TL;DR: Two weeks after House Republicans introduced the SECURE Data Act (HR 8413), the opposition list reads like a who's-who of digital rights. The EFF published a point-by-point takedown calling it "not a serious piece of privacy legislation." EPIC called it "a huge gift to Big Tech." The California Privacy Protection Agency warned it would strip protections from 40 million Californians. Public Knowledge said it hands companies "a get out of jail free card." TechPolicy.Press found the exemptions so broad that "it's as if the rest of the bill simply vanishes." This isn't a few fringe groups complaining. This is every major privacy organization in the country saying the same thing: this bill would make Americans less safe than they are right now.
A Wall of Opposition in Two Weeks Flat
The SECURE Data Act landed on April 22. By May 5, EFF had published its analysis. EPIC followed within days. The California Privacy Protection Agency sent a formal letter to Congress. Public Knowledge issued a rejection statement. TechPolicy.Press ran a detailed critique. IAPP, Venable LLP, Hunton, Mayer Brown, and half the privacy bar in Washington published analysis pieces [1][2][3][4][5].
This kind of unified opposition is rare. Privacy organizations disagree about plenty: whether to prioritize consent models over data minimization, how to handle AI, whether to regulate at the federal level at all. On the SECURE Data Act, they found consensus fast: this bill is worse than doing nothing.
The speed matters. HR 8413 was supposed to be the product of 14 months of deliberation by the House Energy and Commerce Committee's Privacy Working Group. A serious attempt at federal privacy legislation for the 119th Congress. The privacy community treated it like a fire alarm.
EFF: "Not a Serious Piece of Privacy Legislation"
The Electronic Frontier Foundation's May 5 analysis is the most detailed public critique so far. It walks through the bill section by section and finds problems everywhere [1].
Start with data minimization. The bill says companies can only process data for "disclosed" purposes. EFF points out that's already the law under the FTC Act. Companies disclose purposes in their privacy policies, those 15,000-word documents nobody reads. The SECURE Data Act doesn't limit collection to what's necessary. It limits it to what's disclosed. Those are very different things.
Then there's the AI training exemption. The bill explicitly permits companies to use your personal data for "developing AI systems" without restriction. You can't opt out. You can't control whether your medical searches, location history, or browsing patterns train the next corporate model. EFF calls this a carve-out that swallows the rule.
The profiling restrictions look solid on paper, until you read the fine print. Any "human review" of an automated decision satisfies the bill's requirements. EFF argues that a rubber-stamp human glancing at an algorithm's output counts as review, gutting the protections entirely.
On deletion rights: if you request deletion from a company that shared your data with third parties, the third parties don't have to delete it. They just have to stop processing it going forward. Your data stays in their systems. That's not deletion. That's a pinky promise.
And the self-regulatory "Code of Conduct" system? Companies can submit compliance plans to undefined "independent organizations," get audited, and earn a presumption of compliance. EFF's assessment: an industry-designed accountability-avoidance scheme with a 45-day "cure period" that carries no penalties.
EPIC: "A Huge Gift to Big Tech"
The Electronic Privacy Information Center didn't wait for the detailed analysis. EPIC's initial statement called the bill "a huge gift to Big Tech" and warned that "a weak federal standard is worse than no standard at all" [2].
EPIC's argument cuts to the structural problem: the bill eliminates the possibility of private lawsuits under the federal framework. That's not an oversight. It's the feature. When consumers can't sue, enforcement depends entirely on the FTC and state attorneys general. Both are politically appointed. Both have limited budgets. Both face pressure from the same industry the bill is supposed to regulate.
EPIC Deputy Director Caitriona Fitzgerald argued the bill "fails to include even a bare minimum protection for consumers" with its enforcement mechanisms. The organization is now leading a coalition pushing for warrant requirements and private litigation rights in any federal privacy framework [2][3].
The coalition is significant. EPIC isn't just opposing. It's organizing. The group has been coordinating with EFF, ACLU, Public Knowledge, and state-level privacy advocates to push amendments before the bill reaches committee markup.
California's Privacy Agency: "Tens of Millions Would Lose Protections"
The California Privacy Protection Agency, the state's dedicated enforcement body, sent a letter to Congress that reads like a damage assessment [4].
The specific losses CalPrivacy identified:
- The DELETE Act portal: 40 million Californians would lose access to the one-click data broker deletion platform. The SECURE Data Act creates a registry. California built a tool. The tool gets replaced by the list.
- Opt-out preference signals: Over 100 million Americans across states with similar requirements would lose the ability to use browser-based opt-out signals. Companies would no longer have to honor Global Privacy Control.
- Data collection limits: Companies could no longer be forced to limit collection to what consumers would reasonably expect. The SECURE Act's "disclosed purposes" standard is lower than California's "reasonably necessary" standard.
CalPrivacy Executive Director Tom Kemp said: "A strong federal privacy law is worth pursuing, but it should not strip away rights that tens of millions of people already depend on." Deputy Director Maureen Mahoney added: "This bill will block essential flexibility and innovation" [4].
CalPrivacy's letter also invoked history. California passed the nation's first data breach notification law in 2002. It passed the first comprehensive consumer privacy law (the CCPA) in 2018. More than 20 states followed that model. The SECURE Data Act would demolish the template California built.
Public Knowledge: "A Get Out of Jail Free Card for ISPs"
Public Knowledge added a critique nobody else had focused on: the bill strips the FCC of privacy regulatory power over broadband and telecom providers [5].
Right now, the FCC can enforce privacy rules on your internet service provider. Under the SECURE Data Act, that authority moves entirely to the FTC. Public Knowledge's Sara Collins called this "a get out of jail free card for ISPs": the companies that can see every website you visit, every device on your network, and every unencrypted query you make.
Collins also flagged the enforcement gap: "When consumers are left entirely dependent on regulators to enforce the law on their behalf, the law instead becomes a liability shield" for corporations. The bill doesn't empower enforcement. It limits who can enforce [5].
TechPolicy.Press: "The Rest of the Bill Simply Vanishes"
TechPolicy.Press published what may be the most damning structural analysis. The author identified a set of exemptions so broad they effectively hollow out the entire law [6].
Exempt activities under the SECURE Data Act include: processing that a consumer requested, processing required by contract, and "internal research to develop, improve, or repair a product." That last one is the loophole that eats the bill. Nearly any data processing can be framed as product improvement. A/B testing user behavior? Product improvement. Training recommendation algorithms on browsing history? Product improvement. Building behavioral profiles for ad targeting? If it improves the ad product, it's exempt.
TechPolicy.Press also flagged the bill's failure on civil rights protections. Previous bipartisan attempts (the ADPPA in 2022, the APRA in 2024) included safeguards against discriminatory data use. The SECURE Data Act only "reiterates that illegal discrimination is still illegal," which does nothing to address how data is actually used in discriminatory ways that current civil rights law doesn't cover [6].
The Kill List: What the Bill Would Actually Eliminate
Across all these analyses, here's the combined list of what the SECURE Data Act's Section 15 preemption clause would wipe out:
- California's CCPA/CPRA: The private right of action for data breaches. The requirement to honor Global Privacy Control. The CPPA's enforcement authority to innovate with new regulations.
- California's Delete Act: The one-click data broker deletion portal serving 40 million residents.
- Illinois BIPA: The biometric privacy law that produced the $228 million BNSF Railway verdict and the $17 million Clearview AI settlement. The only law in the country that lets individuals sue over biometric data collection.
- Washington's My Health My Data Act: Protections for reproductive health data that were specifically designed for the post-Dobbs environment.
- Maryland's Online Data Privacy Act: Data minimization by default and a ban on selling sensitive data.
- Colorado, Virginia, Texas, Connecticut, Oregon: and every other state's comprehensive privacy framework. At least 20 laws, covering more than half the U.S. population.
- State data broker registries: Multiple states require data brokers to register and give consumers deletion tools. The SECURE Act replaces them with a weaker FTC registry.
- FCC broadband privacy authority: Enforcement over ISPs shifts entirely to the FTC.
The Pattern That Should Worry You
This isn't the first time a "national standard" has been used to weaken protections. It's a pattern.
In March 2026, the White House released an AI executive framework that pushed federal preemption of state AI laws. In April, the SECURE Data Act applied the same logic to privacy. The strategy is consistent: let states build the protections, then override them with weaker federal versions before they mature.
EFF identified this explicitly. Prior federal privacy laws (HIPAA, Gramm-Leach-Bliley, FERPA) set floors. States could go higher. The SECURE Data Act is the first major proposal to set a ceiling and lock it. That's not uniformity. That's a rollback dressed as standardization [1].
What You Can Do
- Contact your House representative. The bill is in the Energy and Commerce Committee. The specific ask: support a federal privacy floor, not a ceiling. Demand a private right of action. Find your representative
- Use your state rights while they exist. If you're in a state with privacy protections, submit data deletion requests. Opt out of data sales. Enable Global Privacy Control in your browser. Create a record of companies honoring (or ignoring) your requests
- Support the organizations fighting this. EFF, EPIC, Public Knowledge, and the California Privacy Protection Agency are all actively organizing opposition
- Watch for the committee markup. The Energy and Commerce Committee will schedule markup in the coming weeks. That's where amendments to add private right of action and weaken preemption will be fought over, and where industry lobbyists will push hardest to keep them out
The Bottom Line
When EFF, EPIC, CalPrivacy, Public Knowledge, Consumer Reports, the ACLU, and TechPolicy.Press all agree that a bill is bad for privacy, pay attention. These organizations fight with each other regularly. They agree on the SECURE Data Act: it's a step backward.
America needs a federal privacy law. Nobody seriously disputes that. But the law should build on the protections 20 states already created, not demolish them. It should let people sue when companies break the rules. It should restrict data collection, not just require companies to disclose it in policies nobody reads.
The SECURE Data Act does none of that. It gives industry the preemption it's lobbied for since 2018 and wraps it in language that sounds like reform. The privacy community isn't buying it.
References
- EFF: "The SECURE Data Act is Not a Serious Piece of Privacy Legislation" (May 5, 2026)
- EPIC: Statement on the SECURE Data Act and GUARD Financial Data Act (April 2026)
- EPIC: "America Needs a Strong Privacy Law. The SECURE Data Act Isn't It." (May 2026)
- California Privacy Protection Agency: Letter Opposing the SECURE Data Act (April 2026)
- Public Knowledge: "Rejects Bill Stripping Americans of Privacy Protections to Benefit Big Tech" (April 2026)
- TechPolicy.Press: "Congress's New Privacy Bill Is Built on Empty Promises" (May 2026)
- IAPP: "SECURE Data Act: Analysis of the New Federal Privacy Bill" (April 2026)
- Venable LLP: "SECURE Data Act: Congress Introduces New Federal Privacy Framework" (April 2026)
Published: May 9, 2026