Digital Safety & Privacy
Legislative Concepts

Protecting Kids, Families, and Personal Data in the Digital Age

As technology evolves, so do the risks to privacy, safety, and personal autonomy. These proposals set clear, enforceable rules to protect children online, safeguard sensitive personal data, and prevent government or corporate overreach. From requiring safety-by-design standards for platforms to limiting how biometric, health, and personal information can be collected and used, this agenda puts guardrails around the digital world without stifling innovation. The focus is simple: stronger protections, greater transparency, and control that stays with individuals and families, not systems that profit from or exploit their data.

  • The State Kids Online Safety Act strengthens protections for minors online by imposing a duty of care on digital platforms that are likely to be accessed by children and teenagers. The Act requires platforms to provide free parental supervision tools, default privacy settings for minors, and age-appropriate design standards. It prohibits manipulative design practices that exploit children’s attention, mental health vulnerabilities, or impulsivity. Transparency requirements include public reporting and access for independent researchers. Enforcement tools and private remedies ensure platforms are accountable for safety-by-design obligations. Click for More Information

  • The Biometric Age Verification Act requires designated high-risk websites to implement biometric age verification systems to prevent minors from accessing restricted content. The Act establishes strict standards for encryption, anonymization, and data minimization, limiting retention and prohibiting secondary use of biometric data. It mandates independent certification and periodic security audits. Meaningful penalties apply for noncompliance or misuse, ensuring child protection measures do not become a backdoor for surveillance or data exploitation. Click for More Information

  • The Digital Privacy Protection Model Act protects residents’ personal information when the state mandates online age verification or similar compliance systems. It requires independent cybersecurity audits, strict limits on collection and retention, and an outright ban on secondary use such as sale, profiling, or reuse of collected data. The Act establishes enforcement mechanisms and penalties to ensure residents are not forced to sacrifice data security in order to comply with state law. Click for More Information

  • The Government Information Privacy Protection Act limits how information collected by state agencies may be shared with federal agencies or third parties. It requires clear documentation of data requests, transparency regarding federal use, privacy training for state employees, and strict vendor controls to prevent downstream misuse. Civil and criminal penalties apply for unauthorized disclosures. The Act strengthens trust by ensuring that residents’ information is not casually repurposed or transferred without accountability. Click for More Information

  • The Menstrual Data Privacy and Protection Act safeguards menstrual and reproductive health data collected by mobile applications, healthcare providers, pharmacies, and related entities. The Act requires explicit, informed consent for collection and use, bans sale or commercial transfer of this data, and mandates strong security practices including encryption, independent audits, and rapid breach notification. Individuals are granted deletion rights and enforcement tools, including civil penalties and a private right of action.Click for More Information

  • The Patient Privacy and Medical Recording Protection Act protects confidentiality and dignity in medical settings by prohibiting unauthorized recording of patients and restricting dissemination of identifiable medical images or information. The Act requires clear notice within facilities, establishes complaint and enforcement processes through the state medical board, and imposes meaningful penalties for violations. It reinforces trust in healthcare settings by establishing enforceable privacy standards in a digital era. Click for More Information

  • The No Toilet Surveillance Act prohibits state and local governments from using wastewater testing to monitor or infer the private medical decisions of citizens. Wastewater monitoring may still be used for legitimate public health purposes such as tracking infectious diseases or environmental contamination. However, sanitation systems may not be used to detect medications or investigate lawful personal behavior. The bill affirms a simple principle of limited government: the state should not analyze what citizens flush in order to monitor their private lives. Click for More Information