
Waiting for a Better Congress on Data Privacy Won't Work
For years, Congress has failed to establish a national framework for data privacy while states have filled the void with their own privacy laws. Now, lawmakers have another opportunity. The SECURE Data Act, championed by House Republicans, would replace the growing patchwork of state privacy laws with a uniform national standard. But without bipartisan support, Congress will once again fail to enact a federal privacy law, leaving the American digital economy fractured. Lawmakers should seize this opportunity to finally establish a national privacy framework, laying the foundation for progress on related issues, such as artificial intelligence (AI) and children’s privacy and online safety.
Since 2018, more than 20 states have passed laws regulating how businesses collect and use consumers’ personal data. Meanwhile, Congress remains trapped in an unproductive cycle: introducing a new privacy bill, failing to come to a bipartisan and bicameral compromise that works for America, and starting from scratch next Congress.
The SECURE Data Act could break this cycle. It draws heavily from existing state privacy laws in red, blue, and purple states to create a durable privacy framework that would protect consumers while enabling digital innovation that benefits Americans and gives the United States its edge on a global stage. For example, the Act’s data minimization provision—a point of contention among critics who assume that stronger-sounding provisions necessarily produce better outcomes—directly mirrors language found in the majority of state privacy laws and comes to a compromise that preserves many of the beneficial uses of data while still giving consumers greater control.
Similarly, the vast majority of state privacy laws do not contain a private right of action—another point of contention in the federal debate—and instead rely on attorney general enforcement. The SECURE Data Act combines state attorney general enforcement with enforcement by the Federal Trade Commission, providing greater consistency and expert oversight and significantly lower costs than a private right of action. Finally, by preempting state privacy laws, the SECURE Data Act creates a national standard that reduces fragmentation and simplifies data privacy for businesses and consumers.
Another critique of the SECURE Data Act argues that it fails to establish new civil rights protections. However, the same protections should—and often do—apply in the online world as they exist in person. Where gaps remain, Congress should amend existing statutes to explicitly cover online interactions. And the SECURE Data Act does include protections that enable consumers to opt out of automated profiling for significant decisions, such as those related to lending, employment, housing, and health care. It also requires businesses to obtain consumers’ affirmative consent before collecting their sensitive personal information—types of data that have the greatest potential to cause harm, such as racial or ethnic origin, religious belief, mental or physical health diagnosis, sexual orientation, and citizenship or immigration status.
Data privacy is the missing foundation for other important issues, including AI, which relies on large amounts of data, and children’s privacy and online safety. While the Children’s Online Privacy Protection Act (COPPA) has protected personal data collected from children under 13 for nearly 2 decades, children between the ages of 13 and 17 would benefit from a federal privacy law that applies regardless of age and includes extra protections for young people, as the SECURE Data Act does, treating all children’s personal data as sensitive data. Additionally, transparency measures that disclose data practices to consumers would give parents more insight into how online services collect, use, and share their children’s personal data—again, especially data from teenagers who fall outside COPPA’s scope.
There is room for compromise on data privacy. Democrats and Republicans alike should take a closer look at state privacy laws and judge how well those provisions have worked for consumers and businesses in those states. Where gaps exist in the SECURE Data Act, Democrats should take inspiration from the prevailing state models, not from overly restrictive measures coming from Europe that would significantly impair the U.S. economy and weaken its position in the global tech and AI race. Meanwhile, Republicans should remain open to compromises that strengthen protections for consumers without overcomplicating compliance.
Waiting for the next Congress is the wrong move for Democrats, Republicans, and all Americans. Republicans cannot pass a privacy law without Democrat support, even with their current majority. Democrats cannot pass a privacy law without Republican support, even if they gain a majority in the upcoming midterms. The SECURE Data Act closely tracks the model enacted in multiple states across the political spectrum, consolidating state innovation into a strong foundation for a federal privacy law. Either party digging its heels in and refusing to compromise will not help everyday Americans. A federal data privacy framework—one that protects consumers and the economy—would.
