US SECURE Data Act: Congress splits over AI, privacy rules
Synopsis
Key Takeaways
A Republican-backed proposal to establish the first nationwide consumer privacy framework in the United States has ignited a sharp congressional clash over data protection, artificial intelligence, and the future of digital regulation. The SECURE Data Act, debated at a House Energy and Commerce Subcommittee on Commerce, Manufacturing and Trade hearing on 4 June, has exposed deep fault lines between those seeking uniform national standards and those warning the bill would hollow out stronger state-level protections.
What the SECURE Data Act Proposes
Supporters of the bill argue that a single national privacy standard is essential to replace a growing patchwork of differing state laws. As of the hearing, 22 US states have already enacted their own privacy legislation, creating compliance headaches for companies operating across state lines.
Kate Goodloe, Managing Director of the Business Software Alliance, told lawmakers: 'Consumers' data should also be used responsibly and kept securely no matter where they live.' Ashli Watts, President and CEO of the Kentucky Chamber of Commerce, said small businesses were struggling to navigate conflicting state requirements, adding: 'The SECURE Data Act provides just that. The model is proven, and the consensus exists across party lines. What remains is for Congress to act.'
Republicans Frame It as an Innovation Imperative
House Energy and Commerce Committee Chairman Brett Guthrie set the tone for the Republican argument, framing the debate in geopolitical terms. 'We're not competing with Europe to regulate. We're competing with China to innovate,' Guthrie said. 'We have to innovate and also protect individuals' data.' The position reflects a broader Republican view that regulatory fragmentation puts American technology companies at a competitive disadvantage.
Democrats and Advocates Warn of Weakened Protections
Frank Pallone, the senior Democrat on the committee, pushed back sharply, saying the bill 'locks in the failed notice and consent status quo' and contains 'loophole upon loophole to water down its provisions.' Critics argue the legislation would override stronger consumer protections already in place in states such as California and Washington.
Caitriona Fitzgerald, Deputy Director of the Electronic Privacy Information Center (EPIC), warned that the bill would create a national standard 'weaker than the weakest state law,' potentially dismantling existing state-level rules on online privacy, children's safety, data brokers, and consumer rights.
AI at the Centre of the Privacy Debate
Much of the hearing's most charged testimony centred on artificial intelligence. Fitzgerald warned that 'AI is turbocharging the ability for companies to make inferences about consumers,' arguing that stronger privacy rules are urgently needed to prevent data misuse, discrimination, and surveillance-based pricing. The concern reflects a widening global consensus — including in India, which is navigating its own digital data protection framework — that AI amplifies the stakes of any privacy legislation.
What Comes Next
The hearing signals that the SECURE Data Act faces significant headwinds in its current form. Democrats and privacy advocates are likely to push for amendments strengthening the bill's enforcement provisions and preserving state-law floors. The outcome will have implications well beyond US borders, potentially influencing how other democracies calibrate the balance between innovation and data rights.