SECURE Data Act Codes of Conduct — How to Get Safe Harbor Compliance Status

What Are Codes of Conduct?

The SECURE Data Act creates a formal pathway for industries to develop their own self-regulatory compliance frameworks — called codes of conduct — that, once approved by the Secretary of Commerce, provide companies with a rebuttable presumption of compliance with the Act.

This is the bill’s most significant business-friendly provision. Rather than requiring every company to independently interpret the law, industries can band together, create a compliance standard tailored to their sector, get it approved, and then certify to it.


How to Get a Code of Conduct Approved

Step 1: Submit an Application

One or more controllers or processors (or an industry group on their behalf) submit an application to the Secretary of Commerce. The application must include:

  • Which specific requirements of the Act the code addresses
  • How the code meets or exceeds those requirements
  • Which entities the code is designed to cover
  • A list of controllers/processors intending to comply
  • Description of the independent organization that will administer and enforce the code
  • How compliance will be assessed
  • How non-compliant companies will be referred to the FTC or state AGs

Step 2: Public Comment Period

Within 90 days of receiving the application, the Secretary must publish it for public comment.

Step 3: Approval Decision

Within 1 year of receiving the application, the Secretary must issue a public determination approving or denying it.

Step 4: Certification

Companies that participate in an approved code must certify on a publicly available website that they comply, including naming the independent organization administering the code.


Updating an Approved Code

If significant updates are made to an approved code:

  • The administering organization must submit an updated application
  • Another 90-day public comment period occurs
  • The Secretary has 180 days to approve or deny the update

Losing Approval — The Withdrawal Process

If the Secretary has clear and convincing evidence that an approved code no longer meets the Act’s requirements, the process is:

  1. Notice to the relevant companies and administering organization
  2. 180-day cure period — companies can propose a fix
  3. If the fix is accepted, approval is maintained
  4. If rejected, withdrawal takes effect 30 days after notification
  5. Withdrawal is published publicly

Small Business Codes

Within 2 years of enactment, the Secretary must publish codes of conduct specifically designed for smaller businesses that would otherwise be covered by the Act but fall below the applicability thresholds. These codes must be:

  • Consistent with the Act’s requirements
  • Cost-effective for participants
  • Appropriate to the size and risk profile of smaller companies
  • Voluntary

Global Cross-Border Privacy Rules (CBPR) System

A certification under the Global Cross-Border Privacy Rules System (or its successor) automatically qualifies as participation in an approved code of conduct. Companies already certified under CBPR get immediate safe harbor status.


Key Takeaways

  • Approved codes of conduct create a rebuttable presumption of compliance — a major safe harbor
  • Must be approved by Secretary of Commerce after public comment
  • Administered by an independent organization
  • Participants must publicly certify compliance
  • Approval can be withdrawn if the code falls below standards
  • Small business codes must be published within 2 years
  • CBPR certification = automatic safe harbor