Home/ Insights/ Congress Just Introduced a Bill That Could Replace 20 State…
Congress Just Introduced a Bill That Could Replace 20 State Privacy Laws With One
Automotive & Mobility · Marqstats Research

Congress Just Introduced a Bill That Could Replace 20 State Privacy Laws With One

Automakers currently navigate more than 20 different state privacy laws. A bill introduced in April 2026 would replace all of them with one federal standard.

12 min read 1,238 words Automotive & Mobility

A new bill in Congress would trade 20-plus state privacy laws for one national standard

Automakers operating nationally currently face a genuinely fragmented compliance landscape: California's Consumer Privacy Act, Texas's Data Privacy and Security Act, and comprehensive privacy statutes in roughly eighteen other states, each with its own definitions, consent requirements, and enforcement mechanisms. A single connected-vehicle feature might need to be configured differently depending on which state the customer lives in. In April 2026, Representative John Joyce introduced a bill aimed squarely at replacing that patchwork with one federal rule.

20+State comprehensive privacy laws currently in effect
H.R. 8413The bill number for the SECURE Data Act
14 monthsLength of stakeholder engagement before the bill's introduction

What the bill actually does

The Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act, known as the SECURE Data Act, would apply to any entity conducting business in the United States or processing the personal data of US residents. Its core mechanism is straightforward: a single national data broker registry, administered by the Federal Trade Commission, requiring any company that meets the bill's data broker definition to publicly register and disclose its data practices.

Congress Just Introduced a Bill That Could Replace 20 State Privacy Laws With One — exhibit 1

The bill defines a data broker specifically as an entity that collects and processes personal data about people who are not its own customers or users, and that derives at least half its annual gross revenue from selling that data. This definition maps closely onto exactly the kind of arrangement General Motors had with LexisNexis Risk Solutions and Verisk Analytics - a company collecting data through one relationship (OnStar subscribers) and monetizing it through a completely separate one (data brokers selling to insurers).

The bill's data-broker definition reads like it was written with GM's old business model specifically in mind.

— Marqstats Analyst Team

The preemption question: does this actually simplify things?

The bill's most consequential provision, and its most contested, is preemption: if enacted as introduced, the SECURE Data Act would establish a single, uniform national standard and prevent states from imposing additional or different privacy requirements. For an automaker currently maintaining separate compliance configurations for California, Texas, Colorado, Virginia and more than a dozen other states, a genuine single national standard would represent real operational simplification - one set of consent flows, one set of disclosure requirements, one enforcement regime to track rather than twenty-plus.

The bill also introduces specific consumer protections beyond what many current state laws require, including mandatory opt-in consent for sensitive data categories - precise geolocation, biometric data, and health information all fall under this heading, which maps directly onto the exact categories of driving and location data at the center of the GM enforcement actions - along with a notably aggressive extension of privacy protections to teenagers aged thirteen to sixteen, requiring verified parental consent.

Who enforces it, and what happens if a company doesn't comply

Enforcement would sit with the Federal Trade Commission and state attorneys general jointly, with a 45-day cure period built in before penalties apply - giving companies a defined window to fix a violation before facing enforcement action, a structure different from some current state laws that allow more immediate penalties. Notably, like most existing state privacy statutes, the bill would not create a private right of action, meaning individual consumers could not sue directly; enforcement would remain the province of regulators rather than private litigation.

The counter-argument: is this actually going to become law?

It's worth being direct about the odds here. Comprehensive federal privacy legislation has been introduced in Congress multiple times over the past several years, and none of the previous attempts, including the American Data Privacy and Protection Act and similar predecessors, made it to enactment. The SECURE Data Act's own analysts have noted this history explicitly, describing it as the third major attempt at this kind of legislation. Fourteen months of stakeholder engagement and bipartisan-adjacent framing give this particular bill a somewhat stronger starting position than some prior efforts, but predicting eventual passage this early in the legislative process would be premature. What can be said with more confidence is that the bill's introduction itself signals that federal lawmakers view the current state-by-state enforcement wave, exemplified by the GM case, as a genuine policy problem worth addressing at the national level.

The SECURE Data Act, introduced in April 2026, would replace the current patchwork of more than twenty state privacy laws with a single federal standard and a national data-broker registry - a structural response to exactly the kind of fragmented, state-by-state enforcement that has already reshaped automotive data practices at General Motors. Whether it becomes law remains genuinely uncertain given the track record of prior federal privacy legislation attempts, but its introduction is itself a meaningful signal that the current enforcement environment is viewed in Washington as unsustainable in its present fragmented form.

What this means for automakers and technology vendors

  • Legal and compliance teams should track the SECURE Data Act's progress through committee specifically, since its preemption provision would be the single most consequential change to current multi-state compliance obligations.
  • Any company meeting the bill's specific data-broker revenue threshold, deriving at least 50% of revenue from selling personal data of non-customers, should evaluate registration and disclosure readiness now rather than waiting for potential enactment.
  • Watch how the bill's sensitive-data opt-in requirements, which explicitly cover precise geolocation, would interact with existing connected-vehicle telemetry practices, since this is the category most directly implicated by the GM enforcement precedent.

Where the bill came from matters for judging its seriousness

The SECURE Data Act did not appear out of nowhere. It's the product of the House Energy and Commerce Committee's Data Privacy Working Group, established in February 2025 specifically to build toward comprehensive federal privacy legislation. Over the following fourteen months, the working group received more than 250 written responses and held meetings with more than 170 different organizations, spanning industry, advocacy groups and other stakeholders, explicitly aiming to build a more durable bill than prior attempts. This process-heavy origin story is itself informative: it suggests the bill's drafters were specifically trying to avoid the fate of earlier federal privacy proposals that stalled partly due to insufficient stakeholder buy-in before introduction.

Congress Just Introduced a Bill That Could Replace 20 State Privacy Laws With One — exhibit 2

Whether that extended engagement process actually translates into a bill with enough political support to pass remains an open question. But it does distinguish the SECURE Data Act's introduction from a purely symbolic gesture, giving it a more substantive starting position in the legislative process than a bill introduced without comparable groundwork.

What automakers specifically should watch for in the bill's final language

If the SECURE Data Act advances through committee, several provisions deserve particular attention from automotive companies specifically, beyond the general data-broker registry. The bill's sensitive-data category explicitly includes precise geolocation data, which would place standard connected-vehicle location tracking squarely within the heightened opt-in consent requirement - a stricter standard than some automakers currently operate under in states without comparable geolocation-specific rules. The bill's teen-data provisions, requiring verified parental consent for data of thirteen-to-sixteen-year-olds, could also carry unexpected relevance for automakers operating driver-monitoring or telematics features on family vehicles where a teenage driver might reasonably be behind the wheel.

The full market picture

Marqstats' complete United States automotive data management market analysis, including the full regulatory landscape and a scenario forecast through 2029, is available in the linked report below.

Related reportUnited States Automotive Data Management Market Size, Share & Forecast 2025 – 2029Automotive and Mobility
Marqstats
Marqstats Research
Market Intelligence & Advisory · marqstats.com
Automotive & Mobility Market Research Marqstats Intelligence
Back to insights