaps in current laws. The study will analyze how neural data (from brain-monitoring devices) and related biometric data are collected, used, and transferred, with recommendations for future privacy protections. It directly affects the FTC (which must complete the study) and federal agencies (which will later receive guidance on using neural technology). The bill does not create new regulations but sets the stage for potential future policy changes based on the FTC's findings.
The INNOVATE Act reforms the Small Business Innovation Research (SBIR) and Small Business Technology Transfer (STTR) programs to better support small businesses developing innovative technologies. Key provisions include creating a new "Phase 1A" program to increase accessibility for new small business entrants (with proposals limited to 5 pages and awards capped at $40,000), requiring fixed-price contracts for SBIR/STTR awards, and strengthening security measures to protect intellectual property from foreign influence. The bill prohibits SBIR/STTR awards to businesses with certain agreements (like with NewsGuard or Disinformation Index), expands outreach to rural communities, and extends program authorization through 2028. It also streamlines administrative processes, improves data collection, and requires GAO reports on due diligence programs.
The DRIVER Act requires car manufacturers and fleet owners to give vehicle owners free, real-time access to their vehicle's data (like location, driving habits, and sensor information) through standard ports or wireless connections. Owners can control how this data is used or shared with third parties (except for foreign adversaries), delete stored data, and cannot be charged for access or decryption. Manufacturers and fleet owners must provide clear opt-out options before selling owner data and are banned from selling data to specific countries like China, Russia, or Iran. The Federal Trade Commission enforces these rules under existing laws, and states cannot create conflicting laws.