SECURE Data Act Data Security Requirements — What Companies Must Implement
Data Security Under the SECURE Data Act
Section 4 establishes a baseline data security requirement for all controllers covered by the bill.
The Core Requirement
Every controller must establish, implement, and maintain reasonable data security practices that protect:
- The confidentiality of personal data
- The integrity of personal data
- The accessibility of personal data
Crucially, what counts as “reasonable” scales with the volume, sensitivity, and nature of the data you hold. A company holding biometric data on millions of users faces a higher bar than a small business with basic customer contact information.
The Safe Harbor — How to Get Presumed Compliant
The bill creates a rebuttable presumption of compliance — meaning you are presumed to meet the data security requirement if you can demonstrate one of the following:
Path 1: Follow an Approved Code of Conduct
Comply with a relevant industry code of conduct that has been approved by the Secretary of Commerce under Section 8 of this Act. (See our page on Codes of Conduct for details.)
Path 2: Meet Industry-Standard Security Frameworks
Establish, implement, and maintain:
- Data security practices appropriate to the state of the art — demonstrated by adherence to a widely accepted technical specification or through third-party attestation
- A comprehensive data security program that reasonably conforms to a relevant federal or widely accepted international risk management framework for identifying, protecting against, detecting, responding to, and recovering from data security events
Frameworks likely to qualify include:
- NIST Cybersecurity Framework (CSF)
- ISO/IEC 27001
- SOC 2 Type II
- FedRAMP (for government contractors)
What “Rebuttable Presumption” Means
If you follow an approved framework and face an enforcement action, the government bears the burden of proving your security was still unreasonable despite your framework compliance. This is significant protection — but it is not absolute immunity. If your implementation of the framework was superficial or negligent, the presumption can be rebutted.
Key Takeaways
- All covered controllers must implement reasonable data security measures
- “Reasonable” scales with the volume and sensitivity of your data
- Safe harbor is available through approved codes of conduct or recognized security frameworks
- Safe harbor is a presumption, not absolute immunity — actual implementation matters
Frequently Asked Questions
We already comply with SOC 2. Does that satisfy this requirement? SOC 2 Type II is likely to qualify as a widely accepted framework, though formal guidance from the Secretary of Commerce will ultimately determine which frameworks are recognized. Consult your legal counsel.
What happens if we have a data breach? The bill does not specify breach notification requirements — those are governed by existing state breach notification laws and sector-specific federal rules. However, a breach would be strong evidence in any enforcement action that your security practices were unreasonable.
Does this requirement apply to processors too? Yes, indirectly. Controllers are responsible for ensuring their processors meet the data security standard through contractual requirements (see Section 6).