No CRS summary available for this bill.
This section states congressional findings that (1) governments exist to protect individual rights to life, liberty, and property; (2) civil liberties, including private property and privacy rights, are hallmarks of a free society; (3) Congress may enact laws protecting individuals from third-party data collection; (4) users own the data they create and retain ownership even if sold or leased with consent; and (5) technology should empower individuals without sacrificing privacy and anonymity.
This section prohibits covered entities from requesting access to a user's contacts without written consent from both the user and contacts and establishes multiple data privacy requirements for covered entities and commercial data operators, including— (1) user rights to access covered data (including lists of recipients and summaries), correct inaccuracies, delete or de-identify data, and receive portable data in a machine-readable format, fulfilled free of charge up to twice per 12-month period and within 90 days of a verified request, with no retaliation in services or pricing and required notifications to third parties; (2) deletion of browsing history or biometric data within 60 days of collection; (3) data minimization limiting collection, sharing, use, and retention to what is reasonably necessary for requested services or fraud prevention (excluding monetization), with fraud data barred from other operational uses; (4) a prominent opt-out icon for data collection on websites and apps, and reasonable steps within two years of enactment to enable direct data deletion; (5) parental or guardian consent, where technically feasible, for collecting, retaining, or transferring data of users under 18; (6) prohibition on tracking cookies without user authorization, with equal services provided regardless; (7) clear privacy notices of 1,000 words or less detailing data practices; and (8) annual reports to users whose data is sold, listing shared data types, purposes, and recipients, plus timely breach notifications.