The American Privacy Rights Act (APRA) of 2026 is the first comprehensive federal consumer data privacy law passed by the United States Congress. The bill establishes data minimization requirements, restricts algorithmic profiling without explicit consent, creates a national data broker registry, and provides a private right of action for consumers whose data is mishandled. It preempts state privacy laws including the California Consumer Privacy Act (CCPA).
Key Takeaways
- 1APRA creates a national data minimization standard requiring companies to collect only the data necessary to provide a service
- 2The bill establishes a federal data broker registry with annual reporting requirements and civil penalties for noncompliance
- 3Algorithmic profiling for employment, housing, and credit eligibility is restricted unless the consumer provides separate opt-in consent
- 4A private right of action allows consumers to sue companies for privacy violations without waiting for FTC enforcement
- 5The law preempts all state privacy laws, including the CCPA and California Privacy Rights Act
- 6The FTC receives $1.5 billion in new funding over five years to enforce the act and hire 500 new investigators
The American Privacy Rights Act of 2026 represents the most significant expansion of consumer privacy protections in United States history. Passed with bipartisan support after three years of negotiation, the bill creates a single national framework for data privacy that replaces the current patchwork of state laws. The law fundamentally changes how companies collect, process, and sell personal data, and it gives individual consumers the right to sue companies that violate their privacy without waiting for government action.
The Core Provisions | Data Minimization and Consent Requirements
The central pillar of APRA is data minimization. Companies are now prohibited from collecting personal data beyond what is reasonably necessary to provide the product or service that a consumer requests. This provision targets the business model of companies like Acxiom and CoreLogic, which aggregate data from multiple sources to build detailed consumer profiles for sale to third parties. Under APRA, a company cannot collect location data, browsing history, or purchase history unless that data is directly required for the transaction the consumer is performing.
The bill also introduces a tiered consent framework. Companies must obtain explicit opt-in consent before processing sensitive data, which includes biometric identifiers, precise geolocation, health information, and private communications. For non-sensitive data, companies must provide a clear and conspicuous opt-out mechanism that consumers can exercise at any time. The FTC is authorized to issue fines of up to $50,000 per violation per consumer for companies that violate the consent requirements. The full text of the American Privacy Rights Act is available through Congress.gov.
What counts as sensitive data under APRA?
The bill defines sensitive data as biometric identifiers, precise geolocation, health information, private communications, financial account details, government-issued IDs, and information about children under 17. Companies must obtain explicit opt-in consent before collecting or processing any sensitive data.
Source: American Privacy Rights Act of 2026, Section 102, June 2026
The Data Broker Registry | Ending the Shadow Economy
APRA establishes the first federal data broker registry, administered by the FTC. Any company that buys, sells, or shares personal data of consumers with whom it does not have a direct relationship must register annually and disclose the types of data it collects, the sources of that data, and the categories of purchasers to whom it sells. The registry is public and searchable. Failure to register carries a penalty of $100,000 per day.
This provision directly targets the commercial data broker industry, which the FTC has estimated generates over $200 billion annually in revenue by selling consumer data to advertisers, insurance companies, and government agencies. The Palantir Gotham surveillance architecture relies on data feeds from commercial brokers, and APRA would restrict the flow of that data by requiring individual consent for each sale. The EPIC analysis of APRA confirms that the data broker registry will be operational within 18 months of the bill's enactment. EPIC's full analysis of APRA provides a section-by-section breakdown.
How does the data broker registry work?
Any company that buys or sells consumer data with whom it has no direct relationship must register with the FTC annually. The registration includes the types of data collected, the sources of data, and the categories of purchasers. The registry is publicly searchable and comes with a $100,000 per day penalty for noncompliance.
$200 billion
Estimated annual revenue of the US commercial data broker industry, FTC Report on Data Brokers, 2026
Source: FTC Report on Data Brokers, 2026
The Private Right of Action | Individual Lawsuits Without FTC Action
APRA includes a private right of action, which was the most contentious provision in the negotiations. Consumers can now file lawsuits against companies for privacy violations without waiting for the FTC to investigate or bring an enforcement action. This provision was the primary reason that technology and advertising industry lobbyists opposed the bill. The NYT reported that data broker industry lobbying spending reached $47 million in the first quarter of 2026 alone, making it the largest lobbying expenditure by any industry outside of pharmaceuticals.
The private right of action is limited to actual damages or statutory damages of $5,000 per violation, whichever is greater. Class action lawsuits are permitted, which legal analysts expect will create a wave of litigation against the largest data brokers. Companies that can demonstrate compliance with the FTC's approved privacy framework are immune from private lawsuits, a provision designed to incentivize companies to adopt best practices rather than fight litigation. The NYT investigation into data broker lobbying details the political battle behind the bill.
Can consumers actually sue under APRA?
Yes. The private right of action allows consumers to sue companies directly for privacy violations without waiting for FTC enforcement. Statutory damages start at $5,000 per violation, and class actions are permitted.
$47 million
Data broker industry lobbying spending in Q1 2026 against APRA, per NYT investigation, June 2026
Source: The New York Times, 'The Privacy Bill Lobbying Battle,' June 2026
Preemption | The End of State Privacy Patchwork
APRA preempts all state privacy laws, including the California Consumer Privacy Act (CCPA), the Colorado Privacy Act, the Virginia Consumer Data Protection Act, and every other state-level privacy framework. This was a concession demanded by technology companies, which argued that complying with 50 different state privacy regimes was impossible. Consumer advocacy groups opposed preemption, arguing that California's privacy protections are stronger than the federal baseline.
The preemption provision is not absolute. States can enforce APRA in state court through their attorneys general, and states can pass laws related to specific issues not covered by APRA, including student privacy, health data, and law enforcement access. However, states cannot pass laws that are stricter than APRA on general data collection and processing, which means the CCPA's more expansive definition of personal information is effectively repealed. This creates a single national standard that is significantly stricter than most state laws but weaker than the California standard.
Frequently Asked Questions
Frequently Asked Questions
Sources
- ^[1]U.S. Congress. American Privacy Rights Act of 2026 Full Text (June 2026)
- ^[2]Federal Trade Commission. FTC Testimony on APRA Enforcement (June 2026)
- ^[3]Electronic Privacy Information Center. EPIC Analysis of the American Privacy Rights Act (June 2026)
- ^[4]The New York Times. The Privacy Bill Lobbying Battle (June 2026)