The SECURE Data Act

Up-to-date developments and updates of the SECURE Data Act

What Is the SECURE Data Act?

The SECURE Data Act (officially: the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act, H.R. 8413) is a federal bill introduced in the US House of Representatives on April 21, 2026. If passed, it will become the first comprehensive national privacy law in the United States.

The bill was introduced by Rep. John Joyce of Pennsylvania, along with eight co-sponsors, and was referred to the House Committee on Energy and Commerce and the Committee on the Judiciary.

What Does the SECURE Data Do?

At its core, the SECURE Data Act does four things:

  1. Gives Americans new rights over their personal data — including the right to access, correct, delete, and move it
  2. Imposes obligations on businesses that collect and process personal data
  3. Preempts state privacy laws — replacing California’s CCPA, Virginia’s CDPA, and ~20 other state laws with a single national standard
  4. Assigns enforcement to the Federal Trade Commission and state attorneys general

Who Does the SECURED Data Act Affect?

The bill applies to any company that:

  • Does business in the United States or handles data of US residents, AND
  • Processes data of 200,000+ consumers per year with $25M+ annual revenue, OR
  • Processes data of 100,000+ consumers per year and earns 25%+ of revenue from selling that data

Small businesses, nonprofits, universities, healthcare entities, and financial institutions have specific exemptions.

The Most Controversial Parts

State preemption is the single most debated provision. Section 15 of the bill wipes out all state privacy laws in one sentence. Privacy advocates say this weakens protections. Industry says it simplifies compliance. This battle will define whether the bill passes.

No private right of action — individuals cannot sue companies directly for violations. Only the FTC and state AGs can enforce. Democrats have pushed hard against this in previous bills.

Frequently Asked Questions

1. Is the SECURE Data Act law yet?
No. As of 2026, it is a bill that has been introduced in the House and referred to committee. It has not been voted on or signed into law.

2. Does the SECURE Data Act replace GDPR?
No. GDPR is a European Union regulation. The SECURE Data Act is a US federal bill. They are separate laws. If your company operates in both the US and EU, both would apply.

3. What states have privacy laws that would be preempted?
California (CCPA/CPRA), Virginia (CDPA), Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, Florida, Delaware, New Hampshire, New Jersey, Nebraska, Minnesota, Maryland, Kentucky, and others.

4. Does it cover employees’ data?
No. The definition of “consumer” specifically excludes individuals acting in an employment or commercial context.

This website is updated as the bill progresses through Congress.