← Back to results
Federal

Data Privacy Act of 2023

Source: Congress.gov  ·  5,785 words in original text
This bill updates federal privacy rules for financial institutions. It requires banks, credit unions, and similar companies to get your permission before collecting or sharing your personal financial information. The bill also gives you the right to access, delete, and control how your information is used. ##
- Individuals with bank accounts, credit cards, loans, or other financial products - Financial institutions (banks, credit unions, finance companies) - Insurance companies - Data aggregators (companies that collect and sell financial information) - Federal and state financial regulators - Foreign governments seeking financial information ##
- Financial institutions must get your permission before collecting or sharing your nonpublic personal information with unaffiliated third parties (companies they don't own) (Sec. 3) - You have the right to request and receive a list of all your personal information a financial institution holds, in a format readable by computers (Sec. 7) - You can request that a financial institution delete your personal information, with limited exceptions (Sec. 7) - Financial institutions must disclose their privacy practices clearly, including what information they collect, why they collect it, and your rights to opt out (Sec. 4) - Financial institutions cannot share your information with foreign governments except for legitimate law enforcement purposes or regulatory examination (Sec. 8) - Financial institutions must respond to your requests to access or delete information within 45 business days (Sec. 7) - Financial institutions cannot collect your login credentials (usernames, passwords) for accounts at other banks unless they clearly explain how they will use those credentials and give you the option to refuse (Sec. 3) ##
If this bill becomes law, you will gain new rights over your financial information. Banks and financial companies will need to ask your permission before collecting and sharing your data with outside companies. You will be able to see exactly what information they hold about you and request deletion of that information. Financial institutions will have to write their privacy policies in clearer language that explains what they collect and why. The bill removes a federal provision that previously blocked stronger state privacy laws, allowing states to create additional protections if they choose. ##
- **Nonpublic personal information**: information that identifies you, relates to you, describes you, or can be connected to you, directly or indirectly - **Customer or consumer relationship**: either a customer relationship (defined by future rules) or a consumer relationship (includes situations where a financial institution collects your information even if you are not formally a customer) - **Account credentials**: information you use to log into your account, such as a username, password, or answer to a security question - **Data aggregator**: a company that operates a business collecting, selling, or sharing people's financial account information - **Affiliated**: owned or controlled by the same company - **Nonaffiliated third party**: a company that is not owned or controlled by the same company ##
The law takes effect on whichever comes first: one year after all required government agencies finish writing their detailed rules, or two years after the bill is signed into law (Sec. 13)
Important: This plain English summary was generated by AI and is provided for informational purposes only. It is not legal advice. Always consult the official bill text on Congress.gov or a qualified attorney for legal matters.