Why Is There No Federal Privacy Law in the US? The Two Disputes That Kill Every Bill, and the Money Behind Them

Why is there no federal privacy law in the US? Two specific disputes, over who preempts whom and who gets to sue, have killed every serious bill, and the groups that benefit from the stalemate spend heavily to keep them unresolved. It is not for lack of bills, and Congress has passed sweeping technology statutes when it wanted to. By legal scholar Graham Greenleaf's running global census, 172 countries had enacted comprehensive data privacy laws by March 2025. When India's act passed in 2023 it became, by the Future of Privacy Forum's count, the 19th G20 member with one, which leaves the United States alone in that group. What America has instead is a sectoral patchwork (HIPAA for health records, COPPA for children, the FCRA for credit files) plus comprehensive statutes in 23 states. Twenty of them are in force on MultiState's count, which includes Florida's narrower Digital Bill of Rights. Leave Florida out and it's 19 in force, count it and the enacted total becomes 24. Either way, none of them reaches across a state line.

The usual explanations (Congress is slow, privacy is complicated, the parties disagree) are all true and all insufficient. A comprehensive bill once cleared committee 53–2. Something more specific is going on. America invented modern privacy law and then declined to apply it to its own economy. Two poison pills have killed every comprehensive federal privacy law proposed since, the constitutional terrain has been re-graded against privacy regulation, and the lobbying strategy behind the stalemate was borrowed from the tobacco industry. The money behind it is public record.

America wrote the rules it never adopted

The United States founded the field, and then wrote rules for the world that it declined to impose on itself.

In 1973 an advisory committee of the Department of Health, Education, and Welfare published Records, Computers, and the Rights of Citizens, the report that first articulated the Fair Information Practice Principles: no secret record systems; people must be able to see what is held about them and correct it; data collected for one purpose must not be reused for another without consent; organisations holding data must keep it reliable and prevent misuse. Those principles became the skeleton of everything that followed. The OECD's 1980 Privacy Guidelines drew on them, European data-protection law absorbed and extended them, and the GDPR is, at bottom, the HEW committee's principles with a Brussels enforcement apparatus attached.

Congress then enacted the Privacy Act of 1974, and the Privacy Protection Study Commission's own assessment records the fork in the road. The Senate bill, S. 3418, introduced by Sam Ervin, would have created a Federal Privacy Board with authority reaching beyond federal agencies. The board "was strongly opposed by the Executive branch, and by the House," and in the final week of the post-Watergate Congress, with no conference committee, it was stripped out and the law's scope was cut to federal agencies only. The private sector was left untouched on the theory that a study commission would revisit the question. It reported in 1977. Congress never acted.

That 1974 decision is the American privacy settlement. The industry of brokers that trades in Americans' data today operates in the space that week left open, and no general law has closed it since.

Does the US have a federal privacy law at all? Only sectoral ones, built by anecdote

With the general question settled by default, American privacy law developed a method: it responds to incidents. Each sectoral statute is a fossil of the scandal that produced it.

The Fair Credit Reporting Act (1970) answered a decade of stories about secret credit files. FERPA (1974) covered student records. The Right to Financial Privacy Act (1978) answered United States v. Miller on bank records, the Cable Act (1984) covered viewing habits, and the Electronic Communications Privacy Act (1986) updated wiretap law. Then in 1987, during Robert Bork's Supreme Court confirmation, a Washington City Paper reporter obtained the judge's video-rental history from his local store and published it. Congress passed the Video Privacy Protection Act (1988) quickly, and the Senate report on the law recounts the Bork episode as its origin. The Driver's Privacy Protection Act (1994) followed the murder of actress Rebecca Schaeffer, whose killer got her home address through DMV records. HIPAA (1996), COPPA (1998) and Gramm-Leach-Bliley (1999) rounded out the century. Beneath all of them sits Section 5 of the FTC Act, which declares "unfair or deceptive acts or practices in or affecting commerce" unlawful and which the FTC has stretched into its general-purpose privacy tool. It reaches a company that breaks its own privacy promise. It says nothing about what the promise has to be, and the Privacy Act of 1974 binds federal agencies only. That is the whole federal data privacy law of the United States.

The method has two properties. It produces rules calibrated to the last scandal and silent on the next one: your VHS-era rentals still have stronger federal statutory protection than your real-time phone location. And it produces statutes at the moment of maximum anecdote and minimum system. The Congressional Research Service's survey of federal data protection law is a catalogue of these fossils, prefaced by the observation that no comprehensive statute exists. Five decades in, an entire data-brokerage economy operates in the seams between the sectors: too diversified to be a credit bureau, not a doctor, not a school, not a video store.

The sectoral privacy laws in the United States, and the gap each one leaves

Each statute below is linked to its text. The right-hand column is the part the summaries skip.

Law Year What it covers Who enforces it The gap it leaves
FTC Act, Section 5 1914 "Unfair or deceptive acts or practices in or affecting commerce" The FTC alone. Under subsection (m) a civil penalty needs a violated trade rule or a violated order, so a first offence ends in a consent order rather than a fine Polices whatever promise a company chose to make. Sets no rule about what may be collected or sold, and gives you no right to sue
Fair Credit Reporting Act 1970 Consumer reports used for credit, employment, insurance and housing decisions, and the agencies that compile them The CFPB and the FTC under 15 U.S.C. 1681s, plus a private suit with $100 to $1,000 in statutory damages for a willful violation Reaches only a "consumer reporting agency." People-search sites disclaim that status on every page, which keeps the same file, sold for curiosity, outside the Act
Privacy Act 1974 Records federal agencies keep about you: access, correction, limits on disclosure A civil suit against the agency in federal court Federal agencies only. No company is covered
FERPA 1974 Education records at schools that take federal money The Department of Education, by threatening the funding No private right of action, per Gonzaga v. Doe (2002). Ed-tech vendors are reached only through the school's contract
ECPA 1986 Interception of calls, email and messages in transit, and stored communications Criminal prosecution, plus a private suit under 18 U.S.C. 2520 with statutory damages of at least $10,000 One party's consent defeats it. Silent on what the recipient does with the message afterwards
Video Privacy Protection Act 1988 Disclosure of what you rented or streamed by a "video tape service provider" Private suit only, with liquidated damages of $2,500 Video and nothing else. Your location history, purchases and searches have no equivalent statute
TCPA 1991 Robocalls, autodialled texts and junk faxes The FCC, state attorneys general, and a private suit for $500 per call, up to triple if willful Regulates the call, not the list. Buying and selling your number is untouched
HIPAA 1996 Health information held by health plans, clearinghouses, and providers that bill electronically HHS, with civil penalties under 42 U.S.C. 1320d-5. No private right of action "Covered entities" only. A period-tracking app, a fitness wearable, or a search for a symptom is outside it
COPPA 1998 Online collection of personal information from children under 13, which needs verifiable parental consent The FTC and state attorneys general under 15 U.S.C. 6505 Stops at the 13th birthday. A 14-year-old has the same federal protection as an adult, which is none
Gramm-Leach-Bliley 1999 Sharing of "nonpublic personal information" by financial institutions with nonaffiliated third parties The CFPB, the banking regulators and the FTC under 15 U.S.C. 6805 Opt-out rather than opt-in, sharing among affiliates is not restricted at all, and there is no private right of action

Why is there no federal privacy law in the US? The two poison pills

Many bills have tried to be comprehensive, and the recent ones died identically. Every serious federal privacy bill of the last five years has been killed by some combination of two questions that sound procedural and are actually the whole fight.

Preemption, meaning whether the federal law wipes out state privacy laws. Industry's answer is yes: one national standard instead of a two-dozen-state patchwork, which is genuinely expensive to comply with. Privacy advocates' answer is only if the federal floor is at least as high as California's, which no industry-supported bill has been. Lawmakers from strong-privacy states won't vote to strip their own residents of protections they already have; industry won't support a bill that leaves state laws standing. This dispute did more than any other to kill the American Data Privacy and Protection Act, the high-water mark of the whole effort, which cleared the House Energy & Commerce Committee 53–2 on July 20, 2022 and never received a floor vote, with California's objections front and centre.

The private right of action, meaning whether a person a company has wronged can sue, or whether enforcement is reserved to the FTC and state attorneys general. Ahead of the June 27, 2024 markup of the American Privacy Rights Act, ADPPA's successor, the CEOs of the ANA and the 4As wrote to congressional leadership against the bill, listing its private right of action among their objections alongside its limits on targeted advertising. The markup was cancelled and APRA died without a vote. It expired with the 118th Congress in January 2025 and has not been reintroduced in the current one.

The pattern is older than both bills. Washington State's legislature ran the experiment three times in miniature: the Washington Privacy Act passed the state Senate in 2019, 2020 and 2021 and died in the House each year because the two chambers could not agree on enforcement, with the private right of action the recurring split. Washington then passed the My Health My Data Act in 2023 with one, which suggests the obstacle was never drafting difficulty.

Every serious federal privacy bill since 2019, and where each one stopped

Read top to bottom, the table is the timeline. Each bill's answer to the two questions is taken from its own text on govinfo.gov, not from a summary.

Bill Sponsor Introduced Preempts states Right to sue Furthest stage What stopped it
Online Privacy Act of 2019, H.R. 4978 Eshoo, with Lofgren Nov 5, 2019 (116th) No Yes, enforced alongside a new Digital Privacy Agency Referred to Energy and Commerce and Judiciary No hearing in either committee
Data Care Act, S. 2961 Schatz, with 15 cosponsors Dec 2, 2019 (116th) No preemption clause No. FTC and state attorneys general Referred to Commerce Never scheduled by a Commerce Committee whose chairman was writing his own bill
Consumer Online Privacy Rights Act, S. 2968 Cantwell, with Schatz, Klobuchar and Markey Dec 3, 2019 (116th) No. Section 302 preserves state law Yes. Section 301(c), $100 to $1,000 per violation per day Commerce hearing, Dec 4, 2019 Opposite of the chairman's bill on both questions. Died with the Congress
Consumer Data Privacy and Security Act, S. 3456 Moran, no cosponsors Mar 12, 2020 (116th) Yes, "express preemption" No. "There shall be no private right of action under this Act" Referred to Commerce No hearing
SAFE DATA Act, S. 4626 Wicker, with Thune, Blackburn and Fischer Sep 17, 2020 (116th) Yes. Section 405: no state may "adopt, maintain, enforce, or continue in effect" a privacy law No. Enforcement by the FTC and state attorneys general only Commerce hearing, Sep 23, 2020 Mirror image of COPRA on both questions. Neither moved, and both died in January 2021
Online Privacy Act of 2021, H.R. 6027 Eshoo Nov 18, 2021 (117th) No Yes Referred to three committees No hearing
American Data Privacy and Protection Act, H.R. 8152 Pallone, with McMorris Rodgers, Schakowsky and Bilirakis Jun 21, 2022 (117th) Yes. Section 404(b), with a list of carve-outs Yes, but only from two years after the Act took effect (Section 403) Reported by Energy and Commerce 53-2 on Jul 20, 2022, H. Rept. 117-669 Speaker Pelosi sided with California on Sep 1, 2022: the bill "does not guarantee the same essential consumer protections as California's existing privacy laws." No floor vote
Online Privacy Act of 2023, H.R. 2701 Eshoo Apr 19, 2023 (118th) No Yes Referred to four committees No hearing
American Privacy Rights Act, H.R. 8818 McMorris Rodgers, with Pallone, Bilirakis and Schakowsky, drafted with Sen. Cantwell Draft Apr 7, 2024, bill Jun 25, 2024 (118th) Yes. Section 118 Yes, limited to listed sections (Section 117) Full-committee markup noticed for Jun 27, 2024 Markup cancelled two days after introduction. Expired Jan 3, 2025, not reintroduced
Online Privacy Act, H.R. 8014 Lofgren Mar 19, 2026 (119th) No. Section 503 leaves state law standing except where directly inconsistent Yes. Section 405 Referred Single sponsor, no action as of Sep 15, 2026
Consumer Data Privacy and Security Act, S. 4211 Moran Mar 25, 2026 (119th) Yes, "express preemption" No, in the same words as the 2020 bill Referred to Commerce No cosponsors, no hearing
SECURE Data Act, H.R. 8413 Joyce, with eight Republicans Apr 21, 2026 (119th) Yes. Section 15 No Subcommittee hearing, Jun 3, 2026 Sixteen attorneys general opposed it the day before. No markup scheduled

Every bill that preempts the states drops the right to sue, and every bill that keeps the right to sue leaves the states alone. Nothing in the middle has been filed since ADPPA.

Why the private right of action is the whole fight

Industry treats the right to sue as existential for reasons that rarely get laid out together: what the FTC actually is, what happened in Illinois, and what the Supreme Court has been doing in the background.

The FTC is smaller than its reputation. The agency industry proposes as the exclusive enforcer of American privacy law told Senate appropriators, in its own 2020 report, that it had 40 to 45 employees in its privacy and identity protection division, and compared itself with the United Kingdom's Information Commissioner's Office, a single country's data regulator, at about 700 staff. The FTC also can't write privacy rules the way other agencies write rules: its Magnuson-Moss procedure layers extra notices and trial-type hearings on top of ordinary rulemaking, and the one time the agency tried anyway, the August 2022 "Commercial Surveillance and Data Security" proceeding, it collected comments and never issued a proposed rule. Proposing this agency as sole enforcer, for an economy of thousands of data companies, is a position on enforcement dressed as a compromise.

Illinois ran the natural experiment. There is one American privacy statute with a strong private right of action attached to real statutory damages: the Illinois Biometric Information Privacy Act of 2008. The Illinois Supreme Court held in Rosenbach v. Six Flags (2019) that a violation itself makes a person "aggrieved," with no further injury required. What followed: Facebook paid $650 million to Illinois users over face-tagging, approved in 2021. In Cothron v. White Castle (2023) the court held that a claim accrues with every scan, with White Castle estimating its potential exposure at more than $17 billion. And Clearview AI, which scraped billions of faceprints, agreed to a class settlement so large relative to the company that it was structured as a 23% equity stake. The White Castle number triggered the backlash: Illinois amended BIPA on August 2, 2024 so that repeated identical collections count as a single violation, and the Seventh Circuit vacated the Clearview settlement on July 13, 2026 over class-representation defects, sending it back to the district court. But the decade in between is the point. The only privacy law in America that large companies demonstrably fear, budget for and change behaviour over is the one ordinary people can enforce themselves. That is what "no private right of action" is designed to prevent.

The Supreme Court has been narrowing the door anyway. Even where Congress grants a right to sue, the Court has been re-grading the terrain. In Spokeo v. Robins (2016) it held that a statutory violation alone doesn't guarantee standing. The plaintiff, fittingly, was suing a people-search site over a false profile. In TransUnion LLC v. Ramirez (2021), a 5–4 Court held that of 8,185 class members TransUnion had falsely flagged as potential terrorists, only the 1,853 whose reports had been sent to a third party had standing; the other 6,332 had suffered, in the Court's words, "No concrete harm, no standing." Add Sorrell v. IMS Health (2011), which struck down a Vermont law restricting the sale of prescriber data because "speech in aid of pharmaceutical marketing... is a form of expression protected by the Free Speech Clause," and the shape is visible: data sales lean toward protected speech, database harms lean toward non-injuries. NetChoice's challenge to California's Age-Appropriate Design Code has kept parts of that law enjoined since 2023 on First Amendment theories that EPIC describes as demanding "an exacting level of scrutiny no privacy law could survive". In March 2026 the Ninth Circuit narrowed the injunction but left the law's data-use restrictions and dark-patterns ban blocked. Any federal privacy law that passes will land on this terrain, which makes the enforcement question sharper rather than moot.

The playbook: what Big Tobacco taught Big Tech

In October 2024 the ACLU of Northern California published an analysis titled "Big Tech is Trying to Burn Privacy to the Ground, and They're Using Big Tobacco's Strategy to Do It," and the EFF published a companion the same month, "Preemption Playbook: Big Tech's Blueprint Comes Straight from Big Tobacco." The play they describe, drawn from tobacco's 1990s campaign to preempt state indoor-smoking laws, has three steps.

Flood the states with weak bills. Don't fight state privacy legislation. Author it. The Reuters special report "Amazon wages secret war on Americans' privacy" (November 2021) documented, from internal company records, that Amazon's lobbying operation had killed or weakened privacy bills in 25 states, and that Virginia's 2021 law, the first after California's, was a bill the company itself had drafted. The Virginia model, rights on paper, broad exemptions, no private right of action, then propagated. When EPIC and U.S. PIRG graded every state privacy law in their State of Privacy 2025 report, nearly half of the 19 laws received an F, none received an A, and "the vast majority closely follow a model that was initially drafted by industry giants such as Amazon." The scale of the operation is in the industry's own words: TechNet, whose members include Amazon and Apple, states on its policy page that in 2025 its state team "engaged on 808 bills across 50 states, Washington D.C., and Puerto Rico, with our policy position prevailing 87 percent of the time." The Markup counted 445 lobbyists and lobbying firms representing Amazon, Apple, Google, Meta, Microsoft and their trade groups across 31 states since 2021. Issue One's March 2026 study of seven statehouses, Laboratories of Capture, found the same machinery still running: lobbyists supplying full bill text modelled on Virginia's, and competing alternatives appearing whenever a stronger bill gains traction. One Connecticut legislator told The Markup that the hearing room for his privacy bill was "literally filled with every single lobbyist I've ever known in Hartford, hired by companies to defeat the bill."

Then brandish the patchwork. Having authored much of the patchwork's weakness and all of its multiplicity, industry then points at it as the problem: two dozen different laws, compliance chaos, small businesses drowning. Multistate compliance is genuinely expensive, but the patchwork is the campaign's output, repurposed as its argument.

Cash in the crisis for preemption. With the patchwork established as an emergency, offer the solution: one federal law that overrides the states, pitched at the level of the weakest state bills the industry drafted, minus a private right of action. As the ACLU's Jake Snow put it, "Federal law should establish a foundation that cities and states can build on, not a ceiling blocking all future progress." Tobacco never got its preemptive federal ceiling. Congress held. The open question of this decade is whether it holds again.

Once you have the playbook, the public record reorganises itself around it. Tim Cook stood in Brussels in 2018, denounced the "data-industrial complex" and endorsed "a comprehensive federal privacy law in the United States." Sundar Pichai wrote in the New York Times that "privacy cannot be a luxury good." Both statements were specific: the federal law being requested was always a ceiling. The ask was never "no law." The ask was one law, written once with maximum industry input, that turns off the states for good, which lets a company campaign for privacy while working to cap it.

The money behind privacy lobbying, itemised

Strategy needs a budget, and the budget is public. In 2024, a record year for federal lobbying overall, OpenSecrets data compiled by Issue One shows Meta spending $24.4 million on federal lobbying (its own record), Alphabet $14.8 million and Microsoft $10.4 million. Those figures cover all issues, and the state-level operation described above runs on top of them.

Where the corporate name is a liability, the argument arrives under friendlier letterhead. The Connected Commerce Council presented itself as a grassroots coalition of small businesses opposing tech regulation until a spokesman confirmed to CNBC in 2022 that its funders were Google and Amazon. Dozens of the small businesses in its member directory told Politico the same month that they had never heard of it. The App Association says it represents thousands of small developers. It confirmed to Bloomberg in 2022 that more than half of its roughly $9 million in sponsorship revenue came from Apple, which is not a member. And the advertising trade groups say the quiet part at full volume: the ANA's top lobbyist dismissed private rights of action, in a line preserved by The Markup, as "a bonanza for the trial bar," and the IAB told a House committee that laws targeting data-driven advertising "would destroy jobs and the U.S. economy."

None of this is illegal. All of these organisations dispute the "anti-privacy" label, and most say they support federal privacy legislation. The dispute is over the two poison pills, and on those the record is consistent. The bills these groups support preempt the states and lack a private right of action; the bills they oppose do not.

Is a federal privacy law coming in 2026? The SECURE Data Act and the Online Privacy Act

Probably not this year, but the current Congress offers the cleanest side-by-side yet of the two competing visions, and a Senate bill on the side.

The SECURE Data Act (H.R. 8413), introduced on April 21, 2026 by Rep. John Joyce with eight Republican cosponsors, came out of the privacy working group Energy & Commerce chairman Brett Guthrie set up in 2025. It is step three of the playbook filed as legislation: a national standard that preempts state privacy laws and contains no private right of action, leaving enforcement to the FTC and state attorneys general, with a 45-day cure period before any penalty. The Electronic Frontier Foundation's review ran under the headline "The SECURE Data Act is Not a Serious Piece of Privacy Legislation." On June 2, 2026, California Attorney General Rob Bonta led a coalition of 16 attorneys general, plus the California Privacy Protection Agency and Hawai'i's consumer protection office, in a letter opposing the bill on the ground that it would erase stronger state protections, state data broker registries among them. A subcommittee hearing the next day split along party lines, and as of mid-September 2026 the bill has had no markup.

The Online Privacy Act (H.R. 8014), reintroduced by Rep. Zoe Lofgren on March 19, 2026, is the maximal alternative: an independent Digital Privacy Agency to supply the enforcement capacity the FTC lacks; a private right of action; data minimisation, so companies may collect no more than the service requires; and a "right to impermanence" limiting retention. It has a single sponsor and no committee action, as its 2019, 2021 and 2023 versions did before it. In the Senate, Jerry Moran's Consumer Data Privacy and Security Act (S. 4211), introduced March 25, 2026, sits in the Commerce Committee with no cosponsors.

None of the three is likely to become law this session. For the groups that prefer no law to a strong one, that outcome is fine, and it comes up for renewal every Congress. Ask why there is no federal privacy law in the US in 2026 and the answer is the one from 2022 and 2024: preemption and the right to sue, still unresolved.

Privacy preemption is the prize, and why it keeps every bill stuck

Everything protecting an American's data today is state law, and the states' story explains the ferocity of the federal fight.

California got its law by accident of direct democracy. Real-estate developer Alastair Mactaggart spent roughly $3 million qualifying a privacy initiative for the 2018 ballot, and with polls favouring it the legislature drafted and passed the CCPA in about a week, signed on June 28, 2018, in a deal to keep the stronger measure off the ballot. Mactaggart returned in 2020 with Proposition 24, which created the CPRA and the country's only dedicated privacy agency. The one strong state law exists because a single wealthy citizen created a credible threat outside the legislature, where the lobbying playbook has no purchase. Virginia's law, the Amazon draft, arrived the following year as the template for containing that contagion, and per EPIC and PIRG's grading, containment has largely worked. The exceptions prove the pattern: Illinois's BIPA predates the playbook, and Washington passed a health-data law with a right to sue after industry killed its comprehensive bill three years running. And California keeps compounding. Its Delete Act platform, one free request ordering every registered data broker to delete your data, opened in January 2026, and brokers have been required to process those requests since August 1.

Read from the industry side, this is a slowly losing battlefield: fifty legislatures, ballot initiatives that can't be lobbied, one state whose private right of action produces nine- and ten-figure exposure, and another running a deletion platform with fines attached. Preemption is the only move that wins all fifty boards at once. That, rather than tidiness or small-business compassion, is why every industry-backed federal bill contains it. A strong national law is worse for the lobby than no law, but a preemptive weak law is better than either, and that is the bill industry keeps filing.

US privacy law vs GDPR: the costs of the vacuum, quantified

People search for the US equivalent of GDPR, and there isn't one. The closest thing is California's CCPA and CPRA, which cover one state's residents, run on opt-out rather than opt-in consent, and set penalties per violation rather than as a share of global revenue. Three numbers make the gap concrete.

The consent regime doesn't work, measurably. The patchwork's governing theory is notice and choice: companies disclose, you choose. Aleecia McDonald and Lorrie Cranor calculated in 2008 that merely reading the privacy policies an American encounters in a year would take roughly 201 hours per person, a national opportunity cost they put at $781 billion a year, before smartphones. In Obar and Oeldorf-Hirsch's "The Biggest Lie on the Internet" experiment, 74% of participants joining a fictitious social network skipped the policies entirely, and 98% of those who "read" them missed the clauses agreeing to hand over their firstborn child and share their data with the NSA. Every industry-preferred bill re-enacts this model.

Enforcement is two orders of magnitude apart. Since 2018, European regulators have issued a cumulative €7.1 billion in GDPR fines, €1.2 billion of it in 2025 alone. The FTC's largest privacy penalty remains the $5 billion Facebook order of 2019, an enormous number that was also a one-off produced by a consent-decree violation. One regime produces continuous pressure; the other has produced one very large fine in seven years.

The vacuum has trade costs too. Twice the EU's top court has struck down the legal bridge carrying transatlantic data, Safe Harbor in 2015 and Privacy Shield in 2020, each time because US law offered inadequate protection and redress. The third bridge, the Data Privacy Framework, survived its first challenge at the EU General Court on September 3, 2025, but that judgment is under appeal to the Court of Justice, and every American business moving European data lives with the recurring risk. Meanwhile the "US alone" framing stopped being rhetorical some time ago: with Saudi Arabia (2021), Indonesia (2022) and India (act in 2023, rules notified in November 2025), the rest of the G20 has finished the job.

GDPR vs US privacy law, side by side

GDPR (EU, in force 2018) Federal US law California CCPA and CPRA
Legal basis for processing Required. One of six lawful bases under Article 6, consent being one of them None required. Collection is lawful unless a sectoral statute says otherwise None required. The consumer gets rights after the fact
Who is covered Any organisation processing the data of people in the EU, wherever the organisation sits (Article 3(2)) Depends on the sector: a bank, a hospital, a school, a video store Businesses over revenue or data-volume thresholds, for California residents only
Your rights Access, correction, erasure (Article 17), objection (Article 21), portability, and notice within a month when your data was obtained from someone else (Article 14) Access and correction of a credit file under the FCRA, access to federal agency records, otherwise nothing general Know, delete, correct, opt out of sale and sharing, limit use of sensitive data
Enforcement body A dedicated supervisory authority in every member state (Article 51), which must take your complaint (Article 77) The FTC's privacy division, 40 to 45 staff in 2020 The California Privacy Protection Agency and the attorney general
Maximum penalty €20 million or 4% of worldwide turnover, whichever is higher No general penalty. Section 5 civil penalties only for rule or order violations $2,500 per violation, $7,500 if intentional or involving under-16s, before inflation adjustment
Private action Yes. Article 82 gives compensation for material or non-material damage Only under a sectoral statute that provides one (FCRA, VPPA, TCPA, ECPA) Only for data breaches, $100 to $750 per consumer per incident
Data brokers No special category. Article 14 makes them tell you what they hold, and the erasure right applies to them No federal definition, no registry Registration and, since 2026, the DROP deletion platform

Frequently asked questions about the missing federal privacy law

Does GDPR apply to Americans?

In one direction only. GDPR reaches any company, American ones included, that offers goods or services to people in the EU or monitors their behaviour there (Article 3(2)), which is why US sites show cookie banners to European visitors. It gives no rights to a person in the United States. The same company's file on an American is governed by whichever state law applies, or by none.

Is the American Privacy Rights Act still alive?

No. The Cantwell and McMorris Rodgers draft was released on April 7, 2024, introduced as H.R. 8818 on June 25, 2024, and lost its markup two days later. It expired when the 118th Congress ended on January 3, 2025, and nothing under that name has been filed since. The 119th Congress bills split its two provisions between them: the SECURE Data Act keeps the preemption and drops the right to sue, and the Online Privacy Act does the reverse.

Does the Privacy Act of 1974 protect you from companies?

It does not. 5 U.S.C. 552a governs records that federal agencies keep about you. You can see them, ask for corrections, and sue the agency if it discloses them unlawfully. A data broker, a bank or an app is not an "agency." The Senate version would have reached the private sector through a Federal Privacy Board, and that was the part stripped out in the final week of 1974.

Can you sue a company for selling your data?

Not under any general federal law. You can sue under a sectoral statute that provides for it: a consumer reporting agency under the FCRA ($100 to $1,000 for a willful violation), a video service under the VPPA ($2,500), a robocaller under the TCPA ($500 per call), or an Illinois company that scanned your face under BIPA. Under the CCPA you can sue only over a data breach, at $100 to $750 per incident. A European can sue any controller for material or non-material damage under Article 82 of GDPR.

Why doesn't the FTC simply fine companies that sell your data?

Because Section 5 lets it stop unfair or deceptive practices, not fine them at first sight. Under subsection (m) a civil penalty needs a violated trade rule or a violated order, and the FTC has no general privacy rule. The $5 billion Facebook penalty of 2019 rested on a 2012 consent order. A first-time case ends in a consent order, and the money, if any, comes years later when the order is broken.

Which law covers a people-search site?

None of the sectoral ones, by design. A people-search site is not a credit bureau unless it sells reports for FCRA purposes, not a health provider, not a school and not a financial institution, so the only federal hook is Section 5 if it breaks its own privacy policy. At state level, California defines a data broker as a business that sells the personal information of people it has no direct relationship with, and makes it register. That definition, and the registries built on it, are among the state protections the SECURE Data Act would override.

What this means for you today

So why is there no federal privacy law in the US after five decades of trying? Because the lobby that could end the deadlock prefers the deadlock to any bill it didn't write, and the advocates who could end it prefer no law to a preemptive weak one. Until that resolves, and the honest forecast is slowly, the levers available to an individual are the unglamorous ones: your state's privacy rights if you have them, California's deletion platform if you live there, and direct opt-outs from the data brokers holding your profile, which work in all fifty states because they depend on broker policy rather than statute.

In order of what to do first:

  1. Check whether your state has a law in force. Nineteen do today, 20 with Florida, and the state-by-state list names them along with the four whose laws start in 2027 and 2028. If yours is on it, a broker over the law's thresholds must honour a deletion or opt-out request, and your enforcer is the attorney general, not a court.
  2. If you live in California, file one DROP request. Every registered broker has had to process those since August 1, 2026. For sites that are not registered brokers, send a deletion request and an opt-out of sale under the CCPA directly, which an authorised agent can file for you.
  3. Use the FCRA where a site sells background reports. A site that markets reports for tenant, employment or credit screening is acting as a consumer reporting agency, and 15 U.S.C. 1681i obliges it to reinvestigate a disputed item free of charge within 30 days (45 if you send more evidence part-way through) and delete what it cannot verify. Put the dispute in writing, keep the date, and file a CFPB complaint if the deadline passes. People-search sites that disclaim FCRA use are outside this, which is why they disclaim it.
  4. Everywhere else, use the broker's own opt-out. Our opt-out guides cover the forms, the phone verifications and the Cloudflare walls site by site. Those routes rest on broker policy, so they work in all 50 states, and they decay for the same reason.
  5. Robocalls and texts are the one place a federal private right is cheap to use. The TCPA pays $500 per unlawful call or text, up to triple if willful, and small-claims court will do.

Two things from our own removal work show how much the state line matters in practice. Some people-search sites decide whether to honour an opt-out based on whether your state has a comprehensive privacy law at all: the automated denials quoted in the BBB complaints we read for our FastBackgroundCheck guide tell requesters they live "in a state that does not have a comprehensive consumer privacy law that applies to our data," and the listings came down only after an appeal citing a safety concern or a BBB complaint. And where a state does grant a right to delete, what you can ask for changes: PeopleConnect's Privacy Center offers a deletion route only for residents whose state law provides one. Everyone else gets suppression, which hides the report and leaves the underlying record in place. Understanding where those brokers get your data explains the catch either way: removals decay because the supply chain keeps flowing, so removal is a maintenance task rather than an event.

Delist My Data is being built to do that maintenance for you, including the re-filing when a listing comes back, for as long as the law leaves the job to you. We're in pre-launch. If you want founding-member access, the waitlist is open.

Sources

Find out which brokers are publishing your details.

No spam. One email when Delist My Data opens for your area.