CiberLATAMbywhalemate

U.S. Congress advances privacy and CIRCIA rules

Congress moves on data privacy and incident reporting, while CISA’s CIRCIA rule remains pending and could affect cross-border operations.

Whalemate Labs · AI-assisted researchPublished:4 min read

The U.S. Congress and federal regulators kept moving in September 2026 on privacy, biometrics and cyber incident reporting. Several specialist sources say CIRCIA’s final rule is still not in force, though reporting duties for critical infrastructure entities could begin by late 2026 or early 2027, depending on the effective date set in the rule. At the same time, the Senate still has a bill pending that would let travelers opt out of TSA facial recognition, and several analyses say the impact could reach companies with cross-border operations, including subsidiaries and data flows tied to Latin America.

The U.S. Congress and the federal regulatory apparatus kept moving in September 2026 on privacy, biometrics and cyber incident reporting. In parallel, several specialist sources maintain that CIRCIA’s final rule is still not in effect, although it could start requiring reports from critical infrastructure entities by late 2026 or early 2027, depending on the effective date set in the rule.

What privacy bill advanced in education?

H.R.10449 was introduced in the House of Representatives on September 16, 2026, by Rep. Mary E. Miller and was referred to the House Committee on Education and Workforce. The bill would establish a ban on certain disclosures of personally identifiable information under the Family Educational Rights and Privacy Act of 1974.

The proposal adds to a series of legislative moves in the House tied to personal data and information protection. One day earlier, on September 15, 2026, the House took up H.Res.1530, a resolution setting the procedure to consider, among other proposals, H.R.10326, aimed at improving information sharing between federal and state agencies to detect, investigate and prosecute fraud in certain federal programs, with specific provisions to protect individual privacy.

What is still happening with CIRCIA incident reporting?

CISA still has September 2026 as its target for publishing the final rule that implements CIRCIA, but that obligation is not yet in force. According to analysis from The Legal 500, Law.com and other industry outlets, covered entities across 16 critical infrastructure sectors would only come under the rule once the final regulation is published and takes effect, something several analyses place in late 2026 or early 2027.

The timeline has kept slipping. Tech Insider reported that the original milestone was October 2025, then moved to May 2026 and finally to September 2026. Industry sources also say that, because of Congressional Review Act review, there are usually at least 60 days between publication in the Federal Register and the rule taking effect.

How are the 72-hour and 24-hour clocks counted?

The 72-hour clock for reporting a covered incident under CIRCIA would begin when the organization reasonably believes the incident occurred, not when it is definitively confirmed. For ransomware payments, the 24-hour deadline would start when the funds leave the entity’s control, according to a legal analysis cited by Fedlaws.org.

That design increases the need for early detection processes and fast decision-making, something executive-focused articles on critical infrastructure already describe as the first broad federal incident-reporting framework for 16 sectors. Other analyses add that the definitions of covered cyber incident and discovery are critical for groups with global operations, even when the event is detected in foreign subsidiaries that affect critical infrastructure assets in the United States.

What other federal initiatives are on the agenda?

The Senate still has pending the Traveler Privacy Protection Act of 2025, S.1691, a bipartisan bill that would give travelers the option to opt out of TSA facial recognition systems at airports, prevent them from being treated unfavorably for exercising that option, and limit retention and secondary uses of facial biometric data.

On the artificial intelligence front, OpenRepublic lists technology bills such as the AI Incident Reporting Act and other privacy and data security proposals for chatbot providers, with a focus on incident reporting and safeguards during model development and operation. That legislative push overlaps with the personal data debate, since there are also initiatives aimed at restricting certain disclosures of personally identifiable information under frameworks such as FERPA.

Why does this matter for companies with operations in Latin America?

Because the sources reviewed see a regulatory environment that is starting to align around tighter reporting windows. Sysdig, Finrep.ai and other analyses argue that CIRCIA will align with SEC reporting obligations and European frameworks, and that multinationals will need unified procedures to meet different deadlines for the same incident.

Mailgun adds that, if the American Data Privacy Protection Act moves forward with a two-year compliance period, companies with cross-border operations should prepare for data minimization, limits on secondary uses and possible transfer rules, including flows to and from Latin America. That same analysis says coexistence with strict state regimes such as California would push multinationals toward a uniform corporate standard for user data in the United States, the EU and Latin America.

Several expert comments cited in the material also say the new U.S. incident-reporting frameworks and AI regulation initiatives are being designed to fit into a global environment where companies already face demanding deadlines in Europe. In that context, groups with regional operations would need to strengthen their monitoring and logging capabilities to meet U.S. requirements even if the event starts outside the country.

Sources

View all