The bipartisan bill, introduced in April 2024, is the latest attempt at passing a federal privacy law in the US. It aims to put individuals in control of their data and eliminate the patchwork of state laws
Alexis Kateifides
Director, Regulatory Intelligence
April 10, 2024
On April 7, 2024, representatives from the US House and Senate introduced a draft federal privacy law that would grant individuals greater control over their personal information, define processing principles, and set out a range of consumer rights, among other things. The American Privacy Rights Act (APRA) represents the latest attempt at passing a federal privacy law since the American Data Privacy and Protection Act (ADPPA) failed to make it to a vote on the House floor in June 2022. The APRA includes a provision that would see it preempt the growing patchwork of state-level privacy legislation.
In a press release, House Energy and Commerce Committee Chair Cathy McMorris Rodgers (R-WA) and Senate Commerce Committee Chair Maria Cantwell (D-WA) said, “This bipartisan, bicameral draft legislation is the best opportunity we’ve had in decades to establish a national data privacy and security standard that gives people the right to control their personal information […] It strikes a meaningful balance on issues that are critical to moving comprehensive data privacy legislation through Congress […] This landmark legislation gives Americans the right to control where their information goes and who can sell it.”
Calls for a federal privacy law in the US have been increasing since the introduction of the California Consumer Rights Act (CCPA) kick-started a wave of state-level legislation aimed at giving consumers greater rights over the use of their personal information. Most recently, New Jersey, New Hampshire, and Kentucky have added their names to the ever-growing list of states with comprehensive state privacy laws with Maryland sending its privacy bill to the Governor for signature.
This patchwork has made navigating privacy in the US a complex challenge and there have been several attempts to pass a federal privacy law over the years to simplify the equation. The most recent attempt was the bipartisan ADPPA that was introduced in early 2022 and was tipped as having genuine potential to become law. Like many that came before, the ADPPA fell short of reaching the House floor in June 2022 with many citing issues with state law preemption.
The APRA is the latest bipartisan attempt at embedding privacy and security requirements at a federal level – enshrining consistent consumer protections and individual rights across state borders. There is an intricate path ahead for the APRA if it were to make its way into law and would require greater agreement on a range of issues – such as the preemption of state law – that hampered the ADPPA.
The APRA offers many familiar concepts as part of its 53-page draft with the central aims of eliminating differing concepts across state borders and giving consumers greater control over their personal information. The APRA includes requirements relating to data minimization, transparency, and security provisions as well as enhanced requirements for data brokers and the establishment of a national data broker registry.
The APRA introduces a recognizable set of consumer rights including:
The right to access
The right to correction
The right to deletion
The right to data portability
There is also a right to opt out that would allow consumers to opt out of certain data transfers, to opt out of decisions made using algorithms, and to opt out of targeted advertising. The law would call for a centralized mechanism for consumers to exercise their consent and opt-out preferences that recognize universal signals and businesses would not be able to deny a service as a result of individuals exercising their rights.
In addition to the above requirements, the APRA will require businesses to designate one or more qualified employees to serve as privacy or data security officers. Such designated officers will be responsible for implementing privacy and security programs in line with the requirements of the APRA and for ensuring compliance with the law.
Enforcement will be overseen by the Federal Trade Commission (FTC) with a dedicated bureau scoped to be established within the FTC no later than one year after the APRA is enacted.
One issue that has blighted previous attempts to pass federal privacy legislation is the matter of preemption. This has been a sticking point, particularly in California, where talks over the ADPPA broke down in 2022 citing that the ADPPA "does not guarantee the same essential consumer protections as California’s existing privacy laws.”
In response to the APRA, the Executive Director of the California Privacy Protection Agency (CPPA), Ashkan Soltani issued a statement; “Americans shouldn’t have to settle for a federal privacy law that limits states’ ability to advance strong protections in response to emerging threats in policy – particularly when Californians’ fundamental stakes are at stake. Congress should set a floor, not a ceiling”
The APRA will expressly maintain a preemption provision to try and ensure a consistent privacy and security standard across the US as well as minimizing the costs and burdens placed on organizations conducting interstate business. There are, of course, exceptions including state-level consumer protection laws of general applicability, civil rights laws, and laws that address the privacy rights or other protections of employees or employee information, among others. The APRA also includes exceptions related to the Gramm-Leach-Bliley Act (GLBA) and the Health Insurance Portability and Accountability Act (HIPAA), among other federal laws that include privacy and security rules.
As stated, there is a long road ahead for the APRA including the preemption hurdle to overcome. However, US Representative Cathy Rodgers and US Senator Maria Cantwell have described the act as, "The best opportunity we've had in decades to establish a national data privacy and security standard.” Should the APRA make its way through the House and Senate before being enacted into law, it would be effective 180 days after its enactment and the FTC would be required to report on the law’s effectiveness four years after. For now, more and more states are passing privacy laws and will require the attention of covered businesses. As for the APRA, the prospect of a federal law – like always – remains under discussion and could find a similar fate to the federal bills that came before.
Speak to an expert to learn more about the current US privacy landscape and how you can build your privacy program to meet an ever-growing list of requirements.
Webinar
Join us for a webinar on the latest updates and emerging trends in global privacy regulations.
Webinar
Join DataGuidance and a panel of experts as we discuss US privacy laws the protection of minors' data.
Webinar
Rhode Island has become the 20th US State to pass a privacy law. On June 25, 2024, the Governor of Rhode Island transmitted the Data Transparency and Privacy Protection Act (RIDTPPA) without signature allowing the Act to become law. Join the webinar to learn more.
Webinar
Join us for a discussion on preparing your organization for healthcare privacy compliance that goes beyond HIPAA.
Webinar
In this webinar, OneTrust DataGuidance and expert contributors unpack the MCPA and VDPA, examining the requirements, exceptions, and practical implications of the legislations on the data controllers and processors.
Webinar
Prepare your organization for the new wave of US privacy laws.
Checklist
Download this checklist to learn what questions to ask when designing a third-party risk management program that enables privacy compliance.
Infographic
Download our infographic and compare the many US state privacy law requirements that have been enacted or will soon come into effect.
Webinar
Join OneTrust DataGuidance and expert contributors for an overview of the Kentucky Consumer Privacy Act (KCPA), Maryland's Senate Bill 0541, and the draft American Privacy Rights Act and explore how a federal bill could shape the US privacy landscape.
Infographic
View our timeline to understand the progression of current US state privacy laws and key dates.
Webinar
Join us for an interactive webinar we dive into the CPRA, which will go into force on March 29th.
Webinar
oin OneTrust DataGuidance for a webinar highlighting the key requirements within the new US laws, New Jersey Senate Bill 332 and New Hampshire Senate Bill 255.
Webinar
Join us for a webinar on Embedding Privacy by Design through PIA Automation.
Webinar
Learn how Privacy Rights Automation helps to fully automate privacy rights requests.
Webinar
Join us for a webinar as we explore the impending implementation of the Utah Privacy Law, set to take effect on December 31, 2023.
Webinar
We explore the new Oregon and Delaware privacy laws, how they differ from other US privacy laws, and what they mean for your business.
Regulation Book
Download the Utah Consumer Privacy Act law book and have the official UCPA text at your fingertips for when the law takes effect on December 31, 2023.
Blog
Get in-depth analysis on two upcoming US Privacy laws, the Oregon Consumer Privacy Act (OCPA) and the Delaware Personal Data Privacy Act (DPDPA), with OneTrust DataGuidence and a panel of experts.
Resource Kit
Download our EU-US Data Privacy Framework resource kit to better understand the new aggreement for cross-border personal data transfers and how to educate your stakeholders.
Resource Kit
Download our US privacy resource kit designed to access a range of materials to help you understand how the US privacy landscape is evolving.
Webinar
In this free webinar, our privacy experts delve into the new Colorado and Connecticut privacy laws and how they differ from other US state regulations.
Webinar
Join our expert panel where we examine upcoming privacy legislation in Indiana, Montana, Tennessee, and Florida and the key requirements of each law.
Infographic
Adapt to Google's June 2023 CMP requirements with this infographic and confidently engage your audience while staying compliant.
Webinar
Join our live webinar as OneTrust DataGuidence and privacy experts examine new privacy legislation in Indiana, Montana, Tennessee, Florida, and Texas.
eBook
Download this eBook and learn how marketers can apply consent and preference principles to build a relationship with their audience built on trust.
Regulation Book
The Colorado Privacy Act (CPA) comes into force on July 1. Get the law's official text right at your fingertips.
Webinar
The Washington My Health My Data Act was signed into law on April 27, 2023 and will be enacted the following year. Join OneTrust DataGuidance and a team of legal experts and get the knowledge you need for compliance.
Webinar
Join the Privacy experts at OneTrust for an update on the new law and learn key requirements of Iowa’s new privacy law and more.
White Paper
Download our white paper and learn how privacy teams help organizations establish and implement polices that ensure AI applications are responsible and ethical.
Blog
Learn how to navigate the new US privacy law exemptions and see how they compare.
Webinar
Join this interactive webinar to learn how OneTrust Privacy Rights Automation helps you to fully automate privacy rights requests for your organization.
Webinar
OneTrust DataGuidance’s webinar discusses Iowa’s CDPA, its similarities to other US privacy laws, its implications on organizations, and steps for compliance.
Webinar
Biometric laws are emerging, and companies must ensure compliance to avoid hefty fines. Join the OneTrust DataGuidance panel of experts to learn more.
Infographic
Businesses at different stages of privacy maturity will need to approach US privacy compliance in different ways. Download the infographic to learn more.
Webinar
Join this US Privacy Demo Series webinar to see a live demo of the OneTrust privacy risk or data protection assessments (PIA's) automation solution.
Webinar
Learn the steps you can take to boost employee trust in compliance with US Privacy Laws in our US Privacy Masterclass on Employee Rights Fulfilment.
Webinar
Join us in our US Privacy Masterclass as we delve into the evolving US privacy landscape and how you can build a trust-based privacy program in 2023.
Webinar
Join us in our US Privacy Masterclass on Risk and DPIAs to understand the operational components for risk assessments/data protection assessments.
Webinar
Our US Privacy Masterclass on Retention & Minimization will help you understand data policy requirements across US Privacy Laws.
Webinar
Join industry experts at OneTrust & Protiviti for an operational deep dive and interactive Q&A on the upcoming US State laws set to go into effect in 2023.
Checklist
Download this checklist to make sure your organization follows the right steps to implement processes that achieve California Privacy Rights Act compliance.
eBook
Learn about the different opt-out requirements, such as a “Do Not Sell My Personal Information” in the US privacy landscape, and how to comply with them.
eBook
Learn more about the three priorities for managing US privacy requirements, including addressing the most visible aspects of US privacy compliance.
Webinar
Join our experts to understand the operational impact of these newly-expanded US consumer rights and how to automate consumer rights request fulfillment.
Webinar
In this webinar, OneTrust experts discuss requirements for conducting PIAs: why they exist, when you should do them, and what they should include.
Webinar
In this session, legal experts Michelle Schaap and Andy Lee are joined by OneTrust DataGuidance to provide an overview of what the ADPPA entails.
Webinar
Attend our webinar, "Establishing and enforcing retention policies," part of the US Privacy Laws Masterclass Series.
eBook
Download this guide to learn how you can comply with the CCPA's opt-out requirements to get on the right track to CCPA compliance.
White Paper
This guide to California privacy law compliance helps your organization understand the requirements under the CCPA and CPRA.
Webinar
Watch our webinars on the latest privacy laws from Utah and Connecticut and what you need to know to prepare in 2023.
Webinar
Join us for a Q&A on the several US state laws going in effect in 2023.
eBook
Download this eBook and explore the key areas of US state privacy laws and how they compare.
Resource Kit
These resources provide key information on US privacy law through blogs, webinars, and eBooks.
Checklist
Download our six step checklist for US privacy laws and ensure that your company remains compliant in 2023.
Webinar
Join us for an overview of Utah's Consumer Privacy Act (UCPA) and its impact on your organization.
Webinar
Attend our webinar, to better understand privacy laws in the US.
Webinar
Watch our webinar as we discuss privacy impact assessments and how they relate to US privacy laws.
Webinar
Watch our US Privacy Law masterclass to learn about opt-out of sales and share requirements and best practices for approaching compliance.
Webinar
Watch our webinar on US privacy laws and gain insight on effective personal information managment strategies.
Webinar
Join us for an overview of US privacy laws and strategies for dealing with compliance.
Webinar
In the first part of our US Privacy Series, we discuss US privacy laws such as the CPRA and best practices towards compliance.
Infographic
Download our infographic on employee rights under the CPRA to help prepare for the law's expansion in CPRA.
eBook
The Ultimate Guide to CCPA Compliance eBook highlights key compliance areas of the CCPA that you should consider when building a privacy program.
eBook
Download this eBook for an overview of the Virginia Consumer Data Protection Act (CDPA) to understand what it means for organizations.
Webinar
Watch our OneTrust CCPA Masterclass Series and learn how to prepare your organization for CCPA compliance.
Webinar
Join this US Privacy Masterclass series as we delve into the evolving US privacy landscape and how you can build a trust-based privacy program in 2023.
Webinar
Watch the OneTrust US Privacy Masterclass series and gain insight on the major US privacy law and best practices.