US House Committee Advances Comprehensive Federal Privacy Bill With Power to Preempt State Laws
A bipartisan House committee has advanced sweeping federal privacy legislation that would establish nationwide data protections while overriding a patchwork of state-level laws. The bill introduces strict data minimization rules and gives consumers new rights to opt out of targeted advertising.
By Factlen Editorial Team
- Federal Standardization Advocates
- Argue that a single national privacy law is essential for innovation and compliance, preferring to eliminate the confusing patchwork of state regulations.
- State-Level Privacy Defenders
- Fear that federal preemption will water down robust protections already won in progressive states, acting as a ceiling rather than a floor for consumer rights.
- Consumer Baseline Supporters
- Focus on the massive upgrade in rights for the residents of the 35 states that currently have zero comprehensive data protections.
What's not represented
- · Small business owners facing new compliance costs
- · International data brokers operating outside US jurisdiction
Why this matters
For years, Americans' digital privacy has depended entirely on their zip code, with some states offering robust protections and others offering none. A federal law would standardize these rights nationwide, fundamentally shifting the burden of data protection from the consumer to the tech companies.
Key points
- The House Energy and Commerce Committee advanced a comprehensive federal privacy bill with bipartisan support.
- The legislation shifts the internet to a 'data minimization' model, restricting companies from collecting non-essential user data.
- The bill would preempt 15 existing state privacy laws, creating a single national standard that tech companies favor but state regulators oppose.
- Consumers would gain a 'private right of action' to sue companies over sensitive data violations, subject to a 30-day cure period.
- The use of sensitive data—including health, biometric, and precise location information—for targeted advertising would be strictly banned.
The US House Energy and Commerce Committee has overwhelmingly advanced a comprehensive federal privacy bill, marking the most significant legislative momentum for national data protection in nearly a decade. The bipartisan vote signals a growing consensus in Washington that the current unregulated data broker ecosystem requires federal intervention.[1]
The legislation, currently dubbed the American Privacy Rights Act of 2026, aims to establish a unified national standard for how companies collect, store, and monetize consumer data. If passed, the bill would fundamentally rewrite the rules of the internet economy, shifting the baseline of privacy from a consumer opt-in model to a default corporate restriction.[2][3]
At the heart of the legislation is a structural shift known as "data minimization." For the past two decades, the internet has operated on a "notice and consent" model, where companies write lengthy, opaque privacy policies and consumers must click "accept" to access a service, legally signing away their data rights in the process.
Under the new federal framework, companies would be legally restricted to collecting only the data strictly necessary to provide the specific product or service the consumer requested. The burden of proof shifts to the company to justify why a specific data point is required for functionality.[1]

For example, a digital flashlight application would no longer be permitted to collect, store, and sell a user's precise GPS location to third-party data brokers, regardless of what is buried in its terms of service. If the data is not needed to turn on the phone's LED light, its collection becomes a federal violation.[3]
The most contentious mechanism in the bill, however, is federal preemption. The legislation is explicitly designed to override the existing patchwork of state-level privacy laws, replacing them with a single, unified national rulebook that supersedes local legislation.[2][4]
Currently, 15 states have enacted their own comprehensive privacy frameworks. This has created a complex compliance nightmare for technology companies, who must build different data infrastructure for users in California, Colorado, and Virginia, while leaving residents of the remaining 35 states with virtually no digital rights.
Currently, 15 states have enacted their own comprehensive privacy frameworks.
Industry groups and major tech conglomerates have heavily lobbied for this preemption clause. They argue that a fragmented regulatory landscape stifles innovation and disproportionately burdens mid-sized tech firms that cannot afford massive legal and compliance teams to navigate 15 different state laws.[2]

Conversely, state regulators and digital rights organizations argue that federal preemption sets a "regulatory ceiling" rather than a floor. They warn that the federal bill, while an improvement for states with no laws, actively strips away stronger protections that citizens in progressive states have already voted for.
California lawmakers, in particular, have voiced strong opposition. They note that the federal bill lacks some of the stringent automated decision-making protections and algorithmic audit requirements currently enforced by the California Privacy Protection Agency under the state's existing laws.[4]
To bridge this partisan and geographic divide, the committee negotiated a delicate compromise regarding the "private right of action"—the legal mechanism that allows individual consumers to sue companies directly for privacy violations, rather than waiting for the Federal Trade Commission to act.[1]
The advanced bill allows consumers to file lawsuits against companies that illegally sell their sensitive data or suffer a negligent data breach. However, it mandates a 30-day "cure period," giving businesses a window to delete the data and fix the violation before facing class-action litigation.

The legislation also introduces strict new boundaries on the digital advertising ecosystem. It outright bans the use of sensitive data—such as health information, biometric scans, precise geolocation, and private communications—for targeted advertising under any circumstances.[3]
For non-sensitive data, the bill requires companies to provide a clear, standardized opt-out mechanism for targeted advertising. It also mandates that large data brokers register with the FTC and provide a "one-click" deletion tool allowing consumers to wipe their profiles from broker databases nationwide.[1][3]
While the committee vote represents a major milestone, the bill now faces a deeply divided Senate. Previous iterations of federal privacy legislation have historically stalled in the upper chamber over the exact balance of state preemption and the scope of consumer lawsuits, leaving the final fate of the 2026 act uncertain.[1][4]
How we got here
2018
California passes the CCPA, becoming the first US state to enact a comprehensive consumer privacy law.
2022
The American Data Privacy and Protection Act (ADPPA) advances out of committee but fails to reach a floor vote over preemption disputes.
2024
A renewed bipartisan effort introduces the American Privacy Rights Act, attempting to bridge the gap between state and federal enforcement.
July 2026
The House Energy and Commerce Committee advances the latest iteration of the bill, sending it toward a potential floor vote.
Viewpoints in depth
Tech Industry & Compliance Teams
Advocates for a single national standard to reduce the massive overhead of navigating fragmented state laws.
For the technology sector, the current landscape of 15 different state privacy laws is an unsustainable compliance burden. Industry groups argue that mid-sized startups are forced to spend millions on legal fees just to ensure their apps are legal across state lines. They view federal preemption as the only way to create a predictable regulatory environment that allows for software innovation without the constant threat of localized lawsuits.
State Regulators & Privacy Advocates
Warns that federal preemption will erase hard-won digital rights in progressive states.
Organizations like the Electronic Frontier Foundation and California state delegates argue that federal preemption is a Trojan horse. While it raises the baseline for states with no laws, it acts as a 'regulatory ceiling' that prevents states from passing stronger protections in the future. They point out that California's existing laws include strict algorithmic audits and automated decision-making opt-outs that the federal bill dilutes or ignores entirely.
Consumer Rights Groups
Celebrates the shift to data minimization and the establishment of baseline rights for all Americans.
National consumer advocacy groups focus on the structural shift away from 'notice and consent.' They argue that expecting consumers to read 50-page privacy policies is a failed experiment. By mandating data minimization at the federal level, the bill forces companies to stop hoarding unnecessary data by default, providing immediate, tangible protections to the millions of Americans living in states that currently offer zero digital privacy rights.
What we don't know
- Whether the deeply divided Senate will take up the bill before the end of the legislative session.
- How the Federal Trade Commission will be funded to handle the massive influx of new enforcement responsibilities.
- Exactly how courts will interpret the 'strictly necessary' clause for data minimization in complex software products.
Key terms
- Data Minimization
- A legal requirement that companies only collect the specific personal data absolutely necessary to provide the service the consumer is actively using.
- Preemption
- A legal doctrine where a federal law overrides and invalidates state-level laws on the same subject, creating a single national standard.
- Private Right of Action
- A provision allowing individual citizens to file lawsuits directly against companies that violate the law, rather than relying solely on government agencies to enforce it.
- Data Broker
- A business that aggregates information from various sources to create detailed profiles of consumers, which are then sold or licensed to other companies.
Frequently asked
Will this law delete the data companies already have on me?
Not automatically. However, it requires data brokers to provide a centralized 'one-click' deletion mechanism, allowing you to easily request the removal of your historical data.
Does this apply to small local businesses?
The strictest rules, including algorithm audits and executive certification, apply only to 'large data holders' (typically companies with over $25 million in revenue or processing millions of records), exempting most small businesses.
Can I still get targeted ads if I want them?
Yes. The law bans the use of sensitive data for ads entirely, but for general data, it operates on an opt-out basis. If you do nothing, you may still see targeted ads, but you will have a clear, standardized way to turn them off.
Sources
[1]ReutersFederal Standardization Advocates
House committee advances bipartisan federal privacy framework
Read on Reuters →[2]BloombergFederal Standardization Advocates
Tech Industry Cautiously Backs Federal Privacy Bill to Avoid State Patchwork
Read on Bloomberg →[3]TechCrunchConsumer Baseline Supporters
Sam Altman’s space data center trash talk is what most experts already believe
Read on TechCrunch →[4]The Washington PostState-Level Privacy Defenders
California lawmakers push back as federal privacy bill clears key hurdle
Read on The Washington Post →
Every angle. Every day.
Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.






