The SCAM Act requires online platforms that display paid advertisements (like social media sites) to verify advertiser identities, implement scam detection systems, and remove fraudulent ads within 24 hours of confirmation. It directly affects platforms that accept payment for ads, targeting scams such as fake giveaways, romance scams, and AI impersonations that cost consumers $195 billion in 2024 (per FTC data). Key mechanisms include mandatory identity checks for advertisers, active monitoring systems, and a 72-hour investigation window for reported scams. The law aims to reduce fraud by shifting responsibility to platforms, with enforcement by the FTC and state attorneys general.
HR 2885, the Bank Loan Privacy Act, amends the Equal Credit Opportunity Act to require the Consumer Financial Protection Bureau (CFPB) to follow a specific process before deleting or modifying credit data. The bill mandates that the CFPB issue a rule through advance notice and comment, detailing exactly what data changes it plans to make and how those changes will protect privacy interests. This applies directly to the CFPB’s handling of consumer credit data, not to borrowers or lenders. The key provision is a new procedural requirement for transparency in data modifications, ensuring the public understands the Bureau’s actions. It does not change credit terms or consumer rights but alters how the CFPB manages its data.
The Unsubscribe Act of 2025 regulates "negative option" billing practices, where companies automatically charge consumers unless they actively opt out. It requires merchants to clearly disclose all terms before charging, obtain explicit consumer consent, and provide an easy online cancellation method. The bill specifically targets contracts like free-to-pay conversions (e.g., "free trial" followed by automatic charges), mandating clear upfront terms about pricing and renewal. Consumers directly benefit through greater transparency and control, while merchants must comply with new disclosure, consent, and cancellation rules starting one year after enactment. Enforcement falls to the Federal Trade Commission and state attorneys general.
The Don't Sell My DNA Act amends the U.S. Bankruptcy Code to protect genetic information by requiring written consent from all affected individuals before any sale, lease, or use of genetic data in bankruptcy cases. It mandates that bankruptcy trustees and debtors must provide prior written notice to every person whose genetic information is involved in such transactions. The bill also requires trustees to delete genetic information from bankruptcy estates if it isn't sold, using court-approved methods like NIST guidelines. This directly affects individuals with genetic data in bankruptcy cases, as well as bankruptcy trustees and debtors managing those estates.
HR 6449, the "DO NOT Call Act," amends the Telephone Consumer Protection Act of 1993 to strengthen penalties for illegal robocalls. It increases criminal penalties for willful violations to up to one year in prison (or three years for aggravated offenses like repeated high-volume calls or calls intended to support felonies), and raises fines for inaccurate caller identification from $10,000 to $20,000 per violation. The bill directly affects businesses and entities making unsolicited calls without consent, including those using auto-dialers or prerecorded messages. Key provisions define "calls" broadly to include unsolicited texts sent via auto-dialers without prior permission.
HR 533, the Bank Privacy Reform Act, strengthens privacy protections for individuals' financial records by requiring government agencies to obtain a warrant before accessing bank account information. The bill amends the Right to Financial Privacy Act to mandate warrants for accessing customer records, removes outdated exceptions, and updates the $3,000 threshold for reporting transactions to be adjusted annually for inflation. This directly affects banks, credit unions, and their customers by limiting government access to personal financial data without judicial oversight. Key provisions include requiring warrants for record access (except under specific legal exceptions), removing obsolete sections of financial privacy law, and updating reporting thresholds. The bill focuses on concrete changes to privacy safeguards, not broader financial regulation.
HRES 314 is a resolution requesting the President and Secretary of Health and Human Services to provide documents to the House of Representatives about the so-called Department of Government Efficiency (DOGE) seeking access to two federally protected data systems: the National Directory of New Hires (NDNH) and Federal Parent Locator Service (FPLS). The resolution seeks records on DOGE's requests for taxpayer and child support data, data security measures, legal opinions, and staff changes related to these systems, which store sensitive information on over 40 million Americans. This procedural resolution focuses on transparency around access to legally protected data, not on enacting new policy.
HR 3437, the Insurance Data Protection Act, prevents duplicate data collection from insurance companies by requiring federal financial regulators to coordinate with state insurance regulators before gathering data already available through other channels. It reinforces confidentiality by ensuring that sharing nonpublic data with federal regulators does not waive privacy protections under federal or state law, and maintains existing confidentiality agreements. The bill also establishes that data shared with regulators can only be provided to state regulators through new agreements that comply with privacy laws. This directly affects insurance companies (as "covered entities"), federal financial regulators, and state insurance regulators. The key change is creating a formal process to avoid redundant data requests while strengthening data privacy for the insurance industry.
The NO FAKES Act of 2025 establishes legal rights for individuals to control how their voice and visual likeness are used in digital replicas, which are defined as highly realistic computer-generated representations readily identifiable as a specific person. The bill requires authorization from the individual or their designated right holder before using their likeness in digital replicas, with specific rules for minors (limiting licenses to 5 years) and post-mortem rights (allowing 10 years of protection with possible 5-year renewals). It creates civil liability for unauthorized use of digital replicas or for distributing products/services designed to create such replicas without authorization, with penalties ranging from $5,000 to $750,000 per violation depending on the entity involved. Online services are provided safe harbor protections if they follow procedures for handling takedown notices and have designated agents for copyright issues, while also including exemptions for news, commentary, criticism, and historical uses. The law preempts most state laws regarding digital likeness rights but has exceptions for certain historical uses, news, and sexually explicit content.
The Safe and Private Rides Act (S 1654) requires ride-sharing companies like Uber or Lyft to inform passengers when drivers have cameras recording in vehicles and provide a clear option to avoid those rides. Companies must register camera locations, display prominent opt-out choices in their apps, and restrict recording use to only reporting crime, insurance, or service compliance. Passengers can revoke their consent to ride in camera-equipped vehicles through an easily accessible app feature, separate from standard terms of service. The Federal Trade Commission will enforce these rules, with requirements taking effect 180 days after enactment.