Referred to the Committee on Energy and Commerce, and in addition to the Committee on the Judiciary, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
The SECURE Data Act establishes a federal data privacy framework that gives consumers rights to access, correct, delete, and port their personal data, as well as opt out of targeted advertising and data sales, with companies required to respond to requests within 45 days. The law applies to companies doing business in the U.S. that collect data on 200,000 or more consumers annually with at least $25 million in revenue, or 100,000 or more consumers where at least 25 percent of revenue comes from selling data, though it exempts government agencies, financial institutions, healthcare providers, and entities already covered by laws like HIPAA and FERPA. The bill requires data processors to implement safeguards and follow controllers' instructions, allows companies to adopt approved industry codes of conduct that provide a presumption of compliance, and includes exceptions for law enforcement cooperation, legal defense, and approved scientific research. Most provisions take effect two years after the law is enacted, though core consumer rights to access and delete data and restrictions on sensitive data processing apply one year after enactment, giving companies time to adjust their practices. The law preempts all state and local privacy laws, establishing uniform federal standards across the country.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.