All CRS Reports
R47569

Federal Data Privacy: Current Law, Gaps, and Legislative Proposals

Federal & State Law Editorial TeamLast reviewed: April 2026
Chris JaikaranSeptember 30, 2025
data privacyconsumer protectionhipaaccpa

Summary

This report examines the current patchwork of federal data privacy laws, including sector-specific statutes such as HIPAA for health information, COPPA for children's online data, and GLBA for financial data. It identifies gaps in the existing framework and discusses the absence of a comprehensive federal privacy law.

The report analyzes state privacy legislation, including the California Consumer Privacy Act (CCPA) and similar laws enacted in other states, and discusses how the lack of federal preemption creates compliance challenges for businesses operating nationwide.

Congressional considerations include proposals for comprehensive federal privacy legislation such as the American Data Privacy and Protection Act (ADPPA), debates over a private right of action, FTC enforcement authority, data minimization requirements, and the treatment of sensitive categories of data including biometric and geolocation information.

Full Report Analysis

Key Findings

The United States lacks a comprehensive federal data privacy law, relying instead on a patchwork of sector-specific statutes, FTC enforcement, and a growing body of state privacy legislation that creates compliance complexity for businesses operating nationwide.
As of 2025, over 15 states have enacted comprehensive privacy laws, including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Oregon, Texas, Delaware, New Jersey, New Hampshire, and Kentucky, with additional states considering legislation.
The American Data Privacy and Protection Act (ADPPA) achieved bipartisan, bicameral support and was reported favorably by the House Energy and Commerce Committee in 2022, but stalled over disagreements regarding federal preemption of state laws and the private right of action.
Data broker activities remain largely unregulated at the federal level, with these companies aggregating and selling personal information from public records, commercial transactions, online activities, and other sources, often without individuals' knowledge or meaningful consent.

Background

Federal data privacy regulation in the United States has developed on a sector-specific basis, with each major statute addressing a particular type of data or industry. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) protects individually identifiable health information held by covered entities and their business associates. The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices and protect sensitive customer data. The Children's Online Privacy Protection Act (COPPA) restricts the collection of personal information from children under 13 by commercial websites and online services.

The Federal Trade Commission serves as the de facto federal privacy regulator, using its authority under Section 5 of the FTC Act to pursue enforcement actions against companies engaged in unfair or deceptive data practices. FTC enforcement actions have addressed unauthorized data collection, inadequate data security, deceptive privacy policies, and violations of consent decrees. However, the FTC's authority is limited to "unfair or deceptive" practices rather than establishing comprehensive privacy requirements, and its enforcement resources are finite relative to the scope of the data economy.

Current Law

HIPAA's Privacy Rule establishes national standards for the protection of individually identifiable health information by covered entities (healthcare providers, health plans, and healthcare clearinghouses) and their business associates. COPPA requires verifiable parental consent before collecting personal information from children under 13, with the FTC proposing updates to address changes in technology since the rule was last revised. The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records. The Fair Credit Reporting Act (FCRA) regulates the collection, dissemination, and use of consumer credit information.

The Electronic Communications Privacy Act of 1986 (ECPA), including the Stored Communications Act, governs law enforcement access to electronic communications and stored data. However, ECPA was enacted before the modern internet and has not been comprehensively updated, creating significant gaps in privacy protection for cloud-stored data and digital communications. The Carpenter v. United States (2018) Supreme Court decision extended Fourth Amendment protections to cell-site location information but left broader questions about digital privacy unresolved.

Policy Options

The primary legislative approach is comprehensive federal privacy legislation establishing baseline privacy protections applicable across sectors. Key design choices include: the scope of covered data and entities; individual rights (access, correction, deletion, portability, opt-out of targeted advertising); data minimization requirements limiting collection to what is reasonably necessary; heightened protections for sensitive data categories (biometric, health, financial, geolocation, children's data); consent and notice requirements; enforcement mechanisms (FTC authority, state attorney general authority, private right of action); and whether federal law preempts state privacy laws.

Alternative approaches include strengthening sector-specific statutes, expanding FTC rulemaking authority, establishing a dedicated data protection agency, enacting targeted legislation addressing specific harms such as data broker regulation or algorithmic accountability, and developing industry self-regulatory frameworks with FTC oversight. The tension between comprehensive federal preemption (favored by industry for regulatory certainty) and preservation of state authority to enact stronger protections (favored by privacy advocates and some state officials) remains a central obstacle to legislative progress.

Recent Developments

State privacy legislation continues to advance rapidly, with each new law creating additional compliance obligations for businesses. The FTC has undertaken rulemaking on commercial surveillance and data security, potentially establishing more comprehensive requirements under existing authority. International developments, including the EU's General Data Protection Regulation enforcement and adequacy determinations, create additional pressure for U.S. federal legislation. Congressional bipartisan interest in children's online privacy, data broker regulation, and AI-related privacy concerns may provide pathways for incremental progress even absent comprehensive legislation.

Note: This is a summary of a Congressional Research Service report. CRS reports are prepared for Members of Congress and their staffs. This summary is provided for informational purposes and does not constitute legal advice.

This is legal information, not legal advice. Laws vary by jurisdiction and change frequently. Always verify current law with official sources and consult a licensed attorney in your jurisdiction for advice on your specific situation.