A wooden judges gavel resting on a dark polished surface with the scales of justice visible in soft focus behind it
Photo via Unsplash

TL;DR: Two federal privacy bills are competing in the 119th Congress. HR 8413, the SECURE Data Act, would preempt every state privacy law in America and replace it with a weaker federal floor. HR 8014, the Online Privacy Act, would set a federal floor and let state laws go further [1][2]. The House Energy and Commerce Subcommittee on Commerce, Manufacturing, and Trade held its first hearing on HR 8413 on June 3, 2026. HR 8014 has not received an equivalent hearing [3]. No committee markup has compared the two bills side by side. This is the comparison the committee should have done before it writes a federal floor: who wins, who loses, and which industries are lobbying for which outcome.

The Two Bills, in One Paragraph Each

HR 8413, the SECURE Data Act (sponsored by Rep. Brett Guthrie, R-KY, introduced April 22, 2026), would establish a federal consumer data privacy framework, preempt every state consumer privacy law, strip the private right of action that exists in states like California and Illinois, give companies a 45-day cure period before any enforcement action, and explicitly authorize companies to process "sensitive data" including precise geolocation, biometric, and health data for "operational purposes" without opt-in [4][5].

HR 8014, the Online Privacy Act (introduced in the 119th Congress with bipartisan co-sponsorship), would also establish a federal consumer data privacy framework, but it sets a minimum floor and explicitly preserves the right of states to enact and enforce stronger protections [2][6]. The text analyzed by the Future of Privacy Forum maintains a private right of action for certain violations, requires explicit opt-in for sensitive data including precise geolocation and biometric data, and gives state attorneys general primary enforcement authority [6].

Both bills claim to give Americans a national privacy standard. The difference is whether that standard is a ceiling that caps what states can do, or a floor that lets states keep going.

The Eight Axes That Matter

Side-by-side comparisons of privacy bills tend to drown the reader in cross-referenced subsections. Here is the compressed version, on the eight axes that decide whether a bill protects you or just looks like it does.

1. Preemption of State Laws

HR 8413: Express preemption of "any provision of any law or regulation of a State or political subdivision thereof" that covers the same ground as the federal framework [4]. Twenty-one state consumer privacy laws get cut off at the root. The California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), Illinois BIPA on its privacy side, Vermont's data broker law, Washington's My Health My Data Act, the Texas Data Privacy and Security Act, the Colorado Privacy Act, and the rest [1][4][5].

HR 8014: Express non-preemption. State laws that are "more protective" of consumer privacy are preserved [2][6]. A state AG can still enforce its own statute. A consumer in California still has CCPA rights. A consumer in Illinois still has BIPA rights. The federal floor is the worst-case scenario for that state's residents, not the only-case scenario.

Who wins: HR 8014, decisively. Privacy advocates, every state AG, and 21 state legislatures win under 8014. The industries that want one national rulebook win under 8413.

2. Private Right of Action (Your Right to Sue)

HR 8413: No private right of action. Enforcement is exclusively by state attorneys general and the FTC [4][5]. The California Privacy Protection Agency, the Illinois AG, the Texas AG: those are the only people who can sue on your behalf. The statutory damages provision that makes class actions economically viable in California and Illinois is gone [4].

HR 8014: Limited private right of action for certain violations, including data breach claims and unauthorized disclosure of sensitive personal information [6]. Statutory damages are available. The bar is higher than California's current regime, but the door is open.

Who wins: Consumers, under HR 8014. Industry counsel, under HR 8413, where the only realistic enforcement threat is an AG with limited budget and political incentives to bring a case.

3. The 45-Day Cure Period

HR 8413: Companies receive a 45-day cure period after receiving notice of a violation, during which no enforcement action can be brought [4][5]. This is the cure-period language that was in the 2022 ADPPA, the federal bill that died in the Senate in 2023 over this exact provision. Privacy advocates call it a "get out of jail free" card. Industry calls it a chance to fix mistakes.

HR 8014: No across-the-board cure period for substantive violations [6]. Notice-and-cure is preserved only for procedural violations (failure to publish a privacy notice, failure to maintain records), not for substantive privacy harms.

Who wins: Industry, under HR 8413. The cure period effectively turns the first 45 days of any AG investigation into a free compliance window, after which the company can argue the violation has been remedied and seek dismissal. The 2022 ADPPA lost the civil-society coalition over this provision. HR 8413 brought it back.

4. Sensitive Data and Opt-In

HR 8413: Defines "sensitive data" to include government identifiers, financial account credentials, precise geolocation, biometric data, genetic data, health data, sex life or sexual orientation, citizenship/immigration status, and a child's personal information [4]. But the bill allows processing of sensitive data for "operational purposes" without affirmative opt-in [4]. The opt-in right is preserved, but the carve-out is broad enough to cover most of what companies actually want to do with the data.

HR 8014: Defines "sensitive personal information" with a similar list, and requires explicit opt-in consent before processing [6]. The "operational purposes" carve-out is narrower, and any subsequent change in purpose requires renewed opt-in.

Who wins: Consumers, under HR 8014. The opt-in versus operational-purpose carve-out is the single biggest substantive difference between the two bills for everyday data: location, biometrics, health.

5. Data Minimization

HR 8413: Requires "reasonable" data minimization, with a safe harbor for processing that is "reasonably necessary and proportionate" to provide the product or service [4]. The "reasonably necessary" framing is industry-friendly: the company defines necessity.

HR 8014: Requires data minimization to be "reasonably necessary, appropriate, and limited" to the disclosed purpose, with stricter limits on secondary uses [6]. The "appropriate" qualifier gives AGs and courts a real handle for challenges to bulk collection practices.

Who wins: Marginal difference. Both bills are weaker than the GDPR's strict-necessity standard. HR 8014's "appropriate" language gives regulators a slightly stronger hand. HR 8413's "reasonably necessary" framing is closer to the safe-harbor language in the ADPPA.

6. AI Training and Automated Decisionmaking

HR 8413: The text analyzed by EFF does not explicitly address AI training or automated decisionmaking [1][4]. The omission effectively preserves the status quo: companies can train AI on user data under the bill's general processing framework. Section 4 of HR 8413, the operational purposes section, does not exclude training, fine-tuning, or evaluation [4].

HR 8014: Requires opt-out for AI training on user-submitted content, and requires disclosure when an automated decisionmaking system materially affects a consumer's access to housing, employment, credit, healthcare, or insurance [2][6]. Algorithmic discrimination is on the books, with a private right of action tied to the discrimination finding.

Who wins: Consumers, under HR 8014. The AI training question is the biggest story in U.S. privacy law right now, and HR 8413 is silent on it. HR 8014 at least puts the disclosure obligation on the table. Neither bill is as strong as the Colorado AI Act or California's AB 2013, but only HR 8014 acknowledges the issue.

7. Enforcement: Who, How, and How Fast

HR 8413: Primary enforcement by state attorneys general, with concurrent FTC jurisdiction. Civil penalties up to $50,000 per violation. No private right of action [4]. Cure period delays real action.

HR 8014: Primary enforcement by state AGs and the FTC, with a limited private right of action for data breach and unauthorized disclosure of sensitive data [6]. Civil penalties up to $50,000 per violation, plus statutory damages for the private claims.

Who wins: Taxpayers, marginally, under HR 8413, in that the AGs are funded. Consumers, under HR 8014, in that they can hire their own lawyer. The actual enforcement track record for federal privacy law is mixed: the FTC's 23 privacy cases in the last decade produced meaningful settlements, but the agency's budget is a fraction of what the AGs collectively spend on state-level privacy enforcement.

8. Preemption of Sectoral Laws (HIPAA, GLBA, COPPA)

HR 8413: Preserves existing sectoral laws, including HIPAA, GLBA, and COPPA [4]. Sectoral carve-outs are necessary but narrow. Most consumer-facing data is not covered by sectoral law.

HR 8014: Same sectoral carve-outs [6].

Who wins: Tie. Both bills preserve the sectoral framework. This is the one axis where the bills agree.

Who Is Lobbying for What

The lobbying coalitions on each side are not hard to read once you know what to look for.

For HR 8413: The Software & Information Industry Association (SIIA, now called SIIA | The Association of Software Publishers), the Consumer Technology Association (CTA, the trade group that runs CES), the U.S. Chamber of Commerce, the Internet Association (now folded into CCIA), and the major ad-tech trade associations have all filed comments or made public statements supporting a federal preemption bill, with HR 8413 as the working text [4][7]. The argument is consistent: a single national rule is cheaper to comply with than 21 state rules. They are not wrong about the compliance cost. They are wrong that the cheapest compliance cost is the right public policy.

For HR 8014: Consumer Reports, the Future of Privacy Forum (with caveats), and most state AGs have filed in support of non-preemption language [2][6]. The argument: a federal floor that allows stronger state protections preserves the experimentalist dynamic that has driven most privacy progress in the last five years. California's Delete Act, Washington's My Health My Data Act, Colorado's AI Act, Texas's data broker law: all of them passed at the state level because state legislatures had room to move.

Against HR 8413, broadly: The California Privacy Protection Agency, the Electronic Frontier Foundation, the Electronic Privacy Information Center, the American Civil Liberties Union, Public Knowledge, Consumer Reports, and 19 state attorneys general (Democrat and Republican) have filed joint or individual comments opposing the preemption language in HR 8413 [1][5][7].

The shape of the coalition tells you what you need to know. The preemption coalition is industry. The anti-preemption coalition is civil society, state government, and a bipartisan AG alliance. There is no consumer-facing organization of any size that has filed in support of HR 8413 as written.

What the June 3 Hearing Actually Said

The House Energy and Commerce Subcommittee hearing on June 3, 2026, on HR 8413 ran just over two hours. Three themes came out of the testimony [3].

Industry witnesses argued that a federal preemption bill is the only path to "regulatory certainty," a phrase that appears 14 times in the hearing transcript [3]. The witnesses did not address the cure period question directly, but their written submissions did, and the position is consistent: a 45-day cure window is "industry best practice" and the federal bill should codify it.

Civil-society witnesses (representing EFF, EPIC, and the California Privacy Protection Agency) argued the opposite: a federal preemption bill that does not preserve state enforcement and does not include a private right of action will be weaker than the state laws it replaces, and "regulatory certainty" is a euphemism for "less enforcement" [1][3][5].

Subcommittee members from both parties asked pointed questions about the cure period and the private right of action, but did not commit to amendments [3]. The committee markup, which is where the bill text gets rewritten, has not been scheduled. Industry and civil-society submissions for the hearing record closed on June 10, 2026, and the next open question is whether the subcommittee will hold an HR 8014 hearing before markup, or whether HR 8413 will go to markup as the standalone vehicle [3].

What You Stand to Lose Under HR 8413

For people who already live under state privacy laws, the list of what HR 8413 would preempt is the list of what you currently have. The 21 laws are not identical, but the strongest features are common to most of them [4][5][7].

  • California's right to delete and right to correct, and the California Privacy Protection Agency's dedicated enforcement budget and rulemaking authority, are preempted by HR 8413 [4][5]. California's Delete Act, the state-level data broker deletion tool that goes into effect August 1, 2026, is in the crosshairs [4].
  • Illinois BIPA's per-violation statutory damages ($1,000 negligent, $5,000 intentional, per violation) are the only biometric privacy damages regime in the country with a private right of action. HR 8413 preempts the privacy side of BIPA, and the damages regime goes with it [4].
  • Washington's My Health My Data Act requires opt-in for health-adjacent data that is not covered by HIPAA. HR 8413 preempts it, and consumer health data goes back to opt-out [4].
  • Colorado's AI Act algorithmic-discrimination provisions go into effect June 30, 2026. HR 8413 does not address AI, but its general preemption clause reaches Colorado's law because algorithmic discrimination is treated as a form of consumer data processing [4].
  • Texas's data broker registration requirement and the Vermont data broker law, both of which are funded by registration fees and dedicated to enforcement, lose their dedicated funding under HR 8413 [4].

For people who do not live under a state privacy law, the difference between the two bills is smaller, because they have less to lose. But the difference is not zero: HR 8014's opt-in for sensitive data, its algorithmic-discrimination provision, and its data-breach private right of action would all be new federal rights for residents of states without comprehensive privacy laws.

What HR 8014 Does Better, Specifically

HR 8014 is not a perfect bill. It is weaker than the California Privacy Protection Agency's enforcement model, weaker than the GDPR in several respects, and weaker than the Colorado AI Act on automated decisionmaking [6]. But on the specific axes where HR 8413 fails, HR 8014 does better [2][6].

  • Non-preemption. State laws go further, with state AGs and (limited) private rights of action preserved.
  • Opt-in for sensitive data. No broad "operational purposes" carve-out.
  • Limited private right of action. Real access to courts for data breach and unauthorized sensitive-data disclosure.
  • No 45-day cure period for substantive violations.
  • Algorithmic-discrimination disclosure for material decisions in housing, employment, credit, healthcare, and insurance.
  • AI training opt-out for user-submitted content.

It is not the privacy bill civil society would write from scratch. It is the bill that does not require you to lose the rights you already have in order to gain a federal floor that you would otherwise get from a non-preemption clause.

The Political Math

HR 8413 has the votes in the House Energy and Commerce Committee, where Republicans hold a 29-23 majority [3]. It does not have the votes in the Senate, where bipartisan support for a preemption bill has not materialized. The Senate Commerce Committee, with jurisdiction over federal privacy legislation, has been the graveyard of two previous preemption bills (the 2022 ADPPA and the 2024 APRA), and a third is not expected to clear the committee without substantial changes to the preemption language [3].

HR 8014's coalition is bipartisan in the House and the Senate, with co-sponsors from both parties, but the bill has not received a hearing and is not on a markup schedule [3]. The procedural question is whether the subcommittee will hold a hearing on HR 8014 before it marks up HR 8413, or whether HR 8413 will move to markup alone.

The most likely scenario, as of June 11, 2026, is that the subcommittee holds an HR 8413 markup in the next two weeks, the bill passes the committee on a party-line vote, and the bill goes to the House floor where it either passes narrowly or fails. The Senate is not expected to take up HR 8413 as written. The fallback is a conference process that could produce something closer to HR 8014, or that could collapse and leave the state laws intact for another year [3].

What to Watch in the Next Two Weeks

Three dates to keep on your calendar, all of which will tell you where this is going.

  • The subcommittee markup date for HR 8413. Watch the amendments. If the bill comes out of markup with the cure period preserved and the preemption language intact, the industry's win is locked in. If the cure period is narrowed or the preemption language is softened, civil society won something.
  • Any HR 8014 hearing announcement. A hearing for HR 8014 would be the first signal that the committee is willing to do the side-by-side comparison it has not yet done. The absence of a hearing, on the other hand, would tell you the committee has decided to move HR 8413 alone.
  • The 19 state AG comments on the hearing record, due June 10, 2026. The bipartisan AG coalition (Democrat and Republican) has been the most effective voice on preemption in 2024 and 2025. A joint statement, or a coordinated set of individual filings, would be the strongest signal that HR 8413's preemption language is politically radioactive in the states [3][7].

What You Can Do

If you are a constituent of a House Energy and Commerce Committee member:

  • Call your representative and tell them you support a federal privacy bill that sets a floor, not a ceiling. The Subcommittee on Commerce, Manufacturing, and Trade has jurisdiction. The members to focus on are the 29 Republicans, of whom 18 represent competitive seats where constituent pressure on privacy cuts in unpredictable directions. The number is 202-224-3121 for the Capitol switchboard. The script is on 5Calls.
  • Submit a comment to the hearing record. The June 3 hearing record is still open for written submissions. The submission portal is on the House Energy and Commerce Committee website. The committee accepts comments from individuals, not just organizations. The EFF has a template you can adapt.

If you are a privacy professional:

  • Brief your trade association on the AI training and algorithmic-discrimination gaps in HR 8413. The industry trade associations have been telling members that HR 8413 is "comprehensive." It is not. It is silent on the biggest consumer-privacy fight of 2026.
  • File comments on the state side. The Colorado AI Act implementation guidance is open for comment. The California Privacy Protection Agency's draft regulations on automated decisionmaking are open for comment. The state-level fights matter more than the federal one if HR 8413 passes.

If you are a state legislator or staffer:

  • Track the AG filings on the hearing record. The bipartisan AG coalition is the most credible voice on preemption. A strong filing from your state's AG gives you a model for state-level pushback in the markup.
  • Pass a state law while you still can. HR 8413 preempts "any provision of any law." Bills introduced in state legislatures this session are not preempted retroactively, but bills introduced after the federal bill takes effect are. The window is closing.

The Bottom Line

One bill preserves what you have. The other takes it away. The House Energy and Commerce Subcommittee has not done the side-by-side comparison. The industry coalition that supports HR 8413 has done it, and decided that the public does not need to see it. The civil-society coalition that supports HR 8014 has done it, and decided that the public needs to see both bills named.

The two bills share a name ("Privacy Act" in some form), share a goal (a federal privacy standard), and share a sponsor count (broad bipartisan interest). They diverge on every operational axis. The choice is not between federal privacy and no federal privacy. The choice is between a federal floor that respects state authority, and a federal ceiling that kills it.

The bill that does the killing is named with the word "SECURE." The bill that does not is named with the word "Online." Neither name is informative about what the bill does. Read the text. The text is what matters.

Sources

  1. Electronic Frontier Foundation: "The SECURE Data Act is Not a Serious Piece of Privacy Legislation" (May 2026)
  2. Congress.gov: H.R. 8014, Online Privacy Act (119th Congress)
  3. House Energy and Commerce Subcommittee on Commerce, Manufacturing, and Trade: June 3, 2026 hearing record on HR 8413 (written submissions open through June 10, 2026)
  4. Congress.gov: H.R. 8413, SECURE Data Act (119th Congress, introduced April 22, 2026, sponsor Rep. Brett Guthrie, R-KY)
  5. California Privacy Protection Agency: public comments on federal privacy preemption proposals, 2025-2026
  6. Future of Privacy Forum: analysis of federal privacy proposals, 2026 cycle, including HR 8014 framework and non-preemption provisions
  7. Electronic Privacy Information Center (EPIC): federal privacy preemption campaign and coalition statements, 2024-2026