SECURE Data Act advances in the US
The bill remains in committee and has not reached the House floor. It could expand federal control over data
The SECURE Data Act still has no vote scheduled on the floor of the U.S. House of Representatives and, according to official calendars dated August 17, 2026, remains in committee or subcommittee. Sector analysis also places it at the center of the debate over federal privacy, with possible new powers for the Commerce Department and the FTC.
The SECURE Data Act still has no vote scheduled on the floor of the U.S. House of Representatives and, according to official calendars dated August 17, 2026, remains in committee or subcommittee. The bill also stands out as one of the most active drafts in the discussion over a comprehensive federal privacy law, against a backdrop of sector-specific rules and FTC enforcement under Section 5 of the FTC Act.
What is the bill's legislative status?
The bill does not yet appear among the measures with a floor vote date, according to the House's official calendars as of August 17, 2026. For now, that leaves it in an earlier stage, before final consideration by the full chamber.
That status aligns with GDPRI / DataProtection.gi, which describes it as part of a group of sector proposals and active drafts while Congress still has not passed a comprehensive federal privacy law. The same source notes that current federal enforcement relies on the FTC and on a patchwork of separate rules.
What would change if it is approved?
Approval of the SECURE Data Act would move the United States from a fragmented setup to a single horizontal framework, according to GDPRI / DataProtection.gi. That would have direct implications for multinational companies and for Latin American subsidiaries that process data belonging to U.S. residents.
Today, that patchwork includes Section 5 of the FTC Act and sector rules such as COPPA, the GLBA Safeguards Rule, FCRA, the Health Breach Notification Rule, and PADFAA. GDPRI / DataProtection.gi says a comprehensive federal privacy law would represent a structural shift from the current framework.
What powers would Commerce and the FTC gain?
A public analysis by DLA Piper on the SECURE Data Act 2026 and the GUARD Financial Data Act says the bill would give expanded authority to the U.S. Commerce Department and the FTC to oversee data collection and use.
That reading reinforces the role of both agencies as key authorities in any future federal privacy standard. At the same time, GDPRI / DataProtection.gi already identifies the FTC as the main federal anchor in the absence of an integrated law.
What happens with data in relation to foreign adversaries?
The bill would operate within an environment where rules on transfers of data to foreign adversaries already exist, such as the Protecting Americans' Data from Foreign Adversaries Act, or PADFAA.
According to GDPRI / DataProtection.gi, that law bars data brokers from selling or disclosing sensitive data on Americans to entities controlled by North Korea, China, Russia, or Iran. The coexistence of PADFAA and the SECURE Data Act suggests the draft under discussion could incorporate or align rules already in force on those transfers.
That point carries more weight because recent compliance and cybersecurity coverage indicates that the Justice Department has already begun enforcing a Data Security Program based on Executive Order 14117, with a distinction between prohibited and restricted data transactions involving countries of concern and with new governance and recordkeeping obligations for cross-border transfers of sensitive data.
What did the FTC say about data brokers?
The regulatory risk around data brokers was already tightening before a comprehensive law. Coverage from 2026 reported FTC warnings to 13 data brokers under PADFAA and orders against brokers such as Kochava.
According to DailySynapse, that front is reshaping how sensitive data is handled and whether foreign adversaries can access it. In that context, the SECURE Data Act could include strict requirements for data brokers, a point that is especially relevant for international business groups operating across multiple markets.
Sources
- House Calendars for August 17, 2026 - 119th Congress, 2nd Sessiongovinfo.gov· GovInfo / U.S. Government Publishing Office
- March 2026 roundup on privacy, security and AI regulationdailysynapse.com· DailySynapse
- Subcommittee Holds Hearing on Data Privacy Billbroadbandbreakfast.com· Broadband Breakfast
- The SECURE Data Act 2026 and GUARD Financial Data Act – overview of proposed federal powersx.com· DLA Piper
- 2026 Cybersecurity and Privacy Enforcement Trendssecuritypost.org· SecurityPost.org
- United States Data Protection & Privacy Regulation Monitordataprotection.gi· GDPRI / DataProtection.gi



