#
No federal omnibus statute exists; coverage is fragmented across sectoral statutes and enforcement authorities, creating material compliance and mapping complexity even though enforcement activity is high.
Sub-modules (5)
Regulator And AuthorityAmber
The FTC's Bureau of Consumer Protection is the principal federal enforcer of privacy/data-security norms via Section 5 of the FTC Act; state Attorneys General and, for California, CalPrivacy, exercise parallel authority under state comprehensive statutes.
Claims (2):
- The FTC continues to bring privacy and data-security claims under Section 5 of the FTC Act as its primary enforcement lever in the absence of a comprehensive federal privacy statute.
- CalPrivacy (the California Privacy Protection Agency) is responsible for implementing and enforcing the CCPA as well as the Delete Act, which creates additional data-broker requirements.
Act And InstrumentsAmber
Key federal instruments: FTC Act §5, COPPA (as amended 2025), GLBA Safeguards Rule, FCRA, the Health Breach Notification Rule, and PADFAA (2024). State instruments include the CCPA/CPRA, Delete Act, and 19+ state comprehensive privacy statutes.
Claims (1):
- No comprehensive federal privacy lawmaking initiative has been enacted as of the current legislative session; recent federal activity is limited to sectoral statutes and draft bills such as the SECURE Data Act.
Material ScopeAmber
Federal sectoral statutes apply to defined categories of data/processing (children's data, financial data, credit data, health-adjacent data, foreign-adversary transfers of sensitive PII); no general federal 'personal data' scope exists analogous to GDPR Art.4.
Claims (1):
- No comprehensive federal privacy lawmaking initiative has been enacted as of the current legislative session; recent federal activity is limited to sectoral statutes and draft bills such as the SECURE Data Act.
Territorial ScopeAmber
FTC jurisdiction attaches to entities in or affecting US commerce; PADFAA specifically reaches data brokers dealing in Americans' sensitive data regardless of the broker's location when the counterparty is a foreign adversary.
Claims (1):
- PADFAA prohibits data brokers from selling, releasing, disclosing, or providing access to personally identifiable sensitive data about Americans to foreign adversaries including North Korea, China, Russia, and Iran.
Regulator Registration And FilingAmber
No federal controller-registration regime exists. California's Delete Act requires data brokers to register annually with CalPrivacy and fund the DROP deletion platform; failure to register has been actively fined.
Claims (1):
- California's Delete Act requires data brokers to register annually with CalPrivacy and pay a fee funding the Data Broker Registry and DROP platform; failure to register has resulted in fines (e.g., Datamasters, $45,000; S&P Global, $62,600).
Regulator & Framework
The United States continues to lack comprehensive federal privacy legislation, and the Federal Trade Commission enforces privacy matters primarily through Section 5 of the FTC Act's general unfair-or-deceptive-practices authority, supplemented by sectoral statutes. This standing enforcement architecture remained unchanged this cycle, but the state-level regulatory landscape it sits alongside continued to expand: comprehensive consumer data privacy laws in Kentucky, Indiana, and Rhode Island took effect January 1, 2026, bringing the total number of states with comprehensive privacy laws to twenty.
This continues a multi-year pattern of incremental state-by-state comprehensive privacy legislation in the absence of a federal framework, reinforcing the United States' fragmented, jurisdiction-by-jurisdiction approach to data protection. Each new state framework operates independently, layering additional compliance obligations onto entities operating across state lines, without any federal harmonizing statute in place.
Outlook
The trajectory of incremental state-level comprehensive privacy legislation is likely to continue, and prospective entrants to the US compliance landscape should expect further state additions to the twenty-state baseline established this cycle. No federal comprehensive privacy legislation was indicated as imminent within this cycle's evidence.
Sources and claims (5)
- ProbableIAPP — The FTC continues to bring privacy and data-security claims under Section 5 of the FTC Act as its primary enforcement lever in the absence of a comprehensive federal privacy statute.observed
- ProbableCPPA — CalPrivacy (the California Privacy Protection Agency) is responsible for implementing and enforcing the CCPA as well as the Delete Act, which creates additional data-broker requirements.observed
- ProbableIAPP — No comprehensive federal privacy lawmaking initiative has been enacted as of the current legislative session; recent federal activity is limited to sectoral statutes and draft bills such as the SECURE Data Act.observed
- ProbableFTC — PADFAA prohibits data brokers from selling, releasing, disclosing, or providing access to personally identifiable sensitive data about Americans to foreign adversaries including North Korea, China, Russia, and Iran.observed
- ProbableCPPA — California's Delete Act requires data brokers to register annually with CalPrivacy and pay a fee funding the Data Broker Registry and DROP platform; failure to register has resulted in fines (e.g., Datamasters, $45,000; S&P Global, $62,600).observed