Congress tightens rules on military personnel data—with a five-year loophole
S. 3161 — Protecting DOD Data Act of 2025 · Filed by Elissa Slotkin (D-MI) · 1 cosponsor · Introduced Nov 7, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires the Department of Defense to strengthen protections for personal data of military personnel and civilian employees, particularly data that could compromise their operational security or safety. The SecDef must review and update data protection policies by June 2026, restrict storage of sensitive personnel data to authorized DOD servers unless the individual consents, and notify Congress within 30 days of any policy changes, data breaches, or security incidents involving military personnel information.
Why we flagged it
The bill's core function is establishing statutory safeguards for sensitive personal data of DOD personnel, with mandatory congressional notification of breaches and policy changes. It is a protective measure, not a carve-out or subsidy.
What the text implies
- The bill's reference to 'practices relating to privacy that were in effect on the day before the date of the enactment' may lock DOD into older privacy standards and could complicate adoption of newer, potentially more robust data protection technologies.
- The five-year sunset on congressional notification of policy changes (but not on the core data protection requirements) creates a window after 2031 where DOD could alter protections without legislative oversight.
The full analysis lists 4 implications of this text.
Who stands to gain
cybersecurity and data protection service providers; defense contractors specializing in secure cloud infrastructure; compliance and audit consulting firms