Federal privacy law highly unlikely in 2026, leaving states to continue setting their own rules
Efforts to pass a comprehensive federal privacy law have stalled for years, and privacy experts believe the prospects for legislation this year amid midterm elections and other priorities appear highly unlikely, leaving states to continue setting their own rules and further expand an already patchwork privacy landscape.
Over the next two years, several new state privacy laws and amendments will take effect, expanding requirements around sensitive, health and children’s data while lowering thresholds for coverage and increasing oversight of vendors and data brokers.
Oklahoma, Louisiana and Alabama have recently enacted comprehensive privacy laws that are set to take effect in 2027, while Vermont’s more expansive law begins in 2028. Virginia, Maryland, Connecticut, New Hampshire and Delaware have also passed amendments to their existing laws, adding restrictions on things like precise geolocation, sensitive-data inferences, facial recognition, children’s data and third-party data processing. Delaware’s amendments will notably require businesses to conduct and document due diligence on third parties that receive personal data.
States are also developing more targeted regimes. New Jersey is broadening its data-broker requirements, while Texas, Utah, Louisiana and California are adopting age-signal and children’s privacy rules that impose new obligations on apps and services used by minors.
Together, the changes highlight how states are continuing to expand and refine privacy requirements even as federal efforts have repeatedly faltered.
Congress has recently explored three major proposals, each facing disputes over how strong a national standard should be and how much it should preempt existing state laws. With each failed effort, however, optimism has dwindled about enacting a law capable of replacing the state-by-state approach, privacy experts told StateScoop. Businesses, state governments and attorneys general offices may instead have to adjust to a landscape of dozens of differing privacy requirements.
The chances, especially this year, have become increasingly slim.
“As DC gears up for the midterm elections, the likelihood of passing a comprehensive consumer privacy law before the end of the year is vanishingly small,” said Cobun Zweifel-Keegan, managing director of IAPP, a data-privacy nonprofit. “There are very few legislative days left, many competing priorities including on emerging technology issues like catastrophic AI risk, and no bipartisan privacy bill that has any meaningful momentum.”
However, Zweifel-Keegan pointed out that just because federal data privacy legislation doesn’t make it through Congress doesn’t mean the work done this term is meaningless. Specifically, he noted that Rep. Brett Guthrie, a Republican from Kentucky and chair of the Energy and Commerce Committee, has made meaningful progress developing a GOP model for consumer privacy with his SECURE Data Act, introduced in April.
A House Energy and Commerce subcommittee held a hearing on the SECURE Data Act in June, where the party divide was pronounced: Republicans argued that businesses need one national standard, while Democrats and privacy advocates argued that federal legislation shouldn’t eliminate stronger protections states have already enacted
“Regardless of the outcome in November, this bill will continue to contribute to the policy discourse, and the committee’s work to build understanding of complex privacy issues among its members will help to contribute to a richer conversation,” Zweifel-Keegan told StateScoop in an emailed statement.
Preceding the SECURE Data Act, Congress came close to passing a comprehensive federal privacy law in 2022 with the American Data Privacy and Protection Act. The bill would have established national consumer privacy rights and requirements for companies, including a data-minimization obligation, and included preemption of state privacy laws, with some exceptions. It ultimately failed to advance out of committee.
Then, Senate Commerce Committee Chair Maria Cantwell, D-Wash., and House Energy and Commerce Chair Cathy McMorris Rodgers, R-Wash., attempted to revive the effort in 2024 with the bipartisan, bicameral American Privacy Rights Act. It sought to create a national privacy framework but featured a very broad preemption of the growing patchwork of state privacy laws, including stronger state protections like Illinois’ Biometric Information Privacy Act and Washington’s My Health My Data Act.
David Saunders, a partner at the global law firm McDermott Will & Schulte who specializes in privacy and cybersecurity, explained that some of these past efforts failed following a lack of support from lawmakers in California and other states, who opposed preemption of their existing state privacy laws.
Congress also has other priorities, Saunders said.
“You have to motivate Congress in some way because I don’t think they’re likely to put privacy law as the top factor when they’re dealing with the economy, when they’re dealing with immigration, when they’re dealing with national security,” Saunders told StateScoop. “These other things that I think they all view — and for good reason — as higher priorities.”
While he concurs with Zweifel-Keegan about the unlikelihood of Congress passing a federal privacy law this session, Saunders said that work done in past Congresses — such as the work done on the SECURE Data Act to garner a consensus amongst Republicans — doesn’t reliably carry over to new ones.
“Unfortunately, at this point, I think it is safe to assume we are not going to have a federal privacy law,” Saunders said, adding that Congress may not take action until it is forced to following a crisis.
He said that when it comes to AI — which many view as related to privacy — the crisis is likely going to occur at “some point in the next year, year and a half.”
“I’m not an AI doomsdayer, but I do believe that at some point there will be a significant crisis with respect to AI,” Saunders said. “At that moment, Congress will have to do something. When you’re considering AI, ancillary to it is privacy — protecting consumers from a disclosure of their information to a tool they can’t control. To me, that’s the lever.”