#
No federal omnibus statute exists; coverage is fragmented across sectoral statutes and enforcement authorities, creating material compliance and mapping complexity even though enforcement activity is high.
Sub-modules (5)
Regulator And AuthorityAmber
The FTC's Bureau of Consumer Protection is the principal federal enforcer of privacy/data-security norms via Section 5 of the FTC Act; state Attorneys General and, for California, CalPrivacy, exercise parallel authority under state comprehensive statutes.
Claims: CLM-US-a1b2c3d4, CLM-US-b2c3d4e5
Act And InstrumentsAmber
Key federal instruments: FTC Act §5, COPPA (as amended 2025), GLBA Safeguards Rule, FCRA, the Health Breach Notification Rule, and PADFAA (2024). State instruments include the CCPA/CPRA, Delete Act, and 19+ state comprehensive privacy statutes.
Claims: CLM-US-c3d4e5f6
Material ScopeAmber
Federal sectoral statutes apply to defined categories of data/processing (children's data, financial data, credit data, health-adjacent data, foreign-adversary transfers of sensitive PII); no general federal 'personal data' scope exists analogous to GDPR Art.4.
Claims: CLM-US-c3d4e5f6
Territorial ScopeAmber
FTC jurisdiction attaches to entities in or affecting US commerce; PADFAA specifically reaches data brokers dealing in Americans' sensitive data regardless of the broker's location when the counterparty is a foreign adversary.
Claims: CLM-US-d4e5f6a7
Regulator Registration And FilingAmber
No federal controller-registration regime exists. California's Delete Act requires data brokers to register annually with CalPrivacy and fund the DROP deletion platform; failure to register has been actively fined.
Claims: CLM-US-e5f6a7b8
No periodic updates recorded against this sub-brief.
Sources and claims (5)
- ConfirmedIAPP — The FTC continues to bring privacy and data-security claims under Section 5 of the FTC Act as its primary enforcement lever in the absence of a comprehensive federal privacy statute.
- ConfirmedCPPA — CalPrivacy (the California Privacy Protection Agency) is responsible for implementing and enforcing the CCPA as well as the Delete Act, which creates additional data-broker requirements.
- ConfirmedIAPP — No comprehensive federal privacy lawmaking initiative has been enacted as of the current legislative session; recent federal activity is limited to sectoral statutes and draft bills such as the SECURE Data Act.
- ConfirmedFTC — PADFAA prohibits data brokers from selling, releasing, disclosing, or providing access to personally identifiable sensitive data about Americans to foreign adversaries including North Korea, China, Russia, and Iran.
- ConfirmedCPPA — California's Delete Act requires data brokers to register annually with CalPrivacy and pay a fee funding the Data Broker Registry and DROP platform; failure to register has resulted in fines (e.g., Datamasters, $45,000; S&P Global, $62,600).