The Auto Data Privacy and Autonomy Act requires automakers to obtain explicit, written consent from vehicle owners before accessing or sharing their vehicle data (including location and personal information), except for safety improvements or emergencies. It prohibits selling personal data to specific foreign governments (like China, Russia, and North Korea) and mandates that owners have free, real-time access to all vehicle data - without fees, proprietary tools, or restrictions - via open interfaces to delete data or adjust settings. The Federal Trade Commission must report to Congress within 180 days on how automakers handle data, including cybersecurity risks and foreign data sharing. The law takes effect three months after enactment and is enforced under existing FTC authority.
This bill modernizes the 1974 Privacy Act by updating definitions of key terms like "personally identifiable information" and "system of records" to better reflect current data practices. It strengthens protections by requiring agencies to use only the minimum necessary personal data for disclosures, disclose legal authorities for data uses, and prohibit adverse actions based on automated matching. The bill adds civil remedies including minimum $1,000 damages for violations and increases criminal penalties for misuse (e.g., up to $250,000 fines or 10 years imprisonment for commercial misuse). These changes directly affect federal agencies handling personal data and apply to all data collection, use, and disclosure activities governed by the Privacy Act.
The Platform Accountability and Transparency Act creates a structured process for researchers to access certain platform data for research while protecting user privacy. Platforms with at least 50 million US monthly users must provide specific data to qualified researchers (affiliated with US universities or nonprofits) whose projects are approved by the National Science Foundation and Federal Trade Commission. The bill requires platforms to publicly disclose information about advertising, algorithms, content moderation, and highly disseminated content, while establishing strict privacy and cybersecurity safeguards for the data. It also creates legal protections for platforms and researchers who comply with the law's requirements, ensuring researchers cannot be sued for accessing data through this process.
The MY DATA Act of 2025 prohibits businesses (referred to as "covered entities") from blocking consumers from using de-identified data (information that cannot be traced back to a person) or cloaked data (unique identifiers that hide a person's identity while enabling communication). It requires covered entities to allow consumers to access or control their data, with enforcement handled by the Federal Trade Commission as an unfair or deceptive practice under existing law. The bill excludes government agencies and specific nonprofits (like those serving missing children cases) from these requirements, focusing on commercial entities that collect personal information.
This bill, HR 3916 (My Body, My Data Act of 2025), requires businesses and other "regulated entities" to minimize collection and sharing of personal reproductive or sexual health data - such as pregnancy status, contraceptive use, or abortion-related information - and gives individuals specific rights. It mandates that entities provide individuals with easy access to their data, the ability to correct inaccuracies, and the right to request deletion of such information within 15 days. The law also requires clear privacy policies detailing data practices and prohibits retaliation against individuals who exercise these rights, such as charging higher prices or denying services. It applies broadly to most businesses (excluding HIPAA-covered healthcare providers) and is enforced by the FTC with private lawsuits allowed for violations.
This bill requires 16 major federal agencies (including Defense, Health, Homeland Security, and Social Security) to report to Congress within 120 days of enactment on whether they have implemented electronic consent systems as mandated by 2020 OMB guidance (M-21-04). The report must confirm implementation status or detail delays, justifications, and timelines for compliance. It directly affects agencies handling personal data under the Privacy Act by enforcing existing requirements for electronic identity proofing, consent templates on websites, and electronic consent acceptance. The bill focuses on accountability for current OMB guidance, not creating new rules.
HR 6253 requires online platforms using personalized recommendation systems (like social media or video sites) to provide clear notices and options to minors under 18. It mandates that platforms offer an input-transparent algorithm as the default setting - meaning it doesn’t use hidden user data to curate content - and gives minors the ability to switch algorithms or limit recommendation types. Platforms must also disclose how data is collected, what the system optimizes (e.g., engagement time), and how user-specific data is used. The Federal Trade Commission will enforce these requirements under existing laws, with the bill preempting conflicting state regulations.
The ACCESS Act of 2025 requires major social media and messaging platforms (defined as services with over 100 million U.S. users that monetize user data) to enable users to easily transfer their data to competing services and ensure their platforms can interoperate with rival services. It mandates that large platforms provide secure, machine-readable data portability and maintain transparent interfaces for competitors to connect with users. The law also establishes rules for third-party agents managing user accounts and prohibits platforms from using data from competitors for commercial gain. Enforcement falls to the Federal Trade Commission, with penalties for violations treated as unfair business practices.
The Data Care Act of 2025 requires online service providers (like social media platforms or apps that collect user data) to securely handle "individual identifying data," especially sensitive information like health details, biometrics, financial data, or precise location. It imposes three key duties: (1) reasonably securing data from breaches, (2) not misusing data to harm users or benefit themselves, and (3) restricting data sharing to third parties only with strict confidentiality contracts. The Federal Trade Commission and state attorneys general can enforce these rules through penalties for violations, with civil fines calculated based on the number of affected users or days of noncompliance. The law directly affects major digital platforms collecting user data and takes effect 180 days after enactment.
This bill creates a voluntary data collection system for farmers to share field-level information on conservation practices and farming methods. It requires the USDA to build a secure data center collecting anonymized farm data on soil health, crop yields, and ecosystem impacts - voluntarily provided by producers - to analyze how practices affect productivity and environmental outcomes. The data will be used to improve USDA programs and provide farmers with internet-based tools showing how specific practices boost yields and sustainability. Strong privacy safeguards prevent disclosure of individual producer data, ensuring compliance with existing privacy laws. The bill does not mandate data sharing or require farmers to adopt new practices.