What Is a Controller?

Under the SECURE Data Act, a controller is any person or company that determines the purpose and means of processing personal data. In plain English: if your business decides what data to collect and why, you are a controller.

This is the broadest category of covered entity under the bill. Most businesses that collect customer data will be controllers.


Controller Obligations at a Glance

1. Data Minimization

You may only collect data that is adequate, relevant, and reasonably necessary for the specific purpose you disclosed to the consumer. Collecting data “just in case it might be useful later” is not permitted.

2. Purpose Limitation

You cannot use personal data for a purpose that is not reasonably related to what you told the consumer when you collected it — unless you go back and get their consent first.

Example: If you collected an email address to process an order, you cannot later use it for unrelated marketing without consent.

3. Civil Rights Compliance

You cannot process personal data in violation of any federal anti-discrimination law. Data processing that results in unlawful discrimination against consumers is prohibited.

4. Non-Discrimination

You cannot punish consumers for exercising their privacy rights. Prohibited retaliation includes:

  • Denying goods or services
  • Charging different prices
  • Providing lower quality service

The loyalty program exception: You can offer discounts, rewards, or premium features in exchange for voluntary data sharing — as long as participation is genuinely optional and the program is legitimate.

5. Consumer Rights Cannot Be Waived by Contract

Any clause in a terms of service, privacy policy, or user agreement that attempts to waive or limit a consumer’s rights under this Act is void and unenforceable from the moment the law takes effect. You cannot contract around these rights.


The Privacy Notice Requirement

Before processing any consumer’s personal data, you must provide a clear, meaningful, and reasonably accessible privacy notice that includes:

  1. Every category of personal data you process
  2. Every purpose for which you process it
  3. How consumers can exercise their rights — including how to appeal a denial
  4. Every category of data you share with other controllers or government entities
  5. Which other controllers or government entities you share data with
  6. Whether any data is transferred to, stored in, or sold to a covered nation (adversary states such as China, Russia, Iran, North Korea)

Targeted Advertising Disclosure

If you use consumer data for targeted advertising, you must clearly and conspicuously disclose this before collecting or using the data — and explain how consumers can opt out.

Data Sale Disclosure

If you sell consumer data, you must disclose this before any collection or sale occurs — and explain the opt-out mechanism.


Automated Decision-Making Disclosure

If your system uses automated profiling to make decisions that have a legal or similarly significant effect on a consumer (denying them housing, healthcare, or employment) — and no human reviews that decision — you must:

  1. Tell the consumer before the decision is made that it will be made by automated means
  2. Explain how they can opt out of being subject to that profiling

Key Takeaways

  • Only collect data you actually need for a disclosed purpose
  • Cannot use data for undisclosed purposes without new consent
  • Cannot discriminate against users who exercise privacy rights
  • Privacy notice must be comprehensive and visible before data collection
  • Contracts cannot strip consumers of their statutory rights
  • Automated decisions affecting housing, health, or employment require disclosure and an opt-out

Frequently Asked Questions

My business already has a privacy policy. Does that satisfy the notice requirement? Possibly not. The SECURE Data Act requires specific disclosures — including whether data flows to covered nations — that most existing privacy policies don’t cover. Your legal counsel should review your current policy against the bill’s requirements.

We use third-party analytics tools. Are we a controller for that data? Yes. If you’ve chosen to deploy those tools and thereby determined that data will be collected, you are the controller. Your analytics vendor is likely a processor.

What is a “covered nation”? The bill uses the definition from 10 U.S.C. §4872(f), which includes China, Russia, Iran, and North Korea. Any data flows to entities in those countries must be disclosed in your privacy notice.