TL;DR: On April 22, 2026, House Republicans introduced the SECURE Data Act (HR 8413), a federal privacy bill that would override every state privacy law in America. That includes California's CCPA, Colorado's CPA, and the 18 other comprehensive state privacy laws now on the books. The bill grants basic rights (access, delete, correct, opt out) but strips your ability to sue companies that violate them. No private right of action. Data minimization requirements so vague the CDT calls them "easy for companies to work around." Health data definitions so narrow that period-tracking and fitness apps are exempt. The ACLU's Cody Venzke called it "a privacy bill in name only." A companion bill, the GUARD Financial Data Act, extends similar preemption to financial data. If you live in one of the 20 states with privacy protections, this bill doesn't add to them. It replaces them.
Two Bills, One Goal: Wipe the State Privacy Slate Clean
Rep. John Joyce (R-PA) introduced the SECURE Data Act on April 22, backed by House Energy and Commerce Committee Chair Brett Guthrie (R-KY). The bill is the product of 14 months of work by a Republican-only Privacy Working Group: no Democrats were involved in drafting it [1].
A companion bill, the GUARD Financial Data Act, applies a parallel framework to financial institutions. Together, they'd create one national privacy standard enforced by the FTC and state attorneys general. Sounds reasonable until you read Section 15.
Section 15 is the preemption clause. It says no state may "prescribe, maintain, or enforce any law, rule, regulation, requirement, standard, or other provision having the force and effect of law" relating to the bill's provisions [2]. That's not a floor. It's a ceiling. States can't go higher.
This would wipe out every comprehensive state privacy law in America. At last count, 20 states have them, covering more than half the U.S. population [3]. California's CCPA. Colorado's CPA. Virginia's CDPA. Texas's TDPSA. All gone, replaced by whatever Congress decides is good enough.
What the Bill Actually Gives You
The SECURE Data Act isn't empty. It grants five consumer rights [2]:
- Access: Know what data companies collect about you
- Correction: Fix inaccurate information
- Deletion: Request your data be erased
- Portability: Get a copy of your data in a usable format
- Opt-out: Say no to targeted advertising, data sales, and certain automated profiling
It classifies data from anyone under 16 as sensitive, requiring opt-in consent and verified parental authorization. That bumps up COPPA protections by three years [2].
Data brokers would have to register with the FTC within 12 months. The FTC gets 18 months to build a public, searchable registry [2].
Companies processing data of 200,000 or more U.S. consumers would need to comply. Small businesses under $25 million in revenue get an exemption [2].
On paper, that's something. In practice, what the bill gives with one hand, it takes away with the other.
What It Takes Away
Start with the biggest one: no private right of action. If a company violates your rights under this law, you can't sue. Period. Your only recourse is hoping the FTC or your state attorney general decides to act [4].
California's CCPA lets consumers sue companies directly for data breaches. The SECURE Data Act eliminates that. Every consumer in California, which covers over 39 million people, would lose their ability to take violating companies to court.
The ACLU's Cody Venzke didn't mince words: "It places the onus on regular people to wade through reams of privacy policies and ask tech companies to stop abusing our data, and it leaves us without real recourse, even blocking us from going to court." He called it "a privacy bill in name only" that "could cause real harm" [5].
Then there's data minimization. The bill says companies must limit collection to what's "adequate, relevant, and reasonably necessary." But the CDT's Eric Null says the provision is "weak" and "easy for companies to work around." He added that the bill would "federally codify industry-favored state privacy rules while preempting state laws that include stronger protections" [5].
The health data definition is particularly bad. Only data related to medical diagnoses counts as sensitive. That means period-tracking apps, fitness trackers, and mental health apps that collect intimate health data don't have to get your consent before processing it [5].
And here's one that should worry anyone who's watched how companies train AI: the bill includes exemptions for "product improvement," which privacy advocates say could include using your data to train AI models without asking [4].
What 20 States Would Lose
This isn't theoretical. States have spent years building privacy protections. California alone has a dedicated enforcement agency, the California Privacy Protection Agency (CPPA), that has already levied fines. In recent months, the CPPA hit Healthline Media for $1.55 million and Jam City for $1.4 million for privacy violations [6].
California's CCPA gives consumers a private right of action for data breaches, requires businesses to honor Global Privacy Control signals, and lets the state innovate with new regulations as threats evolve. The SECURE Data Act would eliminate all of that.
Tom Kemp, Executive Director of CalPrivacy, said the bill is "not a real step forward for privacy." He argued it "seeks to eliminate existing rights and protections" and "would leave tens of millions of Americans less protected than they are today" [5].
Maryland's Online Data Privacy Act, one of the strongest in the country, requires data minimization by default and bans the sale of sensitive data. Gone. Colorado's CPA, which requires data protection impact assessments for high-risk processing. Gone. Oregon, Texas, Virginia, Connecticut, New Jersey, Montana, New Hampshire, Delaware, Indiana, Iowa, Kentucky, Nebraska, Tennessee, Rhode Island, Minnesota, Utah, Florida: all of them would see their privacy laws gutted by Section 15 [3].
State attorneys general could still enforce the federal law. But they couldn't enforce their own, stronger standards anymore. That's the whole point of preemption: Congress sets the rules, and the states lose the ability to do better.
Why This Bill, Why Now
Congress has tried this before. The American Data Privacy and Protection Act (ADPPA) in 2022. The American Privacy Rights Act (APRA) in 2024. Both stalled over two issues: preemption and private right of action [7]. Companies wanted full preemption and no lawsuits. Privacy advocates wanted state laws preserved and consumer litigation rights. Nobody blinked.
The SECURE Data Act resolves the stalemate by giving industry exactly what it wanted. Full preemption. No private right of action. The 14-month drafting process by a Republican-only working group produced a bill that the tech and advertising lobby has pushed for since the CCPA passed in 2018 [1].
Industry's argument: 20 different state privacy laws create compliance chaos. Companies operating nationally need to follow different rules in California, Colorado, Texas, Virginia, and everywhere else. A single federal standard simplifies everything.
That argument has merit. Compliance complexity is real. But the solution doesn't have to be "everyone gets the lowest common denominator." A federal floor (where Congress sets minimum standards and states can go higher) would solve the complexity problem without stripping protections from the 170+ million Americans who already have them.
The SECURE Data Act chose the other option: a ceiling that nobody can exceed.
What Happens Next
The bill faces an uphill climb. Democrats oppose it over preemption and the missing private right of action. The narrow House majority means even a few Republican defections could sink it. And even if it passes the House, the Senate would need 60 votes to overcome a filibuster [4].
But don't dismiss it. The SECURE Data Act changes the baseline for every future privacy negotiation. It tells the industry exactly what Congress's opening offer looks like. And if a compromise eventually happens, the preemption clause will be the thing that sticks, because that's the one provision both parties' corporate donors agree on.
The Energy and Commerce Committee will mark up the bill in the coming weeks. If it moves to the floor, expect amendments fighting to add a private right of action and weaken preemption. Both will face fierce lobbying opposition.
What You Can Do
- Know your current protections. If you live in California, Colorado, Connecticut, Virginia, Texas, or any of the other 14 states with comprehensive privacy laws, you have rights right now that this bill would eliminate. Use them before Congress tries to take them away
- Contact your representative. The bill is in the House Energy and Commerce Committee. If your rep sits on it, they'll hear from the industry lobby. Make sure they hear from you too. The specific ask: support a federal privacy floor, not a ceiling. Support a private right of action
- Exercise your state rights now. Submit data deletion requests. Opt out of data sales. Use Global Privacy Control in your browser. Create a paper trail of companies honoring (or ignoring) your requests under current state law
- Follow the markup. The committee markup is where the bill's fate will be decided. Organizations like the EFF, IAPP, and CDT will publish analysis of any amendments
The Bottom Line
A federal privacy law would be a genuinely good thing. Americans deserve consistent privacy protections no matter which state they live in. But the SECURE Data Act isn't that law.
It's a law that takes the weakest features of existing state frameworks, makes them national, and then prevents anyone from doing better. It gives companies a compliance win while taking away the one enforcement mechanism, private lawsuits, that actually makes them pay attention.
Twenty states built privacy laws because Congress wouldn't act. Now Congress is acting, to make sure those states can't protect their residents anymore.
References
- The Record: "House Republicans Unveil Data Privacy Law That Would Override State Protections" (April 2026)
- IAPP: "SECURE Data Act: Analysis of the New Federal Privacy Bill" (April 2026)
- MultiState: "20 State Privacy Laws in Effect in 2026" (February 2026)
- Fisher Phillips: "House Republicans Unveil National Data Privacy Bill: What Employers Need to Know" (April 2026)
- StateScoop: "The New Federal Consumer Privacy Bill Isn't Very Consumer-Friendly, Critics Say" (April 2026)
- PPC Land: "House Republicans Unveil SECURE Data Act to Replace US State Privacy Laws" (April 2026)
- Future of Privacy Forum: "Preemption in US Federal Privacy Laws" (2026)
Published: April 26, 2026