Pentagon tightens grip on servicemembers' payment data—bans foreign-controlled systems
H.R. 8787 — Servicemember Payment Data Privacy and Security Act · Filed by Ben Cline (R-VA) · 14 cosponsors · Introduced May 13, 2026 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires the Department of Defense to review and prohibit the use of payment processing equipment, systems, or services that are developed, manufactured, or controlled by entities from countries deemed security risks (China, Russia, Iran, North Korea, or others the Secretary of Defense designates). Starting January 1, 2027, the DoD cannot contract with retailers that use such 'covered' payment systems. The bill aims to prevent foreign adversaries from accessing or compromising servicemembers' financial data through payment processing infrastructure.
Why we flagged it
The bill's core function is to protect servicemembers' financial data from foreign adversaries by restricting DoD payment processing contracts. It is a targeted national security measure, not a broad privacy law, and operates through procurement restrictions rather than consumer rights expansion.
What the text implies
- The bill grants the Secretary of Defense broad discretion to designate additional 'countries of concern' beyond the named four, potentially expanding restrictions without congressional approval or public notice.
- Retailers and payment processors may face significant compliance costs to audit and replace payment systems, which could be passed to consumers or servicemembers through higher prices or reduced service options.
The full analysis lists 4 implications of this text.
Who stands to gain
U.S. payment processing companies (AIG, Fiserv, Fidelity, Prudential, PennyMac); Domestic financial technology and cybersecurity firms; Defense contractors with in-house payment processing capabilities