Congress tightens Treasury data access, mandates breach reporting
H.R. 1101 — Taxpayer Data Protection Act · Filed by Haley Stevens (D-MI) · 205 cosponsors · Introduced Feb 6, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill restricts who can access the Treasury Department's payment systems and taxpayer financial data. Only Treasury employees with at least one year of service and a satisfactory performance rating, or cleared contractors, may access these systems—and they must complete ethics training and sign ethics agreements. Anyone else accessing the system is treated as a federal employee subject to conflict-of-interest laws, and the Treasury Inspector General must report all unauthorized access to Congress within 30 days.
Why we flagged it
The bill's core function is to establish eligibility and compliance requirements for accessing Treasury payment systems and taxpayer data, with mandatory reporting of breaches. It is a cybersecurity and data-protection measure, not a tax or appropriations bill.
What the text implies
- The one-year tenure requirement may inadvertently slow emergency response to system failures or crises, as newly hired Treasury staff cannot access systems even in urgent situations.
- The requirement that contractors hold security clearances and meet the same standards as civil servants may increase costs for Treasury to hire and retain qualified contractors.
The full analysis lists 4 implications of this text.
Who it affects
Ordinary citizens benefit from stronger safeguards against unauthorized access to their tax and payment data, reduced risk of fraud or misuse of Treasury systems, and mandatory reporting of breaches. The bill creates enforceable barriers to protect sensitive financial information and government payment integrity.