Privacy bill funds research but skips actual consumer protections
H.R. 8014 — Online Privacy Act of 2026 · Filed by Zoe Lofgren (D-CA) · Introduced Mar 19, 2026 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill establishes a framework for online privacy protection by creating a Digital Privacy Agency and directing the National Institute of Standards and Technology (NIST) and National Science Foundation (NSF) to develop privacy standards, best practices, and research. It takes effect one year after enactment and explicitly preserves all existing federal and state privacy laws without superseding them. The bill funds privacy research and public education but does not appear to create new consumer rights or direct restrictions on data collection.
Why we flagged it
The bill's core function is to mandate NIST and NSF to develop privacy risk-management frameworks, technical standards, and research—not to regulate data collection or create consumer rights. It is a research-and-coordination bill, not a privacy-protection bill in the enforcement sense.
What the text implies
- The bill does not establish a Digital Privacy Agency—it references one as already existing, but no text creates it. This suggests either a prior bill or incomplete legislative text, creating ambiguity about enforcement authority.
- By explicitly preserving all existing federal and state privacy laws without modification, the bill avoids preempting state privacy regimes (CCPA, VMPPA, etc.), but also means it does not harmonize or strengthen baseline protections nationally.
The full analysis lists 4 implications of this text.
Who stands to gain
technology companies (indirect—standards may reduce compliance fragmentation); research institutions (direct—NSF awards); NIST (direct—research funding)