The New US Privacy Reality: A Guide to the SECURE Data Act, National Preemption, and the Data Broker Registry
The proposed SECURE Data Act aims to establish a single national privacy standard, preempting the patchwork of state laws and creating a federal registry for data brokers.
- Federal Standardization Advocates
- Argues that a single national privacy law is essential to eliminate the massive compliance costs and confusion caused by conflicting state regulations.
- State Privacy Defenders
- Maintains that federal preemption undermines consumer protection by overriding stricter state laws like California's CCPA.
- Consumer Rights Advocates
- Focuses on the benefits of the data broker registry and the expansion of COPPA protections for teenagers.
How we got here
2018–2025
Over 20 U.S. states enact their own comprehensive consumer privacy laws, creating a complex regulatory patchwork.
February 2025
The House Energy and Commerce Committee establishes the Data Privacy Working Group to draft a consensus federal bill.
April 2026
House Republicans officially introduce H.R. 8413, the SECURE Data Act, proposing a unified national privacy framework.
June 2026
The House Energy and Commerce Subcommittee holds legislative hearings on the bill to debate preemption and enforcement mechanisms.
Why it matters
If enacted, the SECURE Data Act would fundamentally rewrite the rules of the American digital economy, wiping out the confusing patchwork of state privacy laws, giving consumers a centralized registry to track data brokers, and forcing companies to adopt a single, nationwide standard for data collection.
For years, the United States data privacy landscape has been defined by a fundamental tension: state governments want the freedom to aggressively protect their residents' digital footprints, while businesses desperately need a single, unified rulebook to avoid compliance paralysis. As of early 2026, more than twenty states have enacted their own comprehensive privacy laws, creating a fractured regulatory map where a consumer's fundamental rights depend entirely on their zip code. This patchwork approach has left companies spending millions of dollars to navigate conflicting mandates, while consumers remain largely confused about who actually controls their personal information and how to exercise their rights.[4]
The Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act, commonly known as the SECURE Data Act and formally introduced in the House of Representatives as H.R. 8413, attempts to resolve this legislative gridlock. Drafted after months of stakeholder engagement by the House Energy and Commerce Committee's Privacy Working Group, the legislation proposes a comprehensive federal privacy framework designed to replace the state-by-state labyrinth with a single national standard. It represents the most significant and structured attempt at federal privacy legislation since the American Privacy Rights Act of 2024, providing a detailed blueprint for how data governance could operate nationwide.[1][3]
The most consequential—and politically controversial—mechanism of the SECURE Data Act is its approach to national preemption. Unlike some previous federal proposals that acted as a baseline "floor" allowing states to pass stricter supplementary rules, this bill acts as an absolute regulatory ceiling. It explicitly prohibits states from enacting or enforcing laws that "relate to" its core provisions. If passed into law, this broad preemption clause would effectively displace existing state frameworks, including California's landmark consumer privacy laws, forcing all American businesses to align their operations with one exclusive federal playbook.

For the business community, this preemption clause is the primary operational benefit of the legislation. Companies that are currently forced to build separate, parallel compliance workflows for California, Virginia, Colorado, and other jurisdictions could finally consolidate their efforts. A unified federal standard means a company could deploy a single privacy program, one standardized consumer-rights process, and one set of vendor contracting terms across the entire country. However, privacy advocates argue that this corporate consolidation comes at the steep cost of overriding more protective, innovative state-level regulations that have driven privacy standards forward.
Beyond the preemption debate, the legislation introduces a major transparency mechanism aimed at the third-party data market: a federal Data Broker Registry. Data brokers—defined explicitly in the bill as entities that collect and process the personal data of consumers who are not their direct customers, and derive at least 50 percent of their annual gross revenue from selling that data—operate largely in the shadows of the digital economy. The SECURE Data Act is designed to force these secondary data markets into the light, requiring them to publicly account for their data sourcing and sales practices.[1]
Under the proposed framework, the Federal Trade Commission would be mandated to establish and maintain a public, easily searchable registry of these data brokers. Qualifying companies would be required to register annually and publicly disclose specific operational details. These mandatory disclosures include the exact categories of personal data they sell, their purchaser-credentialing practices to ensure data is not sold to malicious actors, and a public accounting of any prior security incidents. This registry aims to give consumers unprecedented visibility into the third-party data ecosystem and a centralized mechanism to exercise their privacy rights.

Under the proposed framework, the Federal Trade Commission would be mandated to establish and maintain a public, easily searchable registry of these data brokers.
The core of the SECURE Data Act closely mirrors the consumer rights established by the most robust state laws currently in effect. It grants Americans the fundamental right to access, correct, delete, and obtain a portable copy of their personal data from covered entities. Furthermore, it mandates that companies provide clear, accessible mechanisms for consumers to opt out of targeted advertising, the sale of their personal data to third parties, and certain automated profiling activities that produce legal or similarly significant effects on the consumer's life, such as housing or employment decisions.[1][2]
The legislation also imposes strict data minimization obligations on controllers—the businesses and organizations that determine exactly how and why consumer data is processed. Companies would be legally required to limit their data collection to what is adequate, relevant, and reasonably necessary for the specific purposes they have explicitly disclosed to the consumer. Using personal data for secondary, undisclosed purposes would no longer be permitted by default; companies would be required to obtain explicit, affirmative consumer consent before repurposing any collected information.[1][2]
When it comes to sensitive data—a category that includes health records, precise geolocation tracking, financial account information, and biometric identifiers—the SECURE Data Act shifts the regulatory burden from an opt-out model to a strict opt-in requirement. Companies cannot legally process or sell this highly sensitive information without first obtaining affirmative, documented consent from the user. This provision aligns the federal standard with the strictest state laws, ensuring that the most intimate details of a consumer's life cannot be monetized by default.[1]
Notably, the bill significantly expands federal privacy protections for minors by treating the personal data of teenagers aged 13 to 16 as inherently sensitive information. This effectively extends the verifiable parental consent requirements of the Children's Online Privacy Protection Act by three additional years. For social media platforms, digital advertisers, and online services targeting adolescents, this represents a massive operational shift, requiring them to build robust age-verification and parental-consent workflows for a demographic that was previously treated similarly to adults under federal law.[2]

The scope of the SECURE Data Act is carefully calibrated through specific applicability thresholds designed to target major data processors while shielding small businesses. It generally applies to businesses that process the personal data of more than 200,000 consumers annually and generate at least $25 million in gross revenue. Alternatively, it covers entities processing the data of at least 100,000 consumers if they derive 25 percent or more of their total revenue from data sales. Small businesses falling below these marks are entirely exempt, protecting startups and local shops from heavy compliance burdens.[1][2]
In a significant departure from current regulatory boundaries, the bill explicitly extends its privacy mandates to cover common carriers, such as broadband internet service providers and traditional telecommunications companies. Historically, these entities have fallen outside the standard jurisdiction of the Federal Trade Commission, creating a fragmented enforcement landscape for digital infrastructure. The SECURE Data Act closes this long-standing regulatory gap, subjecting internet service providers to the exact same data privacy, minimization, and consumer-rights obligations as major technology platforms, digital retailers, and data brokers, ensuring that the pipes carrying the data are regulated identically to the platforms collecting it.[1]
Enforcement of the SECURE Data Act would be a shared responsibility between the Federal Trade Commission and state Attorneys General, who are authorized to bring civil actions in federal court to enjoin violations and seek damages. Crucially for the business community, the bill explicitly excludes a private right of action. This means individual consumers cannot sue companies directly for privacy violations, a provision that materially lowers the class-action litigation risk for corporations when compared to aggressive state statutes that permit statutory damages for technical infractions.[2]

While the SECURE Data Act represents a mature, consensus-driven approach to federal privacy legislation, its path to becoming law remains highly complex. The fundamental debate over preemption—whether a federal standard should serve as a baseline floor or an absolute ceiling that overrides state-level protections—continues to be the primary ideological hurdle in Congress. Regardless of its immediate legislative success, the framework provides a clear, detailed blueprint of the compliance reality that American businesses must prepare for as the inevitable push for a unified national privacy standard accelerates.[4]
What to know
- The SECURE Data Act proposes a single federal privacy standard that would preempt all existing state-level privacy laws.
- The FTC would establish a public registry requiring data brokers to disclose their data sales and security practices annually.
- Consumers would gain standardized federal rights to access, correct, delete, and port their personal data.
- The bill treats data from teenagers aged 13 to 16 as sensitive, requiring verifiable parental consent for processing.
- Enforcement is limited to the FTC and state Attorneys General, with no private right of action for individual consumers.
- Small businesses are largely exempt, with thresholds targeting entities with over $25 million in revenue and 200,000 consumers.
Where opinion splits
Federal Standardization Advocates
The business case for a unified national privacy standard.
For corporate compliance teams and industry groups, the SECURE Data Act represents a necessary rescue from regulatory gridlock. Operating across state lines currently requires mapping data flows against more than 20 different legal frameworks, each with slight variations in definitions, opt-out mechanisms, and contracting requirements. Standardization advocates argue that this patchwork does not meaningfully improve consumer privacy; it merely drains resources into legal overhead. By establishing a federal ceiling, companies can build a single, robust privacy architecture that applies equally to a user in California and a user in Texas, ultimately making compliance more reliable and consumer rights easier to execute.
State Privacy Defenders
The argument against federal preemption acting as a regulatory ceiling.
State regulators and privacy advocates view the SECURE Data Act's broad preemption clause with deep skepticism. States like California have spent years iterating on their privacy frameworks, developing aggressive mechanisms like the Delete Request and Opt-out Platform (DROP) and strict data broker regulations. Defenders of the state-led model argue that federal preemption threatens to wipe out these hard-won protections, replacing them with a compromised federal standard that may be slower to adapt to emerging technologies like generative AI. From this perspective, federal law should act as a baseline floor that guarantees minimum rights, not a ceiling that prevents states from innovating on consumer protection.
Key terms
- National Preemption
- A legal doctrine where federal law overrides and invalidates state laws on the same subject, creating a single national standard.
- Data Broker
- Under the act, an entity that derives at least 50 percent of its revenue from selling the personal data of consumers who are not its direct customers.
- Controller
- A business or organization that determines the purpose and means of processing personal data.
- Private Right of Action
- A legal provision that allows individual consumers to file lawsuits directly against a company for violating the statute.
- Data Minimization
- The principle that a company should only collect and retain the minimum amount of personal data necessary to provide a specific product or service.
Unanswered questions
- It remains unclear if the bill can overcome partisan gridlock in Congress, particularly regarding the absolute preemption of stricter state laws.
- The exact operational mechanics of the FTC's proposed data broker registry have not yet been fully detailed.
- It is unknown how the federal preemption clause might interact with highly specific sectoral state laws, such as biometric privacy statutes.
Reader questions
What is the SECURE Data Act?
It is a proposed federal privacy law (H.R. 8413) that would establish a single national standard for consumer data rights, preempting existing state privacy laws.
How does the bill affect data brokers?
The legislation requires the FTC to create a public registry of data brokers. Brokers would have to register annually and disclose the categories of data they sell and any security incidents.
Does the SECURE Data Act allow consumers to sue companies?
No. The bill explicitly excludes a private right of action. Enforcement is handled exclusively by the FTC and state Attorneys General.
How does the bill protect children and teenagers?
It expands existing COPPA protections by treating the personal data of teenagers aged 13 to 16 as sensitive, requiring verifiable parental consent before that data can be processed.
Will small businesses have to comply?
Most small businesses are exempt. The law generally applies only to companies with over $25 million in revenue that process the data of more than 200,000 consumers.
Sources
[1]Consumer Finance MonitorConsumer Rights Advocates
U.S. House Committee releases SECURE Data Act to establish new federal privacy framework
Read on Consumer Finance Monitor →[2]DLA PiperConsumer Rights Advocates
U.S.: Comprehensive Federal Privacy Legislation Introduced
Read on DLA Piper →[3]Congress.gov
H.R.8413 - SECURE Data Act
Read on Congress.gov →[4]Factlen Editorial TeamState Privacy Defenders
Synthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
Every angle. Every day.
Get guides stories with full source coverage and perspective breakdowns delivered to your inbox.





