The Data Care Act of 2025 mandates that online service providers adhere to strict duties of care, loyalty, and confidentiality when handling user data, while empowering the FTC and state attorneys general to enforce these protections.
Brian Schatz
Senator
HI
The Data Care Act of 2025 establishes essential duties of care, loyalty, and confidentiality for online service providers regarding the handling of user data. It mandates that companies protect sensitive information, prevent harmful data usage, and ensure third-party compliance. The legislation empowers the Federal Trade Commission and state attorneys general to enforce these standards and hold providers accountable for violations.
Think of the last time you signed up for a new app or bought something online. You probably clicked 'Agree' on a terms-of-service wall of text without a second thought. The Data Care Act of 2025 wants to change the power dynamic by legally requiring online service providers to act like a trusted professional—think of a doctor or a lawyer—when handling your personal info. The bill introduces three big rules: a duty of care to secure your data, a duty of loyalty to not use your info against you, and a duty of confidentiality to make sure anyone they sell your data to follows the same rules. If this passes, companies would have 180 days to get their act together or face heavy fines from the FTC and state attorneys general.
Under Section 3, providers can’t just treat your data like a commodity they found on the street. The 'Duty of Loyalty' is the heavy hitter here; it prohibits companies from using your data in ways that result in 'material physical or financial harm' or anything that would be 'unexpected and highly offensive' to a reasonable person. For example, if a fitness app sold your heart rate data to an insurance company to hike your premiums, that would likely trigger a violation. The bill also defines 'sensitive data' broadly—covering everything from your Social Security number and biometric thumbprints to your precise GPS location and private emails. If a hacker gets their hands on this sensitive info, the company is legally required to tell you promptly.
One of the biggest loopholes in current privacy is the 'third-party' shuffle, where a company you trust sells your data to a shady broker you've never heard of. Section 3’s 'Duty of Confidentiality' aims to close that gap. It mandates that if a provider shares your data, they must have a contract in place that forces the recipient to follow the exact same privacy standards. Plus, the original company has to actually check in on them through regular audits. This means if you’re a small business owner using a third-party payroll software, that software provider is now legally responsible for ensuring their data partners aren't playing fast and loose with your employees' bank details.
This isn't just a list of suggestions; Section 4 gives the FTC and state attorneys general the teeth to sue for violations. Penalties can be calculated based on how many days a company was out of compliance or how many users were hurt, whichever is higher, potentially reaching millions of dollars for major tech firms. However, there is a bit of a gray area: the FTC has the power to grant exemptions based on a company’s size or the 'costs and benefits' of the rules. While this helps a local mom-and-pop shop that accidentally collects an email address, it also creates a space where industry lobbying could lead to carve-outs for bigger players. Additionally, terms like 'highly offensive' are subjective, meaning we might see some long-winded court battles over what actually counts as a privacy violation in the modern age.