Bill would ban sale of Americans’ health and location data

Share
Bill would ban sale of Americans’ health and location data
Image: MidJourney

A new bill in Congress would bar data brokers from selling or transferring some of the most sensitive information Americans generate every day — including health data, location data and personal information entered into AI systems.

The Health and Location Data Protection Act targets the largely unregulated data-broker industry, which collects information from apps, websites, ad networks and other sources and resells it to advertisers, government agencies, political campaigns and other buyers. It was reintroduced by Sen. Elizabeth Warren, D-Mass., and Rep. Mary Gay Scanlon, D-Pa.

The bill comes as privacy advocates warn that location data can reveal visits to abortion clinics, domestic violence shelters, places of worship, union halls, LGBTQ+ community centers and other sensitive locations — often without consumers knowing the information is being collected or sold.

  • The bill would ban data brokers from collecting, selling or transferring health and location data.
  • The updated version explicitly covers data entered into AI systems.
  • The measure would give the Federal Trade Commission, state attorneys general and injured consumers power to sue violators.

“It’s more important than ever that we crack down on data brokers that are raking in giant profits from selling Americans’ most sensitive information,” Warren said. “Especially as more people enter their private health data into AI systems, we need to make sure that information isn’t exploited by the highest bidder.”

Privacy Watch: How to reduce your data-broker footprint
There’s no such thing as complete privacy but there are ways to lock down some of your crucial information

Why it matters

For consumers, the problem is not just targeted ads. Precise location data can show where someone sleeps, works, worships, seeks medical care or attends a protest. Health data can reveal pregnancy, reproductive decisions, mental health concerns, addiction treatment, medication use or other deeply personal details.

Lawmakers and privacy advocates say the danger has grown since the Supreme Court overturned Roe v. Wade and several states moved to ban or sharply restrict abortion. They warn that location and health data could be used to identify abortion patients, providers or people helping someone obtain care.

The FTC has already brought several enforcement actions against data brokers accused of trafficking in sensitive location data. In 2024, the agency accused Gravy Analytics, its subsidiary Venntel and Mobilewalla of unlawfully collecting or selling sensitive location data, including information that could reveal visits to health clinics, religious sites, military installations and other sensitive places.

In January 2025, the FTC finalized an order prohibiting Gravy Analytics and Venntel from selling, disclosing or using sensitive location data except in limited circumstances involving national security or law enforcement.

A $300 billion industry with few federal rules

Warren and Scanlon say the data-broker industry has grown into a $300 billion business, built largely on information consumers never knowingly agreed to sell.

That data can come from ordinary phone apps — weather apps, prayer apps, games, navigation tools, fertility trackers, shopping apps and advertising systems. Once collected, it can be bundled, analyzed and sold in bulk.

The United States still lacks a comprehensive federal privacy law governing the commercial collection and sale of personal data. As a result, enforcement has often depended on the FTC’s ability to challenge specific practices as unfair or deceptive, rather than on a broad federal ban.

The Health and Location Data Protection Act would try to close that gap by making the sale or transfer of health and location data illegal for data brokers. The updated bill also responds to the rapid growth of AI tools that encourage users to upload or disclose medical information, symptoms, images, prescriptions or other health details.

What the bill would do

The legislation would:

  • Ban data brokers from collecting, selling or transferring location data and health data, including data entered into AI systems.
  • Allow the FTC, state attorneys general and injured individuals to sue to enforce the law.
  • Permit remedies such as damages and injunctions to stop illegal practices.
  • Provide $1 billion to the FTC over 10 years to support enforcement and related work.

The bill is cosponsored in the Senate by Bernie Sanders, I-Vt., Sheldon Whitehouse, D-R.I., and Ron Wyden, D-Ore. House supporters include Nydia Velázquez, D-N.Y.; Adriano Espaillat, D-N.Y.; Pramila Jayapal, D-Wash.; and Rashida Tlaib, D-Mich.

Groups endorsing the bill include the National Partnership for Women & Families, All* Above All, the Guttmacher Institute, the National Network of Abortion Funds and the National Council of Jewish Women.

What consumers can do now

Even if Congress acts, consumers should assume that many apps and websites collect more information than they need. Privacy experts generally recommend limiting app permissions, especially location access, and avoiding unnecessary sharing of health details with apps or AI tools.

Consumers can also:

  • Turn off location access for apps that do not truly need it.
  • Use “while using the app” rather than “always” location permission where possible.
  • Delete apps that request excessive permissions.
  • Be cautious about entering medical, reproductive health or mental health information into apps or chatbots.
  • Review privacy settings on phones, browsers and wearable devices.
  • Use a privacy-focused browser or tracker blocker where practical.

The proposed law would shift some of that burden away from consumers by making it illegal for data brokers to traffic in the most sensitive categories of information in the first place.

The bottom line

The Health and Location Data Protection Act is unlikely to end the data-broker economy by itself. But it would draw a bright line around two categories of information that can expose consumers to stalking, discrimination, unwanted surveillance or criminal investigation: where they go and what health care they seek.

As AI systems become another place where people disclose intimate personal details, Warren and Scanlon argue that health and location privacy can no longer depend on fine print, app settings or industry promises.