SECURE Data Act Codes of Conduct — How to Get Safe Harbor Compliance Status
What Are Codes of Conduct?
The SECURE Data Act creates a formal pathway for industries to develop their own self-regulatory compliance frameworks — called codes of conduct — that, once approved by the Secretary of Commerce, provide companies with a rebuttable presumption of compliance with the Act.
This is the bill’s most significant business-friendly provision. Rather than requiring every company to independently interpret the law, industries can band together, create a compliance standard tailored to their sector, get it approved, and then certify to it.
How to Get a Code of Conduct Approved
Step 1: Submit an Application
One or more controllers or processors (or an industry group on their behalf) submit an application to the Secretary of Commerce. The application must include:
- Which specific requirements of the Act the code addresses
- How the code meets or exceeds those requirements
- Which entities the code is designed to cover
- A list of controllers/processors intending to comply
- Description of the independent organization that will administer and enforce the code
- How compliance will be assessed
- How non-compliant companies will be referred to the FTC or state AGs
Step 2: Public Comment Period
Within 90 days of receiving the application, the Secretary must publish it for public comment.
Step 3: Approval Decision
Within 1 year of receiving the application, the Secretary must issue a public determination approving or denying it.
Step 4: Certification
Companies that participate in an approved code must certify on a publicly available website that they comply, including naming the independent organization administering the code.
Updating an Approved Code
If significant updates are made to an approved code:
- The administering organization must submit an updated application
- Another 90-day public comment period occurs
- The Secretary has 180 days to approve or deny the update
Losing Approval — The Withdrawal Process
If the Secretary has clear and convincing evidence that an approved code no longer meets the Act’s requirements, the process is:
- Notice to the relevant companies and administering organization
- 180-day cure period — companies can propose a fix
- If the fix is accepted, approval is maintained
- If rejected, withdrawal takes effect 30 days after notification
- Withdrawal is published publicly
Small Business Codes
Within 2 years of enactment, the Secretary must publish codes of conduct specifically designed for smaller businesses that would otherwise be covered by the Act but fall below the applicability thresholds. These codes must be:
- Consistent with the Act’s requirements
- Cost-effective for participants
- Appropriate to the size and risk profile of smaller companies
- Voluntary
Global Cross-Border Privacy Rules (CBPR) System
A certification under the Global Cross-Border Privacy Rules System (or its successor) automatically qualifies as participation in an approved code of conduct. Companies already certified under CBPR get immediate safe harbor status.
Key Takeaways
- Approved codes of conduct create a rebuttable presumption of compliance — a major safe harbor
- Must be approved by Secretary of Commerce after public comment
- Administered by an independent organization
- Participants must publicly certify compliance
- Approval can be withdrawn if the code falls below standards
- Small business codes must be published within 2 years
- CBPR certification = automatic safe harbor