United States Capitol building dome against a blue sky
Photo via Unsplash

TL;DR: On April 22, 2026, House Republicans introduced the SECURE Data Act (HR 8413) and its companion GUARD Financial Data Act. Together, they'd create a single federal privacy framework that preempts all 20+ state privacy laws, including California's CCPA. The bill gives consumers access, deletion, correction, and portability rights, creates an FTC-run data broker registry, and lets state attorneys general enforce it. But there's no private right of action. If a company mishandles your data, you can't sue them yourself. Consumer Reports says the bill is "a significant step back for privacy."

Twenty States Built Privacy Laws. Congress Wants to Erase Them.

It took years. California started it in 2018 with the CCPA. Virginia followed. Colorado, Connecticut, Texas, Oregon, Montana: state by state, legislators fought to give residents control over their personal data. By April 2026, more than 20 states had comprehensive privacy laws on the books [1].

On April 22, House Energy and Commerce Committee Vice Chairman John Joyce (R-Pa.) introduced HR 8413, the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act, the SECURE Data Act. The same day, Financial Services Chair French Hill (R-Ark.) dropped the companion GUARD Financial Data Act for banks and financial institutions [2].

The pitch: one national standard instead of a patchwork of state rules. Businesses stop worrying about 20 different compliance regimes. Americans get the same rights everywhere.

The reality: those "same rights everywhere" are weaker than what California, Colorado, and a dozen other states already guarantee.

What the Bill Actually Says

The SECURE Data Act does grant real consumer rights [3]:

  • Access. You can see what data a company holds on you.
  • Correction. You can fix inaccurate data.
  • Deletion. You can ask companies to delete your data.
  • Portability. You can get your data "in a format that is both portable and usable."
  • Opt-out. You can say no to targeted advertising, data sales, and automated profiling with legal consequences.

There's also a data minimization requirement: companies can only collect data that's "reasonably necessary" for the service you're using. Sensitive data (health, biometrics, precise geolocation, financial info) needs your opt-in consent [3].

On paper, that sounds decent. Dig into the details and the gaps start showing.

The Preemption Clause Is Total

Section 15 of the SECURE Data Act doesn't set a floor that states can build on. It sets a ceiling that replaces everything underneath it. The exact language [4]:

"No State or political subdivision of a State may prescribe, maintain, or enforce any law, rule, regulation, requirement, standard, or other provision having the force and effect of law, if such law, rule, regulation, requirement, standard, or other provision relates to the provisions of this Act."

That "relates to" language is the kill shot. It doesn't just preempt laws that directly conflict. It preempts anything that touches the same subject matter. That means:

  • California's CCPA/CPRA (the strongest state privacy law in the country) gets overridden
  • State data broker registries (including California's DELETE Act, which created a one-click opt-out portal) potentially wiped out
  • Illinois BIPA (the biometric privacy law that hit Clearview AI with a $17 million settlement) could be preempted for overlapping provisions
  • State children's privacy protections that go beyond the SECURE Act's parental consent requirements for under-16s

The GUARD Act does the same for financial services: "expressly supersede and preempt state laws imposing consumer data privacy or security requirements on nonpublic personal information and on financial institutions" [2].

You Can't Sue. That's the Point.

The SECURE Data Act explicitly excludes a private right of action [3]. If a company violates your privacy rights under this law, you personally cannot take them to court.

Enforcement falls to the FTC and state attorneys general. That's it.

Compare that to what exists now. California's CCPA gives residents a private right of action for data breaches: you can sue for $100 to $750 per violation. Illinois BIPA lets individuals sue for unauthorized biometric data collection, which is how a truck driver won $228 million from BNSF Railway for scanning his fingerprints without consent [5].

Under the SECURE Data Act, those lawsuits disappear. Your only option is to hope the FTC (currently stretched thin and politically contested) decides your case matters enough to pursue. Or that your state AG has the bandwidth to take on Google.

The bill does include a twist: a "Code of Conduct" safe harbor program. Companies can submit their privacy compliance plans, get them audited, and earn a "rebuttable presumption of compliance." Translation: follow the process we designed, and you get the benefit of the doubt when someone accuses you of violations [4].

The Data Broker Registry Without the Good Parts

The SECURE Data Act creates an FTC-administered data broker registry. Companies that buy and sell your personal data would have to register publicly [3].

That sounds like progress until you compare it to California's DELETE Act, signed in 2023. California's version doesn't just register data brokers. It forces them to participate in a centralized opt-out platform where consumers can request deletion from every registered broker at once, with a single click [3].

The SECURE Act's registry is a list. California's is a tool. Under federal preemption, the tool gets replaced by the list.

The Small Business Exemption

Businesses earning less than $25 million annually are exempt from the SECURE Data Act [3]. That sounds reasonable until you remember that a company with $24 million in revenue can still collect, process, and sell enormous amounts of personal data. Many data brokers and adtech firms fall below that threshold.

California's CCPA threshold is different: it applies to any company that processes data of 100,000+ consumers, regardless of revenue. A small company harvesting millions of people's data? California catches it. The SECURE Act might not.

Consumer Reports Already Called It

Consumer Reports' director of technology policy didn't mince words: "The SECURE Data Act falls far short of protecting the privacy of American consumers." The statement called it "a significant step back for privacy in this country as it would replace several stronger state and local laws with a weak federal framework riddled with loopholes" [6].

The IAPP (the International Association of Privacy Professionals) flagged the preemption scope as the most significant element: the "relates to" language likely wipes out state consumer privacy laws, data broker registries, and "possibly some sectoral state laws" [3].

R Street Institute, a center-right think tank, took a more favorable view, calling the bill "a fresh chance to pass a comprehensive data privacy law" and arguing that national uniformity benefits consumers who cross state lines [7]. They're not wrong about the compliance headache, but "uniform" doesn't mean "strong."

The Financial Data Companion Bill

The GUARD Financial Data Act, introduced by Financial Services Chair French Hill (R-Ark.) alongside Reps. Bill Huizenga (R-Mich.) and Bryan Steil (R-Wis.), covers what the SECURE Act doesn't: banks, credit unions, insurance companies, and anyone else under the Gramm-Leach-Bliley Act [2].

Same playbook: data minimization, consumer access rights, opt-in for sensitive data. Same problem: total preemption of state financial privacy laws. Same gap: no private right of action.

Together, the two bills would create a unified federal privacy framework covering both tech companies and financial institutions. The Republican pitch is "one set of rules for everyone." The counterargument: when the one set of rules is weaker than what half the country already has, "uniformity" is a downgrade.

What Happens Next

The bills were introduced April 22. No committee markup has been scheduled yet. The House Energy and Commerce Committee's data privacy working group, led by Rep. Joyce, will likely hold hearings first [2].

The SECURE Data Act faces the same obstacle that killed the American Data Privacy and Protection Act (ADPPA) in 2022: California doesn't want to give up its CCPA. The California Privacy Protection Agency formally opposed the ADPPA for exactly this reason: federal preemption would erase the strongest consumer protections in the country [8].

Expect the same fight. Expect California, Illinois, and every state AG who spent years building privacy enforcement programs to push back. The question is whether Congress values "simplicity for business" over "actual privacy for people."

What You Can Do

  • Contact your House representative. Tell them you oppose federal preemption of state privacy laws, or at minimum, the bill should set a floor, not a ceiling. Find your rep here.
  • Demand a private right of action. If companies violate your data rights, you should be able to sue. The FTC and state AGs can't handle every case alone.
  • Exercise your state rights now. If you live in a state with privacy protections, use them while they exist. Submit data access and deletion requests. Opt out of data sales. These tools work today.
  • Watch the markup schedule. The House Energy and Commerce Committee will likely schedule hearings in coming weeks. Public comment periods are your window to be heard.

The Tradeoff No One Asked For

Twenty states spent years passing privacy laws. California voters passed the CPRA by ballot initiative: 56% voted for stronger protections. Illinois BIPA created the only regime in the country where you can actually hold companies accountable for grabbing your biometrics without asking.

The SECURE Data Act says: thanks for the effort. We'll take it from here. With a weaker law. That you can't enforce yourself.

National privacy legislation is long overdue. The current patchwork is confusing for consumers and costly for businesses. But the fix shouldn't be a race to the bottom. A federal law should set a floor (minimum protections everywhere) and let states go further if their residents demand it.

HR 8413 does the opposite. It sets a ceiling and locks the door.

Sources

  1. National Law Review: New State Privacy Laws Expand Consumer Data Control in 2026
  2. The Hill: House Republicans Release Pair of Bills to Preempt State Privacy Laws (April 22, 2026)
  3. IAPP: SECURE Data Act: Analysis of the New Federal Privacy Bill (April 2026)
  4. National Law Review: New Republican SECURE Data Act Offers Middle of the Road Solution (April 2026)
  5. ABA Banking Journal: House Republicans Unveil Data Privacy Bills (April 2026)
  6. Consumer Reports: Statement on the Introduction of the SECURE Data Act (April 2026)
  7. R Street Institute: Congress Has a Fresh Chance to Pass a Comprehensive Data Privacy Law (April 2026)
  8. California Privacy Protection Agency: CPPA Opposes Federal Preemption of State Privacy Laws (2024)