Numerous businesses outside the US believe that adhering to the European Union’s GDPR or a comparable law from their home country will sufficiently meet US legal obligations, as noted by Kevin Coy and Erin Doyle from Arnall Golden Gregory. However, the regulatory landscape in the US is fragmented, varies significantly by sector and state, and presents unique regulatory and litigation challenges that compliance with home-country laws often does not cover.
Professionals in compliance, in-house legal teams, and business executives should examine 12 key areas related to data privacy and security diligence, contractual terms, and governance when strategizing for operations in the US.
These areas are interconnected and frequently overlap. Additionally, this list is not comprehensive. Various federal and state privacy laws govern numerous other topics not included here, such as motor vehicle records, educational records, video rental records, library records, and loyalty program data, among others.
1. Sectoral federal privacy laws
Although the US lacks a comprehensive privacy law, it does have several sector-specific and issue-focused privacy regulations. Notable examples include HIPAA regulations, which pertain to certain health-related entities, and the Gramm-Leach-Bliley Act, which governs financial institutions.
HIPAA regulates protected health information managed by “covered entities,” which include many healthcare providers and health plans, as well as their “business associates,” a wide range of companies that process protected health information on behalf of covered entities. Both covered entities and their business associates must comply with HIPAA’s privacy, security, and data breach notification regulations, which include specific contracting and compliance obligations.
Some states, like Washington and Nevada, have implemented strong health information privacy laws designed to address gaps in consumer health data privacy where HIPAA does not apply, with Washington’s law providing a private right of action.
The Gramm-Leach-Bliley Act encompasses a broad spectrum of financial institutions beyond just banks, mandating specific privacy notices, regulating the sharing of “non-public personal information,” and enforcing information security standards.
Foreign companies entering the health or financial services sectors should regard HIPAA and the Gramm-Leach-Bliley Act as primary regulatory frameworks rather than mere additions to their home-country obligations.
2. State privacy laws
The US still does not have a singular federal law akin to the GDPR, yet over 20 states have enacted comprehensive consumer privacy laws, beginning with the California Consumer Privacy Act and followed by states such as Virginia, Colorado, Connecticut, Texas, and others. California is particularly demanding in terms of operational requirements: it established a dedicated privacy regulator, the California Privacy Protection Agency, and is notably aggressive in enforcement.
Each state’s legislation is unique, but they generally include requirements for privacy notices, obligations regarding consumer rights (such as access, deletion, correction, and opt-out options), concepts of purpose limitation, data minimization, and vendor contracting obligations. While these laws are applicable across various sectors, they do not apply universally to all businesses due to differing applicability triggers and exceptions. Consequently, the effect of this category of state laws is contingent on the size and scope of business operations and the states in which they will operate. Therefore, conducting a threshold assessment to determine which state laws are relevant to an entity should be viewed as an essential initial step in any US privacy strategy.
3. Marketing and communications privacy
In the realm of marketing and communications, the US federal CAN-SPAM Act and similar state laws establish regulations for commercial email, including identification requirements, opt-out mechanisms, and accuracy of header information. The Telephone Consumer Protection Act and corresponding state mini-TCPA statutes impose strict regulations on telemarketing and text messaging.
Source: Original article