Senator reintroduces federal data protection bill
Revised law includes oversight for big tech mergers
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
Senator Kirsten Gillibrand is back with a revised bill that would create a federal data protection agency in the US to oversee consumer privacy. This time, it includes powers to review big tech company mergers.
The Democratic senator from New York introduced the Data Protection Act of 2021 today, a revised and expanded version of an original bill introduced in February 2020.
At its core lies something the US has lacked to date: a federal regulator dedicated to overseeing data privacy. The bill proposes developing an agency that would make its own data privacy rules or enforce those made by Congress across the government and private companies. It would be an executive agency with a director appointed by the president for a five-year term.
Alongside enforcing data protection rules, the agency would also develop model privacy frameworks for businesses, watch for discrimination in the use of automated algorithms, and advise the government on emerging threats like deep fakes.
The proposed law goes beyond its predecessor with several additions. The most notable is the supervision of mergers that involve data aggregators or any merger that involves transferring over 50,000 peoples' data.
The new bill would also include a civil rights office within the data protection agency, which would protect people from discrimination and clearly define terms such as privacy harm and high-risk data practices.
Under the new law, the data protection agency would have more enforcement powers, including the power to issue penalties and fines for violators.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Gillibrand targeted big tech companies in her remarks. They represent a direct threat to privacy and civil rights, she said, describing them as bad actors at the center of a "data privacy crisis."
Today, there are two main routes to hold companies accountable for privacy infractions in the US. The first is via states with strong consumer protection laws, such as California. The second is via the Federal Trade Commission, which Gillibrand called out for failing to act in dozens of cases and enforce its own orders.
Danny Bradbury has been a print journalist specialising in technology since 1989 and a freelance writer since 1994. He has written for national publications on both sides of the Atlantic and has won awards for his investigative cybersecurity journalism work and his arts and culture writing.
Danny writes about many different technology issues for audiences ranging from consumers through to software developers and CIOs. He also ghostwrites articles for many C-suite business executives in the technology sector and has worked as a presenter for multiple webinars and podcasts.
-
Anthropic promises ‘Opus-level’ reasoning with new Claude Sonnet 4.6 modelNews The latest addition to the Claude family is explicitly intended to power AI agents, with pricing and capabilities designed to attract enterprise attention
-
Researchers call on password managers to beef up defensesNews Analysts at ETH Zurich called for cryptographic standard improvements after a host of password managers were found lacking
-
AI is “forcing a fundamental shift” in data privacy and governanceNews Organizations are working to define and establish the governance structures they need to manage AI responsibly at scale – and budgets are going up
-
26% of privacy professionals expect a “material privacy breach” in 2026 as budget cuts and staff shortages stretch teams to the limitNews Overworked, underfunded privacy teams are being left hung out to dry by executives
-
Salt Typhoon attack on US congressional email system ‘exposes how vulnerable core communications systems remain to nation-state actors’News The Salt Typhoon campaign marks the latest in a string of attacks on US government communications networks
-
EU lawmakers want to limit the use of ‘algorithmic management’ systems at workNews All workplace decisions should have human oversight and be transparent, fair, and safe, MEPs insist
-
‘All US forces must now assume their networks are compromised’ after Salt Typhoon breachNews The announcement marks the second major Salt Typhoon incident in the space of two years
-
Data (Use and Access) Act comes into forcenews Organizations will be required to have an effective data protection complaints procedure and fulfil new requirements for online services that children are likely to use
-
UK businesses patchy at complying with data privacy rulesNews Companies need clear and well-defined data privacy strategies
-
Data privacy professionals are severely underfunded – and it’s only going to get worseNews European data privacy professionals say they're short of cash, short of skilled staff, and stressed
