No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

There’s Always Next Year? The Outlook for National Privacy Law in the US

Until federal law, companies will continue to do the multistate dance

by Rachael Ormiston
November 12, 2024
in Data Privacy, Opinion
us on a globe

A summer 2024 legislative effort appeared momentarily to revive hopes of a federal data privacy law. She doesn’t promise to see into the future, but Osana’s Rachael Ormiston looks at the unpredictability fueled by the lack of such blanket protections.

After years of questions about forward momentum in the U.S. for a national privacy law, optimism rose earlier this year when the American Privacy Rights Act (APRA) gained bipartisan support in the House and Senate. For privacy professionals who have long advocated for a federal data privacy law, finally, there was hope of success with bipartisan support.

But after the bill drew backlash from various stakeholders, a planned hearing on it was abruptly canceled and no movement has taken place on the APRA since June. 

This isn’t the first time something like this has happened to a proposed federal law. Seasoned compliance and privacy pros have seen this movie before with the American Data Privacy and Protection Act (ADPPA), which met a similar fate in 2023. All of this begs the question: Will we see a comprehensive federal privacy law any time soon? 

As we approach 2025, it’s difficult to predict what exactly is around the corner. We’ve already seen months full of surprises on the data privacy front — the rise and possible demise of the APRA, White House executive orders on sensitive data, acclimating to new California regulations and an ever-lengthening list of new state laws. All of that is in addition to an incredibly contentious presidential election. The only thing I can predict for certain is that compliance and privacy professionals will face much more complexity and unpredictability. 

That complexity and unpredictability is, of course, being exacerbated by the lack of a modern federal privacy law. In the absence of one, what we have is an increasingly complex, constantly changing patchwork of state laws that change on nearly a daily basis. Unlike in Europe, where there is a uniform regulatory environment for privacy, companies operating in the U.S. must design privacy programs that are able to keep up with and comply with varying state laws that have hundreds or even thousands of moving parts to them. This poses enormous challenges to compliance teams.

demystifying data de ID collage
Data Privacy

Demystifying Data De-Identification for US Privacy Compliance

by L. Hannah Ji-Otto, David Chen and Julie Kilgore
October 30, 2024

De-identification is a valuable tool for protecting consumer privacy, but the process requires diligent compliance with multiple state and federal standards. L. Hannah Ji-Otto and Julie A. Kilgore, both of Baker Donelson, and legal adviser David Chen explore the various regulatory perspectives on data de-identification and their implications for businesses operating in the United States.

Read moreDetails

Many of these challenges would be solved by a federal law that sets a national standard applicable everywhere in this country. This would help companies to operationalize programs with greater ease, applying the same standards across state boundaries. The corporate teams that now spend their time dealing with the myriad, slightly different laws would have more time to spend updating systems and applying business insights.

A federal law would also benefit consumers by promoting privacy equality across the country and allowing state neighbors to have the same rights and privileges over how they manage their data. If you are in California, you have the right to have your information corrected, but this is not the case in Utah, though both states have privacy laws. Meanwhile, other states lack modern data protections altogether.

Notably, though, there isn’t universal agreement that a federal law is the right solution. Case in point: California. The California Privacy Protection Agency (CPPA) opposes APRA because it believes a federal law would weaken the protections Californians currently enjoy under the CCPA and the California Delete Act. Advocates for existing California protections feel a federal law prevailing over those state-level protections would weaken the state’s intentionally strict protections. 

But is that reason enough to forgo a federal law that could potentially benefit the remainder of Americans, the vast majority of whom do not reside in California? And why not adopt the Golden State’s protections as a baseline? Because those pro-privacy protections may be seen by other states as simply too progressive in a way that potentially harms business. For long-term success, taking a more radical approach at a federal level, straight out of the gate, may be too much; we simply may need time to evolve and get to that place.

And it is worth remembering that a federal law does not solve every problem. With a federal privacy law coming under the purview of a lone regulator, the Federal Trade Commission (FTC), it is easy to imagine the potential delays in enforcement that having a single regulator could create. If that were to occur, perhaps a consequence of that is a focus on Big Tech that would dissuade programmatic change for smaller businesses where arguably change is most needed. 

So what should compliance and privacy professionals do in the meantime? If APRA is not revived later this year or in a new Congress, it will continue to be a waiting game. Given the number of state laws that are proliferating, there is clearly an appetite for wider privacy regulation that would support the idea of a federal regulation, but it is likely that concessions will have to be made. The two most strongly contested points appear to be on the right of preemption and the ability to raise a private right of action, but there is also the small matter of how to enforce. One potential compromise could be to enable regional regulatory supervision, using established agencies under FTC oversight. Or would that simply create more confusion?


Tags: California Consumer Privacy Act (CCPA)
Previous Post

How to Earn a $3B Fine: TD Bank’s Masterclass in Compliance Failures

Next Post

A Behavioral Economics Approach to Privacy by Design

Rachael Ormiston

Rachael Ormiston

Rachael Ormiston is the head of privacy at Osano. With more than 15 years of professional experience, she has deep domain expertise in global privacy, cybersecurity, and crisis and incident response. Rachael is an IAPP FIP and has previously served on the IAPP CIPM exam development board. She has a personal interest in privacy risk issues associated with emerging technologies.

Related Posts

todd snyder runway show scarf

Lessons Learned: Todd Snyder CCPA Enforcement Action

by Richart Ruddie
May 29, 2025

Third-party risk, overcollection of data and lax training all cited by California data privacy enforcer

federal trade commission building

[Q&A] Big Tech & Free Speech Under the Microscope: FTC’s New Direction

by FTI Consulting
April 28, 2025

What compliance teams need to know about the changing approach to consumer protection and data privacy

data governance concept

The US Still Lacks Its Own GDPR, But That Doesn’t Mean Data Privacy Enforcement Isn’t Happening

by Brian McGinnis and Maddie San Jose
April 16, 2025

Despite the absence of comprehensive federal privacy legislation, American businesses face mounting regulatory pressure from multiple directions. Brian McGinnis and...

examining data on laptop screen

Privacy Rights Surge Forces Rethink of Data Management

by Gal Ringel
March 14, 2025

As global privacy regulations multiply, organizations face mounting pressure to efficiently respond to data subject requests amid complex data environments

Next Post
following the leader

A Behavioral Economics Approach to Privacy by Design

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights