Regulation Finder/United States

United States

Moderate

Sectoral: CCPA/CPRA, HIPAA, COPPA, GLBA, state laws

Authority: FTC + State Attorneys General | Enforcement: Active | Enacted: January 2020

Overview

The US lacks a comprehensive federal privacy law. Instead, it relies on a patchwork of sectoral federal laws (HIPAA for health, COPPA for children, GLBA for financial) and rapidly expanding state laws. California's CCPA/CPRA is the most comprehensive, with 19+ states having enacted privacy legislation by 2026. The American Data Privacy and Protection Act (ADPPA) has been proposed but not enacted.

14-Topic Coverage

Data Protection Authority

Partially Addressed

No single federal DPA. FTC has de facto authority through Section 5 (unfair/deceptive practices). California Privacy Protection Agency (CPPA) is the first dedicated state privacy regulator. State AGs enforce state privacy laws.

FTC Act Section 5, CCPA/CPRA

Data Subject Rights

Partially Addressed

CCPA/CPRA provides: right to know, delete, correct, opt-out of sale/sharing, limit use of sensitive data, and non-discrimination. Other state laws provide similar but varying rights.

CCPA Sections 1798.100-125

Cross-Border Transfer

Not Addressed

No general restrictions on international data transfers. EU-US Data Privacy Framework enables transfers from EU. Sector-specific requirements may apply (e.g., ITAR for defence data).

EU-US Data Privacy Framework 2023

Breach Notification

Fully Addressed

All 50 states have breach notification laws. Generally require notification to individuals and state AG. Timelines vary (24 hours to 60 days). No single federal breach notification law.

State breach notification laws (50+)

DPO Requirements

Not Addressed

No general DPO requirement. HIPAA requires a Privacy Officer for covered entities. Some state laws encourage but do not mandate privacy officers.

HIPAA Privacy Rule

Children's Data

Fully Addressed

COPPA requires verifiable parental consent for children under 13. FTC actively enforces. Several states (CA, CT, TX) have additional children's privacy laws. Age-appropriate design codes emerging.

COPPA, CA AADC (AB 2273)

Penalties & Enforcement

Fully Addressed

FTC can impose unlimited penalties for violations. CCPA: $2,500/violation, $7,500/intentional violation. State AGs can pursue civil penalties. Private right of action for data breaches under CCPA.

CCPA Section 1798.155, FTC Act

Sector-Specific Rules

Fully Addressed

HIPAA (health), GLBA (financial), FERPA (education), FCRA (credit reporting), ECPA (electronic communications). Most regulated sectors have specific data rules.

HIPAA, GLBA, FERPA, FCRA

AI & Automated Decisions

Partially Addressed

No comprehensive federal AI law. Colorado AI Act (2024) regulates high-risk AI. NYC Local Law 144 requires bias audits for automated employment decisions. FTC scrutinising AI practices.

Colorado AI Act, NYC LL 144, Executive Order on AI (2023)

Data Localisation

Not Addressed

No general data localisation requirements. Sector-specific requirements for government data (FedRAMP) and some financial data.

FedRAMP, ITAR

Significant Data Fiduciary

Not Addressed

No equivalent concept. Large data brokers subject to registration requirements in some states (California, Vermont).

CA Data Broker Registry, VT Act 171

Government Data

Fully Addressed

Fourth Amendment protections. FISA and Executive Order 14086 govern intelligence community access. Privacy Act of 1974 governs federal agency data. State laws vary.

Privacy Act 1974, FISA, EO 14086

Key Statistics

Maximum Penalty
Varies by law — CCPA: $7,500/violation; FTC: unlimited
Authority
FTC + State AGs

Coverage Summary

Fully Addressed5/14
Partially Addressed5/14
Not Addressed4/14
Pending0/14

Need Compliance Help?

Our data privacy team can help you navigate United States's regulations.

Book a Consultation