Examining Legislation to Establish a Federal Comprehensive Privacy and Data Security Law

Immigration Enforcement and Sanctuary PoliciesHouse Energy and Commerce Subcommittee on Commerce, Manufacturing, and Trade · 2026-06-03 · 119th Congress
The House Energy and Commerce Subcommittee on Commerce, Manufacturing, and Trade held this legislative hearing to examine the SECURE Data Act, a Republican-drafted bill intended to create a single national consumer data privacy and security standard preempting the 22 state comprehensive privacy laws now in effect. Begins at 0:14:39
Transcript
Highlights

Title

House hearing on the SECURE Data Act federal privacy proposal

Purpose

The House Energy and Commerce Subcommittee on Commerce, Manufacturing, and Trade held this legislative hearing to examine the SECURE Data Act, a Republican-drafted bill intended to create a single national consumer data privacy and security standard preempting the 22 state comprehensive privacy laws now in effect. Four witnesses — Kate Goodloe (BSA), Ashli Watts (Kentucky Chamber of Commerce), Caitriona Fitzgerald (EPIC), and Tyler Bridegan (Womble Bond Dickinson) — testified on the bill's data minimization, consent, enforcement, and preemption provisions, while Democrats argued the bill is weaker than existing state laws and industry witnesses argued a uniform federal standard is needed to reduce compliance burdens. Begins at0:14:39

Who spoke

Chairman Gus Bilirakis0:14:39: Opened by describing the SECURE Data Act as establishing a national privacy standard that protects consumers and gives businesses certainty0:15:10, and thanked Rep. Joyce for leading the committee's privacy working group0:16:21.

Rep. Jan Schakowsky (D-IL), Ranking Member0:17:17: Said Democrats have not been included in drafting this bill, unlike past bipartisan privacy efforts0:17:47; later argued the bill protects corporations rather than people0:39:06.

Rep. Brett Guthrie (R-KY), Full Committee Chairman0:20:29: Cited Kentucky's bipartisan privacy law (HB 15) as a model for the SECURE Data Act0:20:58 and argued the U.S. is competing with China to innovate, not Europe to regulate0:21:27; later pressed Ashli Watts on how the bill affects small Kentucky businesses1:01:49.

Rep. Kevin Hern / "Dr. Joyce"0:21:55: Described 15 months of working-group effort reviewing more than 250 RFI responses to reach consensus on the bill0:22:15; later questioned witnesses on the consensus-based, multi-state approach2:39:53.

Rep. Frank Pallone (D-NJ), Ranking Member of Full Committee0:23:34: Argued the bill locks in a "notice and consent" status quo, adds sweeping preemption, and would leave many Americans with fewer protections than today0:25:01; later posed four detailed questions to Fitzgerald on data minimization, enforcement, surveillance pricing, and preemption scope1:05:22.

Kate Goodloe, Business Software Alliance0:29:23: Testified 22 states now have comprehensive privacy laws sharing a common controller/processor structure, and the SECURE Data Act mirrors that structure0:31:36; said companies should not have to track "50 moving goalposts"0:33:19.

Ashli Watts, Kentucky Chamber of Commerce0:34:41: Described Kentucky's HB 15, passed unanimously and signed by a Democratic governor, as the model for the federal bill0:35:58; cited estimates that a fragmented privacy landscape costs the economy up to $1 trillion, $200 billion of which falls on small businesses0:37:21.

Caitriona Fitzgerald, EPIC0:39:22: Argued the bill's data-minimization language is "data maximization" because it only requires disclosure, not actual limits on collection0:41:08; said its preemption is the broadest available to the federal government and would wipe out hundreds of state laws including on robocalls, kids' online safety, and civil rights0:42:54; said passage would be worse for Americans than no federal law at all0:43:44.

Tyler Bridegan, Womble Bond Dickinson (former Texas AG privacy enforcement director)0:44:29: Said Texas's consent-based privacy law has recovered over $1 billion multiple times1:22:22; explained the bill's 45-day cure period is narrow and doesn't undo harm from data already collected1:30:07.

Rep. Cliff Bentz (R-OR)1:21:29: Questioned how meaningful informed consent can be when few people read long privacy disclosures1:21:54; asked whether a state-by-state patchwork entrenches large incumbents over smaller competitors1:25:29.

Rep. Kevin Mullin (D-CA)1:26:34: Said the bill would wipe out California's Delete Act, CCPA, and Age-Appropriate Design Code protections, leaving Californians with fewer rights than they've had for eight years1:27:09; raised a Texas insurance-data lawsuit example to argue the 45-day cure period lets bad actors escape penalty1:29:17.

Rep. Laurel Lee (R-FL)1:31:54: Asked Bridegan about sensitive-data abuses he saw in Texas enforcement, including car manufacturers selling driving data to insurers1:34:08, and the role of parental consent for minors' data1:36:20.

Rep. Yvette Clarke (D-NY)1:36:51: Called the bill a "nonstarter" for comprehensive privacy, criticized its narrowing of civil-rights and consequential-decision protections, and entered a Leadership Conference on Civil and Human Rights letter into the record1:40:35.

Rep. Russ Fulcher (R-ID), Vice Chairman1:41:04: Cited over 4,600 nationwide "wiretapping" lawsuits over ordinary web analytics tools, more than 3,000 in California alone, as evidence of private-right-of-action abuse1:41:54.

Rep. Neal Dunn / "Mr. VC" (name as heard in transcript)1:46:34: Asked Fitzgerald who would enforce civil-rights protections given the bill bars FTC enforcement of its own civil-rights provision, referring complaints to other agencies1:47:02; questioned the fairness of "click-to-consent" boxes1:51:19.

Rep. Craig Goldman (R-TX)1:51:48: Asked Bridegan whether Texas could still hold bad actors accountable under the bill1:52:15; contrasted Texas's consent requirement with California's lack of one for sensitive data1:52:45.

Rep. Robin Kelly (D-IL)1:56:48: Asked whether consumers can meaningfully understand bundled consent terms1:57:41; pressed Goodloe on what standard would ensure consumers understand what they agree to1:59:33.

Rep. Russell Fry (R-SC)2:01:51: Asked Watts about competing interests (privacy vs. innovation) behind Kentucky's law2:02:21 and cited research that GDPR reduced European tech startups2:05:05.

Rep. Kim Schrier (D-WA)2:06:56: Warned that Washington's My Health My Data Act, which covers health data beyond HIPAA, would be preempted and weakened by the bill2:08:32.

Rep. Kat Cammack (R-FL)2:12:14: Asked Goodloe to explain the controller/processor distinction2:12:36 and polled the panel on opt-in versus opt-out defaults2:17:07.

Rep. Darren Soto (D-FL)2:18:04: Argued strong preemption without a strong private cause of action leaves consumers with no recourse, and pressed for injunctive relief and attorney's fees provisions2:19:53.

Rep. Troy Balderson (R-OH)2:23:33: Cited estimates that European-style data rules could cost the U.S. $123 billion and 340,000 jobs2:23:53.

Rep. Lori Trahan (D-MA)2:28:44: Focused on AI's ability to draw sensitive inferences from data-broker data and pushed for a universal opt-out/delete mechanism, noting the bill exempts "de-identified" and pseudonymous data from consumer rights2:29:172:32:34.

Rep. Gabe Evans (R-CO)2:33:33: Linked the bill's data-security requirements to combating fraud and elder scams, citing $355 million in Colorado fraud losses and asking about coordination with law enforcement on financial crime and human trafficking2:34:002:37:38.

Key moments

Fitzgerald said the bill's "data minimization" section actually functions as "data maximization," since companies need only disclose broad purposes like "marketing" to satisfy it1:06:20.

Fitzgerald testified the bill contains the broadest preemption option available to the federal government and attached a list of hundreds of state laws — covering robocalls, data breach notification, civil rights, and kids' online safety — that could be preempted1:09:331:10:21.

Pallone and Fitzgerald discussed that Meta, Snap, YouTube and TikTok agreed to a $27 million settlement with a Kentucky school district over addictive design harming students, and that similar future claims could be barred by this bill's preemption0:43:19.

Fitzgerald and Rep. Obernolte sharply disagreed on standard-setting philosophy: Obernolte said the bill takes a "consensus," middle-ground approach rather than the strongest state standard, and argued no federal law is worse than this bill; Fitzgerald countered that with broad preemption, a floor weaker than the strongest state law strips Americans of rights they already depend on1:13:471:15:04.

Bridegan said Texas's cure period (30 days) has proven narrow in practice — most privacy violations, like unauthorized data collection, cannot actually be "cured" by later deletion or consent1:30:07.

Mullin cited a Texas-led lawsuit alleging an insurer used third-party apps to collect location data from over 45 million consumers to build a "world's largest driving behavior database," noting the SECURE Data Act would give such a company 45 days to fix the issue penalty-free1:28:521:29:17.

Fitzgerald noted California's Delete Act, in effect since January 1, has already been used by roughly 300,000 Californians to request data-broker deletions in a single centralized step — a mechanism the federal bill lacks1:28:032:31:18.

Watts and Guthrie argued Kentucky's HB 15 passed unanimously with support from small businesses and a Democratic governor, showing the model is bipartisan and not simply a big-tech vehicle1:02:411:04:27.

Fulcher cited data that over 4,600 "wiretapping" lawsuits have been filed nationwide over ordinary website analytics tools, with more than 3,000 in California alone, arguing this shows the risk of private rights of action without preemption1:41:54.

Trahan and Fitzgerald flagged that the bill exempts "de-identified" and "anonymous" data — including advertising IDs and IP addresses — from consumer opt-out rights, which Fitzgerald said can effectively neuter the opt-out since such identifiers are commonly used to track individuals2:32:34.

Metadata

CommitteeHouse Energy and Commerce Subcommittee on Commerce, Manufacturing, and Trade
Chamber / CongressHouse · 119th Congress
Date2026-06-03
TypeHearing
Witnesses
Caitriona Fitzgerald — Deputy Director, Electronic Privacy Information Center (EPIC)
Kate Goodloe — Managing Director, Business Software Alliance
Tyler Bridegan — Partner, Womble Bond Dickerson
Ashli Watts — President and CEO, Kentucky Chamber of Commerce
Videoyoutube
Transcript350 caption blocks · 25,866 words · 2:53:08 runtime
EventCongress.gov 119345