Privacy counsel at a national retailer opens the company's compliance roadmap. Twenty-two state privacy programs sit on the page — different thresholds, different exemptions, different consumer rights, different assessment requirements.
An executive asks the question businesses have been asking Congress for years: "Would one federal law finally simplify all of this?" The answer should be yes.
Instead, counsel pauses: "Only if we agree on which state protections disappear."
A Floor, or a Ceiling?
The case for a national privacy law is straightforward: consumers should not receive fundamentally different protections based on where they live, and organizations should not need dozens of overlapping compliance programs. But uniformity has a price when the federal rule replaces stronger state protections rather than establishing a national floor.
That distinction — floor or ceiling — will decide which protections survive the next stage of negotiation in Congress.
What H.R. 8413 Would Actually Do
Introduced as H.R. 8413 on April 21, 2026, the SECURE Data Act would establish a federal consumer privacy framework covering qualifying businesses under Federal Trade Commission jurisdiction. It would provide rights to access, correct, delete, and obtain copies of personal data; permit opt-outs from data sales, targeted advertising, and certain consequential profiling; require consent before processing sensitive data; impose data-minimization and security duties; and create a federal data broker registry. It would also require verifiable parental consent before processing personal data belonging to consumers ages 13 through 15.
The FTC and state attorneys general would enforce the bill, which includes a 45-day cure period and no private right of action. The House Energy and Commerce Subcommittee on Commerce, Manufacturing, and Trade held a hearing on the proposal on June 3, 2026, but the bill remains proposed legislation, not law.
Three Things This Changes
A common set of rights, definitions, notices, vendor duties, and enforcement rules could reduce the cost of maintaining separate state-by-state workflows. But the hidden risk is assuming preemption automatically creates simplicity — employee data, sector-specific information, breach obligations, and biometric protections outside the bill's scope could remain governed by separate laws. The result may not be one privacy program. It could be a new federal layer sitting beside the state obligations that survive.
The bill would require covered controllers to limit collection to data that is adequate, relevant, and reasonably necessary for disclosed purposes. That changes the operational question from "did we disclose this collection?" to "can we justify why we need this data for this purpose?" The blind spot is treating minimization as a retention exercise — real minimization begins before collection and extends through use, sharing, profiling, model development, vendor access, and deletion.
The bill uses broad language to preempt state laws relating to matters it covers. Business groups view that as necessary to end the compliance patchwork; California regulators, state officials, and privacy advocates argue it could displace stronger protections — including biometric, children's privacy, and online safety laws such as Illinois' Biometric Information Privacy Act — without replacing them with equivalent rights. The exact boundaries will depend on the final text and, if enacted, likely judicial interpretation.
Who Feels This First
Legal and Compliance
Teams should compare the bill against their current control environment rather than waiting for a final vote. The most important gaps will involve scope, sensitive-data consent, profiling opt-outs, data brokers, teen data, enforcement, and the state protections that might be displaced.
Business Leadership
A national standard could reduce fragmentation, but weaker rules do not necessarily create lower risk. Consumer expectations, contractual commitments, litigation theories, sector-specific requirements, and reputational exposure can persist even when a particular state obligation does not.
Consumers and States
People in states without comprehensive privacy laws could gain meaningful baseline rights. People in states with stronger or more specialized protections could lose rights, remedies, or enforcement mechanisms if federal preemption reaches further than the bill's substantive protections.
For Organizations
- Compare the bill's requirements with your current state-law control matrix.
- Identify protections your program maintains only because of California, Illinois, or another specific state.
- Map sensitive-data, profiling, teen-data, and data-broker activities.
- Model three outcomes: no federal law, a federal floor, and broad federal preemption.
- Brief leadership on what uniformity could simplify and what it could remove.
For Individuals
- Review which privacy rights your state currently provides.
- Track whether federal proposals preserve or preempt those protections.
- Ask whether a national law should operate as a minimum standard or a maximum one.
- Contact elected representatives if the preemption question matters to you.
One-Line Debate Prompt
A federal privacy law should establish a national floor — not prevent states from going further. Agree or disagree?
Myth vs Reality
Myth: One federal law would automatically end privacy complexity.
Reality: Its effect depends on what it covers, what it preempts, and which obligations remain outside its scope.
Would you accept a simpler national privacy framework if it meant giving up stronger protections already available in some states?
Poll
What should a federal privacy law do about stronger state protections?