How the SECURE Data Act Relates to GDPR, CCPA, HIPAA, COPPA & Other Laws
The SECURE Data Act in the Legal Landscape
The SECURE Data Act doesn’t operate in a vacuum. The US already has a complex patchwork of sector-specific federal privacy laws. Section 14 clarifies how the SECURE Data Act interacts with them.
Laws the SECURE Data Act Does NOT Override
The following federal laws remain fully in force and are not displaced by the SECURE Data Act:
| Law | What It Covers | Relationship |
|---|---|---|
| COPPA (Children’s Online Privacy Protection Act) | Data of children under 13 | Preserved in full |
| HIPAA | Protected health information | Preserved; health data is also exempt from SECURE Data Act |
| Gramm-Leach-Bliley Act (Title V) | Financial institution data | Preserved; financial institutions are exempt |
| HITECH Act | Health data breach notification | Preserved |
| HIPAA regulations | Health privacy rules | Preserved |
| 42 CFR Part 2 | Substance use disorder records | Preserved |
| Fair Credit Reporting Act (FCRA) | Credit reporting data | Preserved; credit data is also exempt |
| FERPA | Student education records | Preserved; education data is also exempt |
| IRB regulations (45 CFR Part 46) | Human subjects research | Preserved |
| Health Care Quality Improvement Act | Medical peer review | Preserved |
| Patient safety work product rules | Medical error reporting | Preserved |
| Federal wiretapping laws (18 USC Ch. 123) | Electronic surveillance | Preserved |
The Video Privacy Protection Act — Repealed
One existing law is explicitly repealed by the SECURE Data Act:
18 U.S.C. §2710 — the Video Privacy Protection Act (VPPA) — is repealed. The VPPA was a 1988 law that protected rental records of video tapes (passed after a reporter obtained Supreme Court nominee Robert Bork’s video rental history). In recent years it has been used aggressively to sue streaming services and websites that share viewing data with advertisers via tracking pixels. Repealing it removes a significant source of private litigation against tech companies.
The Communications Act — Largely Displaced
The FCC’s authority under the Communications Act of 1934 is largely displaced for telecoms regarding the collection, use, processing, transfer, or security of personal data. The exception: FCC authority related to emergency services is preserved.
How It Relates to GDPR
The SECURE Data Act and GDPR are separate legal regimes. The SECURE Data Act does not preempt or replace GDPR for companies with EU operations. Key differences:
| Aspect | SECURE Data Act | GDPR |
|---|---|---|
| Private right of action | No | Yes (in most EU member states) |
| Legitimate interest basis | Not explicitly included | Yes |
| Data Protection Officer | Not required | Required for certain controllers |
| Breach notification | Not specified | 72 hours to supervisory authority |
| Fines | FTC Act penalties | Up to 4% of global annual revenue |
| Threshold | 200k consumers OR $25M revenue | Applies to most businesses |
| Right to erasure | Yes | Yes |
| Data portability | Yes | Yes |
How It Compares to California’s CCPA/CPRA
| Aspect | SECURE Data Act | CCPA/CPRA |
|---|---|---|
| Private right of action | No | Yes (for data breaches) |
| Opt-out of targeted ads | Yes | Yes |
| Opt-out of data sale | Yes | Yes |
| Sensitive data consent | Yes | Yes |
| Enforcement | FTC + state AGs only | CA AG + CA Privacy Protection Agency + private suits |
| Would be preempted? | — | Yes, under Section 15 |
Key Takeaways
- Major sector-specific federal laws (HIPAA, FCRA, COPPA, FERPA, GLB) are all preserved
- The Video Privacy Protection Act is repealed — removing a major source of tech company litigation
- GDPR is a completely separate regime — companies with EU operations must still comply
- CCPA/CPRA would be preempted by Section 15, making this comparison largely academic if the bill passes