A look at a proposed US national privacy law, backed by 200 retailers, banks, and tech companies, that would create universal data collection rules and more
Cat Zakrzewski / Washington Post :
Context & Ripple Effects
This proposal lands four months after tech companies began lobbying for a federal privacy law that would overrule California's and hand them wide leeway over personal data handling. The December version widens the coalition beyond Silicon Valley to 200 retailers and banks, all pushing for one set of universal collection rules instead of a state-by-state patchwork.
It is also the opening move in a pattern the later coverage makes legible: the same push resurfaces as the bipartisan American Data Privacy and Protection Act in 2022 — which would let users opt out of targeted ads and sue companies that improperly sell their data (opt-out rights plus a private right of action) — and again as the American Privacy Rights Act draft in 2024, adding a data broker registry.
First-order effects
- If enacted, the 200 signatories' preferred outcome is a single national compliance standard replacing divergent state rules like California's, cutting multi-state compliance costs for retailers, banks, and tech platforms alike.
Second-order effects
- Privacy advocates and state lawmakers face a preemption fight: an industry-backed federal floor could override stricter state protections, so the battle shifts from whether to regulate to whose baseline wins.
Third-order effects
- The recurring cycle — industry-shaped drafts in 2018, the ADPPA in 2022, the APRA in 2024 — suggests federal privacy law advances through repeated near-passes, leaving the state-versus-federal question unresolved while each new draft normalizes opt-outs, broker registries, and consumer rights as the expected content of any eventual law.
The trend: US federal privacy legislation moves in multi-year waves of industry-influenced bipartisan drafts, each broadening consumer rights while the preemption standoff keeps a final law out of reach.