Federal Privacy Legislation in 2026: The 49 Bills Reshaping U.S. Data Privacy Law

Table of Contents

The United States still does not have a single comprehensive federal privacy law resembling the GDPR.

That does not mean Congress is standing still.

Quite the opposite.

By September 2026, lawmakers in the 119th Congress had introduced a sprawling collection of federal proposals addressing consumer privacy, artificial intelligence, children’s data, employee surveillance, reproductive information, precise location data, financial information, connected vehicles, data brokers, automated decision-making and age verification.

The IAPP’s September 2026 federal privacy legislation tracker identifies 49 distinct legislative proposals across five broad privacy categories. Several proposals have House and Senate companions, so the actual number of bill numbers is higher.

Only two of those tracked proposals have become law so far: the TAKE IT DOWN Act, signed May 19, 2025, and the Homebuyers Privacy Protection Act, signed September 5, 2025.

The rest reveal something arguably more useful than a simple bill count: where federal privacy policy is heading.

Congress is simultaneously debating three different versions of comprehensive consumer privacy legislation while pursuing narrower rules for AI, children, health information, data brokers and employee monitoring. The recurring disputes over state-law preemption and private rights of action remain unresolved.

Meanwhile, several ideas that once appeared primarily in comprehensive privacy legislation are migrating into sector-specific bills: data minimization, deletion rights, opt-outs, sensitive-data restrictions, automated-decision transparency and restrictions on targeted advertising.

The result is no longer simply a debate over whether the United States will pass a “federal privacy law.”

Congress is building a collection of potential federal privacy laws.

Federal privacy proposals in the 119th CongressDistinct legislative proposals tracked by the IAPP through September 2026. Companion House and Senate bills are counted as one proposal where presented together.
category count
Children and education 19
Consumer privacy 15
Health privacy 6
Financial privacy 5
Workplace privacy 4

 

Federal privacy proposals in the 119th Congress

Federal Privacy Legislation by Category

The 49 proposals tracked by the IAPP break down as follows:

Area Tracked proposals What Congress is focusing on
Children’s and educational privacy 19 Social media, age assurance, COPPA expansion, AI chatbots, targeted advertising, recommender systems, data brokers
Consumer privacy 15 Comprehensive privacy laws, AI, connected vehicles, smart devices, automated decisions, deepfakes
Health privacy 6 Reproductive information, consumer health data, genetics, location data, health-plan information
Financial privacy 5 Mortgage leads, financial minimization, transaction privacy, military data
Workplace privacy 4 Employee surveillance, algorithmic management, app-based workers and automated employment decisions

The imbalance itself is instructive.

Almost 40% of the proposals in the tracker concern children or education. Congress is not treating children’s privacy as a small subsection of general consumer privacy. It has effectively become its own federal technology-policy field.

AI is similarly spreading across categories instead of remaining inside an isolated “AI law” bucket.

There are AI proposals involving consumers, workers and children. Automated decision systems appear in employment legislation. AI chatbot rules appear in children’s privacy bills. Algorithmic decision rights appear in comprehensive consumer legislation.

Privacy and AI governance are increasingly becoming overlapping compliance disciplines.

The Three Competing Visions for a Federal Privacy Law

The biggest development of 2026 may be the return of serious comprehensive federal privacy proposals.

Three bills illustrate very different ways Congress could establish a national framework:

  1. the Online Privacy Act of 2026;
  2. the Consumer Data Privacy and Security Act of 2026; and
  3. the SECURE Data Act.

They agree on considerably more than the political debate around federal privacy sometimes suggests.

All three contemplate nationwide rights and obligations governing personal information.

But they differ on two questions that have frustrated federal privacy negotiations for years:

Does a federal law replace state privacy laws?

And can individuals sue companies directly?

Comprehensive Federal Privacy Bills Compared

Issue Online Privacy Act of 2026 Consumer Data Privacy and Security Act of 2026 SECURE Data Act
Bill H.R. 8014 S. 4211 H.R. 8413
Introduced March 19, 2026 March 25, 2026 April 21, 2026
Sponsor Rep. Zoe Lofgren Sen. Jerry Moran Rep. John Joyce
Access rights Yes Yes Yes
Correction Yes Yes Yes
Deletion Yes Yes Yes
Portability Yes Consumer-control framework Yes
Data minimization Yes Processing controls/accountability Yes
Sensitive-data rules Yes Yes Yes
Security obligations Yes Yes Yes
Automated-decision provisions Human review and transparency Consumer control over processing Profiling opt-out
State law Preserves state privacy laws Preempts covered state laws Preempts covered state laws
Private right of action Yes No No
Federal enforcement structure Creates a Digital Privacy Agency Federal enforcement framework FTC plus state attorneys general
Current tracker status Introduced Introduced Introduced

The Online Privacy Act would establish rights including access, correction, deletion and portability, impose data-minimization and security requirements, provide protections around automated decisions, and establish a new Digital Privacy Agency. GovInfo records the bill as introduced March 19, 2026 and referred to three House committees.

Sen. Jerry Moran’s Consumer Data Privacy and Security Act takes another approach. It would establish nationwide rights over the collection, processing and disclosure of personal data, impose security and accountability requirements, and preempt covered state privacy laws. The IAPP tracker identifies no private right of action. GovInfo shows the measure was referred to the Senate Commerce Committee following its March 25 introduction.

Then came the SECURE Data Act.

H.R. 8413 would establish rights relating to personal data while regulating controllers, processors and data brokers. The bill covers data security, sensitive information and consumer opt-outs. It also preempts covered state privacy rules and does not provide the general private right of action identified in the Online Privacy Act.

GovInfo describes SECURE as a proposal “to establish a national framework for consumer privacy rights and the protection of personal data.” As of the latest official material reviewed for this article, it remained at the committee stage.

This is the basic federal privacy divide in miniature.

Congress does not appear to be struggling to invent privacy rights.

Access, deletion, correction, security, sensitive-data controls and opt-outs have become familiar concepts.

The difficult issue is deciding how those rights coexist with state law and who gets to enforce them.

The Federal Preemption Problem Has Not Gone Away

For companies operating nationally, preemption could be one of the most consequential provisions of any comprehensive federal law.

More than 20 states have already enacted broad consumer privacy regimes. The Future of Privacy Forum counted 21 comprehensive state privacy laws when the SECURE Data Act was introduced in April 2026.

A federal law that sits on top of those laws creates a national floor.

A federal law that displaces them creates something closer to a national ceiling.

Those are very different regulatory systems.

The SECURE Data Act illustrates the disagreement.

Industry groups including the Software & Information Industry Association have supported the concept of national uniformity, arguing that companies need a single national privacy framework rather than an expanding collection of state requirements.

California regulators and a coalition of attorneys general have taken the opposite position, arguing that SECURE would displace stronger protections already available under state law.

The IAPP tracker shows this disagreement running through numerous other bills as well. Some expressly preserve state laws. Others expressly preempt them. Many narrow bills do neither.

For privacy departments, “federal privacy law” therefore does not necessarily mean the end of fifty-state analysis.

It depends entirely on which federal model survives.

Private Rights of Action Remain the Other Major Fault Line

The second recurring issue is whether an individual should be able to sue directly.

Some proposals rely almost entirely on government enforcement.

Others create private litigation rights.

The difference is not academic.

For businesses, the practical risk profile of a statute enforced exclusively by the FTC or attorneys general can be materially different from a statute under which potentially millions of individuals can bring claims.

Several proposals in the tracker expressly include private rights, including:

  • the AI Accountability and Personal Data Protection Act;
  • the Stop Price Gouging in Grocery Stores Act;
  • the Artificial Intelligence Civil Rights Act;
  • the Online Privacy Act;
  • the AI Labeling Act;
  • the Empowering App-Based Workers Act;
  • the Stop Spying Bosses Act;
  • the No Robot Bosses Act;
  • the My Body, My Data Act;
  • the Health and Location Data Protection Act;
  • the Don’t Sell Kids’ Data Act;
  • the Parental Rights Relief Act;
  • the Youth AI Privacy Act; and
  • the Safety and Age Filtering Enforcement for Kids Act.

The fact that Congress continues proposing both models suggests there is still no federal consensus on the litigation question.

The Full Consumer Privacy Landscape

The consumer category in the IAPP tracker contains 15 proposals. They range from sweeping national privacy regimes to rules governing a single category of connected device.

The expanded table below shows how different these measures actually are.

Proposal Bill Status in tracker Core concept State law Private action
Informing Consumers about Smart Devices Act S.28 Introduced Disclosure of cameras/microphones in connected appliances N/A No
TAKE IT DOWN Act S.146 / H.R.633 Law Nonconsensual intimate imagery and deepfakes; notice-and-removal N/A No
Advancing Digital Support for Mental Health Services Act S.414 Passed Senate Reporting on mental-health public-service advertising Preserves No
AI Accountability and Personal Data Protection Act S.2367 Introduced Express prior consent for certain AI/data uses; federal tort Preserves Yes
Stop Price Gouging in Grocery Stores Act H.R.4966 Introduced Surveillance-based pricing and facial recognition Preserves Yes
Manage Your Data and Allow Only Trusted Access Act H.R.6043 Introduced Prevents covered entities from blocking use of cloaked/deidentified data N/A No
Deepfake Liability Act H.R.6334 Introduced Duties surrounding cyberstalking and sexually explicit deepfakes N/A No
Artificial Intelligence Civil Rights Act S.3308 / H.R.6356 Introduced Algorithmic discrimination, assessments and human review Preserves Yes
Auto Data Privacy and Autonomy Act S.3494 / H.R.6734 Introduced Connected-vehicle data access, sale and control N/A No
Data Care Act S.3570 Introduced Duties of care, loyalty and confidentiality Preserves No
Promoting Responsible Online Technology and Ensuring Consumer Trust Act H.R.7045 Introduced Repeal of Section 230 protections N/A No
Online Privacy Act of 2026 H.R.8014 Introduced Comprehensive consumer privacy framework Preserves Yes
Consumer Data Privacy and Security Act S.4211 Introduced Comprehensive national privacy rules Preempts No
SECURE Data Act H.R.8413 Introduced Comprehensive controller/processor/data-broker framework Preempts No
AI Labeling Act S.4915 Introduced Labels and machine-readable disclosure for AI-generated content N/A Yes

 

Consent Is Expanding Beyond Traditional Privacy Notices

The AI Accountability and Personal Data Protection Act would establish a federal tort related to the appropriation, collection, processing, use or sale of personal data without express prior consent.

That approach differs substantially from the opt-out structure common to many state privacy laws.

If adopted in that form, the compliance question would become less about whether a privacy notice discloses processing and more about whether the organization can prove authorization before processing occurs.

That is a technical consent-management issue as much as a legal one.

Connected Cars Are Becoming Privacy Systems

The Auto Data Privacy and Autonomy Act addresses vehicle-generated and user data.

It would restrict manufacturers from accessing, selling or sharing covered data without vehicle-owner consent and give owners greater access and control.

GovInfo confirms that the Senate version remains referred to the Commerce Committee.

Modern vehicles can generate location information, driving behavior, device information, diagnostic information and other telemetry.

Privacy compliance is therefore moving into product categories that were once treated largely as hardware.

The Data Care Act Revives Fiduciary-Like Duties

The Data Care Act takes another approach entirely.

Rather than building compliance primarily around a list of consumer requests, it would impose duties of care, loyalty and confidentiality on online service providers.

The bill would require reasonable security and restrict uses that benefit a provider to the detriment of users where foreseeable material harm or conduct highly offensive to a reasonable user could result.

That is a fundamentally different model from “provide notice and offer an opt-out.”

It regulates the relationship between the data holder and the person.

Workplace Privacy Is Becoming AI Governance

Federal employee privacy remains far less comprehensive than consumer privacy.

But the proposals in the current Congress show where workplace regulation could be headed.

Proposal Bill Main requirement State law Private action
Empowering App-Based Workers Act S.2488 / H.R.6646 Notice regarding electronic monitoring and automated decisions Preserves Yes
Worker Privacy Act S.3128 Limits certain employee contact information supplied during labor proceedings N/A No
Stop Spying Bosses Act S.4831 / H.R.9402 Restricts workplace surveillance and collection of worker data Preserves Yes
No Robot Bosses Act H.R.6371 / S.4833 Restrictions and disclosures around automated employment decisions Preserves Yes

 

The Stop Spying Bosses Act is particularly broad in concept. Its stated purpose is to prohibit or require disclosure of certain surveillance, monitoring and collection of worker data. GovInfo shows the Senate version was referred to the Senate HELP Committee on June 18, 2026; the House companion followed on June 23.

The No Robot Bosses Act attacks a related problem from the decision-making side rather than simply the collection side.

The emerging pattern is:

collecting employee data can create one set of obligations;

using algorithms to make employment decisions can create another.

That distinction will matter increasingly as businesses deploy AI for hiring, productivity measurement, scheduling, performance evaluation and termination decisions.

Health Privacy Is Expanding Far Beyond HIPAA

One of the most important misconceptions in U.S. privacy remains the assumption that “health privacy” and HIPAA are synonymous.

They are not.

HIPAA generally applies through covered entities and business associates. A tremendous amount of consumer health information exists outside that structure.

Congress is now considering legislation aimed precisely at those gaps.

Proposal Bill Principal subject State law Private action
American Genetic Privacy Act H.R.2286 Commercial DNA and genealogical information transferred to certain foreign entities N/A No
My Body, My Data Act S.2029 / H.R.3916 Reproductive and sexual health data, minimization, access, correction and deletion Preserves Yes
Health Data Access, Transparency, and Affordability Act H.R.9228 Access to deidentified health-plan claims data N/A No
Secure Access for Essential Reproductive Health Act S.4920 / H.R.9470 Disclosure of pregnancy termination/loss information in proceedings Preserves No
Health and Location Data Protection Act H.R.9482 / S.4946 Restricts data brokers’ transfer of health and location information N/A Yes
Health Data Access, Transparency, and Affordability Act H.R.9486 Health-plan auditing/access to deidentified claims data Preserves No

 

The Health and Location Data Protection Act is especially notable because it explicitly connects health information with location information.

The House measure would prohibit data brokers and other covered actors from selling or transferring certain sensitive data. The Senate companion was introduced July 13, 2026 and referred to the Senate Commerce Committee.

Why combine location and health?

Because location itself can reveal health behavior.

A dataset does not necessarily need a field called “medical diagnosis” to expose sensitive medical activity. Repeated visits to particular clinics, treatment centers or reproductive-health providers may reveal information by inference.

That distinction will become increasingly important for data mapping.

Companies need to ask not just whether they collect expressly medical information, but what apparently ordinary data can reveal when combined.

Financial Privacy Is Shifting Toward Minimization

The financial section is smaller, but it contains one especially important development: explicit data minimization inside the Gramm-Leach-Bliley Act framework.

Proposal Bill Core issue State law Private action
Bank Privacy Reform Act H.R.533 Bank Secrecy Act reporting requirements N/A No
Protecting Privacy in Purchases Act H.R.1181 / S.1715 Merchant-category treatment of firearms retailers N/A No
Homebuyers Privacy Protection Act H.R.2808 / S.1467 Mortgage trigger leads N/A No
Protecting Military Servicemembers Data from Foreign Adversaries Act S.1512 Broker sales of military personnel data N/A No
Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act H.R.8398 GLBA minimization, notices and expanded opt-outs Preempts No

 

The Homebuyers Privacy Protection Act has already become Public Law 119-36.

It amended the Fair Credit Reporting Act to limit the circumstances in which consumer reports associated with residential mortgage transactions may be furnished to third parties.

The Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act goes in a different direction.

It would amend GLBA to require financial institutions to limit collection and disclosure of nonpublic personal information to information that is adequate, relevant and reasonably necessary for a specific purpose.

That language is significant because it represents the migration of modern data-minimization principles into an older sectoral privacy regime.

Children’s Privacy Is Where Congress Is Most Active

No section of the tracker is remotely as crowded as children’s privacy.

Nineteen proposals deal with children, teens, students, age verification, AI, social media, targeted advertising or parental controls.

A more useful way to understand them is by function.

Children’s Privacy and Online Safety Legislation

Proposal Primary mechanism State law Private action
Kids Off Social Media Act Ban accounts for under-13s; restrict recommender systems for minors Preserves No
SCREEN Act Age verification for certain harmful content N/A No
Children and Teens’ Online Privacy Protection Act Expands COPPA protections to teens Preserves No
DELETE Act Centralized deletion system for data brokers Preserves No
Kids Online Safety Act Privacy defaults, parental controls, design restrictions Preserves No
Parents Opt-in Protection Act Consent for student surveys involving personal information N/A No
GAMING Act Parental communication controls and protective defaults Preempts No
SPY Kids Act Restrictions on research involving children and teens Preempts No
Don’t Sell Kids’ Data Act Restricts brokers’ collection/use/disclosure of minors’ data Preserves Yes
Parents Over Platforms Act Age assurance through app-distribution infrastructure Preempts No
RESET Teens Act Restricts minors’ accounts and requires deletion Preempts No
Parental Rights Relief Act FERPA/PPRA private litigation rights N/A Yes
Kids Internet and Digital Safety Act COPPA expansion, privacy/safety and advertising restrictions Preserves No
Sammy’s Law Third-party safety-software API access Preempts No
Youth AI Privacy Act AI chatbot privacy, profiling and model-training restrictions Preserves Yes
Parents Decide Act OS-level age verification and parental verification N/A No
Children’s Health, Advancement, Trust, Boundaries, and Oversight in Technology Act Child chatbot accounts, parental controls and advertising restrictions Preserves No
Safety and Age Filtering Enforcement for Kids Act Age verification plus retention/sale limits N/A Yes
SAFE KIDS Act AI age assurance, privacy restrictions, child-safety audits Preserves No

The underlying measures appear across four pages of the IAPP tracker.

Several distinct policy models are developing inside this category.

Model 1: Expand COPPA Beyond Under-13 Users

The Children and Teens’ Online Privacy Protection Act would extend privacy protections into the teen years and prohibit certain targeted marketing involving children and teens.

This would materially change the compliance boundary for online services.

Today’s familiar COPPA question is frequently:

“Is the user under 13?”

The emerging model increasingly asks:

“Is the user a minor?”

Those are not equivalent compliance obligations.

Model 2: Move Age Verification Into the Operating System or App Store

Some proposals attempt to solve the age-assurance problem at a different layer of the technology stack.

The Parents Over Platforms Act would require application-distribution providers to provide age-assurance capabilities and signals to developers.

The Parents Decide Act would place age collection and verification obligations on operating-system providers and make age information available to developers for verification purposes.

That could represent an important architectural change.

Instead of every website or application independently collecting a birth date or identity document, trusted infrastructure could potentially communicate an age signal.

But that raises another privacy problem:

How do you verify age without creating an enormous new identity dataset?

Age assurance therefore becomes a privacy-engineering problem itself.

Model 3: Regulate AI Chatbots Specifically

2026 also produced a new federal privacy category almost from scratch:

children interacting with AI chatbots.

The Youth AI Privacy Act would require chatbot safeguards, disclosures that users are interacting with AI, restrictions on profiling and personalization, and prohibitions against using minors’ data for model training.

Another proposal would require family accounts, parental consent and parental access to chatbot activity while restricting targeted advertising involving minors.

The bipartisan SAFE KIDS Act would require age assurance, child-safety-by-design measures, parental controls, risk assessments, crisis protocols and independent audits, while restricting advertising and certain uses of children’s personal information. Senators John Curtis and Adam Schiff introduced that measure on June 23.

This is a major change in the privacy discussion.

The legal issue is no longer merely:

Can an AI company collect a child’s information?

Congress is beginning to ask:

Can it train on it?

Can it personalize responses from it?

Can the AI deliberately increase engagement using it?

Can parents see what the system knows?

Can children’s information be used for advertising?

Those are much more specific product-design questions.

AI Privacy Is No Longer a Separate Category

One reason the federal landscape looks confusing is that AI regulation is being embedded inside ordinary privacy law.

At least several proposals in the tracker directly regulate algorithmic or AI activity:

Bill AI/privacy issue
AI Accountability and Personal Data Protection Act AI use of personal information and prior consent
Artificial Intelligence Civil Rights Act Algorithmic consequential decisions
AI Labeling Act AI-generated content disclosure
Online Privacy Act Human review of automated decisions
No Robot Bosses Act Automated workplace decisions
Kids Off Social Media Act Automated recommender systems
Youth AI Privacy Act Chatbot profiling, personalization and training
CHAT-related children’s legislation AI chatbot use by minors
SAFE KIDS Act AI chatbot safety, age assurance and privacy

The AI Labeling Act is a good example.

Introduced June 24, it would require disclosure around covered AI-generated content and machine-readable information identifying that content. GovInfo shows it was referred to the Senate Commerce Committee.

AI governance therefore should not be separated organizationally from privacy as though one team manages “data” and another manages “AI.”

The AI system runs on data.

Increasingly, the law recognizes that relationship.

Data Brokers Are Becoming a Regulatory Choke Point

Another recurring target is the data broker.

Congress is attacking broker activity from several directions.

The DELETE Act would create a centralized mechanism for people to request deletion from registered data brokers.

The Don’t Sell Kids’ Data Act would prohibit certain collection and disclosure of children’s and teens’ information by brokers.

The Health and Location Data Protection Act targets the transfer of health and location information.

The Kids Internet and Digital Safety Act would impose registration requirements on certain brokers dealing in minors’ data.

This suggests that federal privacy policy is increasingly differentiating between two relationships:

a company collecting information directly from its customer;

and an intermediary accumulating information about people with whom it has no direct relationship.

That distinction already exists in multiple state regimes. Congress appears increasingly interested in it as well.

Data Minimization Is Quietly Becoming One of the Most Important Federal Privacy Concepts

Cookie banners and consumer opt-outs receive enormous attention because users can see them.

Data minimization may ultimately matter more operationally.

The concept appears repeatedly across the proposals.

The Online Privacy Act expressly imposes minimization obligations.

The My Body, My Data Act applies minimization to reproductive and sexual-health information.

The proposed financial legislation would limit nonpublic personal information to what is adequate, relevant and reasonably necessary for a specific purpose.

This is a meaningful evolution from an older privacy model centered primarily on notice.

A business can write an accurate privacy policy describing extensive data collection.

Minimization asks a different question:

Why are you collecting it at all?

That question reaches architecture, analytics, advertising, AI training, retention and vendor integrations.

What Has Actually Passed?

One of the easiest mistakes when looking at a tracker this large is treating proposed legislation as though all of it is on the verge of becoming law.

It is not.

Most of the tracked measures remain proposals.

Two have crossed the entire legislative process.

TAKE IT DOWN Act

The TAKE IT DOWN Act became Public Law 119-12 on May 19, 2025. It addresses the intentional disclosure of nonconsensual intimate visual depictions, including qualifying digitally generated content, and imposes removal-related obligations on covered platforms.

Homebuyers Privacy Protection Act

The Homebuyers Privacy Protection Act became Public Law 119-36 on September 5, 2025.

It modifies the Fair Credit Reporting Act to restrict certain “trigger lead” practices associated with residential mortgage transactions.

The tracker also identifies the Advancing Digital Support for Mental Health Services Act as having passed the Senate as of its September update.

Everything else should be treated according to its actual legislative status, not as an enacted obligation.

2026 Federal Privacy Landscape

Trying to predict which of 49 proposals becomes law is less useful than looking at what keeps recurring across otherwise unrelated bills.

Several requirements appear again and again:

Recurring requirement Where it appears
Access and deletion Comprehensive bills, health privacy, children’s privacy
Data minimization Comprehensive privacy, reproductive health, financial data
Sensitive-data restrictions Consumer, health, children
Consent AI, connected vehicles, children’s data, health
Automated-decision transparency Consumer AI, employment
Human review Consumer privacy and algorithmic decision-making
Targeted-ad restrictions Children and teens
Age assurance Children’s platforms, operating systems, AI
Data-broker restrictions Consumer, health, children
Privacy/security assessments AI and children’s systems
Default privacy settings Children’s platforms
Restrictions on AI training Youth AI
Independent auditing AI child-safety legislation

This is where privacy programs should concentrate.

A company does not need to redesign its entire compliance program every time a member of Congress introduces a bill.

But if the same operational control appears in state privacy laws, proposed federal laws and emerging AI rules, it is increasingly difficult to treat that control as an edge case.

Where Should Privacy Teams Focus?

The practical compliance architecture emerging from all of this legislation is surprisingly consistent.

First, organizations need an accurate inventory of what data they collect and where it goes.

That sounds elementary. It is not.

Websites can add advertising scripts, pixels, SDKs and analytics services without the privacy department knowing. Mobile applications communicate with third parties. AI tools ingest internal information. Marketing teams change tags. Vendors change behavior.

A privacy policy cannot accurately disclose a data flow nobody has identified.

Second, consent and preference signals need to affect actual technical behavior.

If someone opts out of targeted advertising, sends Global Privacy Control or refuses a category of cookies, the question is not merely whether the preference was recorded.

Did the relevant processing stop?

Third, organizations need to classify sensitive information more intelligently.

Health information does not exist exclusively in a medical-record field.

Location can reveal health activity.

Search queries can expose medical interests.

Browsing activity can reveal religion or sexuality.

Purchases can expose financial or health characteristics.

AI prompts can contain nearly anything.

Fourth, companies need to know where automated decisions are being made.

That includes hiring.

Credit.

Insurance.

Employee evaluation.

Recommendations.

Pricing.

Eligibility.

AI agents acting for customers.

The legislative trend is toward more transparency and, in some proposals, opportunities for human involvement.

Finally, privacy evidence matters.

Organizations increasingly need to be able to establish what configuration existed at a particular time:

what cookies fired;

what consent was obtained;

which policy was displayed;

which GPC signal was received;

which vendors were active;

what information was transferred;

and when a configuration changed.

That is very different from simply maintaining a privacy policy.

Federal Privacy Law May Arrive in Pieces

For years, discussion of U.S. privacy legislation has centered on one question:

When will Congress finally pass America’s GDPR?

The 119th Congress suggests that may be the wrong way to look at it.

Congress could still pass comprehensive privacy legislation.

The Online Privacy Act, Consumer Data Privacy and Security Act and SECURE Data Act prove that the idea remains active.

But federal privacy regulation is also being assembled piece by piece.

A deepfake law has already passed.

A mortgage-data law has already passed.

Congress is considering separate rules for health and location information, children, chatbots, employee surveillance, connected cars, financial minimization, data brokers and automated decision systems.

Some proposals preserve state privacy regimes.

Others would displace them.

Some rely on regulators.

Others allow individuals to sue.

Some regulate the collection of information.

Others regulate what algorithms may do with information after it has been collected.

That is the real story of federal privacy legislation in 2026.

The United States may eventually enact one broad national privacy statute.

But businesses cannot assume that federal privacy regulation will wait for that moment.

Congress is already constructing the pieces.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.