This bill requires 16 major federal agencies (including Defense, Health, Homeland Security, and Social Security) to report to Congress within 120 days of enactment on whether they have implemented electronic consent systems as mandated by 2020 OMB guidance (M-21-04). The report must confirm implementation status or detail delays, justifications, and timelines for compliance. It directly affects agencies handling personal data under the Privacy Act by enforcing existing requirements for electronic identity proofing, consent templates on websites, and electronic consent acceptance. The bill focuses on accountability for current OMB guidance, not creating new rules.
HR 6253 requires online platforms using personalized recommendation systems (like social media or video sites) to provide clear notices and options to minors under 18. It mandates that platforms offer an input-transparent algorithm as the default setting - meaning it doesn’t use hidden user data to curate content - and gives minors the ability to switch algorithms or limit recommendation types. Platforms must also disclose how data is collected, what the system optimizes (e.g., engagement time), and how user-specific data is used. The Federal Trade Commission will enforce these requirements under existing laws, with the bill preempting conflicting state regulations.
The ACCESS Act of 2025 requires major social media and messaging platforms (defined as services with over 100 million U.S. users that monetize user data) to enable users to easily transfer their data to competing services and ensure their platforms can interoperate with rival services. It mandates that large platforms provide secure, machine-readable data portability and maintain transparent interfaces for competitors to connect with users. The law also establishes rules for third-party agents managing user accounts and prohibits platforms from using data from competitors for commercial gain. Enforcement falls to the Federal Trade Commission, with penalties for violations treated as unfair business practices.
The Data Care Act of 2025 requires online service providers (like social media platforms or apps that collect user data) to securely handle "individual identifying data," especially sensitive information like health details, biometrics, financial data, or precise location. It imposes three key duties: (1) reasonably securing data from breaches, (2) not misusing data to harm users or benefit themselves, and (3) restricting data sharing to third parties only with strict confidentiality contracts. The Federal Trade Commission and state attorneys general can enforce these rules through penalties for violations, with civil fines calculated based on the number of affected users or days of noncompliance. The law directly affects major digital platforms collecting user data and takes effect 180 days after enactment.
This bill creates a voluntary data collection system for farmers to share field-level information on conservation practices and farming methods. It requires the USDA to build a secure data center collecting anonymized farm data on soil health, crop yields, and ecosystem impacts - voluntarily provided by producers - to analyze how practices affect productivity and environmental outcomes. The data will be used to improve USDA programs and provide farmers with internet-based tools showing how specific practices boost yields and sustainability. Strong privacy safeguards prevent disclosure of individual producer data, ensuring compliance with existing privacy laws. The bill does not mandate data sharing or require farmers to adopt new practices.
HR 7064, the AI in Health Care Efficiency and Study Act, requires the U.S. Department of Health and Human Services (HHS) to study how artificial intelligence can streamline administrative tasks in healthcare while protecting patient privacy. The study will examine AI applications for scheduling, claims processing, electronic health records, and cybersecurity threats like ransomware, involving healthcare providers, health plans, AI developers, and privacy experts. HHS must report findings and recommendations to Congress within 6 months of completing the study, focusing on reducing provider workload, improving data security, and ensuring compliance with health privacy laws. This bill does not create new regulations but directs a federal study to inform future policy on AI in healthcare administration.
HR 6499, the Assessing Safety Tools for Parents and Minors Act, directs the Federal Trade Commission (FTC) to review how technology companies promote online safety for minors under 17. The FTC must examine industry efforts like parental controls, age-appropriate content labels, and privacy settings to assess their effectiveness in reducing online harms, consulting with parents, experts, and industry. Within 6 months of enactment, the FTC must begin this review and submit a report to Congress within 3 years, including recommendations for improving online safety. The bill does not create new regulations but requires the FTC to evaluate existing industry practices and provide findings to lawmakers. This review directly affects the FTC and technology companies by mandating their participation in assessing current safety tools.
HR 6734, the Auto Data Privacy and Autonomy Act, gives car, truck, and farm/construction vehicle owners direct control over data generated by their vehicles. It prohibits manufacturers from accessing or sharing vehicle data (including location and personal information) without the owner’s explicit, written consent, and bans selling such data to specific foreign governments like China, Russia, or North Korea. Owners gain free, real-time access to all vehicle data through standard interfaces (like the car’s port or wireless), with no fees for decryption or third-party access, and can delete data or adjust settings via an open application interface. The law requires manufacturers to provide this access without restricting how owners use the data or forcing them to pay for it.