Home>Articles>The SECURE Data Act Isn’t So Secure for State Sovereignty

Congress (Photo: House.gov)

The SECURE Data Act Isn’t So Secure for State Sovereignty

The bill provides no private right of action of its own; enforcement runs through the FTC and state attorneys general only

By Jay Rogers, August 5, 2026 7:00 am

Congress calls it the SECURE Data Act. Californians should read it as a preemption bill wearing a privacy label.

Rep. John Joyce (R-Pa.) introduced H.R. 8413 in April, and it would build the first federal law covering the full sweep of consumer privacy rights. That’s a fine goal. A patchwork of twenty-plus state statutes is a genuine compliance burden, and I’ve spent three decades advising firms that build separate data-handling protocols for California, Virginia, Colorado, and a dozen other jurisdictions, each with a slightly different definition of “sensitive data.” A single federal floor would save money. That’s the strongest argument for the bill, and the Republicans backing it aren’t wrong to make it.

But Section 15 doesn’t set a floor. It sets a ceiling wide enough to cover the whole roof.

The preemption clause bars any state from prescribing, maintaining, or enforcing a law that “relates to the provisions of this Act.” Lawyers who’ve spent a career litigating ERISA preemption know exactly what that phrase does. “Relates to” is not “conflicts with.” It doesn’t require an actual clash between state and federal law, only a connection to the same subject matter, however loose. Courts have read ERISA’s nearly identical language broadly enough to knock out state laws Congress never intended to touch. There’s no reason to expect a narrower result here.

Applied to California, that standard doesn’t lightly graze the California Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA). It guts them. The California Privacy Protection Agency’s audit authority, the state’s one-click data broker deletion mechanism, its rules on automated decision-making, and its private right of action for data breaches all “relate to” the subjects H.R. 8413 covers. Every one of them would likely fall. The bill provides no private right of action of its own; enforcement runs through the FTC and state attorneys general only. Voters approved the CPRA by ballot initiative in 2020. A federal statute preempting it by implication, through six words buried in Section 15, would erase that vote without ever mentioning it. The California Privacy Protection Agency has already said as much in a formal letter opposing the bill.

This is where the fiduciary in me starts asking questions the political debate skips. I sit on the other side of data-handling obligations every working day: the Gramm-Leach-Bliley Act, state breach-notification statutes, custodial requirements that vary by jurisdiction for the ultra-high-net-worth families and institutions I advise. A federal floor that preempted conflicting requirements and left states free to layer stricter protections on top would be a real improvement. That’s how Congress has handled preemption in plenty of other regulatory contexts. It chose not to do that here.

The deeper problem isn’t partisan. It’s structural. The Tenth Amendment reserves to the states the powers the Constitution doesn’t delegate to Congress, and consumer protection has always sat in that reserved space. Congress can regulate interstate commerce under Article I, and data flows across state lines easily enough to fall within that power. But the Commerce Clause has never been read to let Congress commandeer an entire field of consumer protection, extinguishing every state law that touches the same general subject, without so much as a floor-versus-ceiling choice left for states to make. A bill that wants genuine federal uniformity can say so directly: set the standard and let states enforce anything stricter that doesn’t directly conflict. H.R. 8413 does the opposite. It reaches for “relates to” specifically because that language sweeps broader than “conflicts with.” Six words in Section 15 would reorder more California law than Sacramento manages in a typical legislative session, and most of Sacramento hasn’t noticed yet.

Whether the current Supreme Court would sustain that kind of preemption is an open question, and not a comfortable one for conservatives to sit with. The same jurisprudential tools that would let a future Congress override California’s privacy law under a “relates to” standard would let a future Congress override a state’s parental rights law, a state’s religious liberty exemption, or a state’s firearms protections using the identical mechanism. Federalism isn’t a switch conservatives get to flip on for California and off for Texas. The doctrine has to bind Congress regardless of who holds the gavel, or it isn’t federalism. It’s outcome preference wearing a constitutional label.

GovTrack currently gives H.R. 8413 a one percent chance of becoming law this Congress, so nobody should mistake this for an emergency. But federal privacy legislation is coming back in full force, in some form, with some sponsor, for at least the next decade. When it does, the preemption clause deserves the same scrutiny state legislators would give any bill that tried to override their laws without saying so plainly. “Relates to” isn’t a floor. It’s an eviction notice with good public relations.

Print Friendly, PDF & Email
Spread the news:

 RELATED ARTICLES

Leave a Reply

Your email address will not be published. Required fields are marked *