The United States' lack of a comprehensive federal privacy law is not an oversight, and it is not for lack of bills. It is the product of two specific, unresolved disputes — who preempts whom, and who gets to sue — kept unresolved, on purpose, by some of the best-funded lobbying operations in Washington and in all fifty statehouses. More than 170 countries have enacted comprehensive national data privacy laws, by legal scholar Graham Greenleaf's running global census; the United States is now the only G20 member country that has not enacted one. What America has instead is a sectoral patchwork — HIPAA for health records, COPPA for children, the FCRA for credit files — plus comprehensive privacy statutes in roughly twenty-one states, none of which reaches across a state line.
The usual explanations for this — Congress is slow, privacy is complicated, the parties disagree — are all true and all insufficient. Congress is slow, but it has passed sweeping technology statutes when it wanted to. Privacy is complicated, but 170 other legislatures managed. The parties disagree, but a comprehensive bill once cleared committee 53–2. Something more specific is going on, and this article is an attempt to map it completely: the strange history in which America invented modern privacy law and then declined to apply it to itself; the two poison pills that have killed every serious bill; the constitutional terrain that has been quietly re-graded against privacy regulation; the lobbying strategy — borrowed, near-verbatim, from the tobacco industry — that maintains the stalemate; and the documented money behind it. Every factual claim carries a citation to a primary source or a named investigation, because on this subject the record is damning enough without embellishment.
America invented the rules it never adopted
The deepest irony in this story is chronological: the United States is not a privacy laggard that never got around to the subject. It is the field's founder, twice over — and both times it wrote rules for the world that it declined to impose on its own economy.
The first founding is the famous one. In 1890, Samuel Warren and Louis Brandeis published "The Right to Privacy" in the Harvard Law Review — provoked, in part, by the new technologies of their day: "Instantaneous photographs and newspaper enterprise have invaded the sacred precincts of private and domestic life." The article is generally credited with inventing privacy as a legal concept, and it seeded a century of American tort law. It did not seed a statute.
The second founding is the one almost nobody knows, and it matters far more. In 1973, an advisory committee of the U.S. Department of Health, Education, and Welfare published Records, Computers, and the Rights of Citizens — the report that first articulated the Fair Information Practice Principles: there must be no secret record systems; people must be able to see what's held about them and correct it; data collected for one purpose must not be reused for another without consent; organizations holding data must ensure its reliability and prevent misuse. If those sound familiar, it is because they became the skeleton of everything that followed: the OECD's 1980 Privacy Guidelines drew directly on them, European data-protection law absorbed and extended them, and the GDPR is, at bottom, the HEW committee's American principles with a Brussels enforcement apparatus attached.
So what did America do with its own invention? Congress enacted the Privacy Act of 1974 — and here the record contains the fork in the road, documented in the Privacy Protection Study Commission's own assessment. The Senate bill, S. 3418, introduced by Sam Ervin, would have created a Federal Privacy Board with authority reaching beyond federal agencies to state and local government and other organizations. The enforcement board "was strongly opposed by the Executive branch, and by the House," and in the final week of the post-Watergate Congress — with no conference committee — the board was stripped out and the law's scope was cut down to federal agencies only. The private sector was left untouched, on the theory that a study commission would revisit the question. It reported; Congress never acted.
That 1974 decision is the American privacy settlement, and everything since has been a footnote to it: the United States applied the Fair Information Practices to its own government and exempted its economy. Fifty years later, the FIPs govern data processing in Berlin, São Paulo, Tokyo, and Nairobi — and not in the country that wrote them. When Americans ask why their data flows freely to an industry of brokers that no general law constrains, the honest answer begins in that final week of 1974.
Regulation by anecdote: how the sectoral patchwork actually got built
With the general question settled by default, American privacy law developed a distinctive method: it responds to incidents. Each sectoral statute is a fossil of the particular scandal that produced it, and reading the list chronologically is like reading a core sample of the country's embarrassments:
The Fair Credit Reporting Act (1970) answered a decade of horror stories about secret credit files. FERPA (1974) covered student records; the Right to Financial Privacy Act (1978) answered United States v. Miller on bank records; the Cable Act (1984) covered cable-viewing habits; the Electronic Communications Privacy Act (1986) updated wiretap law. Then comes the exhibit that proves the method. In 1987, during Robert Bork's Supreme Court confirmation, a Washington City Paper reporter obtained the judge's video-rental history — 146 titles — from his local store and published it. Congress, containing several hundred people who also rented videotapes, passed the Video Privacy Protection Act (1988) with remarkable speed; the Senate report on the law candidly recounts the Bork episode as its origin. In 1994 the Driver's Privacy Protection Act followed the murder of actress Rebecca Schaeffer, whose killer had obtained her home address through DMV records. HIPAA (1996), COPPA (1998), and Gramm-Leach-Bliley (1999) rounded out the century.
State the method plainly and its two properties become obvious. First, it produces rules exquisitely calibrated to the last scandal and silent on the next one: to this day, your VHS-era video rentals enjoy stronger federal statutory protection than your real-time phone location, because a judge was embarrassed in 1987 and no senator has yet been destroyed by a location broker. Second, it means American privacy law is enacted at the moment of maximum anecdote and minimum system — each statute a memorial, none an architecture. The Congressional Research Service's survey of federal data protection law is essentially a catalog of these fossils, prefaced by the observation that no comprehensive statute exists.
The patchwork's defenders call it flexible and targeted. What it demonstrably is, five decades in, is permeable: an entire data-brokerage economy operates in the seams between the sectors — too diversified to be a credit bureau, not a doctor, not a school, not a video store — and we have traced elsewhere exactly how much flows through those seams. The patchwork is not an alternative to a comprehensive law. It is the absence of one, with landmarks.
The two poison pills
Which brings us to the bills that tried to be comprehensive, because there have been many, and the newer ones died identically. Every serious federal privacy bill of the last five years has been killed by some combination of two questions that sound procedural and are actually the whole ballgame.
Poison pill one: preemption. Should the federal law wipe out state privacy laws? Industry's answer is an emphatic yes — one national standard instead of a twenty-one-state patchwork, which is a genuinely costly thing to comply with. Privacy advocates' answer: only if the federal floor is at least as high as California's, which no industry-supported bill has ever been. Lawmakers from strong-privacy states will not vote to strip their own residents of protections they already enjoy; industry will not support a bill that leaves state laws standing, because a floor without preemption solves none of its problems. This single dispute did more than any other to kill the American Data Privacy and Protection Act — the high-water mark of the entire fifty-year effort, which cleared the House Energy & Commerce Committee 53–2 in July 2022 and then never received a floor vote, with California's objections (including a formal opposition letter from the state's own privacy agency) front and center.
Poison pill two: the private right of action. When a company violates the law, can the injured person sue, or is enforcement reserved to the FTC and state attorneys general? This sounds like a lawyer's quibble. It is actually the question of whether the law will be enforced at all, for reasons the next section makes concrete. The advertising industry has been admirably candid about its position: ahead of the June 2024 markup of the American Privacy Rights Act — ADPPA's successor — the CEOs of the ANA and the 4As jointly warned congressional leadership against the bill, singling out its private right of action. The markup was canceled outright, and APRA died without a vote.
Two bills, two Congresses, one autopsy. And the pattern is older than both: Washington State's legislature ran the same experiment three times in miniature — the Washington Privacy Act passed the state Senate in 2019, 2020, and 2021 and died in the House all three years, with the private right of action the central sticking point each time. (Washington then passed the My Health My Data Act in 2023 with one, suggesting the obstacle was never drafting difficulty.)
Why the private right of action is the whole fight
To understand why industry treats the private right of action as existential, you need three pieces of context that rarely appear in the same article: what the FTC actually is, what happened in Illinois, and what the Supreme Court has been doing in the background.
The FTC is not the regulator you think it is. The agency that industry proposes as the exclusive enforcer of American privacy law told Senate appropriators, in its own 2020 report, that it had roughly 40 to 45 full-time employees devoted to privacy and data security — and contrasted itself with the United Kingdom's Information Commissioner's Office, a single country's data regulator, at around 700 staff. The FTC also cannot simply write privacy rules the way other agencies write rules: its Magnuson-Moss rulemaking procedure layers extra notices, congressional notification, and trial-type hearings on top of ordinary process — the CRS notes it requires substantially more procedure than the standard Administrative Procedure Act path, and its rulemakings have historically taken years. The one time the agency tried anyway — the August 2022 "Commercial Surveillance and Data Security" rulemaking — it collected comments and then never issued a proposed rule; the docket has since been reclassified as a long-term deregulatory item. This is the enforcement monopoly industry is lobbying to codify: forty-odd people, no practical rulemaking, for an economy of thousands of data companies. Proposing the FTC as sole enforcer is not a compromise position on enforcement. It is a position against enforcement, wearing a compromise's clothes.
Illinois ran the natural experiment. There is exactly one American privacy statute with a strong private right of action attached to real statutory damages: the Illinois Biometric Information Privacy Act of 2008. Its history is therefore the closest thing we have to evidence about what private enforcement does. The Illinois Supreme Court held in Rosenbach v. Six Flags (2019) that a violation itself makes a person "aggrieved" — no further injury required. What followed: Facebook paid $650 million to Illinois users over face-tagging (final approval 2021, one of the largest consumer privacy recoveries ever); Clearview AI — the company that scraped billions of faceprints — was forced into a settlement banning it from selling its database to most private entities nationwide, and later into a class settlement so large relative to the firm that it was structured as a 23 percent equity stake in the company itself; and in Cothron v. White Castle (2023) the state supreme court held that a claim accrues with every scan — with White Castle itself estimating its potential class-wide exposure at more than $17 billion. That last number did double duty: it demonstrated the deterrent power of private enforcement, and it triggered the backlash — Illinois amended BIPA in August 2024 so that repeated identical collections count as a single violation. But the decade in between is the point: the only privacy law in America that large companies demonstrably fear, budget for, and change behavior over is the one ordinary people can enforce themselves. Industry noticed the same thing everyone else did. That is what "no private right of action" is designed to prevent — not frivolous lawsuits, but consequential ones.
And the Supreme Court has been narrowing the door anyway. Even where Congress grants a right to sue, the Court has been quietly re-grading the terrain. In Spokeo v. Robins (2016) it held that a statutory violation alone doesn't guarantee standing — the plaintiff, ironically, was suing a people-search site over a false profile. Then in TransUnion LLC v. Ramirez (2021), a 5–4 Court held that of 8,185 class members whom TransUnion had falsely flagged as potential terrorists in its files, only the 1,853 whose reports had been sent to someone had standing; the other 6,332 — falsely labeled terrorists in a database, label poised to publish — had suffered, in the Court's words, "No concrete harm, no standing." Add Sorrell v. IMS Health (2011), which struck down a Vermont law restricting the sale of prescriber data with the declaration that "speech in aid of pharmaceutical marketing... is a form of expression protected by the Free Speech Clause," and the shape of the terrain is visible: data sales lean toward protected speech; database harms lean toward non-injuries. The industry's litigation arm has been probing exactly this ground — NetChoice's ongoing challenge to California's Age-Appropriate Design Code has kept that law largely enjoined since 2023 on First Amendment theories that privacy scholars at EPIC describe as demanding "an exacting level of scrutiny no privacy law could survive." Any federal privacy law that does pass will land on this terrain. Which makes the private right of action question sharper, not moot: a law enforceable only by a forty-person agency, reviewable under a data-is-speech First Amendment, is a law in name.
The playbook: what Big Tobacco taught Big Tech
Now assemble the pieces, because they form a strategy, and the strategy has a documented pedigree.
In October 2024, the ACLU of Northern California published an analysis with an unsubtle title: "Big Tech is Trying to Burn Privacy to the Ground — And They're Using Big Tobacco's Strategy to Do It." The EFF published a companion the same month, "Preemption Playbook: Big Tech's Blueprint Comes Straight from Big Tobacco." The play they describe, drawn from tobacco's 1990s campaign to preempt state indoor-smoking laws, has three steps:
Step one: flood the states with weak bills. Don't fight state privacy legislation head-on — author it. The Reuters special report "Amazon wages secret war on Americans' privacy" (November 2021) documented, from internal company records, that Amazon's lobbying operation had killed or weakened privacy bills in twenty-five states — and that Virginia's 2021 privacy law, the first after California's, was a bill "that Amazon itself drafted." The Virginia model — rights on paper, broad exemptions, no private right of action — then propagated: when EPIC and U.S. PIRG graded every state privacy law in their State of Privacy 2025 report, eight of nineteen received an F, none received an A, and all but California's followed the industry-drafted template. The scale of the influence operation is itself on the record, much of it in the industry's own words: TechNet — whose members include Amazon and Apple — states on its own policy page that in 2025 its state team "engaged on 808 bills" with its position "prevailing 87 percent of the time." The Markup counted 445 lobbyists and lobbying firms working for the five largest tech companies and their trade groups across thirty-one states in a single two-year window. Politico documented the State Privacy and Security Coalition — long run out of the law firm DLA Piper for members including Amazon, Google, Meta, and AT&T — helping strip the private right of action out of Oregon's law. Issue One's 2026 study of seven statehouses, Laboratories of Capture, found the same machinery still running. One Connecticut legislator's description, to The Markup, of a hearing on his privacy bill: the room was "literally filled with every single lobbyist I've ever known in Hartford, hired by companies to defeat the bill."
Step two: brandish the patchwork. Having authored much of the patchwork's weakness and all of its multiplicity, industry then points at it as the problem: twenty-one different laws! Compliance chaos! Small businesses drowning! The complaint is not fabricated — multistate compliance genuinely is expensive — but its provenance matters. The patchwork is not evidence against the lobbying campaign; it is the campaign's output, repurposed as its argument.
Step three: cash in the crisis for preemption. With the patchwork established as an emergency, offer the solution: one federal law that overrides the states — pitched at the level of the weakest state bills the industry drafted, minus a private right of action. As the ACLU's Jake Snow put it: "Federal law should establish a foundation that cities and states can build on, not a ceiling blocking all future progress." Tobacco, he notes, never got its preemptive federal ceiling — Congress held. The open question of this decade is whether it holds again.
Once you have the playbook, the public record reorganizes itself around it. Tim Cook stood in Brussels in 2018, denounced the "data-industrial complex," and endorsed "a comprehensive federal privacy law in the United States." Mark Zuckerberg asked for GDPR-style rules in a Washington Post op-ed. Sundar Pichai wrote in the New York Times that "privacy cannot be a luxury good." None of these statements was insincere, exactly. They were specific: the federal law being requested was always the ceiling, never the floor. The ask was never "no law." The ask was one law, written once, under maximum industry input, that turns off the states forever — which is a stronger position than opposition, because it lets you campaign for privacy while working to cap it. That is the sense in which the "Trojan Horse" label, common among advocates, is earned: the horse is real, the gift is real, and so is what's inside.
The money, itemized
Strategy requires budget, and the budget is public. In 2024 — a record year for federal lobbying overall — OpenSecrets' totals show Meta spending $24.4 million on federal lobbying (its own record), Amazon $19.1 million, Alphabet $14.8 million, Microsoft $10.4 million, and Apple $7.8 million. Those figures cover all issues, not privacy alone — but privacy sits at the top of each company's stated lobbying issue lists, and the state-level operation documented above runs on top of these federal numbers, not inside them.
Where the corporate name is a liability, the argument arrives under friendlier letterhead — and here the investigative record is unusually crisp. The Connected Commerce Council presented itself as a grassroots coalition of thousands of small businesses opposing tech regulation, until a spokesman confirmed to CNBC in 2022 that its funders were Google and Amazon — and Politico, the same day, reported that sixty-one of seventy listed "members" it contacted had never heard of the group. The App Association claims to represent thousands of small app developers; it confirmed to Bloomberg in 2022 that more than half of its roughly $9 million in sponsorship revenue came from Apple, with former employees describing Apple's influence over its positions as pervasive. NetChoice, whose member page lists Amazon, Google, Meta, and TikTok, supplies the movement's litigation arm — the First Amendment challenges described above. The Chamber of Progress, which discloses corporate partners including the major platforms on its own site, works the messaging lane; to its credit it supported ADPPA with reservations, and its stated privacy position — protecting "the ad-supported Internet" — at least names the actual stakes. Even the taxpayer-advocacy flank is on the record: Google's own transparency disclosures have listed the Taxpayers Protection Alliance among groups receiving "substantial contributions," per OpenSecrets, during the fights over tech antitrust bills. And the advertising trade groups say the quiet part at industry volume: the ANA's top lobbyist dismissed private rights of action, in a line preserved by The Markup, as "a bonanza for the trial bar," while the IAB told a House committee that laws targeting data-driven advertising "would destroy jobs and the U.S. economy."
A necessary fairness note, which also sharpens the picture: none of this is illegal, all of these organizations dispute the "anti-privacy" characterization, and most insist they support federal legislation. The dispute is not over whether they want a law. It is over the two poison pills — and on those, the pattern in the record is perfectly consistent: the bills these groups support preempt the states and lack a private right of action; the bills they kill do not.
The 2026 rematch: two bills, one X-ray
The current Congress offers the cleanest side-by-side yet of the two competing visions, and it is worth reading them as an X-ray of everything above.
The SECURE Data Act (H.R. 8413, introduced by Reps. Brett Guthrie and John Joyce) is the playbook's step three, filed as legislation: a national standard that preempts state privacy laws and contains no private right of action, leaving enforcement to the FTC — see above — and state attorneys general. The Electronic Frontier Foundation's review ran under the headline "The SECURE Data Act is Not a Serious Piece of Privacy Legislation." In June 2026, California Attorney General Rob Bonta led a coalition — sixteen state attorneys general plus the California Privacy Protection Agency and Hawai'i's consumer protection office — in a letter opposing the bill, on the ground that it would erase stronger state protections, including the state data-broker deletion mechanisms that currently give consumers their only working leverage.
The Online Privacy Act (H.R. 8014, introduced by Rep. Zoe Lofgren) is the maximal alternative: an independent Digital Privacy Agency — the enforcement capacity the FTC lacks; a private right of action — the Illinois lesson, nationalized; data minimization — companies may collect no more than the service requires; and a "right to impermanence" limiting retention. It has a single sponsor and no committee action, which is itself data: a bill containing everything the lobby opposes attracts co-sponsors the way a preempted state attracts privacy statutes.
Neither will likely become law, and that is the correct reading, not a cynical one. For the parties who prefer no law to a strong one, stalemate is not failure of the system — it is the system's output, purchasable at the lobbying rates listed above, renewable each Congress.
Meanwhile, the states are the only game running — which is exactly why preemption is the prize
Everything protecting an American's data today is state law, and the states' story explains the ferocity of the federal fight.
California, characteristically, got its law by accident of direct democracy: real-estate developer Alastair Mactaggart spent roughly $3 million qualifying a privacy initiative for the 2018 ballot, and with polls favoring it, the legislature drafted and passed the CCPA in about a week — signed hours before the initiative-withdrawal deadline on June 28, 2018 — in a deal to keep the stronger measure off the ballot. Mactaggart returned in 2020 with Proposition 24, which voters passed to create the CPRA and the country's only dedicated privacy agency. Note the mechanism: the one strong state law exists because a single wealthy citizen created a credible threat outside the legislature, where the lobbying playbook has no purchase. Virginia's law — the Amazon draft — arrived the following year as the template for containing exactly that contagion, and per EPIC/PIRG's grading, containment has largely worked: the Virginia lineage now spans most of the country, F grades and all. The exceptions prove the pattern. Illinois's BIPA predates the playbook and survives as the outlier with teeth. Washington, after industry killed its comprehensive bill three years running over the private right of action, passed a health-data law with one. And California keeps compounding: its Delete Act platform — one free request ordering every registered data broker to delete your data — became fully operational for consumers this year, with broker compliance mandatory as of this month. Our coverage of the 2026 state-law expansions tracks the current map.
Read from the industry side, this is a slowly losing battlefield: fifty legislatures, ballot initiatives that can't be lobbied, one state with a private right of action generating billion-dollar outcomes, and another operating a deletion platform. Preemption is the only move that wins all fifty boards at once. That — not tidiness, not small-business compassion — is why every industry-backed federal bill contains it, and why the federal stalemate persists: a strong national law is worse for the lobby than no law, but a preemptive weak law is better than either. The stalemate holds until one side gets its version, and only one side is billing hours toward it.
The costs of the vacuum, briefly quantified
It remains to say what the half-century settlement actually costs, because "no comprehensive law" can sound abstract. Three numbers make it concrete.
The consent regime is fictional, measurably. The patchwork's governing theory is "notice and choice": companies disclose, you choose. Researchers Aleecia McDonald and Lorrie Cranor calculated in 2008 that merely reading the privacy policies an American encounters in a year would consume roughly 201 hours per person — a national opportunity cost they estimated at $781 billion annually, and that was before smartphones. The empirical follow-up is grimmer: in Obar and Oeldorf-Hirsch's "The Biggest Lie on the Internet" experiment, 74 percent of participants joining a fictitious social network skipped the policies entirely, and 98 percent of those who "read" them missed the clauses agreeing to hand over their firstborn child and share their data with the NSA. Notice-and-choice is not a weak privacy regime. It is a load-bearing fiction, and every industry-preferred bill re-enacts it.
Enforcement asymmetry is a two-order-of-magnitude gap. Since 2018, European regulators have issued a cumulative €7.1 billion in GDPR fines across thousands of actions. The FTC's largest privacy penalty remains the $5 billion Facebook order of 2019 — a genuinely enormous number that is also, tellingly, a one-off produced by a consent-decree violation, from an agency with forty privacy staff. One regime produces continuous pressure; the other produces occasional spectacle.
And the vacuum has foreign-policy costs. Twice, the EU's top court has struck down the legal bridge carrying transatlantic data — Safe Harbor in 2015, Privacy Shield in Schrems II (2020) — each time because US law offered inadequate protection and redress. The third bridge, the Data Privacy Framework, survived its first challenge in September 2025, but that ruling is on appeal, and every American business moving European data lives under the recurring risk. Meanwhile the "US alone" framing stopped being rhetorical some time ago: with Saudi Arabia (2021), Indonesia (2022), and India (act in 2023, rules in force from late 2025), every other G20 member country has enacted its comprehensive law. The country that wrote the Fair Information Practices in 1973 is now the last industrial economy running without them.
What this means for you today
Until the federal question resolves — and this article's honest forecast is that it resolves slowly, because the stalemate is a purchased equilibrium, not a misunderstanding — the levers available to an individual are the unglamorous ones. Your state's privacy rights, if you have them; California's deletion platform, if you live there; and direct opt-outs from the data brokers holding your profile — the one mechanism that works in all fifty states, because it depends on broker policy rather than statute. Understanding where those brokers get your data explains the catch: removals decay, because the supply chain keeps flowing, which makes removal a maintenance task rather than an event.
That maintenance is the chore DelistMyData is being built to automate — filing the removals, verifying they took, and re-filing when your data reappears — for as long as the law leaves the job to you. We're in pre-launch; join the waitlist for founding-member access.