
The American Data Privacy and Protection Act: What Happened, What Replaced It, and Why You Still Can't Wait for Congress
The American Data Privacy and Protection Act (ADPPA) was supposed to be the law that finally gave the United States a single, comprehensive federal privacy standard. Introduced in the House as H.R. 8152 in June 2022, it cleared the Energy and Commerce Committee with bipartisan votes, then quietly died before reaching the floor. Four years later, the U.S. remains the only G20 country without a comprehensive federal data privacy statute. If you build products that touch personal data, the implications of that fact are structural, not academic.
Key Takeaways
- The ADPPA passed committee in 2022 but never became law. Its 2024 successor, the American Privacy Rights Act (APRA), also stalled. A new attempt, the SECURE Data Act, was introduced in April 2026 and faces the same preemption fight that killed both predecessors.
- Nearly 20 states now have their own comprehensive privacy laws. Three more took effect on January 1, 2026 alone. The patchwork is the status quo, and it is growing.
- The ADPPA's private right of action, which would have let individuals sue businesses directly, was one of the most contentious provisions and keeps resurfacing in successor bills. If any version passes, products built on data minimization have structurally less litigation exposure.
- Waiting for federal preemption is a losing strategy. Privacy-by-design architecture (data minimization, encrypted-at-rest storage, short retention windows) is the only compliance posture that works regardless of what Congress does or doesn't do.
What Was the ADPPA?
The ADPPA was a proposed federal bill that would have regulated how organizations collect, retain, and use consumer data across the entire United States. It aimed to replace the growing patchwork of state laws with a single national standard. The bill included provisions for data minimization, transparency requirements, algorithmic impact assessments, and, notably, a private right of action allowing individuals to sue businesses directly for violations (after first notifying the FTC or their state attorney general).
It passed the House Energy and Commerce Committee in July 2022 with what looked like genuine bipartisan momentum. Then it stalled. The full House never voted on it. The Senate never touched it. The 117th Congress ended, and the bill expired.
Why Did the ADPPA Fail?
Preemption killed it. The bill would have overridden state privacy laws, including California's CCPA/CPRA. California's congressional delegation, and the state's privacy regulators, opposed ceding that ground. The private right of action provision drew opposition from industry lobbying groups who argued it would create a flood of litigation. And the coalition that briefly aligned in committee fractured once the bill moved toward floor consideration.
This is the pattern that repeats. A bill proposes a uniform federal standard. States with strong existing laws resist being preempted downward. Industry groups resist the enforcement mechanisms. Privacy advocates worry the federal floor is too low. The coalition never holds long enough to clear both chambers.
What Happened After the ADPPA Died?
In 2024, the American Privacy Rights Act (APRA) emerged as the successor. It carried many of ADPPA's structural features, including preemption of state laws and a private right of action. It also lost the support of many privacy and civil-society groups, its markup session was canceled after Republican pushback, and the bill expired in January 2025. As of March 2026, it had not been reintroduced.
Meanwhile, the thing that actually did happen was state legislatures. By early 2026, nearly 20 states had introduced their own comprehensive privacy regulations, with Indiana, Kentucky, and others going live on January 1, 2026. Kentucky even created a dedicated Office of Data Privacy for enforcement. The patchwork didn't wait for Congress.
What Is the SECURE Data Act?
The SECURE Data Act (H.R. 8413) was introduced on April 22, 2026, by Rep. John Joyce. It represents the most significant attempt at comprehensive federal privacy legislation since the ADPPA. The bill followed over 14 months of stakeholder engagement by the Data Privacy Working Group established by Reps. Joyce and Guthrie in February 2025.
Like ADPPA before it, the SECURE Data Act proposes a single, uniform national standard to replace the 20+ state privacy laws. The House Energy and Commerce Subcommittee on Commerce, Manufacturing, and Trade held a legislative hearing on June 3, 2026. By August, the Senate Commerce Committee voted to advance a related bill.
The EFF has argued publicly that the bill is insufficient and still needs full Senate approval. Privacy advocates note it carries the same preemption vulnerability that killed both APRA and ADPPA. To become law, it must clear committee, pass the full House, survive a Senate filibuster (requiring 60 votes), and get a presidential signature. Every predecessor has failed somewhere in that chain.
How Does the Current Federal Privacy Landscape Actually Work?
It doesn't, in the sense of a unified framework. What exists is a collection of sector-specific federal laws (HIPAA for health, COPPA for children, GLBA for financial data, FERPA for education records) and a growing stack of state comprehensive laws. If your product touches consumers in multiple states, you're reconciling potentially 20+ different consent regimes, opt-out mechanisms, data retention rules, and enforcement structures.
Companion bills introduced in 2026 underscore the fragmentation. The Online Privacy Act of 2026 (H.R. 8014) proposes an entirely different approach: a rights-based federal privacy framework enforced by a new Digital Privacy Agency. The GUARD Financial Data Act targets financial data specifically. These aren't coordinated efforts. They're competing visions from different factions, all running in parallel.
Why Does the Private Right of Action Matter So Much?
Most U.S. state privacy laws do not let individuals sue businesses directly for violations. Enforcement falls to state attorneys general or, in some cases, dedicated regulatory bodies. The ADPPA's inclusion of a private right of action was one of its most distinctive and contentious features. It would have allowed individuals to bring suit, provided they first notified the FTC or their state AG.
This provision keeps resurfacing in successor bills because it represents a fundamentally different enforcement model. Under attorney-general-only enforcement, companies face a finite number of potential plaintiffs (50 state AGs, plus federal regulators). Under a private right of action, every user is a potential plaintiff. The litigation surface expands by orders of magnitude.
For founders, this is a design argument, not just a legal one. If a private right of action eventually passes at the federal level, the products with the smallest litigation surface will be the ones that collect the least data. Data minimization stops being a philosophical preference and becomes a liability reduction strategy. You can't be sued over data you never collected.
What Is the "Patchwork Tax" for Builders?
If you ship software to users across the United States, you are paying it right now. The cost is not a single line item. It's diffused across legal review, consent management implementations, data mapping exercises, and the ongoing monitoring of legislative changes in 20+ jurisdictions.
Consider what reconciliation actually looks like in practice. Virginia's VCDPA requires you to conduct data protection assessments for targeted advertising. Colorado's CPA adds a universal opt-out mechanism requirement. Connecticut's CTDPA layers on additional consent requirements for sensitive data. Texas requires you to post a specific notice if you sell biometric data. Each state defines "sale" of data slightly differently. Each state defines "sensitive data" slightly differently. Some require opt-in consent for sensitive data processing; others require opt-out. The differences are not large enough to require entirely separate architectures, but they are large enough that a single implementation doesn't cleanly satisfy all of them.
The operational cost of this reconciliation is real and ongoing. Every time a new state law takes effect (three did on January 1, 2026 alone), you re-audit. Every time an existing law is amended, you re-audit. The audit is not the hard part. The hard part is that each audit may require implementation changes that affect your data pipeline, your consent flows, and your retention schedules.
Federal preemption would collapse this cost. But federal preemption keeps failing. If you are building your compliance posture on the assumption that Congress will simplify things, you are making a bet with a poor track record.
Should Founders Wait for Federal Legislation?
No. The pattern is clear. The ADPPA failed in 2022. APRA failed in 2024. The SECURE Data Act faces the same structural obstacles in 2026. Even optimistic timelines for the SECURE Data Act put passage at late 2026 or 2027, and most privacy law practitioners seem to assign it less-than-even odds given the preemption fight.
The pragmatic move is to build as though the patchwork is permanent. That means:
- Data minimization by default. Collect what you need, delete what you don't, and make deletion real (not soft-delete with a 90-day grace period that becomes permanent).
- Short retention windows for operational metadata. If you don't need it for the product to function, set a TTL and enforce it.
- Encrypt content at rest. This is table stakes, not a differentiator, but a surprising number of products still don't do it consistently.
- Design consent flows that satisfy the strictest state regime you operate in. If you meet Colorado's universal opt-out requirement, you likely satisfy Virginia's and Connecticut's as well. Build to the ceiling, not the floor.
- Automate data mapping. If you can't programmatically answer "what data do we hold on user X, where is it stored, and what's our lawful basis for each element," you're not ready for any regime, state or federal.
None of this requires a federal law to justify. It's just good architecture. The fact that it also happens to reduce your exposure under any plausible future regulation is a bonus, not the primary motivation.
How Does Preemption Keep Killing These Bills?
Preemption is the question of whether a federal law overrides state laws on the same subject. In privacy legislation, it's the central structural tension. States with strong existing laws (California being the most prominent) resist federal preemption because they view it as a rollback of protections their residents already have. States without comprehensive privacy laws tend to favor preemption because it gives them a baseline they haven't legislated themselves.
The ADPPA attempted to thread this needle by including a partial preemption structure, but California's delegation was unconvinced. APRA tried a different formulation and lost different constituencies. The SECURE Data Act proposes its own version of uniform national standards, and analysts are already flagging preemption as its "Achilles' heel."
The dynamic is self-reinforcing. The longer Congress fails to pass a federal law, the more states pass their own laws, and the more entrenched those state regimes become. Each new state law creates a new constituency that will resist preemption. The window for clean federal preemption may already be closed, or at least very narrow.
What Would a Federal Privacy Law Actually Change for Product Teams?
If something like the ADPPA or SECURE Data Act eventually passes, the most immediate effect for product teams would be simplification of the compliance surface. Instead of reconciling 20+ state regimes, you'd have one set of rules. One definition of "sensitive data." One consent framework. One enforcement body (likely the FTC, possibly supplemented by state AGs).
The second-order effect depends on whether the law includes a private right of action. If it does, the litigation calculus changes. Class-action firms would build practices around data privacy violations the way they built practices around TCPA violations. Products that hold large volumes of personal data with loose retention policies would become attractive targets. Products built on data minimization would be structurally harder to sue.
The third-order effect is international. The EU's GDPR, Brazil's LGPD, and other comprehensive regimes all assume that trading partners have equivalent protections. A federal U.S. privacy law would simplify cross-border data transfer agreements and potentially reduce the compliance burden for companies operating internationally. Without one, each adequacy determination remains piecemeal.
What Should You Actually Do Right Now?
Build your data architecture as though the strictest plausible regime is already in effect. That means:
- Audit your data flows. Know what you collect, where it goes, how long you keep it, and why. If you can't answer those questions programmatically, you have a problem that no amount of legal review will solve.
- Minimize by default. Every field you collect is a field you have to protect, map, potentially disclose in response to a data subject request, and eventually delete. The cheapest data to manage is data you never collected.
- Make deletion real. When a user says delete, the data should be gone. Not flagged. Not archived. Gone. This is harder than it sounds when data flows through analytics pipelines, backup systems, and third-party integrations, but it is the standard that both state laws and proposed federal laws converge on.
- Encrypt content at rest. This is not sufficient for compliance with any regime, but it is necessary for all of them.
- Monitor the legislative landscape, but don't build to it. Build to principles (minimization, purpose limitation, transparency, deletion) and you'll satisfy whatever Congress eventually passes, or doesn't.
The ADPPA's failure was not an anomaly. It was the predictable outcome of a structural conflict that hasn't been resolved and may not be resolved for years. The SECURE Data Act is the latest attempt, and it may succeed where its predecessors failed, but the smart money builds as though it won't.
The only compliance posture that survives every legislative outcome, passage, failure, or something in between, is one grounded in architecture rather than legal interpretation. Collect less. Encrypt what you keep. Delete what you don't need. That strategy works under the ADPPA, under the SECURE Data Act, under 20 state laws, and under no law at all. It's just how you should build.
If you're looking for an AI assistant that treats those principles as defaults rather than afterthoughts: start a free 7-day trial, no card required.
Frequently Asked Questions
What was the ADPPA and what happened to it?
The American Data Privacy and Protection Act (H.R. 8152) was a 2022 bill meant to create a single federal privacy standard. It passed the House Energy and Commerce Committee but never got a full House or Senate vote, and it expired when the 117th Congress ended.
Why did the ADPPA and its successors keep failing?
The main sticking points were preemption of state laws like California's CCPA/CPRA and the inclusion of a private right of action letting individuals sue businesses, which industry groups opposed. This same coalition breakdown, states resisting preemption, industry resisting enforcement, advocates worried the federal floor is too low, also doomed the 2024 American Privacy Rights Act (APRA).
What is the SECURE Data Act and is it likely to pass?
The SECURE Data Act (H.R. 8413), introduced in April 2026 by Rep. John Joyce, is the latest attempt at a comprehensive federal privacy law and has had committee hearings and Senate committee advancement. However, it faces the same preemption vulnerability that killed ADPPA and APRA, and must still clear the full House, survive a Senate filibuster, and get a presidential signature.
Why does the private right of action matter for businesses building products?
Most state privacy laws only allow enforcement by attorneys general, limiting the number of potential plaintiffs, but a private right of action would let any user sue, vastly expanding litigation exposure. This makes data minimization a practical liability-reduction strategy, since a company can't be sued over data it never collected.
What should companies do instead of waiting for federal privacy legislation?
Since nearly 20 states already have their own comprehensive privacy laws and federal preemption has failed repeatedly, companies should adopt privacy-by-design practices, data minimization, encrypted-at-rest storage, and short retention windows, as a compliance posture that works regardless of what Congress does.
Sources & References
- First Look at the American Data Privacy & Protection Act (ADPPA)
- American Data Privacy and Protection Act
- U.S. Data Privacy Laws and Regulations in 2026
- American Data Privacy and Protection Act Fact Sheet
- Text - S.4211 - 119th Congress (2025-2026): Consumer Data Privacy and Security Act of 2026 | Congress.gov | Library of Congress
- U.S.: Comprehensive Federal Privacy Legislation Introduced | Privacy Matters
- SECURE Data Act: U.S. House Introduces New National Privacy Framework
- American Privacy Rights Act
- Examining Legislation to Establish a Federal Comprehensive Privacy and Data Security Law | Congress.gov | Library of Congress
- SECURE Data Act: Congress Introduces New Federal Privacy Framework | Insights | Venable LLP
- U.S. House Committee releases SECURE Data Act to establish new federal privacy framework | Consumer Finance Monitor
- House Republicans Introduce Comprehensive Federal Privacy Bill: “SECURE Data Act”
- House Introduces SECURE Data Act to Establish a Federal Privacy Framework
- Data Privacy Update: Federal Bill Introduced…But Will it Go Anywhere?
- Text - H.R.8014 - 119th Congress (2025-2026): Online Privacy Act of 2026 | Congress.gov | Library of Congress
- US Republicans introduce latest comprehensive privacy legislation | IAPP
- The SECURE Data Act: A Federal Privacy Framework Moves Forward | Articles | Finnegan | Leading IP+ Law Firm
- The SECURE Data Act is Not a Serious Piece of Privacy Legislation | Electronic Frontier Foundation
- The SECURE Data Act: What Businesses Need to Know About the New Federal Privacy Bill
- The SECURE Data Act: A Federal Privacy Framework (But for Real This Time?) | Osano
- SECURE Data Act: What This Federal Privacy Law Means for Your Business - CookieYes
- House GOP Unveils Landmark Comprehensive Privacy Draft Alongside GLBA Proposal | Akin
- Text - H.R.8413 - 119th Congress (2025-2026): SECURE Data Act | Congress.gov | Library of Congress
- American Data Privacy and Protection Act (ADPPA): Explained - Securiti
- What Is the ADPPA (American Data Privacy and Protection Act)? | Osano
- The ADPPA — Data Privacy Comes to the USA (and how not to lose sleep over it) - Recast
- What is the ADPPA Privacy Act? - Adsero Security
- American Data Privacy and Protection Act (ADPPA) - TermsFeed
- Debevoise Discusses What the ADPPA Means for U.S. Data Regulation
