---
title: "Comparing Recent Federal Data Privacy Bills"
summary: |-
  As Congress considers a national data privacy standard, the SECURE Data Act represents a significant shift from earlier proposals. This comparison examines how it differs from the American Privacy Rights Act and the American Data Privacy and Protection Act and why those differences matter for consumers, businesses, and innovation.
date: "2026-07-29"
issues: ["Internet", "Privacy"]
authors: ["Ash Johnson"]
content_type: "Blogs"
canonical_url: "https://itif.org/publications/2026/07/29/comparing-recent-federal-data-privacy-bills/"
---

# Comparing Recent Federal Data Privacy Bills

For the past several years, Congress has been locked in a debate over how to safeguard Americans’ data privacy. Each new Congress has put forth its own solution to this pervasive privacy problem, from the 117th Congress’ [American Data Privacy and Protection Act](https://www.congress.gov/bill/117th-congress/house-bill/8152/text) (ADPPA) in 2022, the 118th Congress’ [American Privacy Rights Act](https://www.congress.gov/bill/118th-congress/house-bill/8818/text) (APRA) in 2024, and now the 119th Congress’ [SECURE Data Act](https://www.congress.gov/bill/119th-congress/house-bill/8413/text), introduced earlier this year.

As Congress works toward a federal data privacy standard, the United States continues to rely on a patchwork of sector-specific and [state laws](https://itif.org/publications/2022/01/24/looming-cost-patchwork-state-privacy-laws/) to govern data privacy, leading to ever-increasing compliance costs and confusion. Congress should act quickly to establish a bipartisan national privacy framework that builds on state consensus and preempts the state patchwork. The SECURE Data Act provides a strong foundation for that framework, and a look-back at previous bills demonstrates just how far the federal debate has come.

# Consumer Rights

The SECURE Data Act, APRA, and ADPPA all grant consumers the right to access, port, rectify, and delete their personal data collected by data controllers—entities that make decisions about how to collect and process consumers’ personal data. APRA and ADPPA’s rights to rectify and delete personal data also include requirements for data controllers to notify third parties with which they shared the data of the correction or deletion request.

# Consent Requirements

Another area of overlap between the SECURE Data Act, APRA, and ADPPA is the three bills’ shared two-tiered consent structure, designed to strike a balance between protecting consumers, giving them greater control, and enabling innovation through data. This approach requires data controllers to obtain affirmative, or opt-in, consent to process sensitive data and teens’ personal data and allow consumers to opt out of data processing for all other forms of personal data.

APRA and ADPPA extend this opt-in requirement to all minors under age 17, whereas the SECURE Data Act limits it to teens ages 13 to 16. In practice, these provisions are the same, as existing [children’s privacy law](https://www.ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa) already requires covered entities to obtain affirmative consent to collect personal data from children under 13.

When it comes to consent requirements, the primary difference between APRA and ADPPA compared to the SECURE Data Act is that they would establish a universal opt-out mechanism that would allow individuals to opt out of all covered data transfers. This would likely encourage consumers to broadly restrict data sharing without considering the [societal implications](https://itif.org/publications/2017/10/06/economics-opt-out-versus-opt-in-privacy-rules/) of their decision or the more granular controls available to them, undermining the compromise of the two-tiered approach. The SECURE Data Act commissions a study into universal opt-out mechanisms but does not establish one.

# Data Controller Obligations

There are differences in the obligations the SECURE Data Act, APRA, and ADPPA would impose on data controllers. All three bills require controllers to implement reasonable data security practices, but APRA and ADPPA prescribe specific minimum requirements, which the SECURE Data Act does not. By avoiding prescriptive requirements, the SECURE Data Act gives organizations of all types and sizes increased flexibility to determine what security practices will best protect consumers’ data depending on the level of risk.

To promote transparency into controllers’ data practices, APRA and ADPPA require controllers to maintain privacy policies containing certain information relevant to consumers and notify users when making material changes to those privacy policies. Both bills impose additional requirements on large data holders, including impact assessments and audits. The SECURE Data Act, meanwhile, requires that data controllers provide much of the same information in a notice to consumers. Once again, avoiding prescriptive requirements as much as possible gives organizations flexibility to determine how best to provide necessary information to consumers.

For the most part, existing civil rights law applies the same online as it does in face-to-face interactions. The most recent draft of APRA and the SECURE Data Act do not impose any additional requirements on top of these existing legal obligations. ADPPA requires impact assessments and evaluations of “covered algorithms”—algorithms that make or facilitate decisions using consumers’ personal data—that pose a “consequential risk of harm” to consumers, a significant and costly undertaking.

Finally, while the SECURE Data Act, APRA, and ADPPA all include data minimization provisions, which require data controllers to collect no more data than is necessary to meet specific needs, APRA and ADPPA use a much stricter standard, limiting personal data collection to that which is “necessary and proportionate” to provide or maintain a specific product or service. The SECURE Data Act instead uses the standard [most state privacy laws](https://itif.org/publications/2026/06/03/state-of-privacy-lessons-from-state-laws-for-national-framework/) use, limiting personal data collection to that which is “adequate, relevant, and reasonably necessary.” Data minimization requirements [carry high costs](https://itif.org/sites/default/files/2019-cost-data-privacy-law.pdf) by reducing access to data, limiting data sharing, and constraining its use, and the stricter the standard, the higher those costs will be.

# Enforcement

The SECURE Data Act, APRA, and ADPPA all grant enforcement power to the Federal Trade Commission and state attorneys general. ADPPA also grants power to state privacy authorities, and APRA grants it to any state official authorized to enforce privacy or data security laws, including consumer protection officials.

All three bills give covered entities a 180-day opportunity to cure, a defined period when organizations can correct or remedy a violation before facing penalties. These provisions encourage compliance among good actors—entities that make mistakes but ultimately want to comply with the law—so regulators can focus on acting against bad actors that willfully ignore the law.

Like [virtually all state privacy laws](https://itif.org/publications/2026/06/03/state-of-privacy-lessons-from-state-laws-for-national-framework/), the SECURE Data Act does not include a private right of action, which would allow users to sue organizations directly for civil penalties. APRA and ADPPA each contain [limited private rights of action](https://itif.org/publications/2024/04/10/privacy-bill-faceoff-comparing-the-apra-and-adppa/) that allow users to sue under certain circumstances. A private right of action is [another costly provision](https://itif.org/sites/default/files/2019-cost-data-privacy-law.pdf), since it would open the floodgates for unnecessary, baseless lawsuits against organizations that handle personal data, which would in turn disincentivize organizations from offering innovative new products or services that may open them up to liability.

Finally, while the SECURE Data Act fully preempts state privacy laws, keeping compliance costs and confusion low and ensuring all Americans have equal protection under a single national standard, APRA and ADPPA each include a list of carveouts and exceptions to their preemption clauses that fundamentally undermine the purpose of preemption.

# Conclusion

Compared to previous efforts at comprehensive federal privacy legislation, the SECURE Data Act more closely tracks the [consensus state laws](https://itif.org/publications/2026/05/15/state-privacy-laws-show-the-secure-data-acts-merits-and-political-appeal/) have established, eliminating costly and overly burdensome provisions that were present in APRA and ADPPA. States led by both Democrats and Republicans have adopted provisions similar to the SECURE Data Act, demonstrating bipartisan support for a [targeted, balanced approach](https://itif.org/publications/2022/08/08/maintaining-a-light-touch-approach-to-data-protection-in-the-united-states/) to data privacy that addresses actual privacy harms while reducing costs that hinder productivity and innovation.

Any federal privacy bill will face an uphill battle toward becoming law. However, the progress within just the past four years is cause for cautious optimism. The SECURE Data Act is a vast improvement over previous bills, maintaining areas of consensus already present between APRA and ADPPA while incorporating states’ efforts for a tried-and-tested approach. Congress should take advantage of this momentum and make privacy a priority for the remainder of 2026 in hopes of passing a law that protects American consumers, provides a smooth road to compliance for American businesses, and continues to strengthen the American economy.

**Table 1: Comparing the SECURE Data Act, APRA, and ADPPA**

| Provisions | SECURE Data Act (2026) | American Privacy Rights Act (2024) | American Data Privacy and Protection Act (2022) |
| --- | --- | --- | --- |
| CONSUMER RIGHTS |  |  |  |
| Data access | Yes | Yes | Yes |
| Data portability | Yes | Yes | Yes |
| Data rectification | Yes | Yes | Yes |
| Data deletion | Yes | Yes | Yes |
| CONSENT REQUIREMENTS |  |  |  |
| Opt-in | Sensitive data, teens’ data (13-16) | Sensitive data, minors’ data (<17) | Sensitive data, minors’ data (<17) |
| Opt-out | Adults’ non-sensitive data (17+) | Adults’ non-sensitive data (17+) | Adults’ non-sensitive data (17+) |
| Universal opt-out mechanism | Not yet | Yes | Yes |
| DATA CONTROLLER OBLIGATIONS |  |  |  |
| Data security requirements | Reasonable practices | Reasonable practices with specific minimum requirements | Reasonable practices with specific minimum requirements |
| Transparency requirements | General notice | Privacy policy, additional requirements for large data holders | Privacy policy, additional requirements for large data holders |
| Civil rights provisions | No additional requirements | No additional requirements | Impact assessments, algorithm design evaluations |
| Data minimization | Standard | Strict | Strict |
| Enforcement |  |  |  |
| FTC | Yes | Yes | Yes |
| State attorneys general | Yes | Yes | Yes |
| State consumer protection officials | No | Yes, any authorized officer | Yes, state privacy authority only |
| Private right of action | No | Limited | Limited |
| Opportunity to cure | 180 days | 180 days | 180 days |
| State preemption | Full | Partial | Partial |

---
*Source: Information Technology & Innovation Foundation (ITIF)*
*URL: https://itif.org/publications/2026/07/29/comparing-recent-federal-data-privacy-bills/*