Protecting Privacy in Purchases Act
The Protecting Privacy in Purchases Act would restrict financial institutions from sharing or selling data about customers' individual purchase transactions without explicit consent.
Status and record
Your position
Should this become law?
Verified positions form a citizen mandate: a public tally Civitus compares against the official roll call.
Civitus citizens
Take a position above to see how verified Civitus citizens are weighing in. Positions stay sealed until you have one of your own.
The Civitus brief
AI analysis
Plain English
The Protecting Privacy in Purchases Act would restrict financial institutions from sharing or selling data about customers' individual purchase transactions without explicit consent.
Why it matters
This legislation aims to limit how banks, credit card companies, and other financial institutions can use and share detailed records of customers' individual purchases. Supporters argue it closes a significant gap in consumer privacy law by giving Americans control over their spending data. Critics raise concerns about impacts on fraud detection, data-driven financial services, and the compliance burden on smaller institutions.
Who it affects
- Consumers
- Banks
- Credit unions
- Credit card networks
- Data brokers
- Fintech companies
- Retailers
- Marketers
The case for and against
The case for
- 1Consumers currently have little practical control over detailed records of their purchases, and an opt-in requirement would restore meaningful agency over sensitive personal financial data.
- 2Transaction-level purchase data can reveal highly intimate details about a person's health, religion, political views, and personal relationships, making its unrestricted sale a serious civil liberties concern.
- 3A uniform federal standard would replace the current inconsistent patchwork of state laws, reducing compliance complexity for businesses operating across state lines while providing consistent protection for all Americans.
The case against
- 1Restricting the sharing of transaction data could hamper fraud detection systems, credit risk modeling, and personalized financial services that many consumers value and rely upon.
- 2Compliance costs, especially for smaller community banks and credit unions, could be substantial and may ultimately be passed on to consumers through higher fees or reduced service offerings.
- 3An overly broad opt-in requirement could limit legitimate uses of aggregated and anonymized data that benefit consumers through improved products, economic research, and public health monitoring.
Generated from primary and reputable sources for orientation. These are not endorsements.
What happens next
Current
Introduced in the House
Motion to reconsider laid on the table Agreed to without objection. (Jul 14, 2026)
Next
Committee consideration
Most bills wait here. A committee can hold hearings, amend, or never take it up.
View full legislative path
- IntroducedIntroduced Feb 11, 2025 · Status: Introduced · Motion to reconsider laid on the table Agreed to without objection. (Jul 14, 2026)
- CommitteeMotion to reconsider laid on the table Agreed to without objection. (Jul 14, 2026)
- FloorMotion to reconsider laid on the table Agreed to without objection. (Jul 14, 2026)
- VoteMotion to reconsider laid on the table Agreed to without objection. (Jul 14, 2026)
- LawMotion to reconsider laid on the table Agreed to without objection. (Jul 14, 2026)
Civitus mandate path
- PositionWaiting
- Verified tally0 of 10 verified
- MandateNot yet
- Government notifiedNot yet
- Official voteOn the roll call
- RecordFiled
Citizens vs Government
Civitus citizens
Sealed
Take a counted position to open the tally.
Congress
221 yes · 201 no
Recorded roll call, 9 not voting
Sign in and verify your address to see how your representative voted next to the citizen tally.
Civitus participants are verified users, eligible in this jurisdiction, who chose to weigh in on this record. Not a poll of any district or of the country.
See the full chamber roll callTake action
Public discussion
Add a tag
Opinion on this bill, separate from your position above. Similar opinions on this bill can open a solution poll.
3 similar opinions open a solution poll
Loading opinions
Deeper context
Long-form analysis, legal background, and source material
Read analysisAnalysis · Historical context · Long read
DEEP ANALYSIS
The Protecting Privacy in Purchases Act targets the practice by which financial institutions collect granular transaction-level data, including what consumers buy, where, and how often, and share or sell that information to third parties such as data brokers, marketers, and analytics firms. The bill would generally require explicit opt-in consent from consumers before such data can be shared beyond the immediate transaction purpose, and it would establish penalties for violations.
The constitutional basis for this legislation rests primarily on Congress's Commerce Clause authority, as financial data flows interstate and involves federally chartered and regulated institutions. The bill also builds on the framework established by the Gramm-Leach-Bliley Act of 1999, which created baseline financial privacy protections but has been criticized by consumer advocates as insufficiently protective in the modern data economy. This bill would significantly strengthen those protections by moving from an opt-out to an opt-in model for transaction-level data sharing.
Fiscal impact estimates vary. Financial institutions and data brokers generate substantial revenue from the sale and licensing of consumer transaction data, and restrictions could reduce that revenue stream. Compliance costs, particularly for smaller community banks and credit unions, could be meaningful. On the other side, proponents argue that stronger privacy protections reduce harms such as identity theft and predatory targeting, which carry their own economic costs for consumers and the financial system.
Historically, American financial privacy law has lagged behind other developed nations, particularly the European Union's General Data Protection Regulation framework. High-profile data breaches and revelations about the scale of commercial surveillance have intensified public and legislative interest in this area over the past decade. Several states, including California through its Consumer Privacy Act, have moved independently, creating a patchwork that federal legislation could rationalize.
Stakeholders affected include consumers broadly, large banks and payment networks, credit card issuers, data brokers, retailers who purchase transaction analytics, fintech companies, and law enforcement agencies that sometimes access financial data for investigative purposes. Civil liberties organizations have generally supported stronger purchase privacy protections, while financial industry trade groups have expressed concern about operational impacts.
Two lenses on the same bill. Explain is AI analysis of the civic record. Fiscal covers budget and markets. Neither tells you how to vote.
Informs. Never directs. The vote belongs to you.
AI analysisCivic explanation, not a government record
The Gramm-Leach-Bliley Act of 1999 established the last major federal floor for financial data privacy, but it was written before smartphones and real-time data markets made per-transaction surveillance commercially routine at scale. John Stuart Mill's harm principle, from 'On Liberty,' frames the core tension here: the state may restrict liberty to prevent harm to others, but the exact harm threshold from data sharing versus data restriction remains empirically contested. If this bill passes, an estimated multi-billion-dollar market in consumer transaction data would face its most significant federal constraint since the credit reporting reforms of 1970.
THE CIVITUS BRIEF, IN FULL
The Protecting Privacy in Purchases Act would prohibit banks, credit card companies, and other financial institutions from sharing or selling records of individual customer transactions without first obtaining explicit consent from the consumer. Under current law, financial institutions can share much of this data with affiliates and certain third parties under opt-out arrangements, meaning consumers must take active steps to limit sharing rather than actively agreeing to it. This bill would flip that default, requiring a clear opt-in before purchase-level data moves outside the institution handling the transaction.
Supporters of the bill, including consumer advocacy organizations and a number of civil liberties groups, argue that purchase records are among the most revealing data points about a person's private life, capable of exposing medical conditions, religious practices, political affiliations, and personal relationships. They contend that the existing Gramm-Leach-Bliley framework was written for a different technological era and has failed to keep pace with the rise of data brokers and real-time analytics markets. Proponents also point to broad public polling showing that most Americans are unaware of how extensively their transaction data is bought and sold.
Opponents, primarily drawn from the financial services industry and some technology sector groups, argue that transaction data is essential to fraud prevention algorithms, credit underwriting, and the personalized financial tools that consumers increasingly use. Industry representatives have warned that strict opt-in requirements could degrade the accuracy of risk models and impose significant compliance costs, particularly on smaller institutions with limited technology budgets. Some law enforcement stakeholders have also raised questions about how the bill's restrictions would interact with existing investigative access to financial records.
For ordinary Americans, the bill's most direct effect would be a change in the default setting governing their financial data: instead of needing to find and activate privacy controls, they would need to affirmatively agree before their purchase history could be monetized. Consumers who never engage with consent forms would see their transaction data stay within their financial institution for processing purposes only. Americans who opt in could potentially receive personalized offers or services in exchange, while those who decline would trade less data for potentially fewer targeted financial products.
Sources
Analysis draws from: John Stuart Mill, On Liberty, Gramm-Leach-Bliley Act (1999), Daniel Solove, Understanding Privacy, California Consumer Privacy Act (2018).
A citizen mandate is a Civitus tally of verified users. It does not legally bind any official; its power is the public record.