On April 7th, Congress surprised Americans by releasing a draft of a potential U.S. federal data privacy bill, the American Privacy Rights Act (APRA), along with a companion discussion draft.
It would give Americans control over their personal information and regulate the current patchwork of state-level legislation.
In this guide, I’ll discuss the APRA and how it may impact consumers and businesses.
Key Takeaways
Here’s a brief overview of everything you need to know about the APRA:
- The APRA is a proposed draft of a U.S. federal data privacy law that gives Americans privacy controls and opt-out rights.
- Covered entities must present users with a privacy policy and mechanisms for following through with their rights.
- It gives consumers the right to private action, to opt out of targeted ads, and to transfer their covered data.
What Is the American Privacy Rights Act (APRA)?
The American Privacy Rights Act (APRA) is the newest iteration of a potential federal data privacy law moving through the U.S. government.
It gives Americans uniform rights and control regarding how their personal information is collected, processed, and used by third parties and gives consumers a private right of action.
APRA Effective Date
If passed, the APRA would become effective 180 days after enactment.
APRA Key Terms and Definitions
To help you better understand the APRA, read through our simplified definitions of some key terms introduced by the potential law:
- Covered entity: The entity that determines the purpose and means of collecting, processing, and transferring covered data.
- Covered data: Information that can identify or link to an individual or device, excluding information like de-identified data, employee data, and publicly available information.
- Sensitive covered data: This is a subset of data that includes details like login credentials, precise geolocation, government identification, race, ethnicity, religion, and online browsing activities.
- Large data holder: Covered entities that earn $250 million or more in annual revenue and collect and process covered data of more than 5,000,000 individuals (or 15,000,000 portable devices, or 35,000,000 connected devices) or the sensitive data of more than 200,000 individuals (or 300,000 portable devices, or 700,000 connected devices).
- Small businesses: Businesses with $40 million or less in annual revenue that collect and process covered data of 200,000 or fewer individuals (not including credit card swipe and other transient data) and don’t earn revenue from the transfer of covered data to third parties (these are exempt from the Act).
What Is the Purpose of the APRA?
The APRA aims to provide U.S. citizens with a uniform, comprehensive consumer data privacy law and establish protections for covered data.
It sets standards for data minimization so companies only collect and use necessary data for limited purposes.
Who Supports the APRA?
The APRA was presented by:
- The House Committee on Energy and Commerce Chair Cathy McMorris Rodgers (R-Wash)
- The Senate Committee on Commerce, Science, and Transportation Chair Maria Cantwell (D-Wash)
What’s Included in the APRA?
Below, read through some of the main requirements included in the current draft of the American Privacy Rights Act:
- Data minimization: Covered entities must only collect necessary, proportionate, and limited data to provide a product or service.
- Transparency: Entities need a privacy policy detailing their privacy and security practices and how consumers can exercise their privacy controls and opt-out rights.
- Consumer controls: Consumers have the right to access, correct, and delete their covered data and know of any third party to whom their data was transferred.
- Opt-out rights: Consumers can opt out of the transfer of non-sensitive data, targeted advertising, and algorithms used for consequential decisions.
- Interference with consumer rights: The APRA prohibits using dark patterns to direct an individual’s attention from a privacy notice.
- Prohibition on denial of service and waiver of rights: Covered entities cannot retaliate against individuals who exercise their privacy rights under the Act.
- Data security: Covered entities must establish security practices to mitigate foreseeable risks to consumer data.
- Executive responsibilities: Covered entities must choose a privacy and/or data security officer(s), and large data holders must conduct privacy impact assessments.
- Service providers and third parties: Service providers must adhere to the Act and cease data practices if they know a covered entity is violating it.
- Data brokers: Data brokers must have a public website identifying them as such and provide a tool for individuals to follow through on their controls and opt-out rights.
- Enforcement and a right to private lawsuits: The Act would be enforced by state attorneys general, the Federal Trade Commission, and individuals, who can file private lawsuits against entities that violate their rights.
- Preemption: The act preempts state laws, excluding an enumerated list. As written under the California Consumer Privacy Act (CCPA), California residents maintain the right to pursue private action if their data is part of a data breach.
APRA Impact on Businesses and Consumers
The APRA would impact businesses and consumers in the following ways:
How It Impacts Businesses
Some of the ways the APRA impacts covered businesses include requiring them to:
- Have a compliant privacy policy in place.
- Provide a mechanism for consumers to submit requests to follow through on their rights.
- Perform privacy impact assessments as necessary.
- Ensure their websites accommodate universal opt-out mechanism specifications two years after enactment of the law.
- Implement security measures to protect the data from unauthorized access.
How It Impacts Consumers
Consumers under the APRA would have the following rights regarding their covered data:
- Access the covered data an entity collected from them, the names of third parties to which the data was transferred, and a description of the purpose for which the data was transferred.
- Correct inaccuracies in their data.
- Delete their data.
- Export their data in a portable format.
- Opt-out of targeted advertising, the transfer of their data, and algorithms used for consequential decisions.
- Opt-in to the collection of sensitive data.
- Pursue private action against covered entities that violate their rights.
APRA vs. ADPPA
The APRA is similar to the ADPPA in that both:
- Give users the right to access, correct, and delete their covered data.
- Have guidelines focusing on data minimization.
- Require opt-in consent for the collection of sensitive covered data.
- Allow consumers to opt out of the transfer of their covered data.
- Call for the establishment of a centralized opt-out mechanism.
However, some notable differences between the proposed laws include:
- The APRA has a slightly broader definition of a large data holder than the ADPPA.
- The APRA would preempt state laws but make provisions for stricter elements of laws, like the CCPA.
- The APRA gives consumers a privacy right of action.
Future Outlook of the APRA
It’s still too early to tell what the future looks like for the APRA, but the proposed law currently appears to have bipartisan and bicameral support.
Lawmakers will most likely redraft the Act and have been quoted by sources like the IAPP as saying they’re “open to constructive feedback.”
Be sure to check back for future updates on the APRA.

