Every year for the past several years, the United States has been described as “on the verge” of passing a comprehensive federal privacy law. Every year, the bill has stalled, collapsed, or been shelved before a final vote. The American Privacy Rights Act (APRA), the most recent serious attempt, moved further than most of its predecessors — and still did not become law.
As of August 2026, there is no US federal comprehensive privacy law in effect that broadly governs what companies can do with personal data, including your photos, files, and memories stored in cloud services.
This is not a niche policy detail. It means the default answer to “what privacy rights do I have over my personal data stored by US tech companies?” is: it depends on which state you live in, which company you’re dealing with, and what that company’s terms of service say.
What the American Privacy Rights Act Would Have Done
Understanding what didn’t pass is useful context for understanding the gap.
APRA, as introduced and revised through 2024 and 2025, would have established:
Data minimisation requirements. Companies could only collect personal data reasonably necessary to provide the product or service the user actually requested. This would have prohibited the current common practice of collecting user data well beyond what’s needed to deliver a service, to build advertising profiles or monetise data.
A right to access and correct personal data. Users would have had a universal right to see what data a company holds about them and to correct inaccuracies.
A right to delete personal data. Users could request deletion of personal data held by any covered company, not just those subject to state laws.
Limits on AI-powered profiling. APRA included provisions governing automated decision-making that affects consumers significantly — covering the kind of algorithmic content curation and profiling that shapes what information people see and what prices they’re offered.
A private right of action. This was the most contested provision. APRA would have allowed individuals to sue companies directly for privacy violations, not just wait for the FTC or state attorneys general to act. The private right of action was a major sticking point in negotiations, with business groups opposing it and privacy advocates insisting it was necessary for any meaningful enforcement.
The bill passed committee twice and stalled on the floor, ultimately failing to reach a Senate vote before the end of the session. The reasons are familiar: disagreement between states (California in particular) on whether federal law should preempt stronger state protections, business lobbying against the private right of action, and the perennial challenge of privacy losing out to other legislative priorities.
What Exists Instead: The State Patchwork
In the absence of federal law, US residents’ privacy rights are governed by a complex patchwork of state laws, each with different scope, different rights, and different enforcement mechanisms.
California has the most comprehensive regime. The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives California residents rights to access, delete, correct, and opt out of the sale of their personal data. CPRA established the California Privacy Protection Agency (CPPA), a dedicated enforcement body. The CPPA has become one of the most active privacy enforcers in the United States.
As of mid-2026, over 20 states have enacted their own comprehensive privacy laws, including Virginia, Colorado, Connecticut, Texas, Florida, Iowa, Indiana, Tennessee, Montana, Oregon, Delaware, New Hampshire, New Jersey, Nebraska, and Maryland.
These laws vary significantly. Some follow California’s model closely; others have narrower definitions of covered data or weaker enforcement. Very few include a private right of action — meaning enforcement depends on the state attorney general, who has limited capacity to pursue individual complaints.
The practical result: your privacy rights as a US resident depend heavily on which state you live in. A resident of California has substantially more legally enforceable rights over their personal data than a resident of a state with no privacy law.
Federal Laws That Do Apply
While there’s no comprehensive federal privacy law, several sector-specific federal laws provide privacy protections in specific domains.
COPPA (Children’s Online Privacy Protection Act) requires parental consent before collecting personal information from children under 13. COPPA 2.0, which extends some protections to teenagers and strengthens enforcement, passed in a modified form in 2025 — one of the few federal privacy advances in recent years.
HIPAA governs personal health information held by covered healthcare entities (hospitals, insurers, healthcare providers) and their business associates. It does not cover health data collected by fitness trackers, wellness apps, or consumer tech companies — a significant gap that consumer health apps exploit.
FERPA protects the educational records of students. It covers schools and educational institutions, not third-party EdTech tools used by schools — another significant gap.
The Electronic Communications Privacy Act (ECPA), now several decades old, governs government access to electronic communications. It has significant gaps — most notably, the so-called “third party doctrine,” which holds that data you share with a third party (like a cloud storage provider) receives weaker Fourth Amendment protections than data on your own device.
The FTC Act prohibits unfair or deceptive practices. The Federal Trade Commission uses this authority to bring enforcement actions against companies that violate their own stated privacy policies, engage in deceptive data practices, or fail to implement reasonable security measures. This is the broadest federal enforcement lever for data privacy, but it’s reactive and can’t address data practices that are disclosed in terms of service, however unfavourable to consumers.
The Rights You Have Right Now
Rather than navigate the legal patchwork abstractly, here’s a practical account of the data rights most US residents can actually exercise.
Rights from company policies (available broadly)
Every major tech company now publishes some form of privacy dashboard and data rights request process. These are often voluntary commitments — not legally required for most US users — but they’re contractually binding and can be enforced through FTC unfair practice authority.
Google’s privacy dashboard lets you download your data, review activity, and request deletion of your Google account. Apple’s Data and Privacy page lets you obtain a copy of your Apple data or request account deletion. Meta offers a similar data download tool. These tools exist partly because of GDPR pressure, partly because of CCPA, and partly because public pressure made not having them untenable.
Exercising your rights from company policies is free and doesn’t require a lawyer. Most major platforms have a data request process that takes a few clicks. The data you get back may be voluminous and hard to parse, but the right to access and download exists.
Rights from state law (if you’re in a covered state)
If you live in California or another state with a comprehensive privacy law, you have legally enforceable rights including:
- The right to know what personal data is collected and how it’s used
- The right to request deletion of personal data
- The right to opt out of the sale of your personal data
- The right to correct inaccurate data
- The right not to be discriminated against for exercising these rights
You exercise these rights by submitting a formal data subject rights request to the company’s designated privacy contact (required to be disclosed in the privacy policy). Companies subject to CCPA/CPRA must respond within 45 days. If they don’t comply, you can file a complaint with the CPPA (in California) or the state attorney general.
Rights from the FTC framework (available broadly)
If a company violates its own privacy policy — says it won’t share your data and then shares it, claims to delete data and doesn’t — that may constitute an unfair or deceptive practice under the FTC Act.
Filing an FTC complaint doesn’t guarantee individual remediation; the FTC brings enforcement actions that may result in settlements or orders years later. But filing creates a record, and enough complaints about a specific practice can trigger an investigation. The FTC complaint portal is at ftc.gov/complaint.
What This Means for Cloud Storage and Personal Files
The lack of federal privacy law creates specific risks for personal data stored in US-based cloud services.
Government access without your knowledge. Under current law, federal law enforcement can compel cloud service providers to hand over user data with a valid subpoena or court order. For communication content, a warrant is generally required. For metadata and non-content data, the standard can be lower. Critically, providers are often subject to gag orders that prohibit them from notifying users that their data has been accessed.
No mandatory breach notification at the federal level. There’s no single federal breach notification law for consumer data (there are sector-specific requirements for financial and healthcare data). The FTC’s updated safeguards rules and state breach notification laws create a de facto requirement for most companies to notify users after a significant breach, but the timelines and thresholds vary.
AI training on user data. There’s currently no federal law that restricts companies from training AI models on your personal files, photos, or messages stored in cloud services — unless the company’s own terms prohibit it. COPPA creates limits for children’s data. HIPAA creates limits for health data in covered contexts. General consumer data is governed only by the company’s terms of service and, for covered data types in certain states, state law.
This is the gap that privacy-first services fill by contract rather than by law. A service that commits in its terms not to use your content for AI training, not to sell your data, and to delete your data permanently on request is making a contractual promise enforceable under contract law — even if it’s not a statutory right.
What to Watch Going Forward
The federal legislative landscape in 2026 includes several developments worth watching.
APRA successor legislation. A revised version of APRA is expected to be introduced, with modifications designed to address the preemption and private right of action sticking points. Whether it advances will depend on the composition of the next Congress and the extent to which the existing state-law patchwork creates pressure on Congress to harmonise standards.
FTC rulemaking. The FTC initiated rulemaking on commercial surveillance and data security in 2022. The process has been slow, but the agency has authority to issue binding rules under the FTC Act that would apply nationwide without congressional action. The rules under development would address data minimisation, secondary data use, and certain automated decision-making practices.
State law evolution. California’s CPPA has signalled aggressive enforcement priorities for 2026, including data brokers, AI-powered consumer profiling, and mobile app data practices. California enforcement precedent tends to become a de facto national standard for companies that prefer not to maintain separate compliance programmes by state.
EU-US data transfer framework. The EU-US Data Privacy Framework, which allows transfer of EU personal data to certified US companies, is subject to ongoing review. If it were invalidated again (as its predecessors were), EU residents’ data currently stored on US cloud infrastructure would face significant legal disruption.
The Honest Answer
The honest answer to “what federal privacy rights do I have over my personal data in the US?” is: not many, and the ones you have are mostly voluntary commitments from companies responding to state laws you may or may not be covered by.
If you live in California or a state with a comprehensive privacy law, you have real, enforceable rights — exercise them.
If you don’t, your protections come primarily from company policies (which can change), the FTC’s reactive enforcement (which addresses violations but doesn’t create proactive rights), and the choices you make about which services to use.
Choosing services that make explicit commitments about data use — services that don’t sell your data, don’t train AI on your content, and provide clear data deletion — is one of the few leverage points available to consumers in states without comprehensive privacy protection. In the absence of a federal law that creates those commitments by default, the terms of service is the contract that governs your data. It’s worth reading it.