Does the SECURE Data Act Apply to Your Business? Applicability & Exemptions

Does the SECURE Data Act Apply to You?

Section 13 determines exactly which businesses the bill covers. The answer depends on two factors: what kind of entity you are, and how much data you process.


The Two-Part Test

To be covered, you must satisfy both parts:

Part 1: Jurisdictional Scope

You must be subject to the FTC Act OR be a common carrier under the Communications Act — AND either:

  • Conduct business in the United States, OR
  • Offer products or services to US residents, OR
  • Process or sell personal data of US residents

This is a broad net. If you have any US customers or US user data, you likely meet Part 1.

Part 2: Data Volume & Revenue Thresholds

You must meet at least one of these:

Threshold A:

  • Process personal data of 200,000+ consumers per year (excluding payment transaction data), AND
  • Have annual gross revenue of $25 million or more

Threshold B:

  • Process personal data of 100,000+ consumers per year (excluding payment transaction data), AND
  • Derive 25% or more of annual gross revenue from selling that personal data

Who Is Exempt?

The following are explicitly excluded from the Act:

Entity Exemptions

  • Federal, state, and local governments
  • Entities processing data purely as government processors
  • Financial institutions subject to the Gramm-Leach-Bliley Act
  • Healthcare entities (covered entities and business associates under HIPAA)
  • Nonprofit organizations (501(c)(3))
  • Nonprofits focused on fraud prevention, investigation, or public education
  • Institutions of higher education
  • The National Center for Missing and Exploited Children
  • Insurance guaranty associations
  • Registered futures associations and national securities associations

Data Exemptions

The following types of data are excluded regardless of who holds them:

  • Employee/applicant data and emergency contact information
  • Health information protected under HIPAA
  • Health records
  • Substance use disorder records
  • Clinical research data
  • Credit reporting data (covered by FCRA)
  • Driver’s license data (covered by federal driver privacy law)
  • Education records (covered by FERPA)
  • Farm credit data
  • Financial data already covered by Gramm-Leach-Bliley

Quick Self-Assessment

QuestionIf Yes
Are you a US government entity?Exempt
Are you a nonprofit 501(c)(3)?Exempt
Are you a university?Exempt
Are you a bank or financial institution?Exempt for financial data
Are you a healthcare provider or insurer?Exempt for health data
Do you process data of 200k+ consumers AND have $25M+ revenue?Covered
Do you process data of 100k+ consumers AND earn 25%+ revenue from selling it?Covered
Does none of the above apply?Likely not covered

Frequently Asked Questions

We’re a startup under $25M revenue. Are we covered? Under Threshold A, no — unless you also meet Threshold B (selling data generating 25%+ of revenue). Most early-stage startups will fall below the thresholds.

We’re a European company with US users. Does this apply to us? Yes, if you process personal data of US residents and meet the volume/revenue thresholds, the Act applies regardless of where you are headquartered.

We’re a nonprofit that sells some data. Are we exempt? The exemption applies to all nonprofits organized under 501(c)(3). However, if your nonprofit activities are commercial in nature, the IRS classification may come into question separately.

Does payment transaction data count toward the 200,000 consumer threshold? No. Payment transaction data is explicitly excluded from the threshold calculation under both tests.