What happens when 21 different states each enforce their own version of a privacy law? Businesses juggle conflicting rules, consumers face inconsistent protections, and compliance teams struggle to keep up. That is the reality of data privacy in the United States right now.
The SECURE Data Act, officially known as the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act, is a proposed federal bill introduced in the US House of Representatives in April 2026 under HR 8413. It aims to create a single, unified national privacy framework that would replace the growing patchwork of state privacy laws with one consistent standard.
This blog covers the core provisions of the SECURE Data Act, its impact on businesses, the consumer rights it introduces, and what compliance teams, legal professionals, and business leaders should be preparing for. Every claim in this piece is sourced from the bill text on Congress.gov, official government agency statements, and recognised legal analyses.
The SECURE Data Act is a comprehensive federal privacy bill designed to standardise consumer data protection across the United States.
Representative John Joyce (R-PA), Vice Chairman of the House Energy and Commerce Committee, introduced HR 8413 on 22 April 2026. The bill represents the most significant legislative attempt at comprehensive federal privacy regulation since COPPA passed in 1998. It was referred to committee and, as of mid-2026, has not yet been voted into law.
The full name of the legislation is the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act. It covers personal data processed by entities that fall under the jurisdiction of the Federal Trade Commission.
As of May 2026, 21 US states have enacted their own comprehensive privacy laws. Each one carries different definitions, consent thresholds, and enforcement mechanisms. Businesses operating across state lines must comply with every applicable state law simultaneously. The SECURE Data Act proposes to solve this by establishing a single federal ceiling that replaces all state-level consumer privacy statutes. For context on how existing frameworks compare, the differences between GDPR and CCPA illustrate the complexity that multiplies when dozens of standards coexist.
SECURE stands for Securing and Establishing Consumer Uniform Rights and Enforcement. The word “uniform” is central. The bill is built around the idea that consumer protections should not vary based on which state a person lives in. A resident of Texas should hold the same data rights as a resident of California.
The bill introduces several structural requirements that would reshape how organisations collect, process, and share personal data at a national level.
The SECURE Data Act would limit data collection to what is “adequate, relevant, and reasonably necessary in relation to each purpose for which the data is processed as disclosed to the consumer.” This is one of the most operationally significant provisions in the bill. Organisations would no longer be permitted to collect data speculatively or retain it beyond its stated purpose.
This requirement mirrors principles found in the GDPR and several US state laws but, if enacted, would apply uniformly across all 50 states.
Before processing personal data, controllers must provide a reasonably accessible, clear, and meaningful privacy notice. According to the bill text on Congress.gov, this notice must include each category of personal data processed, how a consumer may exercise their rights, including appeals, each category of personal data shared with other controllers or governmental entities, and the identity of those controllers or entities.
The bill mandates that covered entities implement and maintain reasonable data security practices. These must be proportionate to the volume and sensitivity of the personal data being processed. While the bill does not prescribe specific technical standards, it establishes a baseline obligation that the FTC can enforce.
The bill grants a defined set of privacy rights to all US consumers, creating a national baseline for user consent and data control.
Consumers would have the right to access the personal data a controller holds about them. They could also request corrections to inaccurate data or deletion of data that was provided by or obtained about them. Controllers must respond to these requests within defined timeframes and cannot charge unreasonable fees.
If data is available in a digital format, consumers can request a copy in a portable, readily usable format. This allows individuals to transmit their personal data to another controller without hindrance. The portability right applies to the extent that it is technically feasible for the controller.
The SECURE Data Act grants consumers the right to opt out of personal data processing for targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects. Understanding the distinction between opt-in and opt-out models becomes essential under this framework. Controllers also cannot discriminate against consumers who exercise these rights, such as by denying services or charging higher prices.
The bill creates specific protections for sensitive personal information and introduces expanded rules for data collected from minors.
Sensitive data under the SECURE Data Act includes categories such as racial or ethnic origin, health information, precise geolocation data, biometric data, and financial account information. Controllers must obtain affirmative opt-in consent before processing any sensitive data category. This is a higher threshold than what many current state laws require.
For children under 13, the SECURE Data Act defers to the existing COPPA consent framework for its sensitive data requirements. However, the rest of the bill still applies in parallel. This means data minimisation, privacy notices, and data security obligations all extend to data collected from children, even where COPPA already governs consent.
The bill extends verifiable parental consent requirements to teens aged 13 to under 16. This goes beyond COPPA, which currently covers only children under 13. Personal data collected from teens is classified as sensitive data under the SECURE Data Act, meaning controllers cannot process it without a parent or guardian providing verifiable consent first.
Data brokers face some of the most specific and structured obligations under this proposed legislation.
The bill defines a data broker as a controller that derives at least 50% of its annual revenue from selling personal data about individuals with whom it does not have a direct relationship. This is a narrower definition than some state laws use, but it captures the core commercial data brokerage industry.
Data brokers must register with the Federal Trade Commission within 12 months of enactment and renew annually. They must provide specified information, including categories of data sold and details about any reported security incidents. The FTC must then establish and maintain a publicly available, searchable registry of all registered data brokers within 18 months of enactment.
Each registered data broker must post a conspicuous online notice identifying itself as a data broker and explaining how consumers can exercise their rights. The FTC registry will include links to each broker’s privacy policy and rights-exercise mechanism. This transparency requirement supports broader efforts around Do Not Sell My Personal Information practices at the federal level.
One of the most debated aspects of the SECURE Data Act is its broad preemption clause, which would override existing state privacy laws.
Section 15 of the bill states that no state may “prescribe, maintain, or enforce any law, rule, regulation, requirement, standard, or other provision having the force and effect of law” that relates to the bill’s provisions. This is not a floor. It is a ceiling. States would not be permitted to set higher privacy standards than the federal law establishes.
As of mid-2026, 21 states will have comprehensive privacy legislation in effect. All of these would be superseded. The California Privacy Protection Agency released a formal letter opposing this preemption, arguing it would weaken protections currently available to 40 million Californians. For businesses tracking the key updates in CCPA, this federal shift could redefine the compliance baseline entirely.
If enacted, the SECURE Data Act would replace both the California Consumer Privacy Act and the California Privacy Rights Act. Consumers would no longer have access to tools like the Delete Request and Opt-out Platform (DROP), which currently allows Californians to submit a single request to all registered data brokers simultaneously.
For businesses currently complying with multiple state laws, the SECURE Data Act could simplify operations significantly. Instead of adapting policies and systems for each state, companies would align around a single set of requirements. However, until the bill passes, state laws remain fully enforceable. Dismantling existing compliance programmes prematurely would be a serious misstep.
The bill assigns enforcement authority exclusively to federal and state regulators, with no direct legal pathway for individual consumers.
The Federal Trade Commission and state attorneys general hold sole enforcement power under the SECURE Data Act. They can investigate potential violations, issue fines, and pursue legal action against non-compliant entities. This dual-layer enforcement model mirrors the approach taken in several existing state privacy laws.
Before launching an enforcement action, regulators must provide the entity with written notice of the alleged violation. The entity then has at least 45 days to remedy the issue. This cure period gives businesses a structured window to address compliance gaps before facing penalties. Critics argue this provision weakens enforcement by giving organisations room to delay accountability.
The SECURE Data Act does not include a private right of action. Consumers cannot file civil lawsuits against companies for violations. Enforcement relies entirely on the FTC and state attorneys general. Supporters of this approach argue it prevents frivolous litigation, while opponents say it limits the ability of individuals to seek redress for privacy harms.
Even though the SECURE Data Act has not yet passed, forward-thinking organisations can take steps now to reduce future compliance risk.
Start by mapping what personal data your organisation collects, where it is stored, who it is shared with, and for what purpose. The data minimisation requirement under the SECURE Data Act means you will need to justify every category of data you hold. Investing in a consent management platform can help centralise and automate this process.
If your organisation processes sensitive data, the SECURE Data Act would require affirmative opt-in consent. Review your existing consent flows to ensure they meet this higher threshold. Pay particular attention to data collected from teens aged 13 to 15, which would require verifiable parental consent under the bill.
Until a federal law is enacted, state privacy laws remain in full force. CCPA fines are real. CPRA enforcement is active. Maintaining compliance with current state requirements, such as honouring Global Privacy Control (GPC) signals, is essential. Building towards the federal standard now does not mean abandoning state obligations.
Understanding how the SECURE Data Act compares with other privacy laws helps compliance teams identify gaps and overlaps in their current programmes.
The SECURE Data Act follows a phased implementation approach, with different provisions taking effect at different intervals.
The bill would generally take effect two years after enactment. However, specific sections have their own timelines. Consumer privacy rights, data security requirements, and data broker provisions each carry separate effective dates. Data brokers must register with the FTC within 12 months of enactment, while the FTC must build the public registry within 18 months.
As of mid-2026, HR 8413 has been introduced and referred to the House Energy and Commerce Committee. It has not yet been voted on by the full House or the Senate. The bill text represents an opening position, and significant changes are likely as legislative negotiations continue. Bipartisan support will be necessary for the bill to advance.
The preemption clause, the absence of a private right of action, and the 45-day cure period are the most contentious elements. Any of these could be modified or removed during committee markup or floor amendments. Organisations should monitor the bill’s progress closely rather than assuming the current draft will become the final version.
The SECURE Data Act represents the most serious effort in years to establish a unified federal privacy standard for the United States. Whether it passes in its current form or undergoes significant amendments, the direction is clear. Federal data privacy regulation is moving forward. Businesses that start preparing now, by auditing data practices, strengthening consent mechanisms, and aligning with the bill’s core principles, will be in the strongest position regardless of the final legislative outcome.
Stay ahead of evolving federal and global privacy requirements. Seers helps your organisation manage consent, automate compliance, and build trust with your users through a single, scalable platform.
START FREE TODAYThe acronym stands for the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act. It was introduced as HR 8413 in the 119th Congress by Representative John Joyce on 22 April 2026. The bill aims to create a single federal framework for consumer data privacy, replacing the patchwork of state-level privacy laws currently in effect across the United States.
The Federal Trade Commission (FTC) and state attorneys general would share enforcement responsibility. The bill does not include a private right of action, so individual consumers would not be able to file lawsuits. Before taking enforcement action, regulators must issue a written notice and allow the entity at least 45 days to cure the alleged violation.
The bill classifies data from children under 13 and teens aged 13 to 15 as sensitive data. For under-13s, it defers to COPPA consent requirements. For teens aged 13 to 15, it requires verifiable parental consent before controllers can process their personal data. This extends privacy protections beyond what COPPA currently covers, adding three years to the age range.
The bill includes a broad federal preemption clause. Section 15 prohibits states from maintaining or enforcing any law that relates to the bill’s provisions. If enacted, it would supersede all 21 existing state privacy laws, including the CCPA and CPRA. States would not be permitted to impose higher standards than the federal baseline.
The PPCDA classifies all personal information belonging to individuals under 18 as sensitiveA Data Protection Officer oversees the organisation’s data protection strategy and ensures compliance with GDPR requirements. The DPO advises on data protection impact assessments, acts as a liaison with supervisory authorities, and monitors internal compliance. They must operate independently and report directly to senior management. Organisations that carry out large-scale systematic monitoring or process special category data are legally required to appoint one. information. This triggers higher consent standards, additional safeguards, and stricter obligations for organisations that collect or process children’s data. The Commissioner must also consider the best interests of children when exercising regulatory powers.
The bill requires data brokers, defined as entities earning at least 50% of revenue from selling data about non-customers, to register annually with the FTC. The Commission must create a publicly accessible, searchable registry within 18 months of enactment. The registry will include links to each broker’s privacy policy and consumer rights exercise mechanisms.
Controllers must obtain affirmative opt-in consent before processing any category of sensitive data. This includes health information, precise geolocation, biometric data, racial or ethnic origin, and financial account details. The consent threshold for sensitive data under this bill is higher than what many existing US state privacy laws require.
The bill requires that data collection be limited to what is adequate, relevant, and reasonably necessary for the stated purpose. Controllers cannot collect data speculatively or retain it beyond its disclosed use. This principle mirrors the data minimisation standards found in the GDPR and aims to reduce excessive or unnecessary personal data processing.
The SECURE Data Act grants consumers the right to opt out of personal data processing for targeted advertising, the sale of their data, and profiling that results in legally significant decisions. Controllers cannot penalise consumers for exercising this right by denying services, changing prices, or reducing quality. Loyalty programmes are exempt from this non-discrimination rule.
The bill would generally take effect two years after enactment. Specific sections, including consumer rights, data security, and data broker provisions, have their own separate timelines. Data brokers must register with the FTC within 12 months, and the public registry must be operational within 18 months. As of mid-2026, the bill has been referred to committee.
Both laws include data minimisation, consumer rights, and sensitive data protections. The key differences are in enforcement and scope. GDPR allows individuals to file complaints and seek compensation. The SECURE Data Act relies solely on the FTC and state attorneys general. GDPR applies to any entity processing EU residents’ data, while the SECURE Data Act is limited to FTC-regulated entities within the US.
Rimsha ZafarRimsha is a Senior Content Writer at Seers AI with over 5 years of experience in advanced technologies and AI-driven tools. Her expertise as a research analyst shapes clear, thoughtful insights into responsible data use, trust, and future-facing technologies.
Take our Free Cookie Audit and find out
Join 50,000+ websites using Seers.Ai to turn compliance into trust, insights, & measurable business growth.