Across the United States, evolving data collection and processing practices and advances in artificial intelligence are driving new digital services, technologies, and socially beneficial research – while also raising new opportunities, risks, and questions for individuals and communities. In response, state and federal policymakers are considering new legislative and regulatory frameworks on three interconnected fronts: comprehensive consumer privacy laws that establish baseline rights and protections for personal data across the economy; frameworks that target specific sectors and practices such as automated decisionmaking, biometric identification, companion chatbots, data-driven pricing, data brokerage, frontier AI model safety, genetic data, and health data; and youth-specific privacy and online safety laws that set distinct rules for minors. These three tracks rarely stay in their lanes: a comprehensive privacy law may include AI provisions, an AI safety bill may carve out rules for minors, a youth online safety law may hinge on biometric age verification. Understanding the landscape requires understanding both the individual pieces and how they fit together.
FPF’s U.S. Legislation team provides expert, independent, pragmatic analysis of state and federal legislative and regulatory approaches to privacy, AI, and youth online safety – three distinct but increasingly intertwined issue areas. The team tracks emerging proposals, compares new laws against existing frameworks, analyzes implementation and compliance implications, and helps policymakers and stakeholders understand how legal requirements interact with current technologies, business practices, and data uses.
Through reports, blog posts, legislative and policy analyses, webinars, in-person and virtual peer-to-peer gatherings, and educational programs, FPF helps the broader technology policy and governance community understand the mechanisms and strategies available to protect privacy, promote responsible AI development and deployment, and advance youth online safety. FPF does not typically support or oppose particular bills. Instead, the U.S. Legislation team focuses on explaining the practical and legal implications of proposals – individually and as they interact with one another. This work helps ensure that privacy, AI, and youth safety compliance and policy strategies remain future-looking, adaptable, and workable for the continued, beneficial use of data and AI.
FPF’s U.S. Legislation team is led by Tatiana Rice, Senior Director.
Featured
The Connecticut Data Privacy Act Gets an Overhaul (Again)
Co-Authored by Gia Kim, FPF U.S. Policy Intern On June 25, Governor Ned Lamont signed SB 1295, amending the Connecticut Data Privacy Act (CTDPA). True to its namesake as the “Land of Steady Habits,” Connecticut is developing the habit of amending the CTDPA. Connecticut has long been ahead of the curve, especially when it comes […]
Annual DC Privacy Forum: Convening Top Voices in Governance in the Digital Age
FPF hosted its second annual DC Privacy Forum: Governance for Digital Leadership and Innovation on Wednesday, June 11. Staying true to the theme, this year’s forum convened key government, civil society, academic, and corporate privacy leaders for a day of critical discussions on privacy and AI policy. Gathering an audience of over 250 leaders from […]
FPF Unveils Paper on State Data Minimization Trends
Today, the Future of Privacy Forum (FPF) published a new paper—Data Minimization’s Substantive Turn: Key Questions & Operational Challenges Posed by New State Privacy Legislation. Data minimization is a bedrock principle of privacy and data protection law, with origins in the Fair Information Practice Principles (FIPPs) and the Privacy Act of 1974. At a high […]
Vermont and Nebraska: Diverging Experiments in State Age-Appropriate Design Codes
In May 2025, Nebraska and Vermont passed Age-Appropriate Design Code Acts (AADCs), continuing the bipartisan trend of states advancing protections for youth online. While these new bills arrived within the same week and share both a common name and general purpose, their scope, applicability, and substance take two very different approaches to a common goal: […]
FPF Experts Take The Stage at the 2025 IAPP Global Privacy Summit
By FPF Communications Intern Celeste Valentino Earlier this month, FPF participated at the IAPP’s annual Global Privacy Summit (GPS) at the Convention Center in Washington, D.C. The Summit convened top privacy professionals for a week of expert workshops, engaging panel discussions, and exciting networking opportunities on issues ranging from understanding U.S. state and global privacy […]
Amendments to the Montana Consumer Data Privacy Act Bring Big Changes to Big Sky Country
On May 8, Montana Governor Gianforte signed SB 297, amending the Montana Consumer Data Privacy Act (MCDPA). This amendment was sponsored by Senator Zolnikov, who also championed the underlying law’s enactment in 2023. Much has changed in the state privacy law landscape since the MCDPA was first enacted, and SB 297 incorporates elements of further […]
Little Rock, Minor Rights: Arkansas Leads with COPPA 2.0-Inspired Law
With thanks to Daniel Hales and Keir Lamont for their contributions. Shortly before the close of its 2025 session, the Arkansas legislature passed HB 1717, the Arkansas Children and Teens’ Online Privacy Protection Act, with unanimous votes. As the name suggests, Arkansas modeled this legislation after Senator Markey’s federal “COPPA 2.0” proposal, which passed the […]
Chatbots in Check: Utah’s Latest AI Legislation
With the close of Utah’s short legislative session, the Beehive State is once again an early mover in U.S. tech policy. In March, Governor Cox signed several bills related to the governance of generative Artificial Intelligence systems into law. Among them, SB 332 and SB 226 amend Utah’s 2024 Artificial Intelligence Policy Act (AIPA) while […]
FPF Submits Comments to the California Privacy Protection Agency on Proposed Rulemaking
On February 19, the Future of Privacy Forum (FPF) submitted comments to the California Privacy Protection Agency (CPPA) concerning draft regulations governing cybersecurity audits, risk assessments, automated decisionmaking technology (ADMT) access and opt-out rights under the California Consumer Privacy Act. FPF’s comments identified opportunities to bring additional clarity to key elements of the proposed regulations […]
Twelve Privacy Investments for Your Company for a Stronger 2025
FPF has put together a list of Twelve Privacy Investments for Your Company for a Stronger 2025 that reflects on new perspectives on the work that privacy teams do at their organizations. We hope there is something here that’s useful where you work, and we’d love to hear other ideas and feedback. Privacy Investments for Your […]