This document is a draft version of the SECURE Act (Safe Electronic Communication and User Rights Enforcement) proposal. It is being actively refined and expanded based on public feedback and expert consultation.
We invite lawmakers, civil liberties advocates, technologists, developers, and concerned citizens to review the proposal and share their suggestions, corrections, or concerns.
The SECURE Act: Reclaiming Our Digital Communications
We are seeking support for the SECURE Act (Safe Electronic Communication and User Rights Enforcement), a proposal to bring our digital communications infrastructure under appropriate regulatory oversight. Today's tech giants have gained unprecedented control over how we connect, communicate, and share information, creating a digital landscape that prioritizes profit over privacy and corporate interests over public good.
By establishing the U.S. Postmaster as the regulatory authority for digital communications—similar to the historical regulation of postal mail and telephone services—we can restore crucial protections for privacy, security, and freedom of expression while fostering innovation through open standards. The SECURE Act would establish clear rules for email, social media, and other digital platforms, ensuring that these essential services operate in the public interest rather than solely for corporate gain.
We invite lawmakers, technology experts, civil liberties advocates, and concerned citizens to join us in supporting this critical initiative to reclaim our digital future.
Note: While the SECURE Act assigns administrative oversight to the U.S. Postmaster General, it does not place digital communications under the operational control of the U.S. Postal Service (USPS). Instead, the Act proposes the creation of a new, independent watchdog agency—separate from USPS—that reports to the Postmaster General as a symbol of public trust and civic communication stewardship. This structure honors the historic role of the Postmaster in protecting national communications, while establishing a modern regulatory body purpose-built for the digital age.
Why the Postmaster, not the FCC?
The SECURE Act proposes the creation of a new, independent agency reporting to the U.S. Postmaster General—not the FCC—because modern digital communications are more aligned with the historical mission of the postal system than with traditional broadcast regulation.
The term “post” remains central to how we communicate online: we post emails, post messages, and post content to social networks. Like letters and parcels, these messages are addressed, transmitted, received, and often expected to be private or secure. That makes the Postmaster’s legacy—ensuring the trustworthy delivery of protected civic communication—a more natural institutional anchor than the FCC, whose authority centers on spectrum allocation and one-way broadcasting models.
The new digital watchdog agency will operate independently of the USPS, but under the civic-minded umbrella of the Postmaster’s historical mandate: to safeguard the public’s right to communicate freely, privately, and reliably. This structure is intended to draw on constitutional precedent while addressing the unique challenges of the internet age.
Protection from Both Corporate and Government Overreach
The SECURE Act stands as a critical safeguard for citizens against both corporate exploitation and government surveillance. Unlike current systems where private companies collect and mine our data with minimal oversight, the Act establishes stringent privacy protections including mandatory end-to-end encryption and strict data minimization principles. Most importantly, Section XVIII specifically protects against government overreach by requiring warrants for any access to digital communications, prohibiting bulk data collection and mass surveillance programs, banning secret court orders like National Security Letters, and forbidding the creation of backdoors in encryption systems.
The Act mandates transparency reports on all government data requests and establishes an independent oversight board to review surveillance activities. By requiring notification to users whose data has been accessed by authorities and implementing severe penalties for officials who abuse their power, the SECURE Act creates a comprehensive shield that protects citizens' digital communications from both corporate exploitation and unconstitutional government intrusion. This balanced approach ensures national security needs can be met while fully respecting and preserving individual privacy rights and civil liberties.
Safe Electronic Communication and User Rights Enforcement Act
Overview
This proposal endorses the U.S. Postmaster taking responsibility for the delivery of all digital communications through a regulated delivery system.
The system would regulate email and other communications, including social media, with safeguards for privacy, security, right to delivery, freedom from censorship, right to removal, and fair practices that incentivize innovation.
The Post Office was created in 1775 (over 250 years ago), one year before the Declaration of Independence was signed.
The Second Continental Congress appointed Benjamin Franklin as the first Postmaster General of the United States Post Office.
In 1792, President George Washington signed the Postal Service Act, which formally created the Post Office Department and laid the groundwork for the modern postal system.
The Founding Fathers recognized the critical importance of secure and dependable communications for the fledgling democracy.
A robust communication system was essential for fostering national unity, facilitating democratic participation, and ensuring the effective governance of a geographically expansive nation.
The confidentiality of correspondence, exemplified by the encrypted letters exchanged among early leaders like James Madison and Thomas Jefferson, played a crucial role in the formation of the U.S. federal government.
They realized the enduring need for protected communications in a democracy, as they enable the free exchange of ideas, protect individual privacy, and safeguard against potential threats to the nation's security and stability.
The Bell System was the monopoly that provided telephone services to most of the United States from 1877 to 1984.
It began being regulated by the Communications Act of 1934.
It operated under the FCC and had universal service requirements.
It provided essential services like 411 directory assistance.
Operators were available to help connect people and complete calls.
Phone books were printed and sent universally so contact info was public info.
Privacy could be obtained by unlisting yourself.
These responsibilities were mandated by the Communications Act of 1934 and subsequent FCC regulations.
The Bell System's dominance extended beyond telephone services into local commerce. The Yellow Pages directories, born from the Bell/AT&T monopoly, evolved from early city directories into powerful local search tools. This monopoly effectively controlled local advertising—businesses were forced to purchase listings simply to be discoverable by customers. The model persisted for decades until digital search engines and the internet disrupted it, eventually rendering print directories obsolete despite efforts to digitize. The pattern is instructive: essential communication infrastructure, left unregulated in private hands, inevitably becomes a tollbooth on commerce and civic participation.
Today's communications have shifted from regulated public utilities to a tech oligopoly. The current digital gatekeepers face little oversight.
Giant corporations like Microsoft (Outlook, LinkedIn), Google, Meta (Facebook/Instagram/WhatsApp), Amazon, AOL/Yahoo, and Apple now control our communications infrastructure, wielding unprecedented power over how we connect.
These companies filter our messages, harvest our personal data, and commercialize our relationships with minimal transparency in any way that suits them. They run all our data through machine learning algorithms to find patterns to exploit.
Email is also unreliable for sensitive use. HIPAA does not prohibit email outright, but it requires safeguards—encryption, access controls, and Business Associate Agreements—that ordinary email doesn't provide out of the box, which is why so many healthcare systems had to build costly workarounds.
Despite being a fundamental communication tool, email is plagued by numerous inherent flaws that compromise its effectiveness and security.
The system suffers from vulnerability to phishing attacks and malware, lacks reliable encryption, and provides no guaranteed proof of delivery or receipt.
Users constantly battle with inbox overload, spam, and storage limitations, while attempting to manage unwieldy email chains and attachment version control.
Email can't handle large attachments despite our increasing need to share files. It's a mess.
Imagine:
... if you asked the mail carrier where your letter was, and the reply was, "Check the trash.".
... if you sent a business letter, and the post office read it to determine its deliverability and used the data for its own purposes.
... if all doctors by law were not allowed to use the post office and instead had to build their own private delivery service and you have to pay for it and deal with its shortcomings.
Junk mail false positives are rising due to recent increased security poorly implemented. It's getting worse. The major email providers changed the way they determine deliverability and it's based on nebulous information that is not at all transparent.
This shift from public infrastructure to private control of essential communications - without the consumer protections or universal service requirements that historically existed - represents a profound risk to privacy, democracy, and social cohesion.
This proposal also endorses regulation of cloud platforms. The Internet was invented as a public, vastly distributed network and now Amazon (via AWS) and Microsoft (via Azure) together command a dominant share of the cloud-infrastructure market that the modern web runs on. That is staggering considering the fact that many Americans think of Amazon as a retailer and don't have much awareness of its dominant cloud computing division, AWS.
Key Features
Regulated Delivery System: Overseen by the U.S. Postmaster
Scope: Covers email, social media, and other electronic communications
Transparent Regulations: Federally enforced guidelines for communication delivery
Payment Structure
Free Tier: For personal communications
Scaling Fee System: Increasing with the number of messages sent
Primary Payers: Big Tech companies would pay the bulk of the fees
Funding: Under the Act, fees would fund strict enforcement of regulations and could be used only for that purpose
Safeguards
Privacy protection
Enhanced security measures
Right to delivery guarantee
Freedom from censorship
Right to removal of personal information
Fair practices to encourage innovation
Expected Outcomes
Improved privacy and security for users
Level playing field for tech companies
Reduced monopolistic control over communication channels
Diminished concentration of power over communication platforms
Enhanced user rights and control over personal data
More choice in software and digital services
Better software and digital services
Better user experiences
More opportunities in the technical landscape
More innovation in the technical landscape
Better allocation of venture capital
Accelerated pace of technological advancements and creative solutions
The SECURE Act — Safe Electronic Communication and User Rights Enforcement
This proposal aims to address current issues with Big Tech's control over communication channels and personal data, bringing these critical services under more stringent regulation similar to traditional mail services.
I. Purpose and Scope
The SECURE Act aims to establish comprehensive federal guidelines for regulating digital communications, including email, instant messaging, and social media platforms. It creates a regulatory framework under the authority of the Postmaster General to promote efficient, secure, and fair practices in digital communications while prioritizing user privacy, enhancing user protection and experience, and ensuring open access to communication systems.
II. Definitions
This section will define key terms such as digital communication, email, instant messaging, social media, bulk sending, digital communication provider, personal data, privacy breach, data minimization, API, and interoperability.
III. Authority and Administration
The Postmaster General is proposed as the administering authority for overseeing digital communication regulations, subject to enabling legislation. A new, independent Digital Communications Division shall be established under the authority of the Postmaster General—operating separately from USPS mail operations—to administer the SECURE Act, with a dedicated Privacy Office to oversee all privacy-related matters and an API Standards Office to manage open communication systems requirements.
IV. Privacy Protection and Data Security
This section establishes comprehensive privacy protection measures for all digital communication platforms:
Mandate end-to-end encryption for all personal communications
Guarantee message delivery for legitimate users
Provide notification with reasons for any non-delivery
Establish strict data minimization principles to limit collection and storage of personal data
Require explicit user consent for any data collection beyond what's necessary for service operation
Require transparent reporting for the usage and access of user data and the rationale for it.
Prohibit the sale or sharing of personal data without explicit user consent
Mandate regular privacy audits for all digital communication providers
Establish a "right to be forgotten" across all digital platforms
Require transparent privacy policies in clear, understandable language
Require strict and open data breach notification protocols
V. Regulation of Digital Communication Platforms
A. Email Services
Establish Open APIs to allow developers to build better software and systems
Establish guidelines for email storage, transmission, and delivery
Implement a fee structure for bulk senders while ensuring free access for individual users
B. Instant Messaging Platforms
Establish Open APIs to allow developers to build better software and systems
Set standards for interoperability, data retention, privacy, and security in instant messaging services
Regulate commercial use and implement age verification measures
Require default end-to-end encryption and disappearing messages rules
Allow users to send messages between providers, switch between services and take their history with them
C. Social Media Platforms
Establish Open APIs to allow developers to build better software and systems
Establish transparency requirements for content distribution algorithms
The Act would require measures to identify misinformation and label it as such
Implement measures to protect minors
The Act would regulate political advertisements and provide for resources presenting opposing views
Enforce strict privacy controls, including granular content sharing settings
Implement limitations and transparency on data mining for advertising purposes
D. Streaming Services
Establish Open APIs to allow developers to build better software and systems
Implement strict data protection measures for user viewing habits and preferences
News organizations must maintain an accessible archive of their published content
Archived content should retain its original context and any subsequent corrections or updates
Diversity in Reporting
News organizations should strive for diverse perspectives in their reporting
When covering controversial topics, efforts should be made to present multiple viewpoints
Transparency in Funding
News organizations must disclose their major funding sources and any potential conflicts of interest
Sponsored content must be clearly labeled as such
Data Journalism
When presenting data-driven stories, news organizations must provide access to the raw data or clear explanations of their data analysis methods
VI. Passwordless Authentication Standards
To ensure secure, consistent, and user-friendly authentication across all digital communication platforms, providers must implement standardized passwordless authentication systems. This requirement supports the Act's goals of enhanced security, improved user experience, and reduced vulnerability to common attack vectors such as phishing and credential stuffing.
The shift toward biometric authentication represents a fundamental advancement in digital security. Biometric identifiers - including fingerprints, facial recognition, iris scans, and voice patterns - offer unique advantages over traditional passwords. These biological markers cannot be forgotten, are extremely difficult to duplicate, and provide a more natural and efficient user experience. However, their implementation requires careful consideration of privacy implications and secure storage practices. Unlike passwords, biometric data cannot be simply changed if compromised, making their protection paramount.
A. Core Requirements
Standards Compliance
FIDO2/WebAuthn compliance mandatory
Support for biometric and hardware security keys
Cross-platform compatibility required
Security Features
End-to-end encryption of authentication processes
Phishing-resistant design
Multiple authenticator support
Recovery Methods
Minimum of two backup authentication options
Secure account recovery process
Hardware token backup support
B. Privacy Requirements
Data Protection
Biometric data must remain on user devices
Biometric templates must be encrypted and securely stored
No raw biometric data transmission permitted
Regular security audits required
Clear user consent required for biometric data collection
Right to opt for alternative authentication methods
VII. User Rights and Protections
Define comprehensive user rights regarding data privacy, control, and portability. Establish a "Privacy Bill of Rights" for digital communication users, including the right to access, correct, and delete personal data, and the right to know how their data is being used. Implement universal opt-out mechanisms for unwanted communications.
VIII. Checks on Big Tech Power
The Act would mandate transparency in algorithmic decision-making, enforce strict data privacy standards, and hold platforms accountable for the spread of misinformation. It would prevent arbitrary censorship of lawful communications, ensure interoperability and data portability between platforms, and prohibit the use of personal data for anti-competitive practices.
IX. Open Communication Systems and API Access
This section mandates that large tech companies open their public communication systems through secure and accessible APIs (does not apply to private systems):
Require large tech companies to provide open, well-documented APIs for their communication systems, including but not limited to messaging, email, and social media platforms
Mandate that these APIs provide access to core functionalities, allowing third-party developers to create innovative, interoperable services and applications
Prohibit discriminatory practices in API access, ensuring fair and equal access for all developers, regardless of size or affiliation
Require that API access be provided at no cost or at a reasonable, non-discriminatory cost that does not create barriers to entry for smaller developers or startups
Mandate regular updates and maintenance of these APIs to ensure continued compatibility and security
Establish security standards for API implementation to protect user data and privacy
Prohibit the arbitrary restriction or revocation of API access as a means to stifle competition
Require tech companies to provide adequate notice and transition periods for any significant changes to their APIs
Establish a dispute resolution mechanism for conflicts related to API access and usage
Mandate transparency in API usage policies and any algorithmic processes that might affect the functionality of third-party applications
This will foster User-Friendly Interfaces: Open APIs that are certain to remain open will encourage third party developers to implement user-friendly interfaces that allow individuals to easily navigate and understand their data. This includes clear explanations of what each piece of data means and how it relates to their overall privacy rights. Innovative ways of filtering these communications will emerge which are superior to what is currently available and considered industry standard while being substandard.
X. Economic Controls on Digital Communications
The U.S. Postal Service has effectively managed physical junk mail through a careful balance of economic incentives. While bulk mail rates make mass mailing possible, the tangible costs of printing, preparation, and postage create natural constraints on volume and encourage senders to target their audiences more carefully. This economic model has proven remarkably effective at preventing the postal system from being overwhelmed by spam while still enabling legitimate marketing communications.
Digital communications currently lack these economic constraints. The near-zero cost of sending email has created a "tragedy of the commons" where the absence of meaningful costs has led to rampant spam, compromising the utility of email for everyone. This Act establishes a similar economic framework for digital communications that has proven successful in physical mail.
Detailed metrics on delivery rates and complaint levels
Clear notification when approaching spam thresholds
Immediate alerts when classified as a potential spammer
Violation Explanations
Specific reasons for spam classification
Data-backed evidence of problematic patterns
Historical trend analysis
Comparison to industry standards
Remediation Path
Clear steps to restore good standing
Graduated system of restrictions and reinstatement
Training resources for better practices
Direct access to support for remediation assistance
B. Economic Framework
Cost Structure
Personal communications remain free
Bulk senders pay graduated rates based on volume
Higher rates for less targeted communications
Discounts for authenticated senders with good track records
Quality Incentives
Rate reductions for low complaint rates
Engagement-based pricing
Targeting accuracy bonuses
Reputation-based delivery prioritization
C. Appeal and Reinstatement Process
Appeal Rights
Clear process for disputing spam classification
Right to present evidence and explanation
Independent review of appeals
Expedited process for verified business senders
Reinstatement Requirements
Graduated return to full sending privileges
Mandatory training completion
Probationary period with enhanced monitoring
Regular status review meetings
D. Remediation Support
Resources and Training
Best practices documentation
Interactive training modules
Case studies of successful rehabilitation
Expert consultation services
Compliance Tools
Pre-sending content analysis
List hygiene tools
Engagement monitoring systems
Automated improvement suggestions
The system ensures that no sender is permanently banned without due process and clear opportunities for improvement. By combining economic incentives with transparent enforcement and clear remediation paths, this framework promotes responsible digital communication while providing fair treatment and support for all senders working to maintain or restore their good standing.
XI. Digital Communication Provider Responsibilities
Define minimum standards for security, privacy, and user controls. Require regular auditing and public reporting. Mandate the implementation of anti-impersonation measures. Require providers to appoint a Chief Privacy Officer and implement Privacy by Design principles in all product development.
XII. Enforcement and Penalties
Outline clear enforcement procedures and penalties for non-compliance. Establish a whistleblower protection program for employees of digital communication providers. Implement severe penalties for privacy breaches, unauthorized data sharing, and violations of open API requirements.
XIII. Implementation and Review
Set a phased implementation schedule. Establish a framework for regular review and adaptation of regulations to keep pace with technological advancements. Create an advisory board including technology experts, privacy advocates, user representatives, and API specialists. Conduct annual privacy impact assessments and API accessibility reviews of the Act's implementation.
XIV. International Cooperation
Establish frameworks for international cooperation in regulating cross-border digital communications. Promote the adoption of similar standards in other countries to create a globally coherent regulatory environment. Work towards international agreements on data privacy standards, cross-border data protection, and global standards for open APIs in digital communication systems.
XV. Data Transparency
To further strengthen user rights and transparency regarding personal data, the SECURE Act will include provisions that allow users to view their data in a clear and accessible manner. This will involve:
User Access to Data: All users will have the right to access their personal data as it is stored by digital communication providers. This includes not only the data itself but also metadata that describes how the data is collected, processed, and stored.
Clear Metadata Display: Users will be able to see detailed metadata associated with their data, including:
Collection Date: When the data was collected.
Usage History: How and when their data has been used by the provider including views along with full disclosure of the viewer data
Applicable Policies: Information about the privacy policies that were in effect at the time of data collection, including any changes made to these policies over time.
Policy Transparency: Providers must maintain transparency regarding their data handling practices. This includes making their privacy policies readily available and understandable, ensuring that users are aware of their rights and the implications of their data being collected.
Regular Updates: Users will receive notifications about any significant changes to data policies or practices, ensuring they are always informed about how their data is being managed.
XVI. Large Attachments and Playlists
This section focuses on improving the handling of large files and media content in emails. The main goals appear to be:
Enhancing security through cloud storage and encryption
Improving user experience with easy-to-use interfaces and clear notifications
Optimizing data transfer through compression and streaming protocols
Implementing version control and collaborative features
These guidelines would significantly improve how large files are shared via email, addressing common pain points like size limits and security concerns. The emphasis on secure cloud storage and streaming protocols is particularly relevant in our increasingly media-rich digital communications.
XVII. HIPAA Compliance
This section proposes stringent measures—several of which go beyond HIPAA's current baseline—to secure email communications involving protected health information (PHI). (HIPAA does not categorically bar email; it requires reasonable safeguards such as encryption and Business Associate Agreements.) Key points include:
Mandatory end-to-end encryption for PHI (HIPAA currently treats encryption as an "addressable" safeguard; this Act would make it a firm requirement)
Strict access controls and audit trails
Secure options for healthcare providers, including email-to-fax capabilities
Employee training and regular audits for email service providers
Requirements for Business Associate Agreements (BAAs)
These guidelines would substantially enhance the security and compliance of email communications in healthcare settings. The focus on end-to-end encryption, access controls, and audit trails addresses critical aspects of protecting sensitive health information.
XVIII. Prevention of Government Abuse and Surveillance
This section establishes stringent measures to prevent government overreach and protect citizens from unwarranted surveillance:
Require warrants for any government access to digital communications, with narrow and clearly defined exceptions for immediate threats to life
Prohibit bulk data collection and mass surveillance programs
Mandate transparency reports from both government agencies and digital communication providers regarding government requests for user data
Establish an independent oversight board to review government surveillance activities and ensure compliance with the law
Protect whistleblowers who expose unlawful government surveillance
Ban the use of secret court orders (such as National Security Letters) to compel companies to provide user data without disclosure
Require notification to users whose data has been accessed by the government, with delays only permitted under strict judicial oversight
Prohibit the intentional creation of backdoors or vulnerabilities in encryption systems
Mandate regular audits of government agencies' data access and usage practices
Establish severe penalties for government officials who abuse their authority to access or use personal data
Create a public advocate position in the FISA court system to represent privacy and civil liberties interests
Require detailed logging of all government access to user data, subject to review by the oversight board
Prohibit the use of parallel construction to hide the origin of evidence obtained through surveillance
Mandate the destruction of collected data after a specified period unless its continued retention is justified through a transparent, court-supervised process
These measures aim to balance national security needs with individual privacy rights, ensuring that government surveillance is conducted only when necessary, under strict oversight, and with full respect for civil liberties.
XIX. Public Content Moderation Framework
This Act would establish a unified public moderation system for all digital communications and publications.
Rather than repealing Section 230 of the Communications Decency Act of 1996, it preserves the host immunity that good-faith platforms depend on and supplements it with a transparency, reporting, and appeals layer that applies across all digital platforms.
The system would:
Create a public standardized reporting mechanism (API) so users can flag illegal content, misinformation, disturbing material, scams, age-inappropriate content, hate speech, and other harmful communications.
Create a centralized database of reported content accessible via web and API to law enforcement and authorized moderators and in a redacted format to the public.
Would require all blocked content to have placeholders with reason for removal, with timestamps and moderation links.
Platforms would be expected to monitor this database, enforce restrictions on banned material, and point to placeholders
Encourage development of honest and open public discussion forums about what is banned. The Act would require age and identity verification for sensitive content.
The moderation placeholder will be public, will have an appeals process, a public comments section and will remain while the content is blocked.
Establish clear guidelines for content moderation that social media platforms and other digital communication services would be expected to follow.
Implement a tiered response system based on the severity and frequency of violations.
Implement a tiered system of user's reporting weight based on deviation from the norm.
The Act would require platforms and law enforcement to act on verified reports within specified timeframes.
The Act would mandate transparency in moderation practices and regular public reporting of moderation actions.
Monitor aggressively for abuse from government officials or other parties involved in the administration and security of the system and Provide for severe penalties for such abuse.
XX. Mandatory Public Service Materials
Under this Act, digital communication platforms and services would make available essential public service materials and information. This provision would help ensure that critical public information reaches citizens through all major digital channels.
A. Required Content Categories
1. Emergency Information
Real-time emergency alerts and warnings
Natural disaster preparedness guides
Emergency contact information for local, state, and federal services
Current public health advisories and guidance
2. Civic Education
Voter registration information and deadlines
Information about upcoming elections
Opportunity for access made available to all candidates
Opportunity for opposing views on all public initiatives
Census participation guidance
Basic civics education materials
Information about civic rights and responsibilities
Equitable access made available to all candidates
3. Public Health Resources
Substance abuse prevention and treatment resources
Gambling, eating, stealing and other behavior disorder treatment resources
Warnings of the dangers of driving while impaired or texting
Other public service messages
Vaccination information and schedules
Mental health resources and crisis hotlines
Basic health and wellness guidelines
Information about accessing healthcare services
4. Consumer Protection
Fraud prevention tips and resources
Consumer rights information
Guidelines for identifying and reporting scams
Financial literacy resources
Identity theft prevention information
5. Environmental Information
Local air and water quality data
Recycling and waste management guidelines
Energy conservation tips
Environmental emergency alerts
Climate change information and resources
B. Implementation Requirements
1. Accessibility
Content would be available in multiple languages
Materials would be accessible to users with disabilities
Information would be easily discoverable through platform search functions
Content would be optimized for both desktop and mobile devices
2. Presentation
Public service materials would be clearly labeled and organized
Information would be presented in a clear, concise manner
Regular updates would be made to ensure accuracy
Content would include relevant timestamps and version information
3. Prominence
Platforms would maintain a dedicated section for public service materials
Critical alerts would be displayed prominently when relevant
Regular reminders about available resources would be provided to users
Emergency information would take precedence during crisis situations
C. Quality and Accuracy Standards
1. Content Requirements
All information would come from authorized government sources
Regular verification and updates of all materials
Clear attribution of information sources
Fact-checking protocols for all published materials
2. Update Procedures
Real-time updates for emergency information
Monthly reviews of all static content
Quarterly audits of all public service materials
Annual comprehensive content review
D. Platform Responsibilities
1. Distribution Requirements
Maintain dedicated channels for public service announcements
Integrate public service materials into regular user interfaces
Provide notification systems for critical updates
Enable easy sharing of public service information
2. Reporting and Metrics
Track engagement with public service materials
Report effectiveness metrics to regulatory authorities
Monitor user feedback and accessibility issues
Document distribution and reach of critical information
E. Oversight and Compliance
1. Monitoring
Regular audits of platform compliance
User feedback collection and analysis
Performance metrics tracking
Access and engagement reporting
2. Enforcement
Penalties for non-compliance
Regular compliance reviews
Required remediation plans for violations
Public reporting of platform performance
F. Innovation and Improvement
1. Technology Integration
Implementation of emerging communication technologies
Development of new delivery methods
Integration with platform-specific features
Enhanced user experience innovations
2. Feedback Implementation
User feedback collection systems
Regular stakeholder consultations
Continuous improvement protocols
Innovation incentives for enhanced delivery methods
G. Public Service Materials API
1. API Requirements
All platforms would implement a standardized RESTful API for public service materials
API would support both read and write operations for authorized entities
Implementation would follow OpenAPI 3.0 specifications or later
API would include comprehensive documentation and testing endpoints
Support for real-time updates using WebSocket connections
Rate limiting would not restrict access to critical emergency information
2. Core Endpoints
GET /api/v1/public-service/
GET /api/v1/public-service/emergency
GET /api/v1/public-service/civic
GET /api/v1/public-service/health
GET /api/v1/public-service/consumer
GET /api/v1/public-service/environmental
POST /api/v1/public-service/emergency (authorized entities only)
PUT /api/v1/public-service/{id} (authorized entities only)
DELETE /api/v1/public-service/{id} (authorized entities only)
3. Data Structure Standards
All responses must include standardized metadata fields
Support for multiple content formats (JSON, XML, HTML)
Role-based access control for different API operations
Digital signatures for content verification
Audit logging for all API operations
Required SSL/TLS encryption for all communications
5. Integration Requirements
Support for webhook notifications for critical updates
Batch operation capabilities for efficient data synchronization
Caching mechanisms with clear cache invalidation protocols
Fallback mechanisms for degraded service conditions
Support for bulk data export and import
6. Performance Standards
99.999% uptime requirement for emergency information endpoints
Maximum 500ms response time for critical endpoints
Support for high-volume concurrent requests
Automatic scaling capabilities during emergency situations
Regular performance testing and reporting
7. Developer Support
Comprehensive API documentation with examples
Interactive API testing console
Sample code in multiple programming languages
Development sandboxes for testing
Support for common API management tools
8. Compliance and Monitoring
Real-time API health monitoring
Automated compliance checking for API implementations
Regular security assessments
Performance metrics tracking and reporting
Incident response protocols
Open Items & Refinements
Phased implementation & small-business relief — Specific phase-in periods (18–24 months for large providers, 36 months for small), grace periods, reduced requirements for startups, and technical assistance programs.
Identity & emergency-services integration — Privacy-preserving identity verification standards; requirements for emergency services access, location data sharing, and response-time SLAs.
Funding & cost recovery — Detailed fee tiers scaling with message volume, exemptions for non-profits and educational institutions, cost-sharing provisions, and specification of how collected fees may be used.
Multi-stakeholder technical standards board — An advisory body of industry, civil-society, and government representatives to govern: required API endpoints and schemas, rate limits, encryption and key-management minimums, audit logging standards, and certification processes. Regular review and update cadences.
Innovation sandbox — A regulatory safe harbor for testing new technologies and experimental features, with clear boundaries and sunset provisions.
Enforcement clarity — Specific penalty structures, appeals processes, complaint-resolution timeframes, escalation procedures, and documentation requirements.
Core tenets to preserve — Comprehensive platform scope, strong user-protection focus (privacy, rights, complaint mechanisms), and detailed technical standards (APIs, security, data protection) with future-proofing provisions.
XXI. Documented Correspondence with Covered Entities
⚠️ Data disclaimer: Figures and legal references in this section require independent verification before use in any formal setting.
The Bell System was required to publish a directory and to staff operators who would
connect a caller to the party they were trying to reach. A citizen who needed to reach
a company could find the number, place the call, and be connected. That obligation was
not a courtesy; it was a condition of operating the network.
No equivalent obligation exists today. A consumer with a problem is routed through
chatbots, phone trees, and no-reply addresses, and at the end of it neither party holds
a record of what was asked or what was answered. The company can say it responded. The
consumer can say it did not. Nothing in the channel can settle it.
The absence of that obligation has not made access to a person cheap. It has made it a
product. LinkedIn, a Microsoft subsidiary, sells the right to attempt contact with a
stranger through a credit called an InMail. Sales Navigator Core lists at $99 per month
for fifty credits, which is roughly two dollars for one attempted message; the Advanced
tier runs about three dollars per attempt; Recruiter Lite is higher still, and
enterprise Recruiter carries no public list price at all. A recruiter working a hundred
candidates a month is paying a few hundred dollars for the privilege of trying to reach
people who never agreed to be reachable.
What that money buys is worth reading closely. The credit is refunded only if the
recipient replies, within ninety days. The pricing is therefore explicit that the
product is an attempt, not a delivery — silence is the billable outcome, and it
is the ordinary one. The sender receives no confirmation that the message was delivered,
no confirmation that it was seen, and no stated reason when nothing comes back. The
recipient, for their part, never consented to the transaction, cannot tell a paid
approach from an unpaid one, and holds no record of it either. Two parties, real money
changing hands, and neither of them ends up with proof of anything.
That would be a narrow complaint if the channel stood alone. It does not. LinkedIn has
been a wholly owned subsidiary of Microsoft since 2016, when Microsoft acquired it for
$26.2 billion, and it now reports more than 1.3 billion registered member accounts.
What matters is not that number but what sits beside it inside the same company.
Microsoft operates the professional graph on which the approach is made, the Outlook and
Exchange systems through which a great deal of the resulting business correspondence
travels, the Teams service on which the follow-up conversation happens, the GitHub
platform on which much of the work product is stored, the Azure infrastructure that hosts
roughly a fifth of the world's cloud capacity, and the Windows operating system on the
machine where all of it is typed. It is deploying AI assistants across every one of those
surfaces. No competitor sees that stack, and no citizen can opt out of enough of it to
matter.
None of those holdings is unlawful, and none of this alleges misconduct. The objection is
structural. No regulator sets delivery standards for a social network the way one does for
a bank, a carrier, or a broadcaster. There is no obligation to deliver a message, no
obligation to explain a message that was not delivered, no audit of the ranking that
decides whose approach is seen and whose is buried, and no independent view of any of it.
A single firm sets the price of access, the odds of arrival, and the terms of the record —
and holds the inbox, the infrastructure, and the endpoint besides. The pattern is not
unique to one company; Google assembles the consumer-side equivalent from Gmail, Android,
Search, YouTube, and Google Cloud. Microsoft is named here because the professional graph
and the working inbox sit under one roof, which makes the concentration easiest to see.
In any other channel carrying this much of civic and economic life, that arrangement would
have been given a rulebook decades ago.
A first-class stamp buys carriage of a letter, and for a small additional fee it buys
certified proof that the letter was delivered and to whom. That has been true for over
a century. In the digital channel a sender pays several times the price of a stamp and
receives neither.
This section does not answer that larger problem, and should not be read as claiming to.
It does not break up a holding, regulate a ranking, or set a price. It makes one narrow
demand: that somewhere in the arrangement there exist a channel where the record belongs
to both parties. This section does not compel any entity to answer a message. It requires
that the message be receivable, that its delivery be provable, and that the resulting
record belong to both parties. The Act does not manufacture a reply. It removes
the ability to deny that the question was asked.
⚠️ Data disclaimer: LinkedIn pricing figures come from third-party trackers, not official sources. Verify before citing.
A. Published Points of Contact
Directory Obligation
Every covered entity shall publish and maintain at least one UDCP address designated for correspondence from natural persons.
Designated addresses shall be listed in a public directory maintained by the Digital Communications Division, queryable without charge and without authentication.
Entities operating distinct consumer-facing lines of business shall designate an address for each, so that a consumer is not required to guess which division holds their matter.
A change of designated address shall be reflected in the directory before it takes effect, and messages to the prior address shall continue to be accepted for not less than one hundred eighty days.
B. Obligation to Receive
Acceptance
A covered entity shall accept UDCP messages transmitted to its designated address from any authenticated sender.
An entity may not refuse, discard, or route to an unmonitored destination a message properly addressed and authenticated under the UDCP.
Where an entity declines to accept a message, the non-delivery notification requirements of Section IV apply, and the stated reason becomes part of the correspondence record.
Volume-based rate limiting is permitted against a single sender only where the pattern meets the bulk-sender thresholds of Section IX, and any such limitation shall itself be disclosed to the sender.
Automated Acknowledgment
Delivery confirmation shall be generated by the protocol under the UDCP delivery-confirmation requirement, not authored by the receiving entity.
An acknowledgment records that a message was delivered and, where applicable, retrieved. It is not a substantive response and shall not be represented as one.
C. The Correspondence Record
Thread Identity
Each correspondence initiated under this section shall carry a persistent thread identifier that survives transfer between departments, agents, vendors, and successor entities.
A consumer shall not be required to restate a matter because an entity has reassigned it internally.
Contents of the Record
Authenticated identity of each sender, per the UDCP sender-authentication requirement.
Transmission and delivery timestamps, and retrieval timestamps where retrieval occurs.
Message integrity verification, per the UDCP message-integrity requirement.
Any non-delivery event and the reason stated for it.
Intervals during which no response was transmitted.
Symmetrical Access
Both parties shall be able to export the complete record in a standardized, machine-readable format at any time, without charge and without requesting it from the other party.
Neither party may unilaterally delete, alter, or expire the other party's copy.
Retention shall be not less than seven years, or the applicable statute of limitations for the underlying subject matter, whichever is longer.
D. Evidentiary Standing
Certification
A correspondence record exported under subsection C, accompanied by the Division's certification of the cryptographic process that produced it, is intended to be self-authenticating as to the fact and time of transmission, delivery, and retrieval.
Self-authentication concerns the genuineness of the record only. It does not render the contents admissible for their truth, and does not displace hearsay, relevance, privilege, or any other rule of evidence.
The Division shall publish the certification procedure and the conformance tests a record must pass.
Prohibited Contradiction
A covered entity may not assert in any proceeding, or in any communication to a regulator, that it transmitted a communication that the record shows was not delivered.
Drafting note — this subsection needs counsel before it goes further.
Federal Rules of Evidence 902(13) and 902(14), added by the 2017 amendments, already
provide for self-authentication of records generated by an electronic process and of
data copied from an electronic device, in each case on certification by a qualified
person. Subsection D is modeled on that structure and should be checked against the
current text of those rules rather than against this description of them. Two cautions:
self-authentication under Rule 902 establishes only that a record is what it purports
to be, and an authenticated record can still be excluded on hearsay or other grounds;
and the Federal Rules govern federal proceedings, so state-court treatment will vary
and cannot be assumed. Whether a federal statute should attempt to direct evidentiary
treatment in state proceedings is a real question and is not resolved here.
E. No Compelled Response
Limitation
Nothing in this section requires a covered entity to respond to any message, to respond within any period, or to respond in any particular manner.
An entity may decline to respond. The absence of a response is recorded as an interval in the correspondence record and carries no penalty under this Act.
No provision of this section shall be construed to require a covered entity to adopt, endorse, or transmit any statement of position.
Effect
Where another federal or state law, a contract, or a sector-specific regulation already imposes a duty to respond, the correspondence record is available as evidence of compliance or non-compliance with that separate duty.
This section creates the record. It does not create the duty.
Drafting note — why subsection E is written this way. A mandate that
a private company reply to a consumer on a government-run channel would be compelled
speech, and would be litigated as such. The doctrine here is unsettled and moving:
Zauderer v. Office of Disciplinary Counsel (1985) has been read to permit
compelled disclosure of purely factual, uncontroversial information in commercial
advertising, while NIFLA v. Becerra (2018) declined to extend that reasoning
and applied heightened scrutiny to a state-mandated notice. The safer construction —
and the one adopted here — obliges an entity only to receive, and leaves
speech entirely voluntary. A machine-generated delivery confirmation is produced by
the protocol rather than authored by the entity, which is a meaningful distinction but
not a settled one. This analysis is a starting point for counsel, not a legal opinion,
and the compelled-speech question should be briefed before this section is circulated
to lawmakers.
F. Anti-Circumvention
Prohibited Practices
An entity may not condition the provision of goods or services on a consumer's waiver of the right to correspond under this section.
An entity may not require that a matter be raised only through a proprietary channel that produces no exportable record.
An entity may not impose materially worse terms, longer delays, or reduced remedies on a consumer for having used the designated address.
Proprietary support channels remain permitted and may be offered alongside the designated address. They may not be the only path.
G. Accommodation for Small Entities
Scaled Obligations
Entities below the threshold established by the Division may designate a forwarding address that delivers to an existing mailbox, satisfying subsections A and B without separate infrastructure.
Legacy systems may satisfy this section through the single SMTP header contemplated in the UDCP legacy-support provision.
The phase-in periods of the Technical Standards section apply, and no obligation under this section takes effect before UDCP implementation is required of that entity.
H. Enforcement
Violations of this section are subject to the enforcement procedures and penalties of Section XI.
Failure to maintain a designated address, refusal to accept properly authenticated messages, and the circumvention practices enumerated in subsection F are each independently actionable.
The Division shall publish annual statistics on directory coverage, acceptance rates, and response intervals by sector, in aggregate and without identifying individual consumers.
The intent of this section is narrow and should not be overstated. It does not make any
company helpful. It does not shorten a hold time or improve an answer. It establishes
that when a citizen puts a question to an institution, the asking is a matter of record,
the delivery is a matter of record, and the silence, if there is silence, is a matter of
record too. Every other remedy a consumer might pursue — a regulator, a contract claim,
a court — currently fails at the same first step, which is proving what was said and when.
This section fixes that step and leaves the rest to the law that already exists.
Technical Standards
Universal Digital Communications Protocol (UDCP)
(a) Standard Development:
The Digital Communications Division (see III. Authority and Administration) shall develop and maintain the UDCP in concert with the industry
Protocol must ensure:
End-to-end encryption
Message integrity
Sender authentication
Delivery confirmation
Interoperability
(b) Implementation Requirements:
All providers must implement UDCP within 24 months
Small providers (<100,000 users) given 36 months
Legacy system support requirements
Existing email systems can become compliant with one SMTP header
API Standards
(a) Mandatory APIs:
Message transmission
User authentication
Content moderation
Data portability
Emergency services integration
(b) API Requirements:
RESTful design
OAuth 2.0 authentication
Rate limiting standards
Documentation requirements
Testing environments
APPENDICES
Appendix A: Technical Specifications
[Detailed technical requirements and standards]
Appendix B: Implementation Guidelines
[Detailed implementation guidance for providers]
Appendix C: Compliance Checklist
[Comprehensive compliance requirements]
Appendix D: Fee Schedule
[Detailed fee structures and calculations]
Areas for Improvement
Policy Framework Refinements
Regulatory Authority Clarification: The proposal places authority with the U.S. Postmaster, but should more clearly define how this would interface with existing agencies like the FCC and FTC that currently regulate aspects of digital communications.
Small Business Accommodations: While the document mentions extended compliance periods for smaller providers, it would benefit from more comprehensive accommodations to prevent creating barriers to entry for startups and small tech companies.
First Amendment Considerations: Any government regulation of communication platforms raises important constitutional questions. The proposal should include a thorough legal analysis addressing potential First Amendment concerns and how the regulatory framework preserves free speech.
Technical Implementation
Technical Standards Development: The proposal would benefit from a more explicit process for developing and updating technical standards, perhaps through a multi-stakeholder approach including industry, civil society, and technical experts.
Security Measures: While end-to-end encryption is mentioned repeatedly, more detailed requirements around implementation, key management, and security auditing would strengthen the proposal.
API Standardization: The Open API requirements are promising but would benefit from more detailed specifications and governance mechanisms to ensure they remain truly open and accessible.
Economic Framework
Fee Structure Details: The economic framework could be more clearly detailed, including specific fee tiers, how they scale with message volume, and exemptions for non-profits or educational institutions.
Implementation Costs: A more detailed analysis of implementation costs for both government and private sector would help build support and identify potential challenges.
Competition Impact: Additional analysis on how these regulations would impact competition in the tech sector would strengthen the case for the proposal.
The SECURE Act represents an ambitious attempt to bring comprehensive regulation to digital communications, drawing on historical precedents while addressing modern challenges. With refinements to its implementation framework, technical specifications, and economic model, it could offer a compelling vision for a more secure, private, and user-centric digital communications infrastructure.
The SECURE Act proposes the missing piece: an independent watchdog for digital communications built around privacy, interoperability, and user rights. And by requiring bulk emailers to pay a small fee, we can reduce the flood of unsolicited and unchecked messages clogging our inboxes. It’s a framework that can be adopted now, not a bill waiting on Congress.
Public Comments