HR 5028, the SAFE Act of 2025, amends the Privacy Act to increase accountability for certain federal employees who intentionally or willfully violate privacy rules. It defines "covered special Government employees" as senior-level federal workers (in roles equivalent to GS-13 or higher, excluding advisory committee members or interns) who mishandle personal data. The bill allows individuals harmed by such violations to sue the employee directly, removing immunity and requiring personal liability for damages. It also permits state attorneys general to file lawsuits on behalf of residents affected by intentional privacy breaches by federal personnel.
The Fire Ready Nation Act of 2025 establishes a coordinated fire weather services program within the National Oceanic and Atmospheric Administration (NOAA) to improve wildfire prediction, response, and community resilience. The program will develop advanced weather models, enhance data collection through technologies like uncrewed systems, and provide impact-based decision support services to emergency responders and communities. It specifically prioritizes improving access to these services for remote, rural, and isolated communities where residents often serve as first responders to wildfires. The bill authorizes $15 million for fiscal year 2026, increasing to $50 million by 2030, to fund these activities and support coordination with federal, state, tribal, and local partners.
The INNOVATE Act amends the Small Business Innovation Research (SBIR) and Small Business Technology Transfer (STTR) programs to better support small businesses developing innovative technologies for national security and commercial applications. Key provisions include creating a new "Phase 1A" program to help new small business entrants access the SBIR program with simplified 2-page proposals, establishing "strategic breakthrough" funding for defense-related technology development with specific eligibility requirements, and strengthening security measures to protect against foreign influence in research. The bill also streamlines commercialization requirements, adds new data collection standards for program evaluation, and extends SBIR/STTR program authorization through 2028. These changes primarily affect small businesses seeking federal research funding, federal agencies administering these programs, and defense contractors working on national security technologies.
S 863, the Genomic Data Protection Act, gives consumers greater control over their genetic information collected by direct-to-consumer genetic testing companies (like 23andMe or AncestryDNA). It requires these companies to provide simple tools for consumers to access their genomic data, delete their accounts (including associated data), and request destruction of biological samples (such as saliva swabs). Companies must also clearly disclose how deidentified data may be used for research and notify consumers 30 days before a company acquisition, detailing how consumer rights will be honored under new ownership. The Federal Trade Commission will enforce these requirements as unfair or deceptive practices under existing law, with companies required to fulfill deletion requests within 30 days. This bill directly affects consumers who use genetic testing services and the companies that collect their genomic data, excluding healthcare providers using genetic data for medical diagnosis.
The Saving Privacy Act (S 809) strengthens financial privacy by requiring warrants for government access to customer financial data and amending the Right to Financial Privacy Act to limit government surveillance. It terminates the Consolidated Audit Trail, a centralized database of financial transactions, and prohibits federal agencies from developing a central bank digital currency. The bill also establishes a congressional review process for agency regulations to increase transparency and protects consumers' ability to use convertible virtual currency (like Bitcoin) for personal purchases without federal restrictions. These provisions collectively aim to enhance individual privacy rights in financial transactions and limit government overreach in financial data collection.
The Unsubscribe Act of 2025 regulates "negative option" billing practices, where companies automatically charge consumers unless they actively opt out. It requires merchants to clearly disclose all terms before charging, obtain explicit consumer consent, and provide an easy online cancellation method. The bill specifically targets contracts like free-to-pay conversions (e.g., "free trial" followed by automatic charges), mandating clear upfront terms about pricing and renewal. Consumers directly benefit through greater transparency and control, while merchants must comply with new disclosure, consent, and cancellation rules starting one year after enactment. Enforcement falls to the Federal Trade Commission and state attorneys general.
The Don't Sell My DNA Act amends the U.S. Bankruptcy Code to protect genetic information by requiring written consent from all affected individuals before any sale, lease, or use of genetic data in bankruptcy cases. It mandates that bankruptcy trustees and debtors must provide prior written notice to every person whose genetic information is involved in such transactions. The bill also requires trustees to delete genetic information from bankruptcy estates if it isn't sold, using court-approved methods like NIST guidelines. This directly affects individuals with genetic data in bankruptcy cases, as well as bankruptcy trustees and debtors managing those estates.
HR 533, the Bank Privacy Reform Act, strengthens privacy protections for individuals' financial records by requiring government agencies to obtain a warrant before accessing bank account information. The bill amends the Right to Financial Privacy Act to mandate warrants for accessing customer records, removes outdated exceptions, and updates the $3,000 threshold for reporting transactions to be adjusted annually for inflation. This directly affects banks, credit unions, and their customers by limiting government access to personal financial data without judicial oversight. Key provisions include requiring warrants for record access (except under specific legal exceptions), removing obsolete sections of financial privacy law, and updating reporting thresholds. The bill focuses on concrete changes to privacy safeguards, not broader financial regulation.
This bill reauthorizes the Snow Water Supply Forecasting Program through 2031, updating its focus to prioritize integrated snowpack measurement and advanced modeling technologies. It shifts emphasis from basic data collection to tools like machine learning, imaging spectroscopy, and hydrologic modeling to improve water supply forecasts. The program’s annual funding is reduced to $6.5 million (from $15 million over five years), requiring annual reports on basin applications and technology effectiveness. It directly affects water managers and agencies in snowmelt-dependent regions, particularly those making multi-state or multi-basin water decisions.
HR 3437, the Insurance Data Protection Act, prevents duplicate data collection from insurance companies by requiring federal financial regulators to coordinate with state insurance regulators before gathering data already available through other channels. It reinforces confidentiality by ensuring that sharing nonpublic data with federal regulators does not waive privacy protections under federal or state law, and maintains existing confidentiality agreements. The bill also establishes that data shared with regulators can only be provided to state regulators through new agreements that comply with privacy laws. This directly affects insurance companies (as "covered entities"), federal financial regulators, and state insurance regulators. The key change is creating a formal process to avoid redundant data requests while strengthening data privacy for the insurance industry.