The SECURE Data Act establishes a comprehensive federal privacy framework that grants consumers specific rights to access, correct, delete, and opt out of the sale of their personal data, while requiring companies to provide clear privacy notices and implement reasonable data security measures. It directly affects large businesses and data brokers that process significant amounts of consumer information, mandating that these entities obtain explicit consent for sensitive data and prohibiting discrimination against individuals who exercise their privacy rights. The legislation creates a registration system for data brokers, allows for enforcement actions by the Federal Trade Commission and state attorneys general, and preempts conflicting state laws to ensure a uniform national standard.
The No Rigged Grocery Prices Act prohibits grocery stores and third-party delivery services from using a customer's personal data to raise prices for specific individuals. While the law allows for standard promotions, loyalty rewards, and objective cost differences like shipping fees, it bans dynamic pricing that targets consumers based on their personal information. Retailers must also inform customers if item availability changes or if prices are calculated by weight, and delivery services need explicit permission before swapping out grocery items. Violations of these rules would be treated as unfair business practices enforceable by the Federal Trade Commission. Additionally, the bill requires the Department of Labor to report on how the adoption of electronic shelf labels affects employment at grocery stores.
The Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act strengthens privacy protections for consumers by amending the Gramm-Leach-Bliley Act to require financial institutions to limit data collection to what is necessary, provide clearer privacy notices, and offer new rights for customers to access or delete their personal information. Key provisions include requiring explicit opt-in consent for sensitive data like biometric information, restricting how third parties can use consumer login credentials, and mandating that institutions disclose how they use artificial intelligence in processing financial data. The bill also establishes a right for former customers to request deletion of their data within 45 days and requires regulators to consider the impact of rules on smaller financial institutions with $15 billion or less in assets.
The Surveillance Accountability Act aims to strengthen Fourth Amendment protections against warrantless government searches, directly affecting federal employees involved in surveillance and individuals whose data or privacy is subject to government access. It generally mandates that government entities obtain a warrant based on probable cause for most searches, explicitly requiring one to access data held by third-party companies like internet providers or financial institutions. While outlining exceptions for situations like plain view or publicly available information, the bill specifically prohibits the warrantless collection or analysis of biometric data (e.g., facial recognition) or license plate reader data from public places without informed consent. Additionally, it creates a new legal avenue for individuals to sue federal employees who violate their Fourth Amendment rights, allowing for redress and attorney's fees.
This bill directs the President, through the Department of Defense and the National Intelligence Director, to create strategies for identifying stolen sensitive data and classified information held by foreign entities. It specifically targets financial, medical, biometric data, intellectual property, and trade secrets belonging to U.S. persons. The legislation authorizes these officials to determine if destroying, manipulating, or recovering such stolen data serves U.S. economic and national security interests, and if so, permits them to attempt those actions while potentially informing the data owners. Officials must submit a report to Congress within one year outlining their strategies, actions taken, and recommendations for future legislative or administrative steps.
The Youth AI Privacy Act requires companies that operate artificial intelligence chatbots to take specific steps to protect minors under 18 from potential harm. The law mandates that companies must clearly inform young users that they are interacting with an AI, not a human, and prohibits features designed to encourage compulsive use, such as push notifications or rewards for frequent engagement. Additionally, the bill restricts how companies can use personal data from minors, banning the use of this information for advertising, profiling, or training AI models, with limited exceptions for safety testing. The Federal Trade Commission is tasked with enforcing these rules and issuing guidance to help companies comply, while also authorizing funding for research on the effects of AI chatbots on youth mental health.
This bill requires credit reporting resellers to use reasonable procedures to ensure the accuracy of consumer information they transmit to other agencies or end users. It limits reseller liability when they accurately pass on data obtained from another consumer reporting agency without making changes. The law defines resellers according to existing Fair Credit Reporting Act definitions and focuses on maintaining data integrity during the transfer process. These changes directly affect companies that sell consumer credit reports to other businesses or individuals.
This bill prohibits businesses from using automated systems to set different prices for food and groceries based on surveillance data about individual consumers, such as their browsing history or personal information. It allows exceptions for discounts based on reasonable costs, membership programs, or broad group categories like students and seniors, provided the rules are clearly disclosed and applied uniformly. The Federal Trade Commission would enforce these rules, while states and individuals can also sue for violations, seeking damages of at least $3,000 per violation.
The Online Privacy Act of 2026 establishes a new Digital Privacy Agency to enforce comprehensive privacy protections for individuals in the United States. The bill requires companies that collect personal information to provide consumers with rights to access, correct, delete, and port their data, while also prohibiting discriminatory processing and requiring explicit consent for behavioral personalization. Covered entities must implement data minimization practices, maintain detailed access records for employees, and notify individuals of data breaches within 14 days. The legislation creates a new federal agency with enforcement powers, including the ability to issue cease-and-desist orders, impose civil penalties, and conduct investigations, while also transferring certain Federal Trade Commission privacy enforcement authorities to this new agency.
This joint resolution seeks to formally disapprove a rule from the Bureau of Consumer Financial Protection that would have removed regulations on how large banks and credit unions handle consumer information requests. If passed, the resolution would prevent the Bureau from withdrawing the existing requirements that govern how these financial institutions respond to consumer data inquiries. The measure directly affects the Bureau's regulatory authority and the operational compliance obligations of large financial institutions. By invoking a statutory review process, the resolution aims to keep the current consumer protection standards in place without allowing the proposed regulatory changes to take effect.