Summary#
This bill, the SECURE Data Act, creates a national framework for consumer privacy and protection of personal data. It defines consumer rights (access, correction, deletion, portability, and the right to opt out of targeted advertising, the sale of personal data, and automated profiling decisions with legal or similarly significant effects). It requires consent for processing sensitive data, with special rules for children and teens. The bill sets rules for controllers and processors about data minimization, purpose limits, notices to consumers, security practices, and non-discrimination. It requires data brokers to post notices and to register with the Federal Trade Commission (FTC). The bill also covers deidentified and pseudonymous data, establishes a process for codes of conduct, addresses cross-border data flows, and directs a study on universal opt-out tools. Enforcement is primarily through the FTC and state attorneys general, includes a required notice-and-cure period, and the Act generally preempts state laws. The Act mostly takes effect two years after enactment, with consumer rights, data security, and data broker rules taking effect after one year.
What it means for you#
- If you are a consumer: You can ask companies whether they process your personal data and get a copy (unless it would reveal a trade secret); you can correct or delete data you provided; you can request a digital copy you gave to a company in a portable format; and you can opt out of targeted advertising, the sale of your personal data, and fully automated profiling decisions that have legal or similar effects. Parents must exercise rights for children and teens in many cases. Companies must publish clear privacy notices explaining what data they collect, why, and who they share it with.
- If you are a business that controls or processes personal data: You must limit data collection to what is necessary, avoid incompatible secondary uses without consent, provide clear privacy notices, adopt reasonable data security practices, support consumer requests, and not discriminate against people who exercise their rights. Processors must follow controller instructions and have written contracts with certain minimum terms. Data brokers must post notice that they are data brokers, publish how to exercise consumer rights, and register with the FTC within 12 months and annually thereafter.
- Deadlines and procedures: Controllers generally must respond to consumer requests without undue delay and no later than 45 days (with a possible 45-day extension); appeal decisions must be handled within 60 days. The bill includes a notice-and-cure process giving companies at least 45 days after written notice to fix alleged violations before enforcement actions proceed.
Expenses#
The bill requires data brokers to pay a registration fee set by the Commission and includes other administrative requirements (for example, costs to implement data-security practices, notices, or compliance programs). No publicly available information about specific dollar costs, estimated budget changes, or fee amounts is included in the bill text or metadata provided.
Proponents' View#
No publicly available information.
Opponents' View#
No publicly available information.