The legislative battle over a uniform U.S. data privacy standard officially kicked off on June 3, 2026. The House Subcommittee on Commerce, Manufacturing, and Trade held its first public hearing for the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act (SECURE Data Act).
Introduced in April by U.S. Rep. John Joyce (R-PA), the Republican-drafted bill faces a steep uphill climb. Unlike its predecessors (APRA and ADPPA), the SECURE Data Act currently lacks bipartisan support and does not have a companion bill in the Senate.
Here is a breakdown of the key takeaways from the hearing and what it means for the privacy landscape.
1. The Pro-Business Argument: Overcoming the 22-State Patchwork
Supporters of the bill argue that a single national standard is desperately needed to replace the rapidly growing “patchwork” of state-level privacy regulations.
- The Compliance Burden: With 22 states having passed their own consumer privacy laws, and over 30 separate amendments already complicating those frameworks, compliance has become a moving target.
- Small Business Strain: Organizations like the Kentucky Chamber of Commerce testified that small businesses lack the massive compliance budgets and in-house legal teams required to track 50 different state laws, making a uniform federal standard a matter of economic competitiveness.
- A Uniform Ceiling: The bill features strong preemption language that would override existing state laws, giving businesses regulatory certainty.
2. What’s Inside (and Missing From) the Draft
The SECURE Data Act introduces a few novel concepts but drops several mechanisms found in previous privacy drafts:
- What it includes: A centralized data broker registration managed by the FTC; a “safe harbor” program for companies following a Department of Commerce-approved code of conduct; and strict protections treating data from children under 13 as sensitive.
- What it lacks: The current draft does not include a Private Right of Action (allowing citizens to sue companies directly), nor does it require Data Protection Impact Assessments (DPIAs), Data Protection Officers (DPOs), or universal opt-out mechanisms.
3. The Backlash: “Weaker Than the Weakest State Law”
The bill drew fierce opposition from Democrats, the Electronic Privacy Information Center (EPIC), and state regulators.
- The Notice-and-Consent Loophole: Critics argue the bill perpetuates a broken status quo of “notice and choice,” rather than enforcing strict data minimization (limiting what companies can collect in the first place).
- Enforcement Gaps: EPIC argued that without a private right of action, the bill is functionally unenforceable, as the FTC and state Attorneys General do not have the resources to litigate individual consumer complaints.
- Eviscerating State Rights: A coalition of 18 state Attorneys General and the California Privacy Protection Agency (CPPA) formally opposed the bill. They argue that the sweeping federal preemption would strip away stronger, existing privacy protections that millions of citizens already rely on—especially concerning biometric and health data.
Looking Ahead
While House Democrats soundly criticized the partisan nature of the draft, leadership expressed hope that a compromise could eventually be reached by borrowing elements from past bipartisan frameworks. As AI supercharges the corporate incentive to harvest personal data, the pressure on Congress to find a middle ground has never been higher.
Watch the full hearing on YouTube here.
Leave a Reply