The United States still does not have a single comprehensive federal privacy law resembling the GDPR.
That does not mean Congress is standing still.
Quite the opposite.
By September 2026, lawmakers in the 119th Congress had introduced a sprawling collection of federal proposals addressing consumer privacy, artificial intelligence, children’s data, employee surveillance, reproductive information, precise location data, financial information, connected vehicles, data brokers, automated decision-making and age verification.
The IAPP’s September 2026 federal privacy legislation tracker identifies 49 distinct legislative proposals across five broad privacy categories. Several proposals have House and Senate companions, so the actual number of bill numbers is higher.
Only two of those tracked proposals have become law so far: the TAKE IT DOWN Act, signed May 19, 2025, and the Homebuyers Privacy Protection Act, signed September 5, 2025.
The rest reveal something arguably more useful than a simple bill count: where federal privacy policy is heading.
Congress is simultaneously debating three different versions of comprehensive consumer privacy legislation while pursuing narrower rules for AI, children, health information, data brokers and employee monitoring. The recurring disputes over state-law preemption and private rights of action remain unresolved.
Meanwhile, several ideas that once appeared primarily in comprehensive privacy legislation are migrating into sector-specific bills: data minimization, deletion rights, opt-outs, sensitive-data restrictions, automated-decision transparency and restrictions on targeted advertising.
The result is no longer simply a debate over whether the United States will pass a “federal privacy law.”
Congress is building a collection of potential federal privacy laws.
| category | count |
|---|---|
| Children and education | 19 |
| Consumer privacy | 15 |
| Health privacy | 6 |
| Financial privacy | 5 |
| Workplace privacy | 4 |

Federal Privacy Legislation by Category
The 49 proposals tracked by the IAPP break down as follows:
| Area | Tracked proposals | What Congress is focusing on |
|---|---|---|
| Children’s and educational privacy | 19 | Social media, age assurance, COPPA expansion, AI chatbots, targeted advertising, recommender systems, data brokers |
| Consumer privacy | 15 | Comprehensive privacy laws, AI, connected vehicles, smart devices, automated decisions, deepfakes |
| Health privacy | 6 | Reproductive information, consumer health data, genetics, location data, health-plan information |
| Financial privacy | 5 | Mortgage leads, financial minimization, transaction privacy, military data |
| Workplace privacy | 4 | Employee surveillance, algorithmic management, app-based workers and automated employment decisions |
The imbalance itself is instructive.
Almost 40% of the proposals in the tracker concern children or education. Congress is not treating children’s privacy as a small subsection of general consumer privacy. It has effectively become its own federal technology-policy field.
AI is similarly spreading across categories instead of remaining inside an isolated “AI law” bucket.
There are AI proposals involving consumers, workers and children. Automated decision systems appear in employment legislation. AI chatbot rules appear in children’s privacy bills. Algorithmic decision rights appear in comprehensive consumer legislation.
Privacy and AI governance are increasingly becoming overlapping compliance disciplines.
The Three Competing Visions for a Federal Privacy Law
The biggest development of 2026 may be the return of serious comprehensive federal privacy proposals.
Three bills illustrate very different ways Congress could establish a national framework:
- the Online Privacy Act of 2026;
- the Consumer Data Privacy and Security Act of 2026; and
- the SECURE Data Act.
They agree on considerably more than the political debate around federal privacy sometimes suggests.
All three contemplate nationwide rights and obligations governing personal information.
But they differ on two questions that have frustrated federal privacy negotiations for years:
Does a federal law replace state privacy laws?
And can individuals sue companies directly?
Comprehensive Federal Privacy Bills Compared
| Issue | Online Privacy Act of 2026 | Consumer Data Privacy and Security Act of 2026 | SECURE Data Act |
|---|---|---|---|
| Bill | H.R. 8014 | S. 4211 | H.R. 8413 |
| Introduced | March 19, 2026 | March 25, 2026 | April 21, 2026 |
| Sponsor | Rep. Zoe Lofgren | Sen. Jerry Moran | Rep. John Joyce |
| Access rights | Yes | Yes | Yes |
| Correction | Yes | Yes | Yes |
| Deletion | Yes | Yes | Yes |
| Portability | Yes | Consumer-control framework | Yes |
| Data minimization | Yes | Processing controls/accountability | Yes |
| Sensitive-data rules | Yes | Yes | Yes |
| Security obligations | Yes | Yes | Yes |
| Automated-decision provisions | Human review and transparency | Consumer control over processing | Profiling opt-out |
| State law | Preserves state privacy laws | Preempts covered state laws | Preempts covered state laws |
| Private right of action | Yes | No | No |
| Federal enforcement structure | Creates a Digital Privacy Agency | Federal enforcement framework | FTC plus state attorneys general |
| Current tracker status | Introduced | Introduced | Introduced |
The Online Privacy Act would establish rights including access, correction, deletion and portability, impose data-minimization and security requirements, provide protections around automated decisions, and establish a new Digital Privacy Agency. GovInfo records the bill as introduced March 19, 2026 and referred to three House committees.
Sen. Jerry Moran’s Consumer Data Privacy and Security Act takes another approach. It would establish nationwide rights over the collection, processing and disclosure of personal data, impose security and accountability requirements, and preempt covered state privacy laws. The IAPP tracker identifies no private right of action. GovInfo shows the measure was referred to the Senate Commerce Committee following its March 25 introduction.
Then came the SECURE Data Act.
H.R. 8413 would establish rights relating to personal data while regulating controllers, processors and data brokers. The bill covers data security, sensitive information and consumer opt-outs. It also preempts covered state privacy rules and does not provide the general private right of action identified in the Online Privacy Act.
GovInfo describes SECURE as a proposal “to establish a national framework for consumer privacy rights and the protection of personal data.” As of the latest official material reviewed for this article, it remained at the committee stage.
This is the basic federal privacy divide in miniature.
Congress does not appear to be struggling to invent privacy rights.
Access, deletion, correction, security, sensitive-data controls and opt-outs have become familiar concepts.
The difficult issue is deciding how those rights coexist with state law and who gets to enforce them.
The Federal Preemption Problem Has Not Gone Away
For companies operating nationally, preemption could be one of the most consequential provisions of any comprehensive federal law.
More than 20 states have already enacted broad consumer privacy regimes. The Future of Privacy Forum counted 21 comprehensive state privacy laws when the SECURE Data Act was introduced in April 2026.
A federal law that sits on top of those laws creates a national floor.
A federal law that displaces them creates something closer to a national ceiling.
Those are very different regulatory systems.
The SECURE Data Act illustrates the disagreement.
Industry groups including the Software & Information Industry Association have supported the concept of national uniformity, arguing that companies need a single national privacy framework rather than an expanding collection of state requirements.
California regulators and a coalition of attorneys general have taken the opposite position, arguing that SECURE would displace stronger protections already available under state law.
The IAPP tracker shows this disagreement running through numerous other bills as well. Some expressly preserve state laws. Others expressly preempt them. Many narrow bills do neither.
For privacy departments, “federal privacy law” therefore does not necessarily mean the end of fifty-state analysis.
It depends entirely on which federal model survives.
Private Rights of Action Remain the Other Major Fault Line
The second recurring issue is whether an individual should be able to sue directly.
Some proposals rely almost entirely on government enforcement.
Others create private litigation rights.
The difference is not academic.
For businesses, the practical risk profile of a statute enforced exclusively by the FTC or attorneys general can be materially different from a statute under which potentially millions of individuals can bring claims.
Several proposals in the tracker expressly include private rights, including:
- the AI Accountability and Personal Data Protection Act;
- the Stop Price Gouging in Grocery Stores Act;
- the Artificial Intelligence Civil Rights Act;
- the Online Privacy Act;
- the AI Labeling Act;
- the Empowering App-Based Workers Act;
- the Stop Spying Bosses Act;
- the No Robot Bosses Act;
- the My Body, My Data Act;
- the Health and Location Data Protection Act;
- the Don’t Sell Kids’ Data Act;
- the Parental Rights Relief Act;
- the Youth AI Privacy Act; and
- the Safety and Age Filtering Enforcement for Kids Act.
The fact that Congress continues proposing both models suggests there is still no federal consensus on the litigation question.
The Full Consumer Privacy Landscape
The consumer category in the IAPP tracker contains 15 proposals. They range from sweeping national privacy regimes to rules governing a single category of connected device.
The expanded table below shows how different these measures actually are.
| Proposal | Bill | Status in tracker | Core concept | State law | Private action |
|---|---|---|---|---|---|
| Informing Consumers about Smart Devices Act | S.28 | Introduced | Disclosure of cameras/microphones in connected appliances | N/A | No |
| TAKE IT DOWN Act | S.146 / H.R.633 | Law | Nonconsensual intimate imagery and deepfakes; notice-and-removal | N/A | No |
| Advancing Digital Support for Mental Health Services Act | S.414 | Passed Senate | Reporting on mental-health public-service advertising | Preserves | No |
| AI Accountability and Personal Data Protection Act | S.2367 | Introduced | Express prior consent for certain AI/data uses; federal tort | Preserves | Yes |
| Stop Price Gouging in Grocery Stores Act | H.R.4966 | Introduced | Surveillance-based pricing and facial recognition | Preserves | Yes |
| Manage Your Data and Allow Only Trusted Access Act | H.R.6043 | Introduced | Prevents covered entities from blocking use of cloaked/deidentified data | N/A | No |
| Deepfake Liability Act | H.R.6334 | Introduced | Duties surrounding cyberstalking and sexually explicit deepfakes | N/A | No |
| Artificial Intelligence Civil Rights Act | S.3308 / H.R.6356 | Introduced | Algorithmic discrimination, assessments and human review | Preserves | Yes |
| Auto Data Privacy and Autonomy Act | S.3494 / H.R.6734 | Introduced | Connected-vehicle data access, sale and control | N/A | No |
| Data Care Act | S.3570 | Introduced | Duties of care, loyalty and confidentiality | Preserves | No |
| Promoting Responsible Online Technology and Ensuring Consumer Trust Act | H.R.7045 | Introduced | Repeal of Section 230 protections | N/A | No |
| Online Privacy Act of 2026 | H.R.8014 | Introduced | Comprehensive consumer privacy framework | Preserves | Yes |
| Consumer Data Privacy and Security Act | S.4211 | Introduced | Comprehensive national privacy rules | Preempts | No |
| SECURE Data Act | H.R.8413 | Introduced | Comprehensive controller/processor/data-broker framework | Preempts | No |
| AI Labeling Act | S.4915 | Introduced | Labels and machine-readable disclosure for AI-generated content | N/A | Yes |
Consent Is Expanding Beyond Traditional Privacy Notices
The AI Accountability and Personal Data Protection Act would establish a federal tort related to the appropriation, collection, processing, use or sale of personal data without express prior consent.
That approach differs substantially from the opt-out structure common to many state privacy laws.
If adopted in that form, the compliance question would become less about whether a privacy notice discloses processing and more about whether the organization can prove authorization before processing occurs.
That is a technical consent-management issue as much as a legal one.
Connected Cars Are Becoming Privacy Systems
The Auto Data Privacy and Autonomy Act addresses vehicle-generated and user data.
It would restrict manufacturers from accessing, selling or sharing covered data without vehicle-owner consent and give owners greater access and control.
GovInfo confirms that the Senate version remains referred to the Commerce Committee.
Modern vehicles can generate location information, driving behavior, device information, diagnostic information and other telemetry.
Privacy compliance is therefore moving into product categories that were once treated largely as hardware.
The Data Care Act Revives Fiduciary-Like Duties
The Data Care Act takes another approach entirely.
Rather than building compliance primarily around a list of consumer requests, it would impose duties of care, loyalty and confidentiality on online service providers.
The bill would require reasonable security and restrict uses that benefit a provider to the detriment of users where foreseeable material harm or conduct highly offensive to a reasonable user could result.
That is a fundamentally different model from “provide notice and offer an opt-out.”
It regulates the relationship between the data holder and the person.
Workplace Privacy Is Becoming AI Governance
Federal employee privacy remains far less comprehensive than consumer privacy.
But the proposals in the current Congress show where workplace regulation could be headed.
| Proposal | Bill | Main requirement | State law | Private action |
|---|---|---|---|---|
| Empowering App-Based Workers Act | S.2488 / H.R.6646 | Notice regarding electronic monitoring and automated decisions | Preserves | Yes |
| Worker Privacy Act | S.3128 | Limits certain employee contact information supplied during labor proceedings | N/A | No |
| Stop Spying Bosses Act | S.4831 / H.R.9402 | Restricts workplace surveillance and collection of worker data | Preserves | Yes |
| No Robot Bosses Act | H.R.6371 / S.4833 | Restrictions and disclosures around automated employment decisions | Preserves | Yes |
The Stop Spying Bosses Act is particularly broad in concept. Its stated purpose is to prohibit or require disclosure of certain surveillance, monitoring and collection of worker data. GovInfo shows the Senate version was referred to the Senate HELP Committee on June 18, 2026; the House companion followed on June 23.
The No Robot Bosses Act attacks a related problem from the decision-making side rather than simply the collection side.
The emerging pattern is:
collecting employee data can create one set of obligations;
using algorithms to make employment decisions can create another.
That distinction will matter increasingly as businesses deploy AI for hiring, productivity measurement, scheduling, performance evaluation and termination decisions.
Health Privacy Is Expanding Far Beyond HIPAA
One of the most important misconceptions in U.S. privacy remains the assumption that “health privacy” and HIPAA are synonymous.
They are not.
HIPAA generally applies through covered entities and business associates. A tremendous amount of consumer health information exists outside that structure.
Congress is now considering legislation aimed precisely at those gaps.
| Proposal | Bill | Principal subject | State law | Private action |
|---|---|---|---|---|
| American Genetic Privacy Act | H.R.2286 | Commercial DNA and genealogical information transferred to certain foreign entities | N/A | No |
| My Body, My Data Act | S.2029 / H.R.3916 | Reproductive and sexual health data, minimization, access, correction and deletion | Preserves | Yes |
| Health Data Access, Transparency, and Affordability Act | H.R.9228 | Access to deidentified health-plan claims data | N/A | No |
| Secure Access for Essential Reproductive Health Act | S.4920 / H.R.9470 | Disclosure of pregnancy termination/loss information in proceedings | Preserves | No |
| Health and Location Data Protection Act | H.R.9482 / S.4946 | Restricts data brokers’ transfer of health and location information | N/A | Yes |
| Health Data Access, Transparency, and Affordability Act | H.R.9486 | Health-plan auditing/access to deidentified claims data | Preserves | No |
The Health and Location Data Protection Act is especially notable because it explicitly connects health information with location information.
The House measure would prohibit data brokers and other covered actors from selling or transferring certain sensitive data. The Senate companion was introduced July 13, 2026 and referred to the Senate Commerce Committee.
Why combine location and health?
Because location itself can reveal health behavior.
A dataset does not necessarily need a field called “medical diagnosis” to expose sensitive medical activity. Repeated visits to particular clinics, treatment centers or reproductive-health providers may reveal information by inference.
That distinction will become increasingly important for data mapping.
Companies need to ask not just whether they collect expressly medical information, but what apparently ordinary data can reveal when combined.
Financial Privacy Is Shifting Toward Minimization
The financial section is smaller, but it contains one especially important development: explicit data minimization inside the Gramm-Leach-Bliley Act framework.
| Proposal | Bill | Core issue | State law | Private action |
|---|---|---|---|---|
| Bank Privacy Reform Act | H.R.533 | Bank Secrecy Act reporting requirements | N/A | No |
| Protecting Privacy in Purchases Act | H.R.1181 / S.1715 | Merchant-category treatment of firearms retailers | N/A | No |
| Homebuyers Privacy Protection Act | H.R.2808 / S.1467 | Mortgage trigger leads | N/A | No |
| Protecting Military Servicemembers Data from Foreign Adversaries Act | S.1512 | Broker sales of military personnel data | N/A | No |
| Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act | H.R.8398 | GLBA minimization, notices and expanded opt-outs | Preempts | No |
The Homebuyers Privacy Protection Act has already become Public Law 119-36.
It amended the Fair Credit Reporting Act to limit the circumstances in which consumer reports associated with residential mortgage transactions may be furnished to third parties.
The Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act goes in a different direction.
It would amend GLBA to require financial institutions to limit collection and disclosure of nonpublic personal information to information that is adequate, relevant and reasonably necessary for a specific purpose.
That language is significant because it represents the migration of modern data-minimization principles into an older sectoral privacy regime.
Children’s Privacy Is Where Congress Is Most Active
No section of the tracker is remotely as crowded as children’s privacy.
Nineteen proposals deal with children, teens, students, age verification, AI, social media, targeted advertising or parental controls.
A more useful way to understand them is by function.
Children’s Privacy and Online Safety Legislation
| Proposal | Primary mechanism | State law | Private action |
|---|---|---|---|
| Kids Off Social Media Act | Ban accounts for under-13s; restrict recommender systems for minors | Preserves | No |
| SCREEN Act | Age verification for certain harmful content | N/A | No |
| Children and Teens’ Online Privacy Protection Act | Expands COPPA protections to teens | Preserves | No |
| DELETE Act | Centralized deletion system for data brokers | Preserves | No |
| Kids Online Safety Act | Privacy defaults, parental controls, design restrictions | Preserves | No |
| Parents Opt-in Protection Act | Consent for student surveys involving personal information | N/A | No |
| GAMING Act | Parental communication controls and protective defaults | Preempts | No |
| SPY Kids Act | Restrictions on research involving children and teens | Preempts | No |
| Don’t Sell Kids’ Data Act | Restricts brokers’ collection/use/disclosure of minors’ data | Preserves | Yes |
| Parents Over Platforms Act | Age assurance through app-distribution infrastructure | Preempts | No |
| RESET Teens Act | Restricts minors’ accounts and requires deletion | Preempts | No |
| Parental Rights Relief Act | FERPA/PPRA private litigation rights | N/A | Yes |
| Kids Internet and Digital Safety Act | COPPA expansion, privacy/safety and advertising restrictions | Preserves | No |
| Sammy’s Law | Third-party safety-software API access | Preempts | No |
| Youth AI Privacy Act | AI chatbot privacy, profiling and model-training restrictions | Preserves | Yes |
| Parents Decide Act | OS-level age verification and parental verification | N/A | No |
| Children’s Health, Advancement, Trust, Boundaries, and Oversight in Technology Act | Child chatbot accounts, parental controls and advertising restrictions | Preserves | No |
| Safety and Age Filtering Enforcement for Kids Act | Age verification plus retention/sale limits | N/A | Yes |
| SAFE KIDS Act | AI age assurance, privacy restrictions, child-safety audits | Preserves | No |
The underlying measures appear across four pages of the IAPP tracker.
Several distinct policy models are developing inside this category.
Model 1: Expand COPPA Beyond Under-13 Users
The Children and Teens’ Online Privacy Protection Act would extend privacy protections into the teen years and prohibit certain targeted marketing involving children and teens.
This would materially change the compliance boundary for online services.
Today’s familiar COPPA question is frequently:
“Is the user under 13?”
The emerging model increasingly asks:
“Is the user a minor?”
Those are not equivalent compliance obligations.
Model 2: Move Age Verification Into the Operating System or App Store
Some proposals attempt to solve the age-assurance problem at a different layer of the technology stack.
The Parents Over Platforms Act would require application-distribution providers to provide age-assurance capabilities and signals to developers.
The Parents Decide Act would place age collection and verification obligations on operating-system providers and make age information available to developers for verification purposes.
That could represent an important architectural change.
Instead of every website or application independently collecting a birth date or identity document, trusted infrastructure could potentially communicate an age signal.
But that raises another privacy problem:
How do you verify age without creating an enormous new identity dataset?
Age assurance therefore becomes a privacy-engineering problem itself.
Model 3: Regulate AI Chatbots Specifically
2026 also produced a new federal privacy category almost from scratch:
children interacting with AI chatbots.
The Youth AI Privacy Act would require chatbot safeguards, disclosures that users are interacting with AI, restrictions on profiling and personalization, and prohibitions against using minors’ data for model training.
Another proposal would require family accounts, parental consent and parental access to chatbot activity while restricting targeted advertising involving minors.
The bipartisan SAFE KIDS Act would require age assurance, child-safety-by-design measures, parental controls, risk assessments, crisis protocols and independent audits, while restricting advertising and certain uses of children’s personal information. Senators John Curtis and Adam Schiff introduced that measure on June 23.
This is a major change in the privacy discussion.
The legal issue is no longer merely:
Can an AI company collect a child’s information?
Congress is beginning to ask:
Can it train on it?
Can it personalize responses from it?
Can the AI deliberately increase engagement using it?
Can parents see what the system knows?
Can children’s information be used for advertising?
Those are much more specific product-design questions.
AI Privacy Is No Longer a Separate Category
One reason the federal landscape looks confusing is that AI regulation is being embedded inside ordinary privacy law.
At least several proposals in the tracker directly regulate algorithmic or AI activity:
| Bill | AI/privacy issue |
|---|---|
| AI Accountability and Personal Data Protection Act | AI use of personal information and prior consent |
| Artificial Intelligence Civil Rights Act | Algorithmic consequential decisions |
| AI Labeling Act | AI-generated content disclosure |
| Online Privacy Act | Human review of automated decisions |
| No Robot Bosses Act | Automated workplace decisions |
| Kids Off Social Media Act | Automated recommender systems |
| Youth AI Privacy Act | Chatbot profiling, personalization and training |
| CHAT-related children’s legislation | AI chatbot use by minors |
| SAFE KIDS Act | AI chatbot safety, age assurance and privacy |
The AI Labeling Act is a good example.
Introduced June 24, it would require disclosure around covered AI-generated content and machine-readable information identifying that content. GovInfo shows it was referred to the Senate Commerce Committee.
AI governance therefore should not be separated organizationally from privacy as though one team manages “data” and another manages “AI.”
The AI system runs on data.
Increasingly, the law recognizes that relationship.
Data Brokers Are Becoming a Regulatory Choke Point
Another recurring target is the data broker.
Congress is attacking broker activity from several directions.
The DELETE Act would create a centralized mechanism for people to request deletion from registered data brokers.
The Don’t Sell Kids’ Data Act would prohibit certain collection and disclosure of children’s and teens’ information by brokers.
The Health and Location Data Protection Act targets the transfer of health and location information.
The Kids Internet and Digital Safety Act would impose registration requirements on certain brokers dealing in minors’ data.
This suggests that federal privacy policy is increasingly differentiating between two relationships:
a company collecting information directly from its customer;
and an intermediary accumulating information about people with whom it has no direct relationship.
That distinction already exists in multiple state regimes. Congress appears increasingly interested in it as well.
Data Minimization Is Quietly Becoming One of the Most Important Federal Privacy Concepts
Cookie banners and consumer opt-outs receive enormous attention because users can see them.
Data minimization may ultimately matter more operationally.
The concept appears repeatedly across the proposals.
The Online Privacy Act expressly imposes minimization obligations.
The My Body, My Data Act applies minimization to reproductive and sexual-health information.
The proposed financial legislation would limit nonpublic personal information to what is adequate, relevant and reasonably necessary for a specific purpose.
This is a meaningful evolution from an older privacy model centered primarily on notice.
A business can write an accurate privacy policy describing extensive data collection.
Minimization asks a different question:
Why are you collecting it at all?
That question reaches architecture, analytics, advertising, AI training, retention and vendor integrations.
What Has Actually Passed?
One of the easiest mistakes when looking at a tracker this large is treating proposed legislation as though all of it is on the verge of becoming law.
It is not.
Most of the tracked measures remain proposals.
Two have crossed the entire legislative process.
TAKE IT DOWN Act
The TAKE IT DOWN Act became Public Law 119-12 on May 19, 2025. It addresses the intentional disclosure of nonconsensual intimate visual depictions, including qualifying digitally generated content, and imposes removal-related obligations on covered platforms.
Homebuyers Privacy Protection Act
The Homebuyers Privacy Protection Act became Public Law 119-36 on September 5, 2025.
It modifies the Fair Credit Reporting Act to restrict certain “trigger lead” practices associated with residential mortgage transactions.
The tracker also identifies the Advancing Digital Support for Mental Health Services Act as having passed the Senate as of its September update.
Everything else should be treated according to its actual legislative status, not as an enacted obligation.
2026 Federal Privacy Landscape
Trying to predict which of 49 proposals becomes law is less useful than looking at what keeps recurring across otherwise unrelated bills.
Several requirements appear again and again:
| Recurring requirement | Where it appears |
|---|---|
| Access and deletion | Comprehensive bills, health privacy, children’s privacy |
| Data minimization | Comprehensive privacy, reproductive health, financial data |
| Sensitive-data restrictions | Consumer, health, children |
| Consent | AI, connected vehicles, children’s data, health |
| Automated-decision transparency | Consumer AI, employment |
| Human review | Consumer privacy and algorithmic decision-making |
| Targeted-ad restrictions | Children and teens |
| Age assurance | Children’s platforms, operating systems, AI |
| Data-broker restrictions | Consumer, health, children |
| Privacy/security assessments | AI and children’s systems |
| Default privacy settings | Children’s platforms |
| Restrictions on AI training | Youth AI |
| Independent auditing | AI child-safety legislation |
This is where privacy programs should concentrate.
A company does not need to redesign its entire compliance program every time a member of Congress introduces a bill.
But if the same operational control appears in state privacy laws, proposed federal laws and emerging AI rules, it is increasingly difficult to treat that control as an edge case.
Where Should Privacy Teams Focus?
The practical compliance architecture emerging from all of this legislation is surprisingly consistent.
First, organizations need an accurate inventory of what data they collect and where it goes.
That sounds elementary. It is not.
Websites can add advertising scripts, pixels, SDKs and analytics services without the privacy department knowing. Mobile applications communicate with third parties. AI tools ingest internal information. Marketing teams change tags. Vendors change behavior.
A privacy policy cannot accurately disclose a data flow nobody has identified.
Second, consent and preference signals need to affect actual technical behavior.
If someone opts out of targeted advertising, sends Global Privacy Control or refuses a category of cookies, the question is not merely whether the preference was recorded.
Did the relevant processing stop?
Third, organizations need to classify sensitive information more intelligently.
Health information does not exist exclusively in a medical-record field.
Location can reveal health activity.
Search queries can expose medical interests.
Browsing activity can reveal religion or sexuality.
Purchases can expose financial or health characteristics.
AI prompts can contain nearly anything.
Fourth, companies need to know where automated decisions are being made.
That includes hiring.
Credit.
Insurance.
Employee evaluation.
Recommendations.
Pricing.
Eligibility.
AI agents acting for customers.
The legislative trend is toward more transparency and, in some proposals, opportunities for human involvement.
Finally, privacy evidence matters.
Organizations increasingly need to be able to establish what configuration existed at a particular time:
what cookies fired;
what consent was obtained;
which policy was displayed;
which GPC signal was received;
which vendors were active;
what information was transferred;
and when a configuration changed.
That is very different from simply maintaining a privacy policy.
Federal Privacy Law May Arrive in Pieces
For years, discussion of U.S. privacy legislation has centered on one question:
When will Congress finally pass America’s GDPR?
The 119th Congress suggests that may be the wrong way to look at it.
Congress could still pass comprehensive privacy legislation.
The Online Privacy Act, Consumer Data Privacy and Security Act and SECURE Data Act prove that the idea remains active.
But federal privacy regulation is also being assembled piece by piece.
A deepfake law has already passed.
A mortgage-data law has already passed.
Congress is considering separate rules for health and location information, children, chatbots, employee surveillance, connected cars, financial minimization, data brokers and automated decision systems.
Some proposals preserve state privacy regimes.
Others would displace them.
Some rely on regulators.
Others allow individuals to sue.
Some regulate the collection of information.
Others regulate what algorithms may do with information after it has been collected.
That is the real story of federal privacy legislation in 2026.
The United States may eventually enact one broad national privacy statute.
But businesses cannot assume that federal privacy regulation will wait for that moment.
Congress is already constructing the pieces.