A House Energy and Commerce subcommittee yesterday took up the SECURE Data Act, a Republican-led bill that would create the first national consumer privacy standard and preempt the more than 20 state privacy laws now on the books. For the credit and collections industry, the most consequential language may be what the bill leaves out.
H.R. 8413, introduced in April by Rep. John Joyce [R-Penn.], and co-authored by House Energy and Commerce Chairman Brett Guthrie, [R-Kent.], would let consumers access, correct, and delete their data and opt out of targeted advertising, data sales, and certain automated profiling. It would require data minimization, mandate a public data-broker registry, and leave enforcement to the FTC and state attorneys general. There is no private right of action. The bill applies to businesses handling data on more than 200,000 consumers with at least $25 million in revenue, or 100,000 consumers if a quarter of revenue comes from selling data.
The bill’s reach stops short of much of the financial-services ecosystem. It exempts institutions subject to Title V of the Gramm-Leach-Bliley Act, and it carves out personal data bearing on a consumer’s creditworthiness when that data is collected or disclosed by a consumer reporting agency or a furnisher engaged in activities subject to the Fair Credit Reporting Act. Nothing in the bill, it adds, relieves a business of its existing FCRA or GLBA obligations.
The practical effect is that the consumer-report data and furnishing activities at the center of collections work would remain governed by the FCRA, not the new framework. The carve-out is tied to FCRA-regulated activity rather than a blanket industry pass, so data handling outside those statutes could still be covered. Healthcare clients see a similar pattern: HIPAA-covered entities, business associates, and health records are exempt.
The hearing divided along party lines. Rep. Jay Obernolte, [R-Calif.], said the weakest state standard today is no standard at all, since most states still lack comprehensive privacy laws. A day earlier, a coalition of 18 attorneys general and state privacy agencies urged Congress to reject the bill, arguing a federal law should set a floor rather than a ceiling. They warned its preemption language is broad enough to threaten data-broker registries, breach-notification laws, and other state protections, and noted it sets no data-retention limits and provides no civil penalties in state enforcement actions.
Most members on both sides say they want a federal standard. The unresolved questions are how strong it will be, and how much state law it will sweep away.
.




