Summary#
The Consumer Data Privacy and Security Act of 2026 would create a national framework for how companies and service providers collect, use, store, and share personal data about people in the United States. The bill defines key terms (for example, "personal data," "sensitive personal data," "covered entity," and "service provider") and lists what businesses must do when they collect or process data.
Key rules in the bill include:
- Consent: Covered entities generally must get an individual's consent (explicit or implicit) to collect or process personal data. Express affirmative consent is required for sensitive personal data and for certain third-party disclosures. The bill describes how notices must be given and how individuals may withdraw consent.
- Permitted uses: The bill allows some data uses without consent, such as providing a service requested by the individual, complying with the law, preventing immediate danger, fraud prevention, certain research, and operational needs (for example, billing and network management).
- Rights for individuals: People have rights to a clear privacy policy, to access their personal data, to correct inaccurate data, and to request deletion or de-identification of their data, subject to specified exceptions.
- Privacy policies and notices: Covered entities must publish clear privacy policies with details about data categories, purposes, retention, disclosures to third parties, and how people can exercise rights. They must notify individuals of material changes.
- Security and accountability: Covered entities and service providers must maintain comprehensive data security programs with administrative, technical, and physical safeguards. Very large entities (those processing data for more than 20 million people or sensitive data for over 1 million people) must designate a privacy officer and implement a comprehensive privacy program and privacy impact assessments for material changes involving sensitive data.
- Rules for service providers: Covered entities must contractually require service providers to act only on their direction, maintain protections, and delete or de-identify data when services end. Service providers must help covered entities comply with individual requests and notify covered entities about legal process where allowed.
- Enforcement and penalties: The Federal Trade Commission (FTC) would enforce the law as an unfair or deceptive practice. The bill allows the FTC to seek civil penalties for knowing violations, calculated per affected individual (an amount not to exceed $42,530 per individual). State attorneys general may also bring civil actions. The bill says there is no private right of action.
- Preemption and relations to other laws: The bill declares federal preemption over state privacy and security laws for covered entities, with listed state law exceptions (for example, data breach notification, certain student and health rules, financial privacy, employment data). It also lists federal laws that remain in effect and says compliance with some existing federal laws counts as compliance with this Act.
- Commission resources and timing: The FTC Chair is directed to appoint at least 440 additional staff for enforcement and related work. The Act takes effect one year after enactment, except the preemption section, which takes effect upon enactment.
What it means for you#
- You would generally have the right to know what personal data a covered business collects about you, why it is collected, and who it is shared with.
- You could request access to a copy of your data, ask to correct errors, and ask a covered entity to delete or de-identify your personal data in many situations. There are listed exceptions where those rights do not apply.
- Sensitive personal data (like government IDs, health information, biometric data, precise geolocation, race, religion, or sexual orientation) requires stronger protections and express affirmative consent for many uses.
- Businesses must show clear privacy notices and provide easy ways to exercise your rights at no extra cost for the first two requests each year.
- If a covered entity or service provider seriously breaks these rules and does so with actual knowledge, the FTC or a state attorney general may seek civil penalties.
Expenses#
- The bill directs the FTC Chair to appoint at least 440 additional personnel to enforce this Act and related privacy and security laws.
- The bill authorizes the appropriation of "such sums as may be necessary" to carry out the section on Commission resources.
- Civil penalties for knowing violations may be calculated per affected individual and may be up to $42,530 per individual (the Commission must consider factors when setting penalty amounts).
- No publicly available information on total budgetary costs, overall implementation costs to covered entities, or a comprehensive cost estimate is included in the bill text provided.
Proponents' View#
No publicly available information.
Opponents' View#
No publicly available information.