Federal regulators have spent years warning that consumers have almost no visibility into how their browsing habits are tracked, packaged, and sold. In December 2010, the Federal Trade Commission formalized that concern in a landmark online privacy report and followed it with testimony before Congress, arguing that a browser-based "Do Not Track" mechanism was needed to give people real control over behavioral advertising. The idea was simple in concept but difficult in execution: let a consumer flip a single switch and stop being followed across the web.
That proposal has now taken legislative shape. Representative Jackie Speier, a California Democrat, introduced the "Do Not Track Me Online Act of 2011" (H.R. 654) on February 11, giving the FTC 18 months to write regulations establishing an opt-out mechanism. The law would require that this mechanism "allow a consumer to effectively and easily prohibit the collection or use of any covered information" and compel companies to honor that choice. For everyday users already relying on a vpn service to limit exposure to trackers and data brokers, the bill signals that technical self-defense may soon be reinforced by enforceable federal rights rather than left entirely to browser settings and third-party tools. vpn service
The scope of the bill is broad. It would apply to any person engaged in interstate commerce that stores or collects a person's online activity, including sites visited and time of access, along with IP addresses and personal identifiers such as names, email addresses, phone numbers, or financial account details. Covered entities would need to disclose their data practices in plain terms, including naming the third parties with whom information is shared. The FTC would retain discretion to exempt routine commercial functions, such as billing, that require minimal data use rather than broad behavioral profiling.
Enforcement With Real Teeth
Unlike many privacy proposals that rely on voluntary compliance, H.R. 654 treats violations as unfair or deceptive trade practices, placing them squarely within the FTC's existing enforcement authority. State attorneys general would gain parallel power to bring civil actions, widening the pool of regulators capable of pursuing noncompliant companies. Penalties would accrue daily, up to $11,000 per day of violation, with total liability capped at $5,000,000 per case. That structure is designed to make ignoring opt-out requests financially irrational for companies that profit from large-scale data collection.
A Parallel Push on Financial Data
Speier paired the tracking bill with a second measure, the "Financial Information Privacy Act of 2011," also introduced on February 11. Modeled on legislation she previously passed in California, it would bar financial institutions from sharing nonpublic personal information with affiliates without an opt-out option, and would require explicit opt-in consent before sharing such data with unaffiliated third parties. Together, the two bills reflect a broader argument taking hold in Washington: that privacy protection should not depend solely on a user's technical sophistication, but on enforceable defaults built into law.
What It Would Mean for Consumers
If enacted, the Do Not Track framework would mark one of the first instances in which the United States mandates an opt-out standard for online tracking at the federal level, rather than leaving the matter to industry self-regulation. Whether browsers, advertisers, and data brokers would interpret "effectively and easily" the same way remains an open question, and the FTC's 18-month rulemaking window would likely become a battleground for defining technical compliance standards.