Many non-US businesses mistakenly believe that adherence to the European Union’s General Data Protection Regulation (GDPR) or similar domestic data privacy laws will sufficiently address the complexities of US regulatory requirements. However, Kevin Coy and Erin Doyle of Arnall Golden Gregory highlight a critical misconception: the US regulatory landscape is a fragmented mosaic, heavily influenced by specific sectors and individual states, presenting distinct compliance and litigation risks often overlooked by those solely focused on their home-country laws. This fragmented approach necessitates a granular understanding of at least twelve key areas for any organization planning US operations.
The perceived simplicity of a single, overarching data privacy law like GDPR is absent in the United States. Instead, businesses encounter a multifaceted system where federal laws address specific industries, while a growing number of states are enacting their own comprehensive consumer privacy statutes. This dichotomy creates a challenging environment where compliance with one set of rules does not automatically guarantee adherence to another, leading to potential legal and financial repercussions. The authors emphasize that compliance professionals, in-house legal counsel, and business leaders must conduct thorough diligence across data privacy, security, contract terms, and governance frameworks to effectively navigate this intricate terrain.
The Fragmented Landscape: Sectoral Federal Laws
While a singular, comprehensive federal privacy law akin to GDPR remains elusive in the US, the nation has established a series of sector-specific federal statutes that govern data privacy and security. Prominent among these are the Health Insurance Portability and Accountability Act (HIPAA) and the Gramm-Leach-Bliley Act (GLBA).
HIPAA, a cornerstone of US healthcare regulation, imposes stringent requirements on "covered entities" – which encompass a broad spectrum of healthcare providers, health plans, and their "business associates." Business associates are defined as a wide array of companies that process protected health information (PHI) on behalf of covered entities. Compliance with HIPAA mandates not only privacy and security rules but also detailed data breach notification regulations, along with specific contractual obligations and adherence frameworks. For instance, a breach affecting electronic protected health information (ePHI) under HIPAA can trigger mandatory notification to affected individuals, the Department of Health and Human Services (HHS), and potentially the media, depending on the scale of the breach. The penalties for HIPAA violations can range from tens of thousands to millions of dollars per violation, depending on the level of culpability.
The GLBA, conversely, targets financial institutions, a category that extends beyond traditional banks to include a wide range of entities involved in financial services. This act mandates specific privacy notices to consumers, regulates the sharing of "non-public personal information," and imposes robust information security requirements. Financial institutions are expected to develop and maintain comprehensive information security programs designed to protect customer data, with regular risk assessments and audits becoming standard practice. Failure to comply can result in significant fines and reputational damage.
Foreign businesses operating within these sensitive sectors must treat HIPAA and GLBA not as supplementary to their existing compliance frameworks but as primary regulatory regimes that demand dedicated attention and resources. The implications of non-compliance can be severe, impacting market access and financial stability.
The State-Driven Revolution: A Patchwork of Consumer Privacy Laws
The absence of a federal GDPR-equivalent has spurred a wave of state-level legislative action. As of early 2024, over twenty states have enacted comprehensive consumer privacy statutes, with California’s Consumer Privacy Act (CCPA) serving as the trailblazer. This trend has been further amplified by subsequent legislation in states such as Virginia (Virginia Consumer Data Protection Act – VCDPA), Colorado (Colorado Privacy Act – CPA), Connecticut (Connecticut Data Privacy Act – CTDPA), and Texas (Texas Data Privacy and Security Act – TDPSA), among others.
California’s pioneering role is particularly noteworthy. The state not only enacted the CCPA but also established the California Privacy Protection Agency (CPPA), a dedicated regulator tasked with enforcing its ambitious privacy framework. The CPPA’s proactive enforcement stance and the CCPA’s broad scope, which includes significant consumer rights and stringent business obligations, make California a particularly demanding jurisdiction.
While these state laws share common threads – including requirements for privacy notices, consumer rights for access, deletion, correction, and opt-out options, along with principles of purpose limitation and data minimization – each statute possesses unique characteristics. These differences necessitate careful analysis to determine applicability, as they often contain varied thresholds and exceptions that depend on a business’s operational scale, the types of data processed, and the specific states in which it operates. For example, the CCPA’s applicability is triggered by meeting certain revenue thresholds, processing a significant amount of personal information, or deriving a substantial portion of revenue from selling personal information. Other state laws may have different triggers, such as the number of residents whose personal information is processed.
A foundational step for any US privacy strategy, therefore, involves a granular assessment of which state laws apply to an entity. This initial evaluation is crucial for tailoring compliance programs effectively and avoiding potential enforcement actions. The cumulative impact of these disparate state laws creates a complex compliance burden that demands ongoing monitoring and adaptation.
Specific Regimes: Marketing, Communications, and Digital Interactions
Beyond broad consumer privacy statutes, the US regulatory landscape includes specific laws governing marketing, communications, and digital interactions. The federal Controlling the Assault of Non-Solicited Pornography and Marketing Act (CAN-SPAM Act) sets forth rules for commercial email, including requirements for clear identification, opt-out mechanisms, and accurate header information. Parallel state laws often supplement these federal provisions, creating a layered regulatory environment.
The Telephone Consumer Protection Act (TCPA) and its state-level counterparts impose significant restrictions on telemarketing, text messaging, and the use of automated dialing systems. These laws are particularly relevant for businesses engaging in direct consumer outreach. The proliferation of class-action litigation stemming from TCPA violations underscores the importance of strict adherence to its provisions. For instance, a single unsolicited marketing text message sent without proper consent can lead to substantial statutory damages, often magnified through class action lawsuits.
Furthermore, the use of website tracking technologies, such as cookies and pixels, as well as the recording of videos and calls, are subject to specific US regulations. Federal and state wiretapping and eavesdropping statutes, alongside call-recording laws, mandate varying levels of consent – either one-party or all-party – depending on the jurisdiction. Increasingly, plaintiffs are leveraging these legal frameworks to challenge the deployment of "session replay" technologies, which record user interactions on websites, alleging violations of privacy rights. Businesses with physical retail locations or other operational sites in the US may also face requirements for video surveillance notices. A thorough review of practices related to these digital interactions is essential to mitigate potential legal risks.
Protecting Vulnerable Populations: Children’s Privacy
The privacy of children is a paramount concern within the US regulatory framework, addressed by both federal and state laws. The Children’s Online Privacy Protection Act (COPPA) is the cornerstone of federal regulation in this area. COPPA applies to online services directed at children under 13 or those that knowingly collect personal information from such children. Its core requirements include obtaining verifiable parental consent before collecting most personal data, providing clear and comprehensive privacy notices, limiting the use and disclosure of children’s data, and implementing reasonable security measures. The Federal Trade Commission (FTC) is the primary enforcer of COPPA, often working in conjunction with state attorneys general.
Adding another layer of complexity, an expanding array of state-specific laws are being enacted to bolster protections for minors, often extending safeguards to individuals up to the age of 18. These laws frequently address issues such as age-appropriate design principles, enhanced privacy settings for minors, and restrictions on profiling and targeted advertising directed at younger users. This multilayered approach necessitates a nuanced understanding of both federal and state mandates to ensure comprehensive compliance.
The Rise of AI and Automated Decision-Making
The rapid advancement and deployment of Artificial Intelligence (AI) and automated decision-making technologies have prompted a surge in new and proposed state laws across the US. These emerging regulations are primarily focused on enhancing AI transparency, mandating data minimization practices, addressing bias and discrimination risks, and requiring impact assessments for AI models that rely on sensitive personal information or materially affect individuals’ lives, such as in employment, housing, or credit decisions.
Non-US businesses may find that AI governance programs developed with GDPR or the EU AI Act in mind require significant adaptation to meet specific US expectations. This includes navigating distinct disclosure requirements, consent mechanisms, notice content, and opt-out provisions. Furthermore, US regulations are placing heightened scrutiny on the quality and provenance of training data, the intricacies of consumer and employee data reuse for AI purposes, and the potential for algorithmic bias.
Employee and Applicant Privacy: A Complex Web
Entering the US market can present unexpected challenges regarding employee and applicant privacy due to a fragmented set of rules. The federal Fair Credit Reporting Act (FCRA), alongside numerous state laws, governs the use of third-party background screening reports for both applicants and employees. Many states also have "ban the box" and "fair chance" laws that restrict when and how criminal history information can be requested and utilized during the hiring process, often requiring delayed inquiries and individualized assessments to mitigate discrimination. Additionally, various state laws impose limitations on the use of credit reports and salary history information in hiring.
Employers also face state-specific regulations concerning lawful off-duty conduct, drug-testing protocols, and restrictions on requesting social media credentials or disciplining employees for lawful online activities. These diverse regulations necessitate careful coordination of global human resources and compliance policies to ensure adherence across different jurisdictions. It is also important to note that employee health plans may fall under HIPAA requirements if the employer is considered a covered entity.
Biometric Data and Cybersecurity Mandates
Several US states have enacted specific statutes governing the collection and use of biometric data, with Illinois’s Biometric Information Privacy Act (BIPA) being a prominent example that has frequently been the subject of private class-action lawsuits. These laws typically apply to technologies such as fingerprint time clocks, facial recognition systems, and voiceprints, and often require informed consent, data retention limits, and secure disposal protocols.
Cybersecurity obligations are also increasingly being codified through detailed statutory standards and regulatory guidance. Many state privacy laws now explicitly mandate appropriate technical, administrative, and physical safeguards that are commensurate with the sensitivity and volume of personal data processed. Some state laws even prescribe specific security controls, risk assessments, and governance structures, particularly within the financial services and critical infrastructure sectors. For instance, California is soon to require certain businesses covered by COPPA to conduct cybersecurity audits and submit certifications. These state-level mandates often complement or exceed federal sectoral requirements, such as those found in HIPAA or GLBA.
Businesses that have designed their cybersecurity programs around a single global standard, such as GDPR, must carefully assess whether US state- or sector-specific mandates regarding encryption, access management, multi-factor authentication, vendor oversight, incident response, board-level reporting, and regulatory notification necessitate tailored enhancements for their US operations.
Data Breach Notification: A Universal Requirement
Every US state and territory has enacted data breach notification statutes, imposing obligations to inform individuals, and in some cases regulators or credit bureaus, when defined personal information is accessed or acquired without authorization. These laws typically specify notification timelines and content requirements. However, they vary significantly regarding the scope of covered entities, the definition of covered data, the presence of "risk of harm" exceptions, and permissible delays for law enforcement investigations. Consequently, multistate data breaches demand a coordinated, state-specific analytical approach to ensure compliance.
In addition to state laws, certain businesses may be subject to federal breach notification rules under regimes like the Securities and Exchange Commission (SEC) requirements for publicly traded companies, HIPAA, or GLBA. Therefore, businesses entering the US market should develop US-focused breach notification protocols to anticipate and manage potential data breaches involving US personal data effectively.
Emerging Regulations: Government Data and Sensitive Transfers
Historically, the US has not regulated the export of personal data to other jurisdictions in the same manner as GDPR or many other national data protection laws. However, this landscape is evolving. In January 2025, the US Department of Justice (DOJ) finalized regulations that restrict or prohibit certain "covered data transactions" involving bulk US sensitive personal data or US government-related data with specified "countries of concern" and "covered persons." The definition of "bulk US sensitive personal data" is broad, encompassing categories such as personal identifiers, precise geolocation, biometric identifiers, health and financial data, and human genetic and molecular biological data, when certain thresholds are met within a 12-month period.
A separate law enacted in 2024 also restricts the sale or transfer of personal data by third-party data brokers to "adversary countries" or entities under their control. Compliance with these new regulations necessitates a clear understanding of data flows, as contractual safeguards will differ based on whether parties are US-based, foreign, or considered "covered persons" under these rules. These measures will apply in addition to any data transfer requirements mandated by home-country data protection laws, such as GDPR.
Unfair or Deceptive Practices: A Broad Brush
The Federal Trade Commission (FTC) and state regulators have long utilized prohibitions against unfair or deceptive acts and practices (UDAP) to take action against businesses that fail to uphold their privacy and data security promises, or that engage in unfair data handling practices. While UDAP laws may seem less granular than specific operational compliance regimes, they represent a significant enforcement tool. Federal and state regulators have initiated hundreds of UDAP cases over the years.
To avoid engaging in deceptive practices, businesses must ensure that their public privacy and security promises are consistently reflected in their actual operations. Furthermore, "unfairness" claims do not require a broken promise; they can arise from inadequate data security practices that result in substantial, unavoidable consumer injury. Consequently, businesses considering entry into the US market should review their privacy policies, notices, and other public commitments, alongside their data security practices, from this broader UDAP perspective, in addition to adhering to more specific regulatory requirements applicable to their US operations.
The Dual Threat: Regulatory Enforcement and Litigation Risks
A significant aspect of the US data privacy and security landscape is the robust environment for both regulatory enforcement and private litigation. Many of the laws and regulations discussed above grant private rights of action, making the US a particularly attractive venue for class-action plaintiffs seeking damages for privacy and security violations. Simultaneously, federal and state regulators, including the FTC, sectoral regulators, state attorneys general, and specialized bodies like the California Privacy Protection Agency, actively pursue enforcement actions against businesses found to be in violation of privacy and security mandates.
While compliance with GDPR or other non-US data protection frameworks can provide a foundational level of data protection, it is not a panacea for US compliance. Even when US federal and state laws share similar privacy protection goals with international regulations, they can diverge significantly in crucial areas. These differences include the scope of application, legal bases for data processing, consent standards, the design and content of privacy notices, rules governing automated decision-making, and, critically, the potential for private litigation exposure. Non-US businesses planning to enter or expand within the US market must therefore undertake a targeted US privacy and data use assessment. This assessment should encompass consumer, employee, and business-to-business data flows to inform and calibrate governance, contracting, technology adoption, and insurance strategies to effectively navigate this distinct and dynamic regulatory and litigation landscape. The financial and reputational consequences of missteps can be substantial, underscoring the necessity of a proactive and comprehensive approach to US data privacy compliance.
