Representative · D-CA
The bill significantly strengthens consumers' privacy rights and centralizes enforcement in a new, well‑funded federal Agency—giving people more control and remedies—at the cost of substantial compliance burdens, increased liability and government investigatory power, legal uncertainty, potential service and research disruptions, and risks to free expression and small actors.
Almost all individuals in the U.S. gain stronger, concrete control over their personal data: rights to access, correct, delete, port data, request human review of automated decisions, and (for behavioral personalization) affirmative consent with annual renewal.
Consumers, states, and businesses get a centralized Digital Privacy Agency with sustained funding, a single intake for complaints, and an Office of Civil Rights to coordinate enforcement, improve consistency across jurisdictions, and focus resources on privacy issues.
People harmed by privacy violations can seek stronger remedies—monetary relief (refunds, restitution, disgorgement, damages) and whistleblower incentives—while enforcement procedures include specific process protections for respondents.
Covered businesses (including many online services) and their customers face substantial new compliance costs and operational burdens—documentation, de‑identification, audits, APIs, verification, notice/consent systems, and security programs—that will be greatest for mid‑sized firms and could raise prices or reduce services.
The bill creates very large enforcement and liability exposure: per‑individual (and per‑day) civil penalties, broad compulsory demands, limited ability to pause agency orders, and an exclusive administrative review path that can force compliance while appeals proceed.
Concentrating wide rulemaking and enforcement authority in a single, well‑funded Agency and Director (with pay/hiring flexibilities and statutory deference to agency interpretations) raises accountability, politicization, and separation‑of‑powers concerns.
Based on analysis of 10 sections of legislative text.
Creates a federal data-privacy law with individual access/correction/deletion/portability rights, limits on behavioral personalization, a new Digital Privacy Agency, and NIST/NSF privacy programs.
Official title: To provide for individual rights relating to privacy of personal information, to establish privacy and security requirements for covered entities relating to personal information, and to establish an agency to be known as the Digital Privacy Agency to enforce such rights and requirements, and for other purposes.
Introduced March 19, 2026 by Zoe Lofgren · Last progress March 19, 2026
Creates a comprehensive federal data-privacy and digital rights framework that gives people new access, correction, deletion, and portability rights for personal information; limits how companies may collect, use, and "behaviorally personalize" content and services; and establishes a new independent executive agency (the Digital Privacy Agency) to implement and enforce the law. The bill also creates a new federal crime for certain harmful disclosures of personal information, provides the Agency investigatory tools (subpoenas, civil investigative demands, joint investigations), directs NIST to produce voluntary privacy risk frameworks and public education, and funds NSF research on socio-technical privacy topics. The law applies to broad classes of covered entities (with a small-business de minimis carveout), bans forced waivers and predispute arbitration for claims under the Act, requires notice/consent rules for ancillary uses, requires accuracy dispute and correction mechanisms, and preserves existing federal privacy and other sectoral laws while allowing stronger state laws to remain in effect.