Federal PrivacyPolicy ExplainerJul 15, 2026, 3:32 PM· 4 min read· #3 of 3 in technology

U.S. House Introduces SECURE Data Act, Proposing Comprehensive Federal Privacy Law to Preempt State Patchwork

The proposed legislation aims to replace a fragmented patchwork of state regulations with a unified national standard, granting Americans sweeping new rights over their personal data and AI training consent.

By Factlen Editorial Team

Federal Standardization Advocates 40%State Privacy Defenders 30%Consumer Rights Proponents 30%
Federal Standardization Advocates
Argue that a single national privacy law is essential to reduce compliance costs and provide regulatory certainty for businesses.
State Privacy Defenders
Fear that federal preemption will override stronger state-level protections, effectively lowering the privacy ceiling for millions of Americans.
Consumer Rights Proponents
Support the bill's data minimization and private right of action, viewing it as a massive upgrade for residents of states with no current privacy laws.

What's not represented

  • · Small app developers concerned about the technical overhead of compliance
  • · Data brokers whose entire business model relies on the secondary sale of information

Why this matters

For years, Americans' digital privacy has depended entirely on their zip code. If passed, this law would give every U.S. resident the right to view, delete, and restrict the sale of their personal data, while forcing tech companies to fundamentally redesign how they collect information.

Key points

  • The SECURE Data Act aims to create a single federal privacy standard, overriding 18 existing state laws.
  • Consumers gain the right to access, correct, export, and delete their personal data.
  • The bill mandates 'data minimization,' restricting collection to what is strictly necessary for a service.
  • Companies must obtain explicit opt-in consent to use personal data for AI training.
  • A compromised 'Private Right of Action' allows citizens to sue companies after a 45-day grace period to fix the issue.
  • Small businesses under $25 million in revenue are largely exempt from the heaviest reporting burdens.
18
States with existing privacy laws
30 days
Deadline to honor deletion requests
$25M
Revenue threshold for strict compliance
45 days
Right to cure period before lawsuits

After years of stalled negotiations and fragmented state-level regulations, a bipartisan coalition in the U.S. House of Representatives has introduced the SECURE Data Act. The sweeping legislation represents the most viable attempt yet to establish a comprehensive federal privacy framework in the United States, aiming to fundamentally rewrite the rules of the digital economy.[1]

Currently, digital privacy in America is dictated by a complex patchwork of 18 different state laws, led by California's stringent CCPA. The SECURE Data Act proposes to wipe the slate clean through "preemption"—replacing this state-by-state maze with a single, unified national standard that applies equally from Maine to Hawaii.

The legislation would replace the current patchwork of 18 state laws with a single national standard.
The legislation would replace the current patchwork of 18 state laws with a single national standard.

For the average consumer, the bill introduces a suite of empowering new rights. Under the proposed framework, all Americans would gain the legal right to access the data companies hold on them, correct inaccuracies, export their profiles to competing services, and demand outright deletion. Companies would have 30 days to comply with these consumer requests.[1]

The legislation pivots away from the widely criticized "notice and consent" model—the system responsible for the endless barrage of cookie banners that users blindly click through. Instead, it mandates "data minimization." This legal principle dictates that companies can only collect the specific data strictly necessary to provide the service the user requested, regardless of what a terms-of-service agreement says.

If a user downloads a flashlight app, for example, the app developer would be legally barred from collecting location data or contact lists, because those data points are not required to operate a flashlight. Privacy advocates have long championed data minimization as the only effective way to curb mass surveillance advertising.

The SECURE Data Act also directly addresses the modern artificial intelligence boom. A dedicated provision requires explicit, opt-in consent before a company can use a consumer's personal data to train generative AI models. This clause aims to curb the aggressive data-scraping practices that have fueled the rapid development of large language models over the past three years.

Core consumer rights established under the proposed SECURE Data Act.
Core consumer rights established under the proposed SECURE Data Act.
The SECURE Data Act also directly addresses the modern artificial intelligence boom.

To avoid crushing small businesses, the bill establishes a tiered compliance structure. Companies with less than $25 million in annual revenue and fewer than 50,000 user records are largely exempt from the most burdensome reporting requirements. Conversely, "large data holders" and third-party data brokers face stringent annual algorithmic impact assessments and mandatory executive certifications.[2]

The most fiercely debated mechanism in the bill is preemption. The tech industry has heavily lobbied for this clause, arguing that complying with 18 different state laws costs billions in redundant legal engineering and creates a fractured internet experience for users. A single federal standard, they argue, provides the regulatory certainty needed to build compliant global products.[2]

However, preemption is a double-edged sword. By overriding state laws, the SECURE Data Act would nullify California's existing privacy framework. California regulators and several consumer protection groups argue that the federal bill, while strong, waters down specific protections Californians already enjoy, effectively lowering the ceiling of privacy rights to raise the national floor.[3]

The second major flashpoint is the "Private Right of Action" (PRA). This legal mechanism determines who can actually sue when the law is broken. The SECURE Data Act includes a compromised PRA, allowing individual citizens to sue companies for specific privacy violations, rather than relying solely on government regulators to enforce the rules.[1]

To appease business groups terrified of frivolous class-action lawsuits, the bill's PRA includes a "right to cure" provision. Before a lawsuit can be filed, a consumer must notify the company of the violation and give them 45 days to fix the issue. If the company deletes the data or stops the unauthorized sharing within that window, the lawsuit cannot proceed.[2]

Under the new law, companies would have 30 days to locate and delete a user's data upon request.
Under the new law, companies would have 30 days to locate and delete a user's data upon request.

On the regulatory side, the bill would dramatically expand the Federal Trade Commission (FTC). It mandates the creation of a new dedicated privacy bureau within the agency, armed with expanded rulemaking authority and a proposed budget increase to hire technologists, auditors, and enforcement attorneys capable of policing Silicon Valley.[1]

If passed, the legislation would bring the United States closer to alignment with the European Union's General Data Protection Regulation (GDPR). This harmonization is highly anticipated by multinational corporations, as it would smooth international data flows and reduce the friction of operating across the Atlantic.

The bill now heads to committee markups, where the specific language around preemption and the private right of action will face intense scrutiny. While bipartisan introduction is a significant milestone, the legislation must navigate a deeply divided Congress and a ticking clock ahead of the midterm election cycle.[1][3]

How we got here

  1. 2018

    California passes the CCPA, kicking off a wave of state-level privacy legislation.

  2. 2022

    The ADPPA federal privacy bill advances out of committee but fails to reach a floor vote over preemption disputes.

  3. 2024

    The number of states with comprehensive privacy laws reaches 18, increasing compliance complexity for tech firms.

  4. July 2026

    Bipartisan lawmakers introduce the SECURE Data Act to establish a unified national standard.

Viewpoints in depth

Federal Standardization Advocates

Tech companies and business groups argue that a single national rule is necessary for the modern digital economy.

For multinational corporations and tech startups alike, the current landscape of 18 different state privacy laws is a logistical nightmare. Industry groups argue that engineering separate compliance pipelines for users in Colorado versus Virginia drains resources that could be spent on innovation. They view federal preemption not as an escape from regulation, but as a necessary harmonization that allows them to build a single, secure data architecture for all American users.

State Privacy Defenders

Regulators in states with strong existing laws fear the federal bill will erode their citizens' rights.

California regulators and privacy purists view federal preemption as a Trojan horse. They argue that states have historically served as the 'laboratories of democracy,' pioneering aggressive privacy protections while Congress stalled. By establishing a federal ceiling, they fear the SECURE Data Act will wipe out specialized state-level protections—such as California's specific rules on automated decision-making—and prevent states from rapidly passing new laws to address future technological threats.

Consumer Rights Proponents

Advocacy groups celebrate the shift toward data minimization and the inclusion of a private right of action.

For consumer advocates, the bill's move away from 'notice and consent' is a monumental victory. They have long argued that expecting users to read 50-page privacy policies is a broken model. By mandating data minimization, the burden shifts from the consumer to the company. Furthermore, they view the Private Right of Action as the only true enforcement mechanism, arguing that the FTC, even with expanded funding, cannot possibly police every data violation in the country without the help of citizen lawsuits.

What we don't know

  • Whether the bill can survive the intense lobbying efforts from California lawmakers determined to protect their state's existing laws.
  • How strictly the FTC will interpret 'data minimization' in borderline cases, such as personalized content algorithms.
  • If the 45-day 'right to cure' period will effectively prevent frivolous lawsuits or simply create a loophole for serial privacy violators.

Key terms

Preemption
A legal doctrine where a higher level of government (federal) overrides laws passed by a lower level (state), creating a single unified rule.
Data Minimization
The principle that an organization should only collect the absolute minimum amount of personal data required to deliver a specific product or service.
Private Right of Action (PRA)
A provision in a law that allows everyday citizens to file lawsuits directly against companies for violations, rather than relying on government agencies to enforce the rules.
Right to Cure
A legal grace period allowing a company to fix a privacy violation after being notified, preventing a lawsuit if the issue is resolved within the timeframe.

Frequently asked

Will this law ban targeted advertising?

No, but it shifts the model. Instead of relying on confusing cookie banners, the law enforces 'data minimization,' meaning companies can only collect data strictly necessary for the service, severely limiting the broad data collection that fuels targeted ads.

Can I sue a company if they misuse my data?

Yes, the bill includes a 'Private Right of Action.' However, you must first notify the company and give them 45 days to fix the violation before a lawsuit can proceed.

How does this affect AI companies?

The bill requires explicit, opt-in consent from consumers before their personal data can be used to train generative AI models.

Does this apply to small businesses?

Mostly no. The bill exempts companies with less than $25 million in annual revenue and fewer than 50,000 user records from the most burdensome requirements.

Sources

Source coverage

3 outlets

3 viewpoints surfaced

Federal Standardization Advocates 40%State Privacy Defenders 30%Consumer Rights Proponents 30%
  1. [1]ReutersFederal Standardization Advocates

    U.S. lawmakers unveil bipartisan SECURE Data Act to unify privacy rules

    Read on Reuters
  2. [2]The Wall Street JournalFederal Standardization Advocates

    Tech Industry Backs New Federal Privacy Push to Override State Laws

    Read on The Wall Street Journal
  3. [3]The Washington PostState Privacy Defenders

    California regulators push back against federal privacy preemption

    Read on The Washington Post
Stay informed

Every angle. Every day.

Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.