SECURE Data Act Privacy Fight
Coverage from JD Supra, mePrism, and others

Congressional debate has hardened around the SECURE Data Act, a federal privacy bill that would replace much of the state-law patchwork with one national standard, limit private lawsuits, and expand FTC-led enforcement.
The main fault line is whether federal preemption and narrower remedies would weaken stronger state protections, especially for biometrics, data brokers, and sensitive data.
The story has shifted from a general fight over federal preemption to a more specific debate over the SECURE Data Act’s enforcement mechanics and carveouts. The current version adds that the bill would rely on FTC/state AG enforcement, bar private lawsuits, and raise new concerns around data brokers, biometrics, and other sensitive-data rules.
The story is largely confirmed, but the current version adds clearer detail on the bill’s substantive limits and procedural exemptions, while identifying Hawaiʻi officials and the California Privacy Protection Agency as visible participants in the opposition landscape.
The story has become more concretely procedural: the SECURE Data Act is now described as moving through committee activity and hearings, with specific congressional proponents and opponents identified. Its substantive disputes and likely weaknesses remain largely unchanged.
The main update is a reframing of the SECURE Data Act from a bill that mainly preempts state privacy laws into one that more explicitly adds a national framework with expanded consumer rights and tighter federalized enforcement. The latest version also broadens the criticism to include biometric, AI, retention, and civil-rights concerns.
The story has sharpened from a general fight over federal privacy preemption into a more concrete legislative clash, with the current version adding specific enforcement details and clearer organized resistance from California officials and privacy groups. It now reads less like an abstract committee debate and more like an active push for a national standard facing coordinated state-level opposition.
The story has sharpened from a general federal privacy bill debate into a more specific legislative push, with new emphasis on a June 3 hearing and clearer details about the draft's enforcement and preemption contours. The main substantive change is the added prominence of data broker oversight and the framing of the bill as a single national standard that would override many state regimes.
The story is now framed less as a finished legislative push and more as an active, still-moving draft process, with hearings and revisions continuing. The new emphasis is on unresolved consumer remedies and safeguards, especially criticism that the bill lacks dark-pattern rules, opt-out signals, and stronger enforcement tools.
House Republicans have advanced the SECURE Data Act as a national privacy framework meant to replace a patchwork of state laws, but the bill is defined by disputes over preemption, enforcement, and how much protection it really adds. The clearest pattern is a push for federal uniformity through FTC and state attorney general enforcement, no private lawsuits, and new rules for opt-outs, sensitive data, and data brokers. Critics consistently argue the draft weakens stronger state protections, narrows remedies, and leaves major loopholes around consent, civil rights, and surveillance-prone data uses.
