Federal privacy law gives consumers data rights—but lets companies cure violations repeatedly
H.R. 8413 — SECURE Data Act · Filed by John Joyce (R-PA) · 10 cosponsors · Introduced Apr 21, 2026 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
The SECURE Data Act creates a comprehensive federal privacy framework giving consumers rights to access, delete, and opt out of the sale of their personal data, while establishing a code-of-conduct system administered by independent organizations to help companies comply. It applies to large data collectors (those processing 200,000+ consumers annually with $25M+ revenue, or 100,000+ consumers if 25%+ revenue comes from data sales), exempts healthcare, financial, and government entities, and enforces violations through the FTC and state attorneys general with a 45-day cure period before enforcement action.
Why we flagged it
The bill's core mechanism is establishing enforceable consumer privacy rights (access, deletion, opt-out) and a federal regulatory framework for data handling. While it includes cross-border data flow provisions favoring U.S. commercial interests, the primary functional character is consumer protection, not deregulation or industry carve-out.
What the text implies
- The 45-day cure period before enforcement may allow repeat violators to delay consequences by repeatedly 'curing' the same violation, creating a compliance loophole if not monitored closely.
- The rebuttable presumption for code-of-conduct participants may incentivize companies to join industry-friendly codes rather than comply with the statute directly, potentially weakening enforcement.
The full analysis lists 5 implications of this text.
Who stands to gain
Independent organizations administering codes of conduct; Compliance and privacy technology vendors; Data brokers (via code-of-conduct safe harbor)