The SECURE Data Act would replace every state privacy law with a single federal standard
The SECURE Data Act would replace every state privacy law with a single federal standard. That's the sales pitch. Here's what it actually does.
The House Energy and Commerce Committee introduced the "Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act" on April 22, 2026. SECURE Data Act, because the acronym had to land somewhere pronounceable.
If it passes, the bill preempts state privacy laws – all of them – and hands enforcement to the FTC and the Department of Commerce. Twenty states have comprehensive privacy laws in effect in 2026 (MultiState, 2026). California's Delete Act, which went live August 1, created a centralized system for consumers to delete their data from every registered broker in one request. The SECURE Data Act would kill that, along with every other state-level protection that goes further than the federal floor.
The pitch is "uniformity." Businesses operating in multiple states currently navigate a patchwork of overlapping and conflicting requirements – different definitions of personal data, different opt-out mechanisms, different breach notification windows. The compliance burden is real. A single federal standard would simplify that.
But uniformity cuts both ways. It simplifies compliance by capping protection at the weakest common denominator the lobbyists can live with. States that wanted to go further – and did – lose that option. Federal preemption doesn't just harmonize the rules. It ends the experiment.
California has been the test bed for privacy enforcement in the US for over a decade. The CCPA gave residents enforceable rights years before most states considered the question. When the CCPA worked, other states adapted it. When it didn't, they fixed the gaps. That's how Delaware, Connecticut, and Oregon ended up with stronger breach notification requirements and Virginia with tighter data minimization rules.
The SECURE Data Act replaces that process with a static federal law. Once it passes, the floor becomes the ceiling. If the federal standard doesn't cover something, nobody can. States can't iterate, can't respond to new threats, can't raise the bar when enforcement proves the old one was too low.
The bill expands FTC and Commerce Department authority. That sounds like stronger enforcement until you remember the FTC has been chronically underfunded and outgunned for years, and political turnover has repeatedly gutted its independence. The Supreme Court's 2026 decision in Trump v. Slaughter ended FTC independence by allowing the President to fire the chair at will. Enforcement that depends on an administration's willingness to enforce isn't enforcement. It's a permission structure.
Here's the math that matters: businesses subject to the FTC Act and common carriers under Title II of the Communications Act of 1934 would be covered. That means telcos, ISPs, data brokers, and anyone conducting business in the US who collects consumer data. The penalties for violations are not specified in the summaries released so far. Neither are the private right of action provisions – whether individuals can sue directly or have to wait for the FTC to act.
Those details are the difference between a law with teeth and one that exists to say the problem has been handled.
Twenty state laws worked because they gave residents standing. You could sue. You could force a company to prove compliance or pay. A federal law that replaces that with "file a complaint and wait for the FTC" is a downgrade, no matter how uniform it is.
The SECURE Data Act is being sold as simplification. What it is, is consolidation – taking enforcement out of the hands of state AGs who've been aggressive and handing it to federal agencies that have been systematically weakened.
Uniformity is good when the uniform standard is high. This one isn't. It's the floor the industry can live with, presented as a ceiling nobody's allowed to exceed.