---
title: What America’s Federal Privacy Bill Means for Data Protection
description: What’s in the APRA? Like the GDPR, the proposed legislation both empowers data subjects with new rights over their personal information (and what organizations do with it), and obliges those organizations to take strict measures to protect that data.
image: https://insights.comforte.com/hubfs/comforte%20AG_What%20Americas%20Federal%20Privacy%20Bill%20Means%20for%20Data%20Protection%20_23.05.png
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![comforte AG - What America’s Federal Privacy Bill Means for Data Protection](https://insights.comforte.com/hubfs/comforte%20AG_What%20Americas%20Federal%20Privacy%20Bill%20Means%20for%20Data%20Protection%20_23.05.png)](https://insights.comforte.com/what-americas-federal-privacy-bill-means-for-data-protection)

[Dan Simmons](https://insights.comforte.com/author/dan-simmons) l May 23, 2024 l [Data Protection](https://insights.comforte.com/tag/data-protection), [Compliance](https://insights.comforte.com/tag/compliance)

# What America’s Federal Privacy Bill Means for Data Protection

After [years of false starts](https://insights.comforte.com/is-the-us-ready-for-centralized-data-privacy-enforcement?hsLang=en), the US is edging closer to a federal data privacy law. In a surprise move, two lawmakers last month introduced a bipartisan, bicameral piece of legislation described as “the best opportunity we've had in decades” to finally enshrine a national privacy and security standard into law.

With detailed provisions mandating strict control of sensitive information, it will force organizations to revisit and enhance their data security policies and controls.

## Filling the void

Up until now, state legislatures have been forced to take matters into their own hands to protect American’s privacy rights. California was the first to do so in 2018, with a GDPR-like law, the California Privacy Protection Act (CPPA). It’s been followed by many others. As of March 2024, there were 15 discrete state-level data protection laws, plus a privacy-focused act in Florida aimed specifically at large technology companies.

The battle to get the same passed at a federal level has been fought since the early days of the internet, but bipartisan agreement has thus far proven a step too far. In 2022, an American Data Privacy and Protection Act (ADDPA) was canned after Democrat concerns that it would “pre-empt” or overrule stronger state privacy laws at a state level – particularly in California. It’s unclear why the stars have aligned at this specific moment – especially in an election year. But [experts are predicting](https://iapp.org/news/a/new-draft-bipartisan-us-federal-privacy-bill-unveiled/) the legislation – sponsored by Democratic senator Maria Cantwell and Republican representative Cathy McMorris Rodgers – has a great chance of becoming law.

## What’s in the APRA?

Like the GDPR, the proposed legislation both empowers data subjects with new rights over their personal information (and what organizations do with it), and obliges those organizations to take strict measures to protect that data. The part of the bill related to data security [is Section 9](https://d1dth6e84htgma.cloudfront.net/American_Privacy_Rights_Act_of_2024_Discussion_Draft_0ec8168a66.pdf) which states:

*“A covered entity and service provider shall establish, implement, and maintain reasonable data security practices to protect—the confidentiality, integrity, and accessibility of covered data; and covered data against unauthorized access.”*

The exact measures organizations will be expected to take will depend on the size and complexity of the organization, the volume and sensitivity of the data and other factors. But at a minimum they could include:

- Vulnerability assessments to routinely identify “any reasonably foreseeable internal or external risk to, and vulnerability in” data processing, retention, collection or transfer technologies. This could include unauthorized access, “human vulnerabilities,” access rights, service provider risk, and more
- Preventative and corrective action to fix any discovered risks/vulnerabilities, including “implementing administrative, technical, or physical safeguards or changes to data security practices or the architecture, installation, or implementation of network or operating software”
- Updating the above in light of any changes to technology, internal/external threats and business operations
- Permanently erasing data that is no longer necessary for the purpose for which the data was collected, processed, retained, or transferred
- Employee training in data protection/handling best practice
- Incident response so that the organization can detect, respond to and recover from data security incidents/breaches

Sensitive data covered by the act includes government-issued identifiers (Social Security numbers, passports and driver’s licenses), health, genetic, biometric and financial information, log-ins and other personally identifiable information (PII). Organizations will also be forced to appoint a Data Security Officer to run their data privacy and security program.

There’s no mention of fines for erring companies at this stage. But crucially, the law gives individuals the right to sue bad actors who violate their privacy rights—and recover money for damages when they’ve been harmed.

“A federal data privacy law must do two things: it must make privacy a consumer right, and it must give consumers the ability to enforce that right,” [said Maria Cantwell](https://energycommerce.house.gov/posts/committee-chairs-rodgers-cantwell-unveil-historic-draft-comprehensive-data-privacy-legislation), chair of the Senate Committee on Commerce, Science and Transportation. “Working in partnership with Representative McMorris Rodgers, our bill does just that. This bipartisan agreement is the protections Americans deserve in the Information Age.”

## Putting controls in place

It follows that the quickest and easiest way to meet the Section 9 requirements for “reasonable data security practices” is through strong data protection. In fact, the draft law mandates the launch of a pilot program within a year to encourage private sector use of “privacy-enhancing technology.” This includes “any software or hardware solution, cryptographic algorithm, or other technical process of extracting the value of the information without risking the privacy and security of the information.”

This is exactly what tokenization can do – enabling organizations to use data in analytics and other business-enhancing use cases without compromising on security. Comforte’s [Data Security Platform](https://www.comforte.com/data-security) offers this and other data protection options including format-preserving encryption. It continually and automatically discovers and classifies sensitive data wherever it resides in the organization, and applies these protections seamlessly in line with policy.

As a federal data privacy law edges closer, the need to enhance corporate data protection policy with powerful security controls has never been greater.

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/what-americas-federal-privacy-bill-means-for-data-protection&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/what-americas-federal-privacy-bill-means-for-data-protection&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/what-americas-federal-privacy-bill-means-for-data-protection&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/what-americas-federal-privacy-bill-means-for-data-protection&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/what-americas-federal-privacy-bill-means-for-data-protection&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Learn how to discover, classify, and protect all sensitive data.

Click the button below to download the solution brief for our Data Security Platform:

[![Download Solution Brief](https://no-cache.hubspot.com/cta/default/4026697/65e094b1-44ae-496e-be17-1678a1876675.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/65e094b1-44ae-496e-be17-1678a1876675)

### Related posts

![Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/hubfs/comforte%20AG_%20Reuse%20Reward_%20How%20Banks%20Can%20Safely%20Unlock%20the%20Value%20of%20Their%20Data_03.2025.png)

 Mar 12, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Payments Transformation](https://insights.comforte.com/tag/payments-transformation) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

The financial world is awash with data. But too few organizations are able to use it effectively. In [Bank Director’s *2025 Technology Survey*](https://www.bankdirector.com/wp-content/uploads/2025/09/2025TechReport-OpenVersion.pdf), one-third of US banking leaders cite an inability to harness data as a top technology challenge facing their...

[Read more](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

![Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/hubfs/comforte%20AG_Delivering%20a%20Secure%2c%20Trusted%20Foundation%20for%20Cloud%20Growth%20at%20LGT_01.2026.png)

 Jan 15, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

There’s a world of difference between retail and private banking. While the former is transactional and focused on the mass market, the latter is built on trust and personal relationships. That trust can be hard won, but is easily lost, especially...

[Read more](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

![Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/hubfs/comforte%20AG_Top%20Indicators%20You%20Have%20a%20Cybersecurity%20Problem_and%20What%20to%20Do%20About%20It.png)

 May 22, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Digital Enablement](https://insights.comforte.com/tag/digital-enablement)

### [Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

Data is both blessing and curse to the modern enterprise. Yes, when analyzed effectively it can surface intelligence to improve decision making, customer engagement, process efficiency and, ultimately, drive revenue. But it also represents a major...

[Read more](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>