How the Proposed SECURE Data Act Would Rewrite American Privacy Law and Preempt State Protections
The newly introduced SECURE Data Act aims to establish the first comprehensive federal privacy standard in the U.S., granting consumers new data rights while broadly preempting existing state laws like California's CCPA. The legislation would expand youth privacy protections and bring telecom carriers under federal oversight, though critics argue it strips away stronger state-level safeguards.
By Sergei Orlov
- Federal Preemption Advocates
- Argue that a single national privacy standard is necessary to eliminate the confusing and costly patchwork of state laws.
- State Privacy Defenders
- Argue that federal law should set a baseline floor, not preempt stronger state-level protections like California's CCPA.
- Compliance Analysts
- Focus on the operational impacts of the bill, such as the 45-day cure period and the expansion of youth privacy rules.
Why this matters
For years, American businesses and consumers have navigated a confusing patchwork of 22 different state privacy laws. If passed, this legislation would fundamentally change how every major company collects, uses, and deletes your personal data—establishing a single nationwide rulebook while eliminating your ability to sue tech companies directly for privacy violations.
Key points
- The SECURE Data Act proposes a single, uniform federal privacy standard, preempting 22 existing state laws.
- Consumers would gain federal rights to access, correct, delete, and port their personal data.
- The bill expands COPPA protections, requiring verifiable parental consent for teenagers up to age 16.
- Enforcement is limited to the FTC and state attorneys general, with no private right of action for consumers.
- Companies are granted a 45-day right to cure period to fix violations and avoid liability.
- California's privacy regulator strongly opposes the bill, arguing it weakens existing state-level protections.
For more than a decade, the United States has stood alone among major Western economies in its lack of a comprehensive national privacy law. Instead, American data protection has evolved into a fractured landscape of 22 distinct state-level frameworks. Now, a sweeping legislative proposal aims to rewrite that architecture. Introduced by members of the House Energy and Commerce Committee's Privacy Working Group, the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act—dubbed the SECURE Data Act—proposes a single, unified federal privacy standard for the entire country.[1][2]
The legislation represents the most significant attempt to date to federalize consumer data rights. If enacted, the SECURE Data Act would grant Americans a suite of enforceable rights over their personal information, including the ability to access, correct, delete, and port their data across platforms. It would also establish strict data minimization requirements, forcing companies to limit their data collection strictly to what is necessary to provide a requested product or service, rather than hoarding information for future monetization.[5][7]
However, the bill's most consequential and controversial mechanism is its broad preemption clause. The SECURE Data Act is explicitly designed to override the existing patchwork of state consumer privacy laws, replacing them entirely with its federal framework. For businesses that have spent millions of dollars building compliance programs for states like California, Virginia, and Colorado, the legislation promises a simplified, single-rulebook environment.[2][4]
Under the proposed framework, consumers would gain the explicit right to opt out of targeted advertising and the sale of their personal data. Furthermore, the bill introduces a heightened standard for sensitive data—which includes biometric information, precise geolocation, and certain financial records. Companies would be legally prohibited from processing this sensitive information without first obtaining affirmative, opt-in consent from the consumer.[5][7]

The SECURE Data Act also takes direct aim at youth privacy, an area that has seen aggressive regulatory focus in recent years. Currently, the Children's Online Privacy Protection Act (COPPA) only shields minors under the age of 13. The new House bill would classify the personal data of teenagers between the ages of 13 and 16 as sensitive data. This expansion means that tech platforms and data brokers would need to secure verifiable parental consent before processing the data of high schoolers, a massive operational shift for social media and gaming companies.[4][7]
In a notable jurisdictional expansion, the legislation expressly brings common carriers—such as broadband internet service providers and traditional telephone companies—under the enforcement umbrella of the Federal Trade Commission (FTC). Historically, these telecom giants have fallen outside the FTC's privacy jurisdiction, creating regulatory blind spots. The SECURE Data Act would subject them to the exact same data privacy obligations as other covered technology businesses.[4]
To prevent the law from crushing small businesses, the drafters included specific applicability thresholds. The SECURE Data Act generally applies to companies that process the personal data of more than 200,000 U.S. consumers annually and generate at least $25 million in gross revenue. Alternatively, it covers businesses that process the data of 100,000 consumers if they derive 25 percent or more of their revenue directly from data sales. Companies falling below these marks would be exempt from the heaviest compliance burdens.[5]

To prevent the law from crushing small businesses, the drafters included specific applicability thresholds.
Alongside the primary bill, lawmakers also introduced a companion measure known as the GUARD Financial Data Act. While the SECURE Data Act covers non-financial entities like tech platforms and retailers, the GUARD Act is designed to modernize the Gramm-Leach-Bliley Act (GLBA), which governs financial institutions. Together, the two bills aim to create a synchronized privacy regime across both the general economy and the highly regulated financial sector.[2]
Despite the broad new rights it grants, the SECURE Data Act has drawn fierce opposition from privacy advocates and state regulators, primarily due to its enforcement mechanisms. Most notably, the bill does not include a private right of action. This means that everyday consumers cannot hire a lawyer and sue a company directly for violating their privacy rights under the Act.[5][6]
Instead, enforcement authority is centralized and shared exclusively between the FTC and state attorneys general. If a company violates the law, only these government bodies can bring a civil action to seek damages or equitable relief. Industry groups have long lobbied against a private right of action, arguing it would unleash a flood of frivolous class-action lawsuits that enrich attorneys rather than protecting consumers.[4][6][7]
Adding another layer of corporate protection, the bill mandates a 45-day right to cure period. Before the FTC or a state attorney general can initiate any enforcement action, they must provide the offending company with written notice of the alleged violation. If the company corrects the issue within 45 days and provides a written assurance that the violation will not recur, it is entirely shielded from liability for that specific incident.[4][7]
This combination of broad preemption, no private right of action, and a generous cure period has sparked a severe backlash from states that have spent years building robust privacy frameworks. The California Privacy Protection Agency (CPPA), the nation's first dedicated state privacy regulator, issued a formal letter of opposition to the bill. The agency argued that the SECURE Data Act would strip away vital protections currently enjoyed by over 100 million Americans living in states with comprehensive privacy laws.[3]

California regulators specifically pointed out that the federal bill's data minimization standard is weaker than the California Consumer Privacy Act (CCPA). While California law strictly limits data retention to what is reasonably necessary and considers the consumer's expectations, the SECURE Data Act uses a looser reasonably necessary or compatible standard. Furthermore, the federal bill would likely preempt California's newly launched Delete Act, which allows residents to wipe their data from hundreds of registered data brokers with a single request.[3]
The CPPA wrote in its opposition that the SECURE Data Act includes preemption language that seeks to strip away a substantial amount of important privacy protections. State regulators are urging Congress to pass legislation that sets a federal floor for privacy rights—establishing baseline protections for all Americans—while allowing individual states to build stronger ceilings on top of it to address local concerns.[3]
The legislative path forward remains highly uncertain. While the desire for a unified national privacy standard enjoys bipartisan support in theory, the specific mechanics of preemption and private lawsuits have derailed every major federal privacy push over the last decade. As the SECURE Data Act moves toward committee markups, the battle lines are clearly drawn between an industry desperate for a single rulebook and state regulators fighting to defend their hard-won privacy mandates.[1][6]
How we got here
2018
California passes the California Consumer Privacy Act (CCPA), kicking off a wave of state-level privacy legislation.
2022-2024
Previous attempts at comprehensive federal privacy legislation fail to pass Congress due to disagreements over preemption and private lawsuits.
April 22, 2026
House Republicans introduce the SECURE Data Act and the companion GUARD Financial Data Act.
April 27, 2026
The California Privacy Protection Agency issues a formal letter opposing the bill's preemption clauses.
Viewpoints in depth
Federal Preemption Advocates
Industry groups and federal lawmakers pushing for a single national standard.
Proponents of the SECURE Data Act argue that the current landscape of 22 different state privacy laws is fundamentally unworkable for modern commerce. They contend that a fragmented system forces companies to spend millions on redundant compliance programs, costs that are ultimately passed down to consumers. By establishing a single, uniform federal standard, advocates believe the U.S. can provide clear, consistent privacy rights to all Americans regardless of their zip code, while giving businesses the regulatory certainty needed to innovate.
State Privacy Defenders
State regulators and consumer advocates fighting to preserve local laws.
Opponents, led by agencies like the California Privacy Protection Agency, argue that federal preemption is a Trojan horse designed to weaken consumer protections. They point out that states have historically served as the 'laboratories of democracy,' pioneering aggressive privacy measures like California's Delete Act. These defenders argue that any federal privacy legislation should serve as a baseline floor, not a ceiling, allowing individual states to enact stricter rules to combat emerging technological threats.
Legal and Compliance Analysts
Experts focused on the operational and enforcement realities of the bill.
Legal analysts emphasize that the bill's enforcement mechanisms—specifically the lack of a private right of action and the 45-day right to cure—heavily favor corporate defendants. Without the threat of class-action lawsuits, analysts note that enforcement will rely entirely on the resources and political will of the FTC and state attorneys general. However, they also acknowledge that the expansion of COPPA to protect teenagers up to age 16 represents a massive, complex operational hurdle that will force major architectural changes across the tech industry.
What we don't know
- Whether the bill can garner enough bipartisan support to pass the Senate, given historical Democratic opposition to preempting state laws.
- How the FTC will interpret and enforce the 'reasonably necessary' data minimization standard in practice.
- Whether state attorneys general will aggressively utilize their enforcement powers under the new federal framework.
Key terms
- Preemption
- A legal doctrine where a higher level of government (federal) overrides or displaces laws enacted by a lower level (state).
- Private Right of Action
- A provision in a law that allows everyday citizens to file a lawsuit directly against a violator, rather than relying on government regulators to enforce the law.
- Data Minimization
- The principle that companies should only collect and retain the minimum amount of personal data necessary to provide a specific product or service.
- Right to Cure
- A grace period (in this case, 45 days) allowing a company to fix a legal violation and avoid penalties before enforcement action is taken.
- Common Carrier
- Telecommunications providers, such as broadband internet and telephone companies, which would be brought under FTC privacy jurisdiction by this bill.
Frequently asked
What is the SECURE Data Act?
It is a proposed federal law that would create a single, nationwide standard for consumer data privacy, overriding existing state laws.
Will I be able to sue companies that misuse my data?
No. The bill does not include a private right of action, meaning only the FTC and state attorneys general can sue companies for violations.
How does this affect children and teenagers?
The bill expands youth privacy protections by requiring companies to obtain verifiable parental consent before processing the sensitive data of teenagers between the ages of 13 and 16.
What happens to state laws like the CCPA?
If passed, the SECURE Data Act would broadly preempt comprehensive state privacy laws, effectively replacing them with the new federal framework.
Sources
[1]Factlen Editorial TeamCompliance Analysts
Synthesis by Factlen editorial team
Read on Factlen Editorial Team →[2]House Financial Services CommitteeFederal Preemption Advocates
Financial Services, Energy & Commerce Committees Partner to Strengthen American Data Privacy
Read on House Financial Services Committee →[3]California Privacy Protection AgencyState Privacy Defenders
Opposition to H.R. 8413, the SECURE Data Act
Read on California Privacy Protection Agency →[4]FinneganCompliance Analysts
The SECURE Data Act: A Federal Privacy Framework Moves Forward
Read on Finnegan →[5]DLA PiperFederal Preemption Advocates
U.S.: Comprehensive Federal Privacy Legislation Introduced
Read on DLA Piper →[6]Morgan LewisCompliance Analysts
Congressional Activity: The SECURE Data Act
Read on Morgan Lewis →[7]Mayer BrownCompliance Analysts
House Republicans Introduce the Secure Data Act
Read on Mayer Brown →
Comments
Every angle. Every day.
Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.











