House Panel Debates Legislation On Federal Data Privacy

June 22, 2026 8:46 pm

Source: site

House lawmakers are sharply divided over new Republican-backed federal privacy legislation that would set a single national standard for personal data, preempting most state privacy laws and creating a separate regime for financial institutions. The debate centers on the SECURE Data Act and the GUARD Financial Data Act, with Republicans emphasizing uniformity and business certainty and Democrats and advocates warning about the loss of stronger state protections and limits on enforcement.

What the House Panel Is Debating

At a recent hearing titled “Examining Legislation to Establish a Federal Comprehensive Privacy and Data Security Law,” the House Energy and Commerce Subcommittee on Commerce, Manufacturing, and Trade took up H.R. 8413, the SECURE Data Act. The session highlighted deep partisan splits over whether Congress should override the growing patchwork of state privacy statutes in favor of a uniform federal framework.

Republican leaders on Energy and Commerce presented the SECURE Data Act as the culmination of more than a year of work by the committee’s Data Privacy Working Group, which was formed in early 2025 to “reset” the privacy debate after earlier bipartisan efforts stalled. At the same time, the House Financial Services Committee is advancing the GUARD Financial Data Act, which would modernize the Gramm‑Leach‑Bliley Act (GLBA) regime for financial institutions and customer financial data.

Overview of the SECURE Data Act

The Securing and Establishing Consumer Uniform Rights and Enforcement over Data (SECURE Data) Act is designed as a comprehensive federal privacy law covering non‑financial entities that control and process personal data. It would create a nationwide privacy and data security standard that expressly preempts nearly all overlapping state privacy obligations, replacing the current patchwork of more than 20 state comprehensive privacy laws.

Republican sponsors describe the bill as “pro‑innovation” and small‑business‑friendly, asserting that it incorporates the “best of” state privacy frameworks while avoiding conflicting mandates. The bill builds around familiar consumer data rights but omits several elements popular with privacy advocates, such as a private right of action or mandatory data protection impact assessments and data protection officers.

Key Consumer Rights in the SECURE Data Act

Under the SECURE Data Act, consumers would receive a core bundle of federal privacy rights that parallel, but do not fully replicate, leading state laws. These rights include:

  • The right to know that personal data is being collected and used.

  • The right to access their personal data, including in a portable format.

  • The right to delete personal data held by covered entities.

  • The right to opt out of targeted advertising, the sale of personal data, and certain automated decisions.

  • A requirement that sensitive data be processed only with the consumer’s consent, and that children’s and teens’ data be processed only with parental consent.

Children’s data under age 13 is expressly treated as “sensitive,” aligning it with categories such as health and geolocation data, and triggering heightened protections under the bill. For consumers, these rights would apply uniformly across the country, regardless of where they live or which state framework is currently in force.

Obligations on Businesses and Data Brokers

On the business side, the SECURE Data Act imposes several baseline duties on covered entities designed to implement privacy by design without mirroring the more aggressive requirements found in some state laws. Covered companies must limit collection of personal data to what is “adequate, relevant, and reasonably necessary” for the purposes they disclose to consumers, and they must implement reasonable data security practices.

The bill also creates a federal data broker regime overseen by the Federal Trade Commission (FTC). Data brokers would have to register with the FTC, describe their privacy and security practices, and disclose the types of personal data they sell, with the FTC maintaining a public, searchable registry so consumers can learn where their data is being traded and how to exercise their rights.

Preemption of State Privacy Laws

Preemption is the flashpoint of the House debate. The SECURE Data Act would preempt almost all state comprehensive privacy laws and many related sectoral protections that touch personal data. Republicans argue that eliminating the state patchwork is necessary to reduce compliance costs, resolve conflicting requirements, and create clear expectations for both businesses and consumers.

Democrats and civil‑liberties advocates, however, have criticized the bill as “weaker than the weakest state law,” warning that it would nullify stronger protections in states like California, Connecticut, Illinois, and Washington. Opponents are particularly concerned that the bill would override statutes such as California’s Delete Act, Connecticut’s Delete‑inspired law, Illinois’ Biometric Information Privacy Act (BIPA), and Washington’s My Health, My Data Act, each of which currently imposes aggressive obligations around deletion, biometrics, and health data.

Enforcement Structure and Notable Omissions

The SECURE Data Act relies primarily on federal and state public enforcement rather than private lawsuits. The FTC would serve as the lead federal enforcer, with state attorneys general authorized to bring actions on behalf of residents, a structure broadly consistent with other consumer protection regimes.

The draft notably omits a private right of action, as well as mandated data protection impact assessments, data protection officers, or universal opt‑out mechanisms that many privacy advocates see as critical in modern privacy regimes. Critics argue these omissions will limit both deterrence and consumers’ practical ability to vindicate their rights, especially in comparison to enforcement models in California and under the EU’s General Data Protection Regulation (GDPR).

The GUARD Financial Data Act and GLBA Modernization

In parallel, House Financial Services leaders introduced the GUARD Financial Data Act to update the GLBA framework for financial institutions. This bill would apply to financial institutions and financial data traditionally regulated by GLBA, effectively carving financial services out of the SECURE Data Act’s non‑financial scope.

According to the sponsors, the GUARD Financial Data Act would minimize financial data collection and disclosures, give customers and former customers a right to access the financial data held about them, and let former customers request deletion of their data. It also would require financial institutions to obtain affirmative opt‑in consent before disclosing sensitive personal information, positioning the bill as a modernization of GLBA tailored to the current data‑driven financial ecosystem.

Political Dynamics and Prospects

The House debate reflects a broader history of stalled federal privacy efforts, including the American Data Privacy and Protection Act in 2022 and the American Privacy Rights Act in 2024, both of which failed to reach the finish line. Unlike those prior attempts, the SECURE Data Act and GUARD Financial Data Act are Republican‑only initiatives that did not include Democratic co‑authors, setting up a partisan clash from the outset.

Analysts note that while the SECURE Data Act may have a viable path through the House, its prospects in the Senate are uncertain given concerns over preemption strength, enforcement tools, and the absence of a private right of action. Privacy and civil‑rights organizations are already signaling opposition and calling for a stronger, more rights‑protective federal standard, suggesting significant negotiations would be needed for any final bill to clear both chambers.

Implications for Credit, Collections, and Financial Services

For credit and collection firms, a two‑track federal framework would reshape compliance planning. Non‑bank servicers, data aggregators, and third‑party collection agencies could fall primarily under the SECURE Data Act, while banks and GLBA‑covered entities would operate under GUARD‑modernized GLBA requirements. The move toward uniform federal standards could alleviate some complexity created by diverging state privacy laws, but it may also remove stronger consumer protections in key jurisdictions that have driven industry data‑handling practices.

For consumer financial protection stakeholders, the bills raise questions about how new federal privacy rights will interact with existing obligations under statutes such as the FCRA, FDCPA, and other consumer protection laws enforced by federal regulators. The outcome of the House and eventual Senate debates will determine whether the United States finally moves to a comprehensive national privacy regime, and whether that regime enhances or diminishes the protections many consumers have come to expect from leading state laws.

© Copyright 2026 Credit and Collection News