How the SECURE Data Act Relates to GDPR, CCPA, HIPAA, COPPA & Other Laws

The SECURE Data Act in the Legal Landscape

The SECURE Data Act doesn’t operate in a vacuum. The US already has a complex patchwork of sector-specific federal privacy laws. Section 14 clarifies how the SECURE Data Act interacts with them.


Laws the SECURE Data Act Does NOT Override

The following federal laws remain fully in force and are not displaced by the SECURE Data Act:

LawWhat It CoversRelationship
COPPA (Children’s Online Privacy Protection Act)Data of children under 13Preserved in full
HIPAAProtected health informationPreserved; health data is also exempt from SECURE Data Act
Gramm-Leach-Bliley Act (Title V)Financial institution dataPreserved; financial institutions are exempt
HITECH ActHealth data breach notificationPreserved
HIPAA regulationsHealth privacy rulesPreserved
42 CFR Part 2Substance use disorder recordsPreserved
Fair Credit Reporting Act (FCRA)Credit reporting dataPreserved; credit data is also exempt
FERPAStudent education recordsPreserved; education data is also exempt
IRB regulations (45 CFR Part 46)Human subjects researchPreserved
Health Care Quality Improvement ActMedical peer reviewPreserved
Patient safety work product rulesMedical error reportingPreserved
Federal wiretapping laws (18 USC Ch. 123)Electronic surveillancePreserved

The Video Privacy Protection Act — Repealed

One existing law is explicitly repealed by the SECURE Data Act:

18 U.S.C. §2710 — the Video Privacy Protection Act (VPPA) — is repealed. The VPPA was a 1988 law that protected rental records of video tapes (passed after a reporter obtained Supreme Court nominee Robert Bork’s video rental history). In recent years it has been used aggressively to sue streaming services and websites that share viewing data with advertisers via tracking pixels. Repealing it removes a significant source of private litigation against tech companies.


The Communications Act — Largely Displaced

The FCC’s authority under the Communications Act of 1934 is largely displaced for telecoms regarding the collection, use, processing, transfer, or security of personal data. The exception: FCC authority related to emergency services is preserved.


How It Relates to GDPR

The SECURE Data Act and GDPR are separate legal regimes. The SECURE Data Act does not preempt or replace GDPR for companies with EU operations. Key differences:

AspectSECURE Data ActGDPR
Private right of actionNoYes (in most EU member states)
Legitimate interest basisNot explicitly includedYes
Data Protection OfficerNot requiredRequired for certain controllers
Breach notificationNot specified72 hours to supervisory authority
FinesFTC Act penaltiesUp to 4% of global annual revenue
Threshold200k consumers OR $25M revenueApplies to most businesses
Right to erasureYesYes
Data portabilityYesYes

How It Compares to California’s CCPA/CPRA

AspectSECURE Data ActCCPA/CPRA
Private right of actionNoYes (for data breaches)
Opt-out of targeted adsYesYes
Opt-out of data saleYesYes
Sensitive data consentYesYes
EnforcementFTC + state AGs onlyCA AG + CA Privacy Protection Agency + private suits
Would be preempted?—Yes, under Section 15

Key Takeaways

  • Major sector-specific federal laws (HIPAA, FCRA, COPPA, FERPA, GLB) are all preserved
  • The Video Privacy Protection Act is repealed — removing a major source of tech company litigation
  • GDPR is a completely separate regime — companies with EU operations must still comply
  • CCPA/CPRA would be preempted by Section 15, making this comparison largely academic if the bill passes