U.S. House Introduces SECURE Data Act, Proposing Comprehensive Federal Privacy Law to Preempt State Patchwork
The proposed legislation aims to replace a fragmented patchwork of state regulations with a unified national standard, granting Americans sweeping new rights over their personal data and AI training consent.
- Federal Standardization Advocates
- Argue that a single national privacy law is essential to reduce compliance costs and provide regulatory certainty for businesses.
- State Privacy Defenders
- Fear that federal preemption will override stronger state-level protections, effectively lowering the privacy ceiling for millions of Americans.
- Consumer Rights Proponents
- Support the bill's data minimization and private right of action, viewing it as a massive upgrade for residents of states with no current privacy laws.
Perspectives this story doesn't cover
- Small app developers concerned about the technical overhead of compliance
- Data brokers whose entire business model relies on the secondary sale of information
At a glance
- The SECURE Data Act aims to create a single federal privacy standard, overriding 18 existing state laws.
- Consumers gain the right to access, correct, export, and delete their personal data.
- The bill mandates 'data minimization,' restricting collection to what is strictly necessary for a service.
- Companies must obtain explicit opt-in consent to use personal data for AI training.
- A compromised 'Private Right of Action' allows citizens to sue companies after a 45-day grace period to fix the issue.
- Small businesses under $25 million in revenue are largely exempt from the heaviest reporting burdens.
Why it matters now
For years, Americans' digital privacy has depended entirely on their zip code. If passed, this law would give every U.S. resident the right to view, delete, and restrict the sale of their personal data, while forcing tech companies to fundamentally redesign how they collect information.
After years of stalled negotiations and fragmented state-level regulations, a bipartisan coalition in the U.S. House of Representatives has introduced the SECURE Data Act. The sweeping legislation represents the most viable attempt yet to establish a comprehensive federal privacy framework in the United States, aiming to fundamentally rewrite the rules of the digital economy.[1]
Currently, digital privacy in America is dictated by a complex patchwork of 18 different state laws, led by California's stringent CCPA. The SECURE Data Act proposes to wipe the slate clean through "preemption"—replacing this state-by-state maze with a single, unified national standard that applies equally from Maine to Hawaii.
For the average consumer, the bill introduces a suite of empowering new rights. Under the proposed framework, all Americans would gain the legal right to access the data companies hold on them, correct inaccuracies, export their profiles to competing services, and demand outright deletion. Companies would have 30 days to comply with these consumer requests.[1]
The legislation pivots away from the widely criticized "notice and consent" model—the system responsible for the endless barrage of cookie banners that users blindly click through. Instead, it mandates "data minimization." This legal principle dictates that companies can only collect the specific data strictly necessary to provide the service the user requested, regardless of what a terms-of-service agreement says.
If a user downloads a flashlight app, for example, the app developer would be legally barred from collecting location data or contact lists, because those data points are not required to operate a flashlight. Privacy advocates have long championed data minimization as the only effective way to curb mass surveillance advertising.
The SECURE Data Act also directly addresses the modern artificial intelligence boom. A dedicated provision requires explicit, opt-in consent before a company can use a consumer's personal data to train generative AI models. This clause aims to curb the aggressive data-scraping practices that have fueled the rapid development of large language models over the past three years.
The SECURE Data Act also directly addresses the modern artificial intelligence boom.
To avoid crushing small businesses, the bill establishes a tiered compliance structure. Companies with less than $25 million in annual revenue and fewer than 50,000 user records are largely exempt from the most burdensome reporting requirements. Conversely, "large data holders" and third-party data brokers face stringent annual algorithmic impact assessments and mandatory executive certifications.[2]
The most fiercely debated mechanism in the bill is preemption. The tech industry has heavily lobbied for this clause, arguing that complying with 18 different state laws costs billions in redundant legal engineering and creates a fractured internet experience for users. A single federal standard, they argue, provides the regulatory certainty needed to build compliant global products.[2]
However, preemption is a double-edged sword. By overriding state laws, the SECURE Data Act would nullify California's existing privacy framework. California regulators and several consumer protection groups argue that the federal bill, while strong, waters down specific protections Californians already enjoy, effectively lowering the ceiling of privacy rights to raise the national floor.[3]
The second major flashpoint is the "Private Right of Action" (PRA). This legal mechanism determines who can actually sue when the law is broken. The SECURE Data Act includes a compromised PRA, allowing individual citizens to sue companies for specific privacy violations, rather than relying solely on government regulators to enforce the rules.[1]
To appease business groups terrified of frivolous class-action lawsuits, the bill's PRA includes a "right to cure" provision. Before a lawsuit can be filed, a consumer must notify the company of the violation and give them 45 days to fix the issue. If the company deletes the data or stops the unauthorized sharing within that window, the lawsuit cannot proceed.[2]
On the regulatory side, the bill would dramatically expand the Federal Trade Commission (FTC). It mandates the creation of a new dedicated privacy bureau within the agency, armed with expanded rulemaking authority and a proposed budget increase to hire technologists, auditors, and enforcement attorneys capable of policing Silicon Valley.[1]
If passed, the legislation would bring the United States closer to alignment with the European Union's General Data Protection Regulation (GDPR). This harmonization is highly anticipated by multinational corporations, as it would smooth international data flows and reduce the friction of operating across the Atlantic.
The bill now heads to committee markups, where the specific language around preemption and the private right of action will face intense scrutiny. While bipartisan introduction is a significant milestone, the legislation must navigate a deeply divided Congress and a ticking clock ahead of the midterm election cycle.[1][3]
Terms to know
- Preemption
- A legal doctrine where a higher level of government (federal) overrides laws passed by a lower level (state), creating a single unified rule.
- Data Minimization
- The principle that an organization should only collect the absolute minimum amount of personal data required to deliver a specific product or service.
- Private Right of Action (PRA)
- A provision in a law that allows everyday citizens to file lawsuits directly against companies for violations, rather than relying on government agencies to enforce the rules.
- Right to Cure
- A legal grace period allowing a company to fix a privacy violation after being notified, preventing a lawsuit if the issue is resolved within the timeframe.
Sources
[1]ReutersFederal Standardization AdvocatesU.S. lawmakers unveil bipartisan SECURE Data Act to unify privacy rules
Read on Reuters →
[2]The Wall Street JournalFederal Standardization AdvocatesTech Industry Backs New Federal Privacy Push to Override State Laws
Read on The Wall Street Journal →
[3]The Washington PostState Privacy DefendersCalifornia regulators push back against federal privacy preemption
Read on The Washington Post →
Comments
More in Technology
See all →Spectrum Regulation
Why Bluetooth Jammers Are Illegal: The Mechanics of 2.4 GHz Interference
4 sources
Lithography Physics
The Rayleigh Criterion: How Wavelength and Numerical Aperture Actually Constrain Chip Scaling
8 sources
Smart TV Privacy
LG Smart TVs Caught Logging Audio and Scanning Local Networks in Standby
4 sources
LMR Battery Tech
LG Energy Solution and Seoul National University Resolve Gas Buildup in Cobalt-Free LMR Batteries
5 sources
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.




