States With Robust Privacy Laws Likely to Oppose Federal Bill

The proposed SECURE Data Act presents a refreshed opportunity to harmonize data protection in the US against a backdrop where many states have passed their own frameworks. While the bill shares some structural and substantive elements with many state laws, it also contains some outliers that could present challenges to its political survival, including preemption of state laws, many of which are now robust.

The Global Standard

The US stands out globally for both its lack of a comprehensive federal privacy regulation and its complex patchwork of privacy laws. As of this year, over 160 countries have enacted national privacy and data protection laws. The EU has been a leader in data protection regulation, with the General Data Protection Regulation fully taking effect in May 2018. The GDPR served as a catalyst for the enactment of national privacy laws across the globe.

Since 2018, countries with large populations such as China, Brazil, India, Thailand, and Saudi Arabia have passed national privacy laws. Despite this trend, historically the US has taken a different path, with our privacy law framework often described as a patchwork quilt, with various state and federal laws that regulate privacy by sector, industry, or type of data.

The State Approach

States have sought to fill the gaps left at the federal level by enacting their own comprehensive privacy laws. California led the way when it enacted the California Consumer Privacy Act in 2018. Virginia then enacted the Virginia Consumer Data Protection Act in 2021, which became a template for other states.

As of July 2026, 23 states have enacted comprehensive privacy laws. Most states generally follow the “Virginia Model” but many deviate slightly with respect to provisions concerning data related to minors, sensitive data, consumer privacy rights, and applicable exemptions.

Possible Obstacles

The House Energy and Commerce Committee introduced the SECURE Data Act in April. While the bill has renewed discussion about a federal path forward, several provisions have garnered opposition from lawmakers and states.

Prominently, as a factual matter, the preemption provision is quite broad, and could preempt not only the 23 comprehensive state privacy laws, but many other related privacy laws developed at the state level over the past two decades. These include laws related to consumer health privacy, data broker regulation, and transparency regarding information practices. Given its breadth, we expect this provision to face pushback, particularly because past federal efforts largely failed for similar reasons.

The bill also provides a limited definition of data broker compared to the current state data broker laws and subjects data brokers to less stringent obligations. The bill requires data brokers to publicly identify as such and to register with the Federal Trade Commission, which is less burdensome than in California, where the state’s one-stop shop for data broker deletion and opt-out requests (known as DROP) is about to become operative. CalPrivacy, the California agency tasked with privacy enforcement, already has voiced its opposition to the SECURE Data Act.

While these types of provisions will face an uphill climb, others are likely to gain bipartisan support. For instance, violations of the law would be enforceable by the FTC and state attorneys general. Empowering state AGs to act as regulators protecting the interests of their constituents may garner more support from state lawmakers who are wary of turning enforcement over entirely to a federal body. In addition, the bill doesn’t provide consumers with a private right of action, which increases the likelihood of passage, as the inclusion of a private right of action has historically been one of the main impediments to the passage of previous federal privacy proposals.

Finally, despite concerns over the preemption of more protective state laws, the SECURE Data Act would create one federal standard for data privacy, alleviating the challenges and high costs organizations face navigating compliance with the complex patchwork of laws currently in force. Further, harmonizing data protection in the US would mark an achievement that legislators have been striving toward for decades.

In its current form, the SECURE Data Act will likely face key challenges from lawmakers and industry stakeholders and may need revision to outlast its predecessors. That said, the legislative momentum in the privacy space as a result of this bill is encouraging, and companies should be following along.

This article does not necessarily reflect the opinion of Bloomberg Industry Group Inc., the publisher of Bloomberg Law, Bloomberg Tax, and Bloomberg Government, or its owners.

Author Information

Aaron P. Simpson is a partner, Danielle Dobrusin is counsel, and Luke Fischer is an associate at Hunton Andrews Kurth.

Interested in writing? Review our author guidelines and submit pitches to Insights@bloombergindustry.com.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *