The Data Protection Amendment
I. The Right With No Institution
Two everyday stories illustrate why this amendment is necessary. One person worries about physical safety in her neighborhood. Another discovers that an app she barely uses has been selling her location data to advertisers for years. Both describe the same underlying right: security of person, in the physical world and in the digital one. The physical half already has real institutions behind it, police powers, tort law, and long-established enforcement mechanisms most Americans take for granted. The digital half has never had one. Privacy means having a right to a life that belongs to you. Your home, your conversations, your medical records, your financial information, your movements should all be free from corporations that buy and sell them and governments that monitor them without clear legal justification and judicial oversight. This amendment is what makes that promise enforceable rather than aspirational.
II. The Consent Principle
The same throughline runs through this amendment as through the rest of this volume: nothing happens to you without proof that it is safe and without your genuine agreement. In practice, “consent” to data collection today means clicking past a terms-of-service document few people read and fewer still understand, as a condition of using a service that has, in many cases, become close to mandatory for participating in ordinary life. That is not consent in any meaningful sense. It is a formality that transfers legal risk from the company to the individual while changing nothing about what actually happens to the data.
Government surveillance presents a parallel problem. The Fourth Amendment has protected Americans from unreasonable searches of their homes and papers since 1791. It says nothing explicit about a phone that tracks your location every minute of the day, or a browser history that reveals more about your health, your relationships, and your beliefs than a search of your home ever could. Courts have spent decades trying to fit twenty-first century surveillance into an eighteenth-century framework. This amendment closes that gap directly, extending the warrant requirement the Constitution already promises for your home to the digital record of your life while respecting, rather than erasing, the real distinctions that framework already draws between the content of a communication, a business record about it, and the categories of government activity, like foreign intelligence and border security, that have always been treated differently.
That warrant requirement is worthless, though, if a government agency can simply buy the same data instead of compelling it. This is not a hypothetical gap; it is the most heavily litigated loophole in surveillance law today. A bill closing it, the Fourth Amendment Is Not For Sale Act, passed the House in 2024 and has stalled in the Senate ever since, while the practice it targets has only grown. The Department of Homeland Security signed a billion-dollar contract with a data-analytics firm in February 2026 to run AI-powered analysis across its border and immigration components, built substantially on commercially purchased data rather than warrants. A right that a government can purchase its way around is not a right. This amendment closes the loophole directly rather than leaving it to the next Congress.
For a minor, the consent problem is not diluted; it is absent. A thirteen-year-old cannot meaningfully consent to a data-collection agreement any more than to a mortgage, yet current law in most states treats a child’s tap through a sign-up screen exactly like an adult’s. States that have tried to fix this by regulating what a minor may see online have mostly lost in court. A federal judge permanently enjoined Ohio’s parental-notification law in 2025 on First Amendment grounds. States that have instead regulated the data collected from a minor and the design choices used to hold that minor’s attention have fared better. A federal appeals court upheld the core of California’s addictive-feed and parental-consent law in 2025. This amendment follows the path that has actually survived: it regulates data and design, not speech.
Consumer credit reporting exposes a different failure of consent entirely, not that it is fictional, but that it barely exists at all. A lender reports your payment history to a bureau you never chose and never agreed to deal with. That bureau then sells a file built from your financial life to landlords, employers, insurers, and other lenders, often without your knowledge that the sale occurred. The one federal statute governing this, the Fair Credit Reporting Act, has proven unstable rather than protective: a federal court vacated the Consumer Financial Protection Bureau’s rule banning medical debt from credit reports in July 2025, the Bureau abandoned its own effort to bring data brokers under the same rules as credit bureaus in May 2025, and the Bureau then declared in October 2025 that federal law preempts state attempts to fill either gap. A protection that can be undone by one rulemaking, one lawsuit, or one change of administration is not a protection. This amendment makes consent to the release of your financial history the rule rather than the exception.
Genetic and biometric data expose the sharpest failure of consent, because consent alone cannot fix it. When a genetic-testing company went bankrupt in March 2025, it sold the DNA data of more than fifteen million people to a nonprofit its own former chief executive created for the purpose of buying it back. A maneuver existing bankruptcy law had no real answer for, because nothing in that law treats a person’s genetic code as anything other than an ordinary corporate asset. The deeper problem is not the bankruptcy; it is that a person’s DNA also describes their parents, their children, and their siblings, none of whom signed anything. No consent form a company can draft solves that. This amendment does not try to solve it with better consent alone, it takes the sale of this category of data off the table entirely.
III. What This Amendment Does
This amendment establishes the Data Protection Authority, an independent constitutional agency, and gives its core terms, personal data, entity, complete record, and the standard governing the Director’s removal fixed definitions. So a court is not left to construct their meaning case by case. It requires affirmative, specific, and revocable consent before an entity may collect, retain, sell, or use a citizen’s personal data. Replacing the current fiction of buried-in-fine-print consent, with precisely bounded exceptions for the direct service a citizen has requested, security and fraud prevention, ordinary internal business operations, legal compliance, and a public-safety purpose Congress has specifically identified by name in its own statute and not a blanket exception any generic law can invoke.
For a minor, this amendment goes further. Collecting or selling a minor's personal data, using it, or enrolling a minor in an algorithmically personalized feed all require a parent's or guardian's consent. The minor's own consent is not enough. Using a minor's data to target ads at them, or to build a behavioral profile of them, is prohibited outright. A minor's account must default to the platform's strongest available privacy settings.
A platform also may not use certain design features on any account it knows belongs to a minor: features built to hold a child's attention rather than serve it. This includes automatic replay without a prompt, a feed engineered to scroll with no natural stopping point, a publicly visible count of likes or streaks, and push notifications sent during school hours or overnight.
None of this limits what a minor may see, read, or say. It only limits the data collected from them and the design used to keep them scrolling.
For consumer credit reporting, this amendment replaces the current permissible-purpose regime with an authorization regime. A lender may still report your payment history to a consumer reporting agency, so that a credit history continues to exist. But that agency may not release, sell, or share your credit information with anyone without your specific, written, advance authorization naming the party who will receive it and itemizing exactly what will be disclosed. No one, public or private, may access your credit information without your prior consent under this Section or a government process under Section 5. Negative information falls off your record after three years, not seven. Medical debt cannot appear on a credit report at all. Medical debt is a byproduct of illness, not a signal of creditworthiness, regardless of how healthcare happens to be financed. A dispute with a landlord, and an eviction proceeding itself, whether or not it resulted in judgment, cannot appear on any report. And if you dispute an item, it must be marked “Disputed” on any report released while that dispute is open, with the agency required to investigate and resolve it within thirty days. The same rules reach a data broker selling the equivalent kind of financial profile, closing the loophole the current federal scheme leaves wide open; a furnisher or reseller must take reasonable care to keep what it reports accurate; you may pull your own complete file at any time at no cost; a security freeze is free and permanent until you lift it; and an agency that loses your data to a breach has to tell you. Credit information may not be used to price or deny insurance.
For biometric and genetic data such as a fingerprint, a faceprint, a voiceprint, or the results of a DNA test, this amendment does not rely on consent alone, because consent from one person cannot bind the relatives that data also describes. Collecting or using this category of data requires its own separate, explicit consent, on top of whatever general consent Section 2 otherwise requires. But no entity may sell it, license it, or transfer it to another company for money, full stop. And that prohibition follows the data into bankruptcy court: it cannot be sold off as a corporate asset when a company fails, the way fifteen million people’s genetic profiles were in 2025. A citizen can revoke consent at any time and require the data, and the physical sample it came from, destroyed within thirty days.
This amendment gives every citizen two rights: the right to get a complete record of the data an entity holds about them, and the right to demand that data be deleted. There are limited exceptions to the deletion right. Data cannot be deleted if a law requires it to be kept, if it is under a litigation hold, if it is subject to a subpoena, or if some other government process authorized by this amendment applies. In other words, no one can use the deletion right to destroy evidence they would not otherwise be allowed to destroy. A parent may exercise both rights on a minor's behalf.
It requires a judicial warrant, issued upon probable cause, before any government agency may access the content of a citizen’s communications or their precise location history, and a lower, judicially supervised standard for ordinary third-party business records which is the same distinction the Supreme Court itself has already drawn. It leaves foreign-intelligence and border-security collection to Congress, within a floor this amendment sets and Congress may not go below, and it replaces the current, undefined emergency exception with a real one: a 48-hour deadline to seek a warrant after the fact, and suppression of anything a court would not have approved in advance. And critically, a government agency cannot evade any of this simply by purchasing the same data from a broker instead of compelling it. A purchase of data that would otherwise require a warrant or court order is now held to that same standard, closing the loophole the Fourth Amendment Is Not For Sale Act has tried and failed to close in Congress since 2024.
That same warrant standard now follows a citizen’s movements when the government compiles them itself. An automated license plate reader or fixed camera network can answer, in seconds, a question the Fourth Amendment has never let the government ask for free: everywhere a specific person has driven over the past month. This amendment treats a historical search of that record the same as it treats a search of a phone’s location history, a warrant is required. Though an agency may still match a specific plate against an active warrant, a missing-person report, or a named investigation in real time without one. Retention is capped at thirty days absent an open investigation, a vendor operating the system may not sell the data it collects on the government’s behalf, and because the immigration-enforcement use of this data has become the most common form of its misuse, no agency may hand it to a federal civil immigration authority without a warrant.
This amendment also gives citizens a private right of action, so enforcement does not depend solely on the Authority acting on its own. That right is backed by a revenue-based penalty, which Congress must set within a defined floor and ceiling. To bring a claim, a citizen must meet a genuine standing requirement: the injury must be their own and concrete. Forced arbitration and class-action waivers cannot be used to block a minor's claim or a serious privacy harm.
The Authority itself is no longer limited to responding to complaints. It can audit an entity's compliance on its own initiative, and it can issue a subpoena to investigate a suspected violation. That subpoena carries the same judicial enforcement and the same right to object as any other federal subpoena.
IV. Addressing the Objections
The most common objection is that a consent requirement this strict would break the advertising-supported business model that funds much of the free internet. The European Union has operated under a comparable consent standard for years without the internet disappearing; businesses adapted, and the precise exceptions this amendment now writes directly into Section 2 for security, fraud prevention, ordinary business operations, and legal compliance. Let routine service operation continue without reopening the loophole this amendment is meant to close.
The second objection concerns national security: that a warrant requirement will hamper legitimate intelligence and law enforcement work. It will not, because this amendment no longer imposes one undifferentiated standard on every kind of government data access. It requires a warrant for content and precise location, a lower court-supervised standard for ordinary business records, and it leaves foreign-intelligence collection and border enforcement to Congress within a defined floor, which is a more precise version of the distinctions the law already draws, not a break from them. Emergency exceptions remain available, now with an actual deadline and an actual judicial check, exactly as they already work for a physical search.
The third objection is that a rule this broad will turn routine business practices like fraud screening, account security, basic analytics into constitutional violations. It will not, because Section 2 now names those practices directly as exceptions to the consent requirement, rather than leaving them to be inferred from a single phrase about “direct provision of a service.”
The fourth objection is that the minor-specific provisions are really a content restriction aimed at what young people can see and say online, the same kind of law that has repeatedly lost in federal court on First Amendment grounds. This amendment is not that law. It restricts what data may be collected from a minor and which design mechanics may be used on them; it says nothing about content, and says so in its own text. The California law this amendment’s minor provisions most closely resemble restricting an addictive feed absent parental consent survived exactly this kind of challenge in 2025, while laws aimed at content moderation or mandatory notification have not.
The fifth objection is that a private right of action against every entity that touches personal data will flood the federal courts with undifferentiated litigation. This amendment answers that directly rather than leaving it to chance: a plaintiff must show the same concrete, individual injury federal courts already require for a statutory privacy claim, must give notice and a chance to cure before suing except for the most serious harms, and Congress sets the penalty structure within a floor it cannot legislate away. The right to sue is real, but it is not a blank check.
The sixth objection is that barring medical debt, evictions, and landlord disputes from a credit file, and shortening negative information to three years, will take real, sometimes predictive information away from a lender or landlord trying to assess risk, and that some of that risk will get priced into everyone else’s credit terms. This is a fair criticism, and this amendment does not pretend a lender or landlord loses nothing. The judgment this amendment makes is that a medical emergency, a disputed security deposit, or a debt now four years old should not follow a person indefinitely through every future financial decision they try to make. The same judgment already embodied, more narrowly, in the medical-debt reporting limits the three major credit bureaus adopted voluntarily in 2023, extended here into a permanent rule a future rulemaking or lawsuit cannot undo.
The seventh objection is that requiring a warrant-equivalent standard before the government may purchase data it could otherwise compel will cripple legitimate uses of commercial data like finding a missing child, tracking a fraud ring, responding to a genuine emergency. It will not, for the same reason the underlying warrant requirement does not cripple those things today: Section 5’s emergency exception, with its 48-hour deadline for after-the-fact judicial review, applies to a purchase exactly as it applies to compelled disclosure. What this amendment forecloses is not urgent, well-justified access; it is routine, suspicionless purchasing used precisely because it avoids the judicial oversight a warrant would require.
The eighth objection is that banning the sale of biometric and genetic data outright, rather than simply requiring stronger consent, will shut down a legitimate consumer genetics industry that millions of people value such as ancestry research, health-risk screening, reuniting separated family members. This amendment does not stop a company from collecting genetic data with a citizen’s separate, explicit consent, or from using it to deliver the service that citizen asked for. What it stops is the sale of that data to a third party for a different purpose, including the sale of a bankrupt company’s entire genetic database to whatever buyer will pay for it. A company that only ever intended to serve its customers loses nothing by being unable to sell their DNA out from under them.
The ninth objection is that giving the Authority the power to audit a company without waiting for a complaint invites exactly the kind of open-ended regulatory harassment any well-drafted enforcement power should guard against. The safeguard is the same one that already limits every other subpoena power in American law: a subpoena issued under this Section is subject to judicial enforcement and to a motion to quash on the same terms as any subpoena issued in a federal civil action. The Authority can investigate; it cannot compel compliance without a court’s say-so if the target objects.
The tenth objection is that a warrant requirement for historical license-plate and camera-network searches will cost law enforcement a genuinely useful tool for recovering a stolen vehicle, finding a missing child, locating a car tied to a specific violent crime. It will not, because the real-time exception in Section 5(g) covers precisely those uses: matching a plate against an active warrant, a missing-person report, or a named investigation happens instantly and without a warrant, exactly as it does today. What this amendment forecloses is the different practice now drawing bipartisan backlash nationwide for a searchable, indefinite record of where a person has driven, built without any suspicion at all, and shared broadly across agencies, including, in documented cases, directly to federal immigration enforcement. More than fifty localities have canceled their camera-network contracts over the past year for exactly that reason. A tool that finds a stolen car in real time is not the same tool as one that reconstructs a law-abiding citizen’s last six months of movement, and this amendment regulates only the second.
V. Why This Belongs in the Constitution
Data protection law in the United States today is a patchwork with a few sector-specific federal statutes, a handful of state laws that vary widely and change with every legislative session, and a great deal of unregulated territory in between. Nowhere is that patchwork more visible, or more unstable, than in the laws states have passed to protect minors online: different rules in Georgia, Florida, New York, and California, several of them enjoined or struck down mid-litigation, none of them binding a family that simply crosses a state line. The same instability runs through credit reporting, where a federal agency’s rule can be finalized, vacated, and abandoned within the same eighteen months, and federal law then blocks a state from filling the resulting gap. It runs through government surveillance, where a bill to close the data-purchase loophole can pass the House and still die in the Senate two years running. And it runs through genetic privacy, where existing law was so unprepared for a company’s bankruptcy that fifteen million people’s DNA changed hands with no meaningful say from any of them. A right that depends on which state you live in, or which Congress happens to be in session, is not a right. It is a privilege of geography and timing. The right to privacy for an adult and for a child, for a citizen’s data and a citizen’s financial history and a citizen’s own genetic code deserves the same permanence as any right worth taking seriously. The same principle extends to a newer threat: an artificial intelligence system trained on that data, making decisions about the people it describes, this is a problem serious enough to warrant its own constitutional response.
PROPOSED CONSTITUTIONAL AMENDMENT
Article [___] — The Data Protection Amendment
Section 1. Establishment and Definitions.
(a) Establishment. There is hereby established the Data Protection Authority, an independent agency of the United States, with jurisdiction over the collection, retention, sale, and use of the personal data of citizens of the United States, and over government access to such data.
(b) Definitions. As used in this Article:
(i) “Personal data” means information that identifies, relates to, or is reasonably linkable to a specific individual. It does not include data that has been aggregated or de-identified such that it cannot reasonably be used to re-identify the individual to whom it relates.
(ii) “Entity” means a person, corporation, partnership, association, or other organization engaged in interstate commerce, and a State agency or instrumentality acting in a commercial or proprietary capacity. It does not include a natural person acting in a purely personal or household capacity, or a government acting in its sovereign or law-enforcement capacity, which is governed by Section 5.
(iii) “Complete record” means the categories and specific items of personal data an entity holds about the requesting citizen, collected or processed within the preceding twenty-four months, together with the sources of that data and the categories of third parties to whom it has been disclosed. It does not require an entity to reconstruct data lawfully deleted before the request, or to disclose data protected by attorney work-product privilege or subject to an active law-enforcement or national-security investigation.
(iv) “Aggrieved” means having suffered a concrete and particularized injury in fact traceable to a violation of a right this Article confers on the citizen individually. A generalized interest in this Article’s enforcement, without more, is not injury for purposes of this Article.
(v) “Material neglect of duty” and “material abuse of authority” mean, respectively, the Director’s willful and sustained failure to perform a duty this Article expressly requires, and the Director’s willful exercise of power under this Article outside its scope, in either case established by clear and convincing evidence before the United States Court of Appeals for the District of Columbia Circuit. A good-faith interpretive disagreement about the scope of this Article, or a discretionary decision later found erroneous but made in good faith, is not material neglect of duty or material abuse of authority.
Section 2. Consent-Based Data Standard.
(a) No entity shall collect, retain, sell, or use the personal data of a citizen without that citizen's affirmative, specific, and revocable consent, except:
(i) as reasonably necessary to provide a product or service the citizen has requested, limited to that purpose;
(ii) as reasonably necessary to detect, prevent, or respond to security incidents, fraud, or unlawful activity directed at the entity or its users;
(iii) for internal business operations that do not involve the sale of personal data or its use to make a consequential decision about the citizen, including accounting, short-term de-identified analytics, and internal research;
(iv) as necessary to comply with a legal obligation, a court order, or a lawful government process, including one described in Section 5; or
(v) as authorized by an Act of Congress for a specifically identified public-safety or public-health purpose, provided the Act states with particularity the purpose, the data involved, and the entities authorized to rely on the exception.
(b) Every citizen has the right to obtain the complete record, as defined in Section 1(b), of personal data held about them by an entity, the right to require its deletion, and the right to receive it in a portable format, except as to: (i) data an entity is required by law to retain, including for tax, financial, employment, or safety recordkeeping, or that is subject to a litigation hold, subpoena, or other lawful legal process, including one described in Section 5; (ii) data that has been aggregated or de-identified as described in Section 1(b); and (iii) data reasonably necessary to detect and prevent fraud or to maintain the security of the entity's systems.
(c) Consent obtained through a general terms-of-service agreement, without a clear and separate affirmative action specific to data collection, does not satisfy this Section. Consent to one use of personal data is not consent to a materially different subsequent use.
(d) Protections for Minors.
(i) An entity shall not collect, retain, sell, or use the personal data of a citizen known or reasonably believed to be under the age of eighteen without the verifiable consent of a parent or legal guardian, nor enroll such a citizen in an algorithmically personalized content feed without that consent.
(ii) An entity shall not use the personal data of a citizen under the age of eighteen to target advertising to that citizen or to construct a behavioral or predictive profile of that citizen.
(iii) An online platform shall apply its most protective available privacy and visibility settings by default to the account of a citizen under the age of eighteen.
(iv) An online platform shall not employ, with respect to an account it knows or reasonably believes belongs to a citizen under the age of eighteen: automatic playback of successive content without an affirmative prompt; a content feed engineered to scroll without a natural stopping point; a publicly visible, quantified metric of engagement, response, or consecutive use; or a push notification delivered during school hours or between the hours of 10:00 p.m. and 6:00 a.m. local time. Congress may by law adjust the hours specified in this clause and define additional design practices within the scope of this clause consistent with its purpose.
(v) The right to obtain the complete record and require deletion under subsection (b) may be exercised by a parent or legal guardian on behalf of a citizen under the age of eighteen.
(vi) This subsection governs the collection, use, and presentation of personal data. It does not authorize, and shall not be construed to permit, restriction of the content a citizen may view or publish.
(e) Consumer Reporting.
(i) Definitions. As used in this subsection, “consumer reporting agency” means an entity that regularly collects, compiles, or maintains personal data on citizens for the purpose of furnishing that data to a third party, and “credit information” means personal data bearing on a citizen’s creditworthiness, credit standing, credit capacity, or payment history. An entity that regularly collects and sells personal data bearing on a citizen’s financial condition, transactions, or behavior, whether or not styled as a consumer reporting agency, is subject to this subsection to the same extent as a consumer reporting agency.
(ii) A creditor, lender, or other furnisher may report a citizen's payment history to a consumer reporting agency in the ordinary course of business without additional consent under this Section, for the sole purpose of compiling the record described in this subsection.
(iii) A consumer reporting agency shall not disclose, release, sell, or share a citizen’s credit information with any party except pursuant to that citizen’s specific, advance, written authorization identifying the party to whom the information will be disclosed and itemizing the specific information to be disclosed to that party. An authorization under this subsection is valid only for the disclosure it specifically describes and does not authorize a future or open-ended disclosure. No person or entity, public or private, may access a citizen’s credit information without that citizen’s prior consent under this subsection, except pursuant to a government process governed by Section 5.
(iv) Negative information shall not be furnished, disclosed, or considered more than three years after the date of the event to which it relates. This clause does not limit the reporting period for information favorable to the citizen.
(v) A consumer reporting agency, furnisher, or other entity subject to this subsection shall not furnish, disclose, or consider medical debt, or a citizen’s inability or failure to pay a debt arising from the receipt of medical care, in any credit information or consumer report.
(vi) A dispute between a citizen and a landlord, and the filing, pendency, or outcome of an eviction proceeding, whether or not it resulted in judgment against the citizen, shall not be furnished, disclosed, or considered in any credit information or consumer report.
(vii) A citizen has the right to have an item of credit information the citizen has disputed marked “Disputed” for as long as the dispute remains unresolved, and a consumer reporting agency shall not disclose that item, in any report released while the dispute is pending, without that marking. A consumer reporting agency shall investigate a disputed item, and correct or remove an item it cannot verify, within a period established by law not to exceed thirty days.
(viii) A citizen has the right to obtain, without cost and without limit on frequency, a complete copy of the citizen's credit information from a consumer reporting agency, and the right to a security freeze, at no cost, restricting disclosure of that information under clause (iii) until the citizen removes the freeze.
(ix) A consumer reporting agency shall maintain reasonable security safeguards against unauthorized access to credit information, and shall notify an affected citizen without unreasonable delay upon discovering a breach of those safeguards.
(x) A furnisher or reseller of credit information shall follow reasonable procedures to assure the maximum possible accuracy of the information it furnishes or resells.
(xi) Credit information shall not be used to determine, or be considered in determining, the price or availability of insurance offered to a citizen.
(xii) This subsection governs the disclosure and use of credit information. In the event of a conflict between this subsection and subsection (a), this subsection controls.
(f) Biometric and Genetic Data.
(i) Definitions. As used in this subsection, “biometric data” means data generated by the measurement of a specific biological characteristic of an individual, including a fingerprint, facial geometry, voiceprint, iris or retina pattern, or gait, used or intended to be used to identify that individual, and “genetic data” means data derived from the analysis of an individual’s deoxyribonucleic acid or ribonucleic acid that reveals information about the ancestry, physical characteristics, or health of that individual or a biological relative of that individual.
(ii) Collection, retention, or use of a citizen's biometric or genetic data requires that citizen's separate, explicit, written consent, distinct from and in addition to any consent given under subsection (a), specifically identifying the biometric or genetic data involved and the purpose of its collection.
(iii) No entity shall sell, license, or otherwise transfer biometric or genetic data to another entity for consideration. This clause does not prohibit the transfer of biometric or genetic data to a laboratory, contractor, or service provider performing a function on behalf of, and under the direction of, the entity that collected the data, provided the recipient is bound by this subsection to the same extent as the entity that collected the data.
(iv) Biometric or genetic data is not an asset that may be sold, assigned, or otherwise transferred in a bankruptcy, insolvency, receivership, or similar proceeding, except to an entity that agrees in writing to be bound by this subsection and, within a period established by law, either obtains the separate consent required by clause (ii) from each citizen whose data is to be transferred or destroys that citizen's data.
(v) A citizen may revoke consent given under this subsection at any time and require the destruction, not merely the deactivation, of the citizen's biometric or genetic data and any physical sample from which it was derived, within a period established by law not to exceed 30 days.
(vi) This subsection governs the collection, retention, use, and transfer of biometric and genetic data by an entity. Government use of biometric or genetic data is governed by Section 5.
Section 3. Net Neutrality.
(a) No broadband internet access service provider shall block, throttle, or degrade lawful internet traffic on the basis of its source, destination, or content, or favor certain lawful internet traffic over other lawful internet traffic in exchange for payment or other consideration.
(b) This Section shall be enforced by the Data Protection Authority established under Section 1, notwithstanding any classification of broadband internet access service under other federal law.
(c) Nothing in this Section prevents reasonable network management undertaken for legitimate technical purposes and applied without discrimination based on source, destination, or content.
(d) Congress may by law define “reasonable network management” for purposes of subsection (c) and classify new or emerging network services as within or outside this Section's scope, provided no such law may authorize discrimination against lawful internet traffic on the basis of its source, content, or the speaker's viewpoint. A law enacted under this subsection is subject to Section 8.
Section 4. State Preemption on Access to Lawful Websites.
(a) No State shall block, ban, or otherwise prohibit an adult's access to a website, online platform, or other internet-based service that does not violate federal law.
(b) This Section does not limit a State's authority to require reasonable, privacy-protective age-verification or content-filtering measures to restrict a minor's access to material that is obscene as to minors, consistent with federal law.
(c) A State law or regulation that has the purpose, or the predominant practical effect, of prohibiting adult access to a lawful website or online service is void to that extent. A State age-verification, parental-control, or content-labeling measure described in subsection (b) is not void under this subsection solely because it imposes an incidental burden on adult access, if it is reasonably tailored to restricting minors' access to the material described in subsection (b) and offers at least one privacy-protective compliance method.
(d) Nothing in this Section limits a State's authority to regulate an entity's data practices, business conduct, or consumer protection generally, provided the regulation does not have the purpose or predominant effect described in subsection (c).
Section 5. Government Access to Data.
(a) Content. No agency of any government shall compel the disclosure of, or directly access, the content of a citizen's communications or a citizen's precise geolocation history, without a warrant issued upon probable cause by a court of competent jurisdiction, except as provided in this Section.
(b) Non-content records. Government access to non-content subscriber, transactional, or metadata records held by a third party is not subject to subsection (a). It requires a court order issued upon a showing of specific and articulable facts that the records sought are relevant to a legitimate investigation, or a grand jury or administrative subpoena subject to judicial enforcement upon objection.
(c) Foreign intelligence. This Section does not limit the collection of foreign intelligence information concerning a person who is not a citizen or lawful permanent resident of the United States, as authorized by Act of Congress and subject to such judicial oversight as Congress shall provide.
(d) Border security. This Section does not limit a search conducted at an international border, or its functional equivalent, for the purpose of enforcing customs, immigration, or border-security law, as authorized by Act of Congress, except that a forensic examination of the data on an electronic device at the border shall require a standard established by law no less protective than reasonable, articulable suspicion.
(e) Emergency exception. In circumstances involving imminent danger of death or serious physical injury, a government agency may access data described in subsection (a) without prior judicial authorization if: (i) an application for a warrant is submitted to a court of competent jurisdiction within 48 hours of the access; (ii) the court applies the same probable-cause standard that would have applied had the application been made in advance; and (iii) if the court does not approve the application, the agency shall immediately cease use of the data, and any evidence derived from it is inadmissible against the citizen whose data was accessed, except to the extent necessary to address the emergency that justified the access.
(f) Purchase of data. Acquisition by a government agency of data described in subsection (a) or (b), whether by purchase, subscription, license, or other transfer from a third party in exchange for consideration, is subject to the same requirement under this Section that would apply had the agency compelled that disclosure directly, including the emergency exception in subsection (e) where applicable. This subsection does not apply to data that has been aggregated or de-identified as described in Section 1(b), or to data the citizen to whom it relates has lawfully published or made publicly available.
(g) Automated license plate reader and camera networks. Data compiled by an automated license plate reader, fixed camera network, or similar mass-scanning system operated by or on behalf of a government agency is data described in subsection (a). A government agency may query such a system in real time against a specific vehicle identified in an active warrant, an active missing-person report, or an active investigation of a specifically identified crime without a warrant under this subsection, but a search of the historical record of a specific vehicle’s or person’s movements compiled from that data requires a warrant issued under subsection (a). Data collected under this subsection may be retained by a government agency for no more than thirty days from the date of collection, except that data subject to a litigation hold, an active warrant, or an active, specifically identified investigation may be retained only as long as that hold, warrant, or investigation remains open. No agency of the United States, and no agency of any State, territory, or political subdivision, shall disclose data described in this subsection to a federal agency whose primary function is the enforcement of civil immigration law, absent a warrant issued under subsection (a). Disclosure of data described in this subsection between government agencies for any other purpose requires a documented, auditable record identifying the specific investigation to which the disclosure relates. No entity operating a system described in this subsection on behalf of a government agency shall sell, license, or otherwise transfer data collected under this subsection to any person for consideration.
Section 6. Enforcement and Penalties.
(a) Penalties for a knowing or willful violation of this Article shall be established by law and calculated as a percentage of the violating entity's United States revenue, not less than one percent nor more than four percent of the entity's total United States revenue for the preceding fiscal year, sufficient to constitute a meaningful deterrent rather than a routine cost of doing business.
(b) A citizen aggrieved, as defined in Section 1(b), by a violation of this Article has a private right of action against the violator for actual damages, statutory damages as established by law, injunctive relief, and reasonable attorney's fees.
(c) Before commencing an action under subsection (b), a citizen shall give the prospective defendant written notice of the alleged violation and an opportunity to cure it within a period established by law. This notice-and-cure requirement does not apply to a claim involving a minor or alleging a substantial privacy harm, as defined by law.
(d) A predispute agreement to arbitrate, or a predispute waiver of the right to participate in a class or collective action, is unenforceable as to a claim under subsection (b) brought by a minor or alleging a substantial privacy harm, as defined by law. Congress may by law extend this protection to other categories of claims under this Article.
(e) Nothing in this Section limits the Authority's own enforcement authority under this Article.
(f) The Authority may, on its own initiative and without awaiting a citizen complaint, audit an entity's compliance with this Article, issue a subpoena for documents or testimony reasonably relevant to that audit or to the investigation of a suspected violation, and refer a suspected criminal violation to the Attorney General. A subpoena issued under this subsection is subject to judicial enforcement and to a motion to quash on the same terms as a subpoena issued in a civil action in federal court.
Section 7. Leadership and Independence.
The Data Protection Authority shall be led by a Director serving a single nonrenewable term of ten years. A Nominating Commission of seven members shall produce a slate of three qualified nominees for Director: two members appointed by the President, two by the Senate, two by the House of Representatives, and one by the Chief Justice of the United States. The Director shall be the nominee confirmed by majority vote of both chambers of Congress acting independently. If no nominee receives dual-chamber confirmation within ninety days, the Nominating Commission shall produce a new slate under the same procedure. Notwithstanding Article II, Section 1, and any other provision of this Constitution, the President shall have no authority to remove the Director. The Director may be removed only upon a three-fifths vote of both Houses of Congress, sitting separately, upon: (a) conviction of a felony by a court of competent jurisdiction; (b) a judicial finding of mental incapacity by the United States District Court for the District of Columbia, upon petition by the Attorney General, the President, or not less than one-fifth of the Members of either House; or (c) a judicial determination of material neglect of duty or material abuse of authority, as defined in Section 1(b), by the United States Court of Appeals for the District of Columbia Circuit, upon petition by not less than one-third of the Members of either House of Congress.
Section 8. Judicial Review. The rights established by this Article are judicially enforceable. A person aggrieved, as defined in Section 1(b), by a violation of this Article has the right to seek relief in federal court.
Section 9. Transition and Construction.
(a) Congress shall enact implementing legislation within two years of ratification, including reasonable exceptions for routine service operation consistent with the consent standard established by Section 2. Entities engaged in data practices lawful prior to ratification shall have three years from ratification to achieve compliance with this Article.
(b) Legislation enacted under this Article may establish definitions, exceptions, and technical standards not inconsistent with the principles stated in Sections 2 through 5, and is entitled to a presumption of validity so long as it does not narrow those principles.
Section 10. Prohibition on Data-Enabled Individualized Pricing and Compensation.
(a) Definitions. As used in this Section, “personal data” and “entity” have the meanings given in Section 1(b). “Individualized price” means a price, rate, fee, fare, or other charge for a good or service offered to a specific consumer that is set, adjusted, or influenced, in whole or in part, by personal data concerning that consumer obtained, purchased, licensed, or aggregated from a source other than the consumer's direct, contemporaneous interaction with the entity setting the price for that specific transaction. “Individualized compensation offer” means a wage, salary, hourly rate, bonus, or other compensation offered or paid to a specific worker or applicant that is set, adjusted, or influenced, in whole or in part, by personal data concerning that worker or applicant obtained, purchased, licensed, or aggregated from a source other than that worker's or applicant's own direct disclosure to the offering entity for purposes of that specific employment relationship. “Sell” has the meaning given in Section 2, and includes disclosure for consideration to a data broker, pricing-technology vendor, or compensation-benchmarking service.
(b) No entity shall sell, purchase, license, or use personal data for the purpose of setting, adjusting, or influencing an individualized price or an individualized compensation offer, except: (i) a price adjustment based on a consumer's own directly disclosed loyalty-program membership, purchase volume, or documented creditworthiness, where the program's terms and the categories of data used are disclosed to the consumer in advance; (ii) a compensation offer based on a worker's own directly disclosed salary or wage history, education, certifications, or documented prior job performance, voluntarily disclosed for purposes of that specific application; or (iii) risk-based pricing for insurance, credit, or lending independently regulated by federal or state law governing permissible underwriting factors.
(c) No entity shall participate in, contribute data to, or purchase access to a compensation-benchmarking pool, service, or algorithm that aggregates non-public wage, salary, or benefits data from two or more employers for the purpose of, or having the effect of, setting or recommending compensation for a class of workers, where that participation restrains competition for workers' labor.
(d) An entity that offers goods or services to consumers using a price determined in whole or in part by an automated or algorithmic system shall disclose, in a clear and conspicuous manner prior to purchase, that the displayed price may differ from the price displayed to other consumers, and the general categories of data used to determine it.
(e) A consumer or worker injured by a violation of this Section has a private right of action for actual damages or one thousand dollars per violation, whichever is greater, plus reasonable attorney's fees. A violation of subsection (c) is additionally subject to the enforcement authority of any federal or state antitrust enforcement agency.
(f) This Section does not limit an entity's ability to offer a discount, promotion, or price difference applied uniformly to all consumers meeting objective, disclosed, non-individualized criteria, such as student status, senior status, or membership open to the general public on equal terms.
(g) Congress may by law establish additional categories of permitted differentiation consistent with this Section, technical compliance standards, and civil penalties for a violation, but may not authorize an exception broader than those provided in subsections (b) and (f).