U.S. Congress advances data rules
Congress still has no federal privacy law, while debate moves ahead on NDAs, AI rules, and a cybersecurity liability extension.
The U.S. Congress has still not passed a comprehensive federal data privacy law, while debate continues over NDAs in data centers, AI regulation, and extending liability protections for voluntary cyberthreat information sharing.
Update August 27, 2026: The note adds that the limited-liability extension for companies that share cybersecurity information with peers expires on September 30, 2026, according to Global Finance Magazine. The rest of the legislative front on privacy, AI, and technology transfer controls remains open.
On August 20, 2026, the U.S. House of Representatives introduced H.R. 10118, the No Data Center NDAs Act, which would bar members of Congress from signing certain confidentiality agreements tied to data centers. The bill was sent that same day to the House Committee on House Administration and remains in the Introduced stage.
What would the No Data Center NDAs Act change?
The bill is aimed at preventing federal lawmakers from entering into certain nondisclosure agreements related to data centers, according to the official title filed in Congress.gov. The legislative text also includes the phrase "and for other purposes," but the available materials do not spell out any further substantive details on its operational scope.
What is the context for this initiative?
The measure lands in a Congress that, as of August 2026, still has not passed a comprehensive federal data privacy law. A recent analysis cited by Legis1 says a federal-level gap persists for personal data protection, even in sensitive areas such as vehicle geolocation, despite multiple bills moving through the process.
Among them are H.R. 8413, which would regulate data brokers and certain consumer data exchanges; H.R. 6734, which could cover access to, sale of, and sharing of vehicle data, including geolocation; and H.R. 2110, designed to help survivors of domestic violence disable connected vehicle technologies. All of them are still pending and have not been enacted by Congress.
What other regulatory fronts are still open in Washington?
The federal debate also remains active on artificial intelligence, cybersecurity, and technology transfer controls. CDT reported that several proposals to regulate chatbots and protect minors are moving through the process, including the Youth AI Privacy Act and the GUARD Act, introduced in December 2025, with no approval yet in the current session.
At the same time, the Cybersecurity Information Sharing Act is back at the center of the legislative debate. According to Global Finance Magazine, companies that share cybersecurity information with peers have until September 30, 2026, before the limited liability provided under the 2015 law expires. Legis1 added that the voluntary cyberthreat information-sharing program was extended only through that date in budget legislation. Global Finance Magazine also said the House included an extension in parts of the 2027 NDAA, although that section was still awaiting Senate approval at the time of reporting.
The same coverage warned that, without a new extension, the limited-liability protections for voluntary cyberthreat information sharing under the 2015 law will expire.
How does this affect companies and operations outside the United States?
Compliance obligations are also shifting onto a corporate and cross-border level. A bipartisan, bicameral group of lawmakers asked the Commerce Department to finish and strengthen rules proposed in 2024 that would require licenses for U.S. citizens and companies providing technical or technological support to civilian or military intelligence agencies in 45 countries deemed high risk.
The legislative letter proposes narrowing the trusted-country list to governments with strong human rights records and that do not spy on the United States. It also calls for disclosure requirements for surveillance contractors serving intelligence or security agencies in untrusted countries before they receive U.S. technology or assistance, and for expanding facial recognition controls to other biometric surveillance technologies.
That tightening is already showing up in corporate deals. Recent SEC filings include clauses in technology M&A transactions stating that the parties are not subject to Executive Order 14117 or its implementing rules under 28 C.F.R. § 202, a sign that these restrictions on sensitive data are becoming part of compliance checks and contractual representations.
Sources
- Tag – China (Privacy & Cybersecurity Law Blog)hunton.com· Hunton Andrews Kurth – Privacy & Cybersecurity Law Blog
- 119th Congress (2025-2026): No Data Center NDAs Act – All Information (Except Text)congress.gov· Congress.govUnverified URL
- FY2026 NDAA Embeds Cyber and AI Governance Ruleslegis1.com· Legis1
- Congress Faces Vehicle Data Privacy Gap, CRS Sayslegis1.com· Legis1
- Cybersecurity Data Sharing Faces Liability Deadlinegfmag.com· Global Finance Magazine (GFMag)
- Lawmakers press Commerce to restrict Americans from aiding foreign spy agenciesnextgov.com· Nextgov
- The Committee on Foreign Investment in the United States and the Royalty Buyerp05.org· P05 Policy Analysis
- 2026 State and Federal AI Legislation Updatescdt.org· Center for Democracy & Technology (CDT)Unverified URL
- House Calendars – 119th Congressgovinfo.gov· Congress.gov
- Cybersecurity Data Sharing Faces Liability Deadlinegfmag.com· Global Finance Magazine
- tm2621515-3_defm14csec.gov· U.S. Securities and Exchange Commission
- H.R.10148 - 119th Congress (2025-2026): Safeguarding America’s Nonprofits Actcongress.gov· Congress.govUnverified URL
- H.R.10139 - 119th Congress (2025-2026): Ratepayer Bill of Rights Act of 2026congress.gov· Congress.govUnverified URL
- Eight U.S. Carriers Form C2 ISAC: Telecom Closes Ranks ...jain.com· Jain / Industry blog sobre ciberseguridad
- Iranian Hackers Force UK Power Generator Offline for Four Dayskurdistan24.net· Kurdistan24
- Multi-Jurisdiction Privacy Compliance: A Practical Guide for ...osano.com· Osano



