Official title: To establish a national framework for consumer privacy rights and the protection of personal data, and for other purposes.
Introduced April 21, 2026 by John Joyce · Last progress April 21, 2026
The bill significantly strengthens individual privacy rights, transparency, and security standards at the federal level while creating broad enforcement tools, but it also imposes substantial compliance costs on businesses, limits states' ability to set stricter rules, and leaves some exceptions and implementation gaps that could blunt protections in practice.
All consumers gain concrete control over their personal data: new rights to access, correct, delete, port data and to opt out of targeted advertising, sales, and profiling with streamlined annual free requests and timely responses.
Stronger enforcement and oversight: the FTC, state attorneys general, a searchable data-broker registry, and authorized codes of conduct create multiple enforcement tools and transparency mechanisms to hold firms accountable.
Improved data security and incident response: controllers must maintain reasonable security practices, adopt recognized risk‑management frameworks, and may benefit from certification-based presumptions, which should reduce breach impact for customers and improve remediation.
Small and mid-sized businesses, processors, and subcontractors face substantial new compliance costs (contracts, attestations, audits, technical safeguards, registries) that could be passed to consumers through higher prices or reduced services and may drive some smaller firms out of the market.
Preemption and removal of parallel authorities limit state and local ability to enact stronger privacy protections (and repeal of certain statutory protections and FCC authority narrows oversight), potentially rolling back rights for residents in states with tougher rules.
Broad exceptions and liability shields (for internal research, security, cooperation with law enforcement, and certain disclosures) could allow continued extensive data sharing and reduce incentives to verify downstream compliance, weakening practical privacy protections and raising re‑identification risks.
Based on analysis of 18 sections of legislative text.
Establishes a federal consumer privacy law creating rights over personal data, duties for controllers/processors, FTC enforcement, a data-broker registry, codes-of-conduct, and broad state preemption.
Creates a federal privacy law that gives consumers rights over their personal data (access, correction, deletion, portability, and opt-outs for targeted ads, sales, and profiling) and imposes duties on companies that control or process large volumes of U.S. consumer data. It sets security and data-minimization requirements, requires data-broker registration, allows industry codes of conduct, centralizes enforcement with the FTC, and preempts most state and local privacy laws. The bill sets compliance timelines (most rules take effect two years after enactment, with some enforcement and applicability rules effective after one year), preserves specified law-enforcement and safety exceptions, retains existing federal sectoral obligations (HIPAA, GLBA, COPPA, etc.), and assigns a Cabinet-level official to coordinate international data-flow policy and certifications for cross-border transfers.