Under the Congressional Review Act (CRA), Congress may pass resolutions of disapproval of agency regulations which have the effect of repealing the disapproved regulation and preventing the agency from re-promulgating another rule that is "substantially the same" as that which was disapproved, unless and until expressly authorized by Congress. In effect, a resolution of disapproval not only repeals a rule, it also effectively repeals the agency's underlying statutory authority to issue such a rule.
Up until now, the scope of this bar on agency action has not been tested. Today, however, in Ohio Telecom Association v. Federal Communications Commission, the U.S. Court of Appeals for the Sixth Circuit split over whether the passage of a CRA resolution disapproving the FCC's 2016 privacy rule, which contained regulations concerning the reporting of data breaches, barred the FCC from adopting its 2024 Data Breach Reporting Rule.
According to Judge Stranch, joined by Judge Mathis, the 2024 rule was not "substantially the same" as the 2016 rule, because it only addressed one of the subjects contained in the 2016 rule. According to Judge Griffin, in dissent, the 2024 rule is so close to the relevant portions of the 2016 rule that it is barred. (Judge Griffin further argued that the FCC lacked the statutory authority to issue the 2024 rule.)