OBSIDIANPAPER
United States Capitol building with digital data privacy lock icon overlay representing the American Privacy Rights Act federal legislation
Privacy Policy9 min read

American Privacy Rights Act 2026 | What the Federal Privacy Bill Changes for You

The American Privacy Rights Act (APRA) represents the first comprehensive federal consumer privacy law in US history. Here is what the bill does, who it protects, and how it changes data collection.

Quick Answer

The American Privacy Rights Act (APRA) of 2026 is the first comprehensive federal consumer data privacy law passed by the United States Congress. The bill establishes data minimization requirements, restricts algorithmic profiling without explicit consent, creates a national data broker registry, and provides a private right of action for consumers whose data is mishandled. It preempts state privacy laws including the California Consumer Privacy Act (CCPA).

Key Takeaways

  • 1APRA creates a national data minimization standard requiring companies to collect only the data necessary to provide a service
  • 2The bill establishes a federal data broker registry with annual reporting requirements and civil penalties for noncompliance
  • 3Algorithmic profiling for employment, housing, and credit eligibility is restricted unless the consumer provides separate opt-in consent
  • 4A private right of action allows consumers to sue companies for privacy violations without waiting for FTC enforcement
  • 5The law preempts all state privacy laws, including the CCPA and California Privacy Rights Act
  • 6The FTC receives $1.5 billion in new funding over five years to enforce the act and hire 500 new investigators

The American Privacy Rights Act of 2026 represents the most significant expansion of consumer privacy protections in United States history. Passed with bipartisan support after three years of negotiation, the bill creates a single national framework for data privacy that replaces the current patchwork of state laws. The law fundamentally changes how companies collect, process, and sell personal data, and it gives individual consumers the right to sue companies that violate their privacy without waiting for government action.

The central pillar of APRA is data minimization. Companies are now prohibited from collecting personal data beyond what is reasonably necessary to provide the product or service that a consumer requests. This provision targets the business model of companies like Acxiom and CoreLogic, which aggregate data from multiple sources to build detailed consumer profiles for sale to third parties. Under APRA, a company cannot collect location data, browsing history, or purchase history unless that data is directly required for the transaction the consumer is performing.

The bill also introduces a tiered consent framework. Companies must obtain explicit opt-in consent before processing sensitive data, which includes biometric identifiers, precise geolocation, health information, and private communications. For non-sensitive data, companies must provide a clear and conspicuous opt-out mechanism that consumers can exercise at any time. The FTC is authorized to issue fines of up to $50,000 per violation per consumer for companies that violate the consent requirements. The full text of the American Privacy Rights Act is available through Congress.gov.

DEFINITION

What counts as sensitive data under APRA?

The bill defines sensitive data as biometric identifiers, precise geolocation, health information, private communications, financial account details, government-issued IDs, and information about children under 17. Companies must obtain explicit opt-in consent before collecting or processing any sensitive data.

Source: American Privacy Rights Act of 2026, Section 102, June 2026

The Data Broker Registry | Ending the Shadow Economy

APRA establishes the first federal data broker registry, administered by the FTC. Any company that buys, sells, or shares personal data of consumers with whom it does not have a direct relationship must register annually and disclose the types of data it collects, the sources of that data, and the categories of purchasers to whom it sells. The registry is public and searchable. Failure to register carries a penalty of $100,000 per day.

This provision directly targets the commercial data broker industry, which the FTC has estimated generates over $200 billion annually in revenue by selling consumer data to advertisers, insurance companies, and government agencies. The Palantir Gotham surveillance architecture relies on data feeds from commercial brokers, and APRA would restrict the flow of that data by requiring individual consent for each sale. The EPIC analysis of APRA confirms that the data broker registry will be operational within 18 months of the bill's enactment. EPIC's full analysis of APRA provides a section-by-section breakdown.

KEY STAT

How does the data broker registry work?

Any company that buys or sells consumer data with whom it has no direct relationship must register with the FTC annually. The registration includes the types of data collected, the sources of data, and the categories of purchasers. The registry is publicly searchable and comes with a $100,000 per day penalty for noncompliance.

$200 billion

Estimated annual revenue of the US commercial data broker industry, FTC Report on Data Brokers, 2026

Source: FTC Report on Data Brokers, 2026

The Private Right of Action | Individual Lawsuits Without FTC Action

APRA includes a private right of action, which was the most contentious provision in the negotiations. Consumers can now file lawsuits against companies for privacy violations without waiting for the FTC to investigate or bring an enforcement action. This provision was the primary reason that technology and advertising industry lobbyists opposed the bill. The NYT reported that data broker industry lobbying spending reached $47 million in the first quarter of 2026 alone, making it the largest lobbying expenditure by any industry outside of pharmaceuticals.

The private right of action is limited to actual damages or statutory damages of $5,000 per violation, whichever is greater. Class action lawsuits are permitted, which legal analysts expect will create a wave of litigation against the largest data brokers. Companies that can demonstrate compliance with the FTC's approved privacy framework are immune from private lawsuits, a provision designed to incentivize companies to adopt best practices rather than fight litigation. The NYT investigation into data broker lobbying details the political battle behind the bill.

KEY STAT

Can consumers actually sue under APRA?

Yes. The private right of action allows consumers to sue companies directly for privacy violations without waiting for FTC enforcement. Statutory damages start at $5,000 per violation, and class actions are permitted.

$47 million

Data broker industry lobbying spending in Q1 2026 against APRA, per NYT investigation, June 2026

Source: The New York Times, 'The Privacy Bill Lobbying Battle,' June 2026

Preemption | The End of State Privacy Patchwork

APRA preempts all state privacy laws, including the California Consumer Privacy Act (CCPA), the Colorado Privacy Act, the Virginia Consumer Data Protection Act, and every other state-level privacy framework. This was a concession demanded by technology companies, which argued that complying with 50 different state privacy regimes was impossible. Consumer advocacy groups opposed preemption, arguing that California's privacy protections are stronger than the federal baseline.

The preemption provision is not absolute. States can enforce APRA in state court through their attorneys general, and states can pass laws related to specific issues not covered by APRA, including student privacy, health data, and law enforcement access. However, states cannot pass laws that are stricter than APRA on general data collection and processing, which means the CCPA's more expansive definition of personal information is effectively repealed. This creates a single national standard that is significantly stricter than most state laws but weaker than the California standard.

Frequently Asked Questions

Frequently Asked Questions

APRA applies to any entity that collects personal data from more than 50,000 consumers annually or derives more than 25% of revenue from selling personal data. Small businesses with fewer than 50,000 consumers and less than $25 million in annual revenue are exempt from most provisions except the data security requirements.
Yes. APRA grants consumers the right to delete their data, the right to access their data, and the right to port their data to another service. Companies must respond to consumer requests within 45 days.
APRA applies only to private entities. Government agencies are excluded from the law, though the bill does require the Office of Management and Budget to conduct a study on federal data collection practices within two years.
Most provisions take effect 18 months after enactment. The data broker registry must be operational within 12 months. Companies are expected to be in full compliance by January 2028.
Yes. APRA strengthens COPPA (Children's Online Privacy Protection Act) by extending protections to children up to age 17 instead of 13. Targeted advertising to minors is prohibited, and companies cannot collect data from users they know or reasonably should know are minors.

Discussion

Comments post live to the OzoneNews Discord server.
Join server →

Every comment appears live in our Discord server.

Join to see the full conversation and connect with the community.

Join OzoneNews Discord

Comments sync to our OzoneNews Discord · American Privacy Rights Act 2026 | What the Federal Privacy Bill Changes for You.