How the Proposed SECURE Data Act Would Rewrite American Privacy Law and Preempt State Protections
The newly introduced SECURE Data Act aims to establish the first comprehensive federal privacy standard in the U.S., granting consumers new data rights while broadly preempting existing state laws like California's CCPA. The legislation would expand youth privacy protections and bring telecom carriers under federal oversight, though critics argue it strips away stronger state-level safeguards.
By Sergei Orlov
- Federal Preemption Advocates
- Argue that a single national privacy standard is necessary to eliminate the confusing and costly patchwork of state laws.
- State Privacy Defenders
- Argue that federal law should set a baseline floor, not preempt stronger state-level protections like California's CCPA.
- Compliance Analysts
- Focus on the operational impacts of the bill, such as the 45-day cure period and the expansion of youth privacy rules.
Perspectives this story doesn't cover
- Small Business Owners
- Teenagers and Youth Advocates
- Data Brokers
For more than a decade, the United States has stood alone among major Western economies in its lack of a comprehensive national privacy law. Instead, American data protection has evolved into a fractured landscape of 22 distinct state-level frameworks. Now, a sweeping legislative proposal aims to rewrite that architecture. Introduced by members of the House Energy and Commerce Committee's Privacy Working Group, the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act—dubbed the SECURE Data Act—proposes a single, unified federal privacy standard for the entire country.[1][2]
The legislation represents the most significant attempt to date to federalize consumer data rights. If enacted, the SECURE Data Act would grant Americans a suite of enforceable rights over their personal information, including the ability to access, correct, delete, and port their data across platforms. It would also establish strict data minimization requirements, forcing companies to limit their data collection strictly to what is necessary to provide a requested product or service, rather than hoarding information for future monetization.[5][7]
However, the bill's most consequential and controversial mechanism is its broad preemption clause. The SECURE Data Act is explicitly designed to override the existing patchwork of state consumer privacy laws, replacing them entirely with its federal framework. For businesses that have spent millions of dollars building compliance programs for states like California, Virginia, and Colorado, the legislation promises a simplified, single-rulebook environment.[2][4]
Under the proposed framework, consumers would gain the explicit right to opt out of targeted advertising and the sale of their personal data. Furthermore, the bill introduces a heightened standard for sensitive data—which includes biometric information, precise geolocation, and certain financial records. Companies would be legally prohibited from processing this sensitive information without first obtaining affirmative, opt-in consent from the consumer.[5][7]
The SECURE Data Act also takes direct aim at youth privacy, an area that has seen aggressive regulatory focus in recent years. Currently, the Children's Online Privacy Protection Act (COPPA) only shields minors under the age of 13. The new House bill would classify the personal data of teenagers between the ages of 13 and 16 as sensitive data. This expansion means that tech platforms and data brokers would need to secure verifiable parental consent before processing the data of high schoolers, a massive operational shift for social media and gaming companies.[4][7]
In a notable jurisdictional expansion, the legislation expressly brings common carriers—such as broadband internet service providers and traditional telephone companies—under the enforcement umbrella of the Federal Trade Commission (FTC). Historically, these telecom giants have fallen outside the FTC's privacy jurisdiction, creating regulatory blind spots. The SECURE Data Act would subject them to the exact same data privacy obligations as other covered technology businesses.[4]
To prevent the law from crushing small businesses, the drafters included specific applicability thresholds. The SECURE Data Act generally applies to companies that process the personal data of more than 200,000 U.S. consumers annually and generate at least $25 million in gross revenue. Alternatively, it covers businesses that process the data of 100,000 consumers if they derive 25 percent or more of their revenue directly from data sales. Companies falling below these marks would be exempt from the heaviest compliance burdens.[5]
To prevent the law from crushing small businesses, the drafters included specific applicability thresholds.
Alongside the primary bill, lawmakers also introduced a companion measure known as the GUARD Financial Data Act. While the SECURE Data Act covers non-financial entities like tech platforms and retailers, the GUARD Act is designed to modernize the Gramm-Leach-Bliley Act (GLBA), which governs financial institutions. Together, the two bills aim to create a synchronized privacy regime across both the general economy and the highly regulated financial sector.[2]
Despite the broad new rights it grants, the SECURE Data Act has drawn fierce opposition from privacy advocates and state regulators, primarily due to its enforcement mechanisms. Most notably, the bill does not include a private right of action. This means that everyday consumers cannot hire a lawyer and sue a company directly for violating their privacy rights under the Act.[5][6]
Instead, enforcement authority is centralized and shared exclusively between the FTC and state attorneys general. If a company violates the law, only these government bodies can bring a civil action to seek damages or equitable relief. Industry groups have long lobbied against a private right of action, arguing it would unleash a flood of frivolous class-action lawsuits that enrich attorneys rather than protecting consumers.[4][6][7]
Adding another layer of corporate protection, the bill mandates a 45-day right to cure period. Before the FTC or a state attorney general can initiate any enforcement action, they must provide the offending company with written notice of the alleged violation. If the company corrects the issue within 45 days and provides a written assurance that the violation will not recur, it is entirely shielded from liability for that specific incident.[4][7]
This combination of broad preemption, no private right of action, and a generous cure period has sparked a severe backlash from states that have spent years building robust privacy frameworks. The California Privacy Protection Agency (CPPA), the nation's first dedicated state privacy regulator, issued a formal letter of opposition to the bill. The agency argued that the SECURE Data Act would strip away vital protections currently enjoyed by over 100 million Americans living in states with comprehensive privacy laws.[3]
California regulators specifically pointed out that the federal bill's data minimization standard is weaker than the California Consumer Privacy Act (CCPA). While California law strictly limits data retention to what is reasonably necessary and considers the consumer's expectations, the SECURE Data Act uses a looser reasonably necessary or compatible standard. Furthermore, the federal bill would likely preempt California's newly launched Delete Act, which allows residents to wipe their data from hundreds of registered data brokers with a single request.[3]
The CPPA wrote in its opposition that the SECURE Data Act includes preemption language that seeks to strip away a substantial amount of important privacy protections. State regulators are urging Congress to pass legislation that sets a federal floor for privacy rights—establishing baseline protections for all Americans—while allowing individual states to build stronger ceilings on top of it to address local concerns.[3]
The legislative path forward remains highly uncertain. While the desire for a unified national privacy standard enjoys bipartisan support in theory, the specific mechanics of preemption and private lawsuits have derailed every major federal privacy push over the last decade. As the SECURE Data Act moves toward committee markups, the battle lines are clearly drawn between an industry desperate for a single rulebook and state regulators fighting to defend their hard-won privacy mandates.[1][6]
The stakes
For years, American businesses and consumers have navigated a confusing patchwork of 22 different state privacy laws. If passed, this legislation would fundamentally change how every major company collects, uses, and deletes your personal data—establishing a single nationwide rulebook while eliminating your ability to sue tech companies directly for privacy violations.
The essentials
- The SECURE Data Act proposes a single, uniform federal privacy standard, preempting 22 existing state laws.
- Consumers would gain federal rights to access, correct, delete, and port their personal data.
- The bill expands COPPA protections, requiring verifiable parental consent for teenagers up to age 16.
- Enforcement is limited to the FTC and state attorneys general, with no private right of action for consumers.
- Companies are granted a 45-day right to cure period to fix violations and avoid liability.
- California's privacy regulator strongly opposes the bill, arguing it weakens existing state-level protections.
Glossary
- Preemption
- A legal doctrine where a higher level of government (federal) overrides or displaces laws enacted by a lower level (state).
- Private Right of Action
- A provision in a law that allows everyday citizens to file a lawsuit directly against a violator, rather than relying on government regulators to enforce the law.
- Data Minimization
- The principle that companies should only collect and retain the minimum amount of personal data necessary to provide a specific product or service.
- Right to Cure
- A grace period (in this case, 45 days) allowing a company to fix a legal violation and avoid penalties before enforcement action is taken.
- Common Carrier
- Telecommunications providers, such as broadband internet and telephone companies, which would be brought under FTC privacy jurisdiction by this bill.
Sources
[1]Factlen Editorial TeamCompliance AnalystsSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
[2]House Financial Services CommitteeFederal Preemption AdvocatesFinancial Services, Energy & Commerce Committees Partner to Strengthen American Data Privacy
Read on House Financial Services Committee →
[3]California Privacy Protection AgencyState Privacy DefendersOpposition to H.R. 8413, the SECURE Data Act
Read on California Privacy Protection Agency →
[4]FinneganCompliance AnalystsThe SECURE Data Act: A Federal Privacy Framework Moves Forward
Read on Finnegan →
[5]DLA PiperFederal Preemption AdvocatesU.S.: Comprehensive Federal Privacy Legislation Introduced
Read on DLA Piper →
[6]Morgan LewisCompliance AnalystsCongressional Activity: The SECURE Data Act
Read on Morgan Lewis →
[7]Mayer BrownCompliance AnalystsHouse Republicans Introduce the Secure Data Act
Read on Mayer Brown →
Comments
More in Technology
See all →Starship Flight 14
SpaceX Stacks Super Heavy Booster for Starship's First Orbital Payload Flight
4 sources
Robotics Ecosystem
Qualcomm Acquires PickNik Robotics to Integrate MoveIt Software with Dragonwing Hardware
5 sources
Defense Cloud
AWS Becomes First Cloud Provider Approved for NATO Restricted Workloads
6 sources
Frontier Models
OpenAI and Anthropic Slash API Prices in Simultaneous Frontier Model Launches
7 sources
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.




