The SECURE Data Act would create a nationwide consumer privacy framework governing how covered businesses collect, use, share, and secure personal data. It gives consumers rights to confirm whether their data is being processed, access a copy, correct inaccuracies, delete data, obtain portable copies, and opt out of targeted advertising, the sale of personal data, and certain profiling decisions with legal or similarly significant effects. The bill also requires heightened consent for sensitive data, including children’s data and teens’ data, and sets procedures for consumer requests, appeals, and authentication.
The bill imposes broad obligations on data controllers and processors. Controllers would have to minimize data collection, limit secondary uses, provide clear privacy notices, disclose sales and targeted advertising, and maintain reasonable data security practices. Data brokers would face registration and public disclosure requirements, and the Commerce Department would maintain a searchable registry. The bill also creates a framework for approved codes of conduct, recognizes certain cross-border privacy certifications, and directs a study on universal opt-out mechanisms. It includes detailed definitions for terms such as personal data, sensitive data, biometric data, profiling, and data broker, and it preempts state laws that relate to the bill’s subject matter.
The bill’s impact on state law would be significant because it establishes a federal floor-and-ceiling style national regime and expressly bars states and political subdivisions from enforcing laws that relate to the act’s provisions. It would also interact with, but generally preserve, several existing federal privacy regimes such as COPPA, HIPAA, GLBA, FCRA, FERPA, and certain communications and health privacy laws. The bill would be enforced primarily by the Federal Trade Commission, with parallel enforcement authority for state attorneys general, subject to notice and a 45-day cure period. It also repeals section 2710 of title 18, U.S. Code, which concerns video rental records privacy.
The overall sentiment in the available record appears neutral to supportive, but limited, because there are no committee transcripts or recorded votes included. The bill was introduced with bipartisan cosponsors, which suggests an effort to build cross-party support for a national privacy standard. Its structure also reflects a compromise approach by combining consumer rights and enforcement with exemptions, safe harbors, and allowances for loyalty programs, research, and certain internal business uses.
The main points of contention likely center on federal preemption, enforcement scope, and the balance between consumer rights and business flexibility. Privacy advocates may favor the strong consumer rights, data minimization, and opt-out provisions, while businesses may object to compliance costs, the breadth of the definition of personal data, and the limits on targeted advertising and data sales. States that have enacted their own privacy laws may object to the bill’s broad preemption, and industries such as advertising, data brokerage, and large online platforms may be especially affected by the new restrictions and disclosure requirements.
The bill would create a comprehensive federal consumer privacy statute governing covered controllers, processors, and data brokers, while preempting state and local laws that relate to its provisions. It would require new privacy notices, consumer rights request procedures, data minimization, security safeguards, broker registration, and limits on sensitive-data processing, targeted advertising, and data sales. It would also preserve or defer to several existing federal privacy frameworks, shift primary enforcement to the FTC with state AG authority, and repeal the federal video privacy statute at 18 U.S.C. 2710.
No committee debate or vote record is provided, so the formal sentiment cannot be measured from hearings or roll calls. Based on the bill text and bipartisan sponsorship, the measure appears to have been drafted as a serious bipartisan privacy proposal with a generally supportive posture toward consumer data rights. At the same time, the bill’s broad preemption and compliance obligations suggest that support would likely be mixed among states, privacy advocates, and affected industries.
The most likely areas of contention are federal preemption of state privacy laws, the scope of FTC and state attorney general enforcement, and the operational burden on businesses that process large volumes of data. Data brokers, advertisers, and large online platforms may resist the opt-out, disclosure, registration, and data-minimization requirements, while states may object to losing authority to enforce their own privacy standards. There may also be debate over exemptions for existing federal regimes, the treatment of loyalty programs and profiling, and whether the bill goes far enough to protect sensitive data and children’s information.