Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • Senate Bill Would Require GAO to ‘Pick Up’ After DOGE With Cybersecurity Audits
    • Bicameral Legislation Would Restrict Use of Cell-Site Simulators
    • Bipartisan Senate Bill Aims to Jump-Start Transition to Quantum-Proof Encryption
    • House Bill Would Ban DoT From Using Chinese Mapping Tech
    • Privacy Advocates, Industry Groups Take Sides on FCC’s CALEA Cybersecurity Ruling
    • Proposed Privacy Rule Changes Open for Comment in Colorado
    • Rules on Accessible Deletion Mechanism Open for Comment in California
    • Senate Hearing Highlights Calls for National Data Protection Rules
    • Toolkit for Vulnerable Adult Data Protection Published by Irish DPC
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Senate Hearing Highlights Calls for National Data Protection Rules, (Jul 31, 2025)

    Organizations Mentioned:Bureau of Consumer Protection | Federal Trade Commission

    By Jeff Williams

    With numerous state data privacy laws already on the books and more under consideration, lawmakers and witnesses at a hearing of the Senate Judiciary Committee’s subcommittee on privacy, technology, and the law yesterday said that after years ...

    By Jeff Williams

    With numerous state data privacy laws already on the books and more under consideration, lawmakers and witnesses at a hearing of the Senate Judiciary Committee’s subcommittee on privacy, technology, and the law yesterday said that after years of debate it was time for Congress to pass a national law to protect consumers and provide clear guidance to businesses.

    Sen. Marsha Blackburn (R., Tenn.), chair of the subcommittee, called the question of how consumers could protect their data “one of the most consequential issues up for discussion when we talk about the virtual space” and faulted online companies for leaving consumers to “decipher lengthy privacy policies and click ‘agree’ at the bottom of the page, even before they can begin to access any online service.”

    The lack of a comprehensive national data privacy framework “has left millions of Americans vulnerable,” she said.

    Though “numerous states have enacted data privacy laws, the result has been a patchwork that fails to provide the clarity, consistency, and confidence that consumers and responsible businesses need and deserve,” Ms. Blackburn said.

    It is “past time for Congress to take up this issue, take action to pass a bill, and see that bill signed into law,” she said.

    The U.S. needs an enforceable national privacy standard that “empowers consumers, promotes innovation, and ensures accountability,” she said. “It should prioritize transparency, minimize data collection, and provide meaningful consent, not just a box to check."

    Sen. Amy Klobuchar (D., Minn.), the ranking member of the subcommittee, said federal law “doesn’t do enough” to address the privacy concerns that have accompanied technological innovations.

    Though they “collect an enormous amount of information about our daily lives,” she said, “for far too long, the big tech companies, many of which dominate the market they operate in, have been telling American consumers, ‘Just trust us,’ even though their business models are designed to collect personal information and to use it for profit.”

    Ms. Klobuchar said she agreed that the patchwork of state laws was a problem and faulted large tech companies for standing in the way of a national law, while at the same time complaining about the difficulty of complying with differing state laws.

    Kate Goodloe, managing director at the Business Software Alliance, said the U.S. government needed “a strong, clear, comprehensive consumer privacy law” because “consumers deserve to know how their data is being used.”

    Such a law should “require that companies handle consumers’ data responsibly and assign obligations to companies based on their role in handling that data.”

    “Each company must protect the personal data it handles,” she said, adding that “laws should not create a one-size-fits-all obligation. Doing so actually creates new privacy and security concerns for consumers.”

    Ms. Goodloe also credited states for having implemented “remarkably consistent” privacy laws that acknowledge differences between “controllers and processors” of data that “must be part of any federal privacy law.”

    A national law should also provide consumers “new rights” to let them control access to their data and “create strong, consistent enforcement,” she said.

    Joel Thayer, president of the Digital Progress Institute, said that because online companies “know everything about us,” average consumers are “right to be concerned” about their lack of control over their personal information.

    The group welcomes increasing bipartisan support at the federal and state levels for privacy legislation, Mr. Thayer said.

    A national law should have “clearly articulated goals with targeted solutions” that are not “overly sweeping,” he said, pointing to the European Union’s General Data Protection Regulation as a “cautionary tale” that has shown that “privacy regulation without market guardrails can seriously exacerbate today’s competition issues.”

    In sum, Mr. Thayer said, “[T]he reality is that if these Big Tech companies cared about user privacy, they would have done it. Frankly, it’s in their interest not to. Congress needs to act.”

    Paul Martino, founder and general counsel at the Main Street Privacy Coalition, argued that “Americans expect their privacy to be protected the same everywhere” and said the group had a “strong conviction that a preemptive federal privacy law will benefit consumers and Main Street businesses alike.”

    Such a law “would give consumers confidence that their data would be uniformly protected across America, regardless of where they live or choose to do business, and it would provide the certainty that Main Street businesses need to lawfully and responsibly use data to better serve their customers online or across state lines,” he said.

    There should be “equivalent standards for all businesses” and the law should “empower consumers to control their data used by businesses, regardless of business type,” Mr. Martino said, adding that businesses should also “be allowed to use data shared with them to better serve customer needs.”

    Alan Butler, executive director and president of the Electronic Privacy Information Center, said a federal privacy law should “set a consistent and robust standard for protection, while preserving flexibility for states in the future.”

    Mr. Butler criticized many state laws for doing “very little to actually limit abusive data practices and to protect privacy.”

    But, he said, though large companies have lobbied state lawmakers “heavily to water down” state laws, there are ongoing positive efforts among many state legislatures to pass stronger statutes.

    Samuel Levine, senior fellow at the University of California–Berkeley’s Center for Consumer Law & Economic Justice and former director of the Federal Trade Commission’s Bureau of Consumer Protection, cited several problems created by the lack of a national privacy law.

    Among them are “personalized price gouging,” which is “only possible because weak privacy protections are allowing companies to track our behavior and predict how much we can be pushed to pay” using “surveillance pricing” practices, Mr. Levine said.

    “Unchecked data collection is moving us from a world of ‘one product, one price’ to ‘one person, one price,’” he said. “And if we don’t act, this shift will be costly.”

    In addition, Mr. Levine said, “No Americans should be profiled based on their politics, their religion, or their stance on COVID lockdowns. Yet, without strong data protections, that’s exactly what [data] brokers are doing. Political and religious freedom cannot thrive in a society where our beliefs, movements, and behaviors are tracked, recorded, and then sold to the highest bidder. We need to act.”

    News: FederalLegislation DataPrivacy

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use