Publication

June 18, 2026
|
4 minute read
|

The SECURE Data Act and the Business Case for One Federal Privacy Standard

The SECURE Data Act is the latest attempt in Congress to create a federal privacy law. For U.S. companies, the appeal is clear: more than 20 states have passed comprehensive privacy laws, many following a similar structure, but with enough variation to complicate national compliance.

The bill would not radically depart from the framework businesses already know. It largely mirrors the state-law model of consumer rights, targeted-advertising and sale opt-outs, sensitive-data consent, processor contracts, data security obligations, and regulator enforcement. Its practical value is consolidation: one national framework could reduce duplication and make privacy programs easier to operate across state lines.

Three Takeaways for Businesses

  • Preemption. The bill would broadly preempt state laws that relate to its provisions. That is the principal business benefit—and the central policy dispute—because it could replace much of the current state patchwork with a federal ceiling.
  • No private right of action. Enforcement would rest with the FTC and state attorneys general. The bill would not authorize individuals to sue directly, materially changing the litigation risk profile compared with privacy statutes that permit private claims or statutory damages.
  • Timing remains uncertain. The House Energy and Commerce Subcommittee held a legislative hearing on June 3, 2026, but no markup has been announced. If enacted as drafted, the consumer-rights, data-security, and data-broker provisions would take effect after one year; most remaining provisions would take effect after two years.

What the Bill Would Generally Require

The SECURE Data Act would apply to certain businesses subject to the FTC Act, as well as common carriers, if they do business in the United States or process or sell personal data of U.S. residents and meet specified thresholds.

In general, a covered entity would need to process personal data of more than 200,000 consumers annually and have at least $25 million in annual gross revenue, or process personal data of at least 100,000 consumers annually and derive at least 25% of annual gross revenue from selling personal data. Personal data processed solely to complete a payment transaction would not count toward those thresholds.

Covered businesses would need to provide familiar rights to access, correct, delete, and obtain a portable copy of personal data, along with opt-outs for targeted advertising, sales, and certain profiling. The bill would also require consent before processing sensitive data, subject to exceptions, and would impose data minimization and secondary-use limits tied to disclosed purposes.

For companies already operating under state consumer privacy laws, these requirements should look familiar and may require refinement rather than a new compliance strategy. Companies outside current state regimes would first need to analyze the federal thresholds and exemptions before assuming they are covered.

The Data Broker Provisions Matter for More Than Data Brokers

The bill would create a federal data broker registry maintained by the FTC. Data brokers would register annually and disclose information including the categories of personal data sold, links to consumer-rights mechanisms, purchaser-credentialing practices, and certain reported security incidents.

For entities that meet the data broker definition, this would create a new federal registration and transparency obligation. The broader business issue is data sourcing. Many companies buy, license, append, enrich, score, verify, or target using third-party data without viewing themselves as data brokers. That data may feed marketing, fraud prevention, analytics, lead generation, AI tools, or customer segmentation.

The practical lesson is straightforward: companies should know who supplied the data, how it was collected, what contractual restrictions apply, and whether the intended use can be defended. The registry may improve visibility into the broker ecosystem, but it will not replace diligence over third-party data.

Preemption Is the Main Business Benefit

The SECURE Data Act would preempt state laws that relate to the Act’s provisions; it is not limited to direct conflicts between federal and state law. Without meaningful preemption, a federal law could simply become another layer on top of the existing patchwork. With it, companies could build one privacy program, one consumer-rights process, one set of vendor terms, and one operational playbook.

The tradeoff is that broad preemption could displace more protective state requirements, including parts of California’s privacy and data broker regimes. That issue will likely remain central to negotiations. From a business perspective, however, preemption is what could make the federal framework operationally useful rather than additive.

No Private Right of Action Changes the Risk Profile

The bill would be enforced by the FTC and state attorneys general and would not create a private right of action. That would not eliminate privacy litigation, including claims brought under wiretap, biometric, consumer protection, video privacy, and other statutes. It would, however, reduce the risk that every alleged violation of the federal framework becomes a private class action.

Regulatory enforcement can still be expensive, public, and disruptive. But regulator-led enforcement differs materially from litigation driven by statutory damages, class-certification pressure, and competing interpretations across jurisdictions. The absence of a private right of action therefore provides greater predictability, while preserving the need for a well-documented and operationally accurate privacy program.

What the June 3 Hearing Signals

The June 3 House hearing confirmed that the central debate is structural, not whether consumers should receive basic privacy rights. Supporters emphasized the value of building a federal standard from the common features of existing state laws. Critics questioned whether the bill is strong enough to justify broad preemption and whether regulator-only enforcement and the data broker provisions go far enough.

For businesses, the key variables are therefore likely to remain the scope of preemption, the enforcement model, the treatment of data brokers, and whether data minimization remains tied to disclosed purposes. Those issues will determine whether a final bill meaningfully simplifies compliance or merely adds another layer of uncertainty.

Conclusion

The SECURE Data Act is best understood as a federal consolidation bill, not a privacy revolution. For businesses, that may be a good thing. For companies already building around state privacy laws, the bill likely would not require a new privacy strategy. It would largely standardize work many privacy teams are already doing.

But consistency only helps if a company understands its data practices. A federal privacy standard may simplify the legal map, but it will not make unclear data practices easier to defend. The strongest position remains the same: know what personal data the company collects, where it comes from, who receives it, how it is used, and whether those practices match the company’s disclosures and contracts.

Thompson Coburn LLP’s Data Governance, Privacy and Cybersecurity group will continue to monitor developments in this area. If your organization needs support evaluating data governance or privacy compliance obligations, please reach out.

Related People