Blog

  • 18 states are pushing back against the SECURE Data Act, here’s why it matters


    18 States Are Pushing Back Against the SECURE Data Act — Here’s Why It Matters
    Federal legislation Data privacy State rights

    18 states are pushing back against the SECURE Data Act — here’s why it matters

    Congress is trying to pass the first major federal data privacy law in years. But a growing coalition of state attorneys general says it would make things worse, not better.


    What is the SECURE Data Act?

    H.R. 8413 — formally the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act — was introduced on April 22, 2026 by House Energy and Commerce Committee Vice Chair John Joyce (R-PA). It is the first serious comprehensive federal privacy bill of the 119th Congress, the result of a Privacy Working Group that consulted over 170 organizations and received more than 250 written responses.

    On paper, the bill looks like progress. It gives consumers rights to access, correct, delete, and port their personal data. It lets people opt out of data sales, targeted advertising, and profiling. It treats data belonging to teenagers under 16 as sensitive, requiring parental opt-in consent. It establishes a federal data broker registry administered by the FTC.

    The problem, according to critics, is what it takes away.

    The core issue: Section 15 of the bill would preempt state privacy laws — overriding California’s CCPA/CPRA, Illinois’ BIPA, Washington’s My Health My Data Act, and dozens of other state-level frameworks. States that have spent years building stronger consumer protections would be forced back to a weaker federal baseline.

    Who supports it — and who opposes it

    The bill has support from business groups who argue that a patchwork of 50 different state laws creates compliance confusion and costs. Supporters estimate eliminating that patchwork could save businesses up to $1 trillion over 10 years. The bill also has no private right of action — meaning consumers can’t sue companies directly, a feature businesses strongly prefer.

    But that same feature is exactly what critics find alarming.

    Supporters say

    • Creates a single national standard
    • Reduces compliance burden for businesses
    • Eliminates confusing state-by-state variation
    • Includes baseline consumer rights

    Critics say

    • Replaces stronger state laws with weaker rules
    • Removes private right of action for consumers
    • Limits future state-level innovation
    • Concentrates enforcement in politically appointed FTC

    The coalition pushing back

    On June 2, 2026, California Attorney General Rob Bonta led a coalition of 18 attorneys general and state agencies in formally calling on Congress to reject the bill. Their letter argues the SECURE Data Act moves privacy rights in the wrong direction — and that any federal framework must preserve states’ ability to go further.

    “Federal action to protect Americans’ privacy is essential, but not at the expense of the strong state laws that already protect Californians.”

    — AG Rob Bonta, California

    “The SECURE Data Act is another wolf in sheep’s clothing, claiming security on the surface but weakening Virginians’ privacy at its core.”

    — AG Jay Jones, Virginia

    All 18 members of the coalition

    01

    California

    AG Rob Bonta (lead) · CCPA/CPRA

    02

    Connecticut

    AG · CT Data Privacy Act

    03

    Delaware

    AG · DE Personal Data Privacy Act

    04

    Illinois

    AG · BIPA + state privacy law

    05

    Maine

    AG · Maine Privacy Act

    06

    Maryland

    AG Anthony G. Brown · MODPA

    07

    Massachusetts

    AG · State privacy framework

    08

    Minnesota

    AG · MN Consumer Data Privacy Act

    09

    Nevada

    AG · Nevada Privacy of Information Act

    10

    New Hampshire

    AG · NH Privacy Act

    11

    New Jersey

    AG · NJ Data Privacy Act

    12

    New York

    AG · SHIELD Act + pending NYPA

    13

    Oregon

    AG · Oregon Consumer Privacy Act

    14

    Vermont

    AG Charity Clark · Vermont Privacy Act

    15

    Virginia

    AG Jay Jones · VCDPA

    16

    Washington

    AG · My Health MY Data Act

    17

    Hawaiʻi

    Dept. of Commerce & Consumer Affairs

    18

    California Privacy Protection Agency

    CalPrivacy · CPRA enforcement body

    What happens next

    The bill has been referred to the House Committee on Energy and Commerce and the Committee on the Judiciary. The IAPP has described it as “an opening salvo” likely to be refined significantly before any vote. The coalition’s letter, combined with opposition from privacy advocacy groups like EPIC, EFF, and ACLU, suggests the preemption clause in Section 15 will face serious resistance — the same issue that derailed the last two major attempts at a federal privacy bill.

    Whether Congress can thread the needle between national consistency and preserving stronger state protections remains the central question. For now, 18 states have a clear answer: not like this.


  • Hawaii Opposes Federal SECURE Data Act, Joins 15-State Coalition

    The Hawaii Office of Consumer Protection, alongside a coalition of 15 state attorneys general and agencies, has come out against the SECURE Data Act, a proposed federal data privacy bill.

    The core concern is that the bill would create a federal ceiling on privacy protections, effectively overriding stronger state-level laws already in place. States like California, Connecticut, Illinois, and others argue this moves privacy rights in the wrong direction by giving businesses more discretion over data use, weakening enforcement options, and limiting consumers’ ability to opt out of data sales.

    The coalition is calling on Congress to reject the bill and preserve states’ ability to independently legislate on privacy, particularly as new technologies and data practices continue to evolve.

    Read the full press release here.

  • SECURE Data Act Faces Intense Debate in First Congressional Hearing

    The legislative battle over a uniform U.S. data privacy standard officially kicked off on June 3, 2026. The House Subcommittee on Commerce, Manufacturing, and Trade held its first public hearing for the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act (SECURE Data Act).

    Introduced in April by U.S. Rep. John Joyce (R-PA), the Republican-drafted bill faces a steep uphill climb. Unlike its predecessors (APRA and ADPPA), the SECURE Data Act currently lacks bipartisan support and does not have a companion bill in the Senate.

    Here is a breakdown of the key takeaways from the hearing and what it means for the privacy landscape.

    1. The Pro-Business Argument: Overcoming the 22-State Patchwork

    Supporters of the bill argue that a single national standard is desperately needed to replace the rapidly growing “patchwork” of state-level privacy regulations.

    • The Compliance Burden: With 22 states having passed their own consumer privacy laws, and over 30 separate amendments already complicating those frameworks, compliance has become a moving target.
    • Small Business Strain: Organizations like the Kentucky Chamber of Commerce testified that small businesses lack the massive compliance budgets and in-house legal teams required to track 50 different state laws, making a uniform federal standard a matter of economic competitiveness.
    • A Uniform Ceiling: The bill features strong preemption language that would override existing state laws, giving businesses regulatory certainty.

    2. What’s Inside (and Missing From) the Draft

    The SECURE Data Act introduces a few novel concepts but drops several mechanisms found in previous privacy drafts:

    • What it includes: A centralized data broker registration managed by the FTC; a “safe harbor” program for companies following a Department of Commerce-approved code of conduct; and strict protections treating data from children under 13 as sensitive.
    • What it lacks: The current draft does not include a Private Right of Action (allowing citizens to sue companies directly), nor does it require Data Protection Impact Assessments (DPIAs), Data Protection Officers (DPOs), or universal opt-out mechanisms.

    3. The Backlash: “Weaker Than the Weakest State Law”

    The bill drew fierce opposition from Democrats, the Electronic Privacy Information Center (EPIC), and state regulators.

    • The Notice-and-Consent Loophole: Critics argue the bill perpetuates a broken status quo of “notice and choice,” rather than enforcing strict data minimization (limiting what companies can collect in the first place).
    • Enforcement Gaps: EPIC argued that without a private right of action, the bill is functionally unenforceable, as the FTC and state Attorneys General do not have the resources to litigate individual consumer complaints.
    • Eviscerating State Rights: A coalition of 18 state Attorneys General and the California Privacy Protection Agency (CPPA) formally opposed the bill. They argue that the sweeping federal preemption would strip away stronger, existing privacy protections that millions of citizens already rely on—especially concerning biometric and health data.

    Looking Ahead

    While House Democrats soundly criticized the partisan nature of the draft, leadership expressed hope that a compromise could eventually be reached by borrowing elements from past bipartisan frameworks. As AI supercharges the corporate incentive to harvest personal data, the pressure on Congress to find a middle ground has never been higher.

    Watch the full hearing on YouTube here.