This bill directs the FBI to lead a working group of 18 federal agencies - including the FTC, CFPB, and Department of Homeland Security - to develop a National Strategy for Combating Scams within two years. The strategy must establish a common scam definition, coordinate federal efforts, and incorporate input from scam survivors, older adults, businesses, and law enforcement. It requires agencies to improve data sharing, prevent scams through evidence-based methods, and update the strategy every five years. The FBI, FTC, and CFPB must adopt the agreed-upon scam definition within one year of the strategy's publication.
This bill requires large online platforms (with over 100 million monthly U.S. users) to disclose the economic value of individual user data to users every 90 days and provide simple deletion tools. It mandates public companies that rely on user data for revenue to report the aggregate value of that data in SEC filings, including collection methods and revenue streams. The law applies to entities generating significant revenue from user data, such as major social media or ad-driven services. Enforcement of user transparency falls to the FTC, while the SEC oversees the financial disclosures.
HR 4828 expands federal privacy law by adding biometric information, license plate numbers, workplace addresses, school addresses, and GPS coordinates to the list of "restricted personal information" under Title 18, U.S. Code. This directly affects businesses and organizations that collect personal data, requiring them to apply the same strict privacy safeguards to these newly protected data types. The bill modifies an existing legal definition rather than creating new requirements or enforcement mechanisms. It applies to any entity subject to current privacy regulations for restricted data. The key change clarifies which specific information categories receive enhanced protection under federal law.
This bill creates a federal private right of action for individuals whose "covered data" (including personal information, biometrics, location data, and inferred profiles) is used without their clear, upfront permission. It requires explicit consent for data collection, processing, or sharing with third parties, mandating specific disclosures separate from general terms. Individuals can sue for damages (minimum $1,000 per violation), punitive damages, or injunctions, and the law invalidates pre-dispute arbitration agreements for these claims. The bill does not override stricter state privacy laws but establishes a baseline federal standard for data misuse by AI systems and data processors.
The Children and Teens' Online Privacy Protection Act (S 836) extends COPPA protections to teens aged 13-17 by requiring websites, apps, and online services to obtain verifiable consent from parents for children or from teens themselves before collecting or using their personal information for purposes beyond the service. It defines "personal information" broadly to include biometric data, voice recordings, persistent identifiers, and geolocation information, and prohibits using such information for individual-specific advertising without consent. The bill mandates clear notice about data practices and gives children and teens rights to access, correct, and delete their personal information. Additionally, it requires the FTC to conduct studies on mobile app oversight and the GAO to study teen privacy in financial technology products.
The Auto Data Privacy and Autonomy Act requires automakers to obtain explicit, written consent from vehicle owners before accessing or sharing their vehicle data (including location and personal information), except for safety improvements or emergencies. It prohibits selling personal data to specific foreign governments (like China, Russia, and North Korea) and mandates that owners have free, real-time access to all vehicle data - without fees, proprietary tools, or restrictions - via open interfaces to delete data or adjust settings. The Federal Trade Commission must report to Congress within 180 days on how automakers handle data, including cybersecurity risks and foreign data sharing. The law takes effect three months after enactment and is enforced under existing FTC authority.
This bill modernizes the 1974 Privacy Act by updating definitions of key terms like "personally identifiable information" and "system of records" to better reflect current data practices. It strengthens protections by requiring agencies to use only the minimum necessary personal data for disclosures, disclose legal authorities for data uses, and prohibit adverse actions based on automated matching. The bill adds civil remedies including minimum $1,000 damages for violations and increases criminal penalties for misuse (e.g., up to $250,000 fines or 10 years imprisonment for commercial misuse). These changes directly affect federal agencies handling personal data and apply to all data collection, use, and disclosure activities governed by the Privacy Act.
The Platform Accountability and Transparency Act creates a structured process for researchers to access certain platform data for research while protecting user privacy. Platforms with at least 50 million US monthly users must provide specific data to qualified researchers (affiliated with US universities or nonprofits) whose projects are approved by the National Science Foundation and Federal Trade Commission. The bill requires platforms to publicly disclose information about advertising, algorithms, content moderation, and highly disseminated content, while establishing strict privacy and cybersecurity safeguards for the data. It also creates legal protections for platforms and researchers who comply with the law's requirements, ensuring researchers cannot be sued for accessing data through this process.
The MY DATA Act of 2025 prohibits businesses (referred to as "covered entities") from blocking consumers from using de-identified data (information that cannot be traced back to a person) or cloaked data (unique identifiers that hide a person's identity while enabling communication). It requires covered entities to allow consumers to access or control their data, with enforcement handled by the Federal Trade Commission as an unfair or deceptive practice under existing law. The bill excludes government agencies and specific nonprofits (like those serving missing children cases) from these requirements, focusing on commercial entities that collect personal information.
This bill, HR 3916 (My Body, My Data Act of 2025), requires businesses and other "regulated entities" to minimize collection and sharing of personal reproductive or sexual health data - such as pregnancy status, contraceptive use, or abortion-related information - and gives individuals specific rights. It mandates that entities provide individuals with easy access to their data, the ability to correct inaccuracies, and the right to request deletion of such information within 15 days. The law also requires clear privacy policies detailing data practices and prohibits retaliation against individuals who exercise these rights, such as charging higher prices or denying services. It applies broadly to most businesses (excluding HIPAA-covered healthcare providers) and is enforced by the FTC with private lawsuits allowed for violations.