No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

A Field Guide to Privacy Law for Companies Entering the US Market

Businesses wanting to operate in the US have a variety of laws and regulations to consider

by Kevin Coy and Erin Doyle
July 20, 2026
in Compliance, Data Privacy
us flags on wall street

Many non‑US businesses assume that compliance with the European Union’s GDPR or a similar home‑country law will largely address US requirements, Kevin Coy and Erin Doyle of Arnall Golden Gregory write. But the US regulatory picture is fragmented, highly sector- and state-specific and generates distinct regulatory and litigation risks that often are not addressed by compliance with home-country laws.

Compliance professionals, in‑house counsel and business leaders should consider 12 areas of data privacy and security diligence, contract terms and governance when planning US operations. 

These areas are not mutually exclusive, and they often overlap. This list is also not exhaustive. Discrete federal and state privacy laws regulate a host of other areas not addressed here, ranging from motor vehicle records and educational records to video rental records, library records and loyalty program information, among others.

1. Sectoral federal privacy laws 

While the US does not have an omnibus privacy law, it does have a number of sectoral and issue-specific privacy laws. HIPAA regulations, covering certain health‑related entities, and the Gramm-Leach-Bliley Act, which regulates financial institutions, are prominent examples.

HIPAA governs protected health information held by “covered entities,” including many healthcare providers and health plans and their “business associates,” a broad array of companies providing services that involve processing protected health information on behalf of covered entities. Covered entities and their business associates must address HIPAA’s privacy, security and data breach notification regulations, including specific contracting and compliance requirements.

Some states, such as Washington and Nevada, have adopted robust health information privacy laws intended to fill gaps regarding the privacy of consumer health data where the HIPAA privacy rules do not apply, and the Washington law includes a private right of action.

The Gramm-Leach-Bliley Act applies to a wide array of financial institutions, not just banks, and requires specific privacy notices, regulates the sharing of “non‑public personal information” and imposes information security requirements.

Foreign businesses entering the health or financial services sectors should treat HIPAA and the Gramm-Leach-Bliley Act as primary regulatory regimes, not as mere supplements to home-country requirements.

2. State privacy laws

The US still lacks a single federal GDPR‑style law, but more than 20 states have now enacted comprehensive consumer privacy statutes, starting with the California Consumer Privacy Act and followed by states like Virginia, Colorado, Connecticut, Texas and others. California is one of the most operationally demanding states: It created a dedicated privacy regulator, the California Privacy Protection Agency and is comparatively aggressive with enforcement.

Each state’s law is distinct, but they all typically include privacy notice requirements, consumer rights obligations (for example, access, deletion, correction and opt‑out options), purpose limitation concepts, data minimization concepts and vendor contracting obligations. While these laws apply across sectors, they do not apply to all businesses due to a range of different applicability triggers and exceptions. As a result, the impact of this category of state laws depends on the size and scope of business operations and the states where business will be conducted. A threshold assessment of which state laws actually apply to an entity should therefore be considered a necessary first step in any US privacy strategy.

3. Marketing and communications privacy

In the marketing and communications space, the US federal CAN‑SPAM Act and similar state laws set rules for commercial email, including identification requirements, opt‑out mechanisms and header‑information accuracy. The Telephone Consumer Protection Act and parallel state mini‑TCPA statutes heavily regulate telemarketing, text messaging and certain automated calling. Do-not-call list rules also apply particularly but not exclusively to telemarketing communications. Some of these laws have driven substantial class action litigation.

4. Website tracking and video or call recording

Additional US laws regulate the recording of videos or calls and using website tracking technologies. Federal and state wiretapping and eavesdropping statutes, as well as call‑recording laws, require one‑party or all‑party consent to record depending on the jurisdiction. Additionally, plaintiffs are increasingly challenging “session replay” and other online tracking technologies like cookies and pixels under these legal frameworks.

For businesses considering US physical retail stores or other locations in the US, notices regarding video surveillance also may be required. Businesses entering the US market that are planning to engage in these types of activities should carefully review their practices in these areas to address compliance concerns and mitigate potential risk.

5. Children’s privacy

Businesses processing personal data about children must consider federal and state privacy laws. US federal law is anchored by the Children’s Online Privacy Protection Act, which applies to online services directed to children under 13 or that knowingly collect personal information from such children. COPPA requires clear notices, verifiable parental consent before collecting most data, limits on use and disclosure and reasonable security. COPPA is enforced primarily by the US Federal Trade Commission and state attorneys general.

In parallel, an expanding set of state child‑focused privacy and online safety laws (for example, age‑appropriate design‑style codes and teen‑specific protections) for people up to age 18 are imposing additional obligations around profiling, targeted advertising and default settings for minors, creating a multilayered regulatory framework.

website opt out banner
Data Privacy

New CIPA Claims Expand Privacy Litigation Risk Over Website Consent Banners

by Andrew Chase
July 17, 2026

A lawsuit against Ace Hardware demonstrates the claims that can be brought against organizations under new California laws

Read moreDetails

6. AI and automated decision-making technology laws

New and proposed state laws governing AI and automated decision‑making technology are proliferating, focusing on AI transparency, data minimization, bias and discrimination risks and the need for impact assessments where models rely on sensitive personal information or materially affect individuals (for example, employment, housing, credit or access to essential services).

Non‑US businesses may need to adapt AI governance programs built around GDPR, the EU AI Act or other laws to address specific US disclosure, consent, notice and opt‑out expectations, as well as heightened scrutiny of training data, profiling and the reuse of consumer and employee data for AI purposes.

7. Employee and applicant privacy

Businesses entering the US market may be surprised by the patchwork of US employee‑focused rules. The federal Fair Credit Reporting Act and similar laws in many states regulate the use of third‑party background screening reports regarding applicants and employees, as well as use of such reports for other purposes. State and local “ban the box,” “fair chance” and antidiscrimination laws restrict when and how criminal history information can be requested and used during hiring, typically requiring delayed inquiries and individualized assessments. Other state laws restrict the use of credit reports and salary history information as part of the hiring process.

Employers also face state laws regarding lawful off‑duty conduct (for example, protecting certain lawful products or activities), drug‑testing constraints and restrictions on requesting social media credentials or disciplining employees for lawful online activity. These laws collectively require careful coordination of global human resources and compliance policies. Employee health plans also may be subject to HIPAA requirements for covered entities.

8. Biometrics privacy laws

Several states have enacted biometric privacy statutes, the Illinois Biometric Information Privacy Act being the most prominent example that is frequently cited in private class actions. These laws can apply to technologies like fingerprint time clocks, facial recognition for physical or logical access and voiceprints. These often require informed consent, data retention limits and secure disposal.

9. Cybersecurity laws

Data security obligations are increasingly being codified not just as general “reasonable security” requirements but as more detailed statutory standards and regulatory guidance. Many state privacy laws expressly require appropriate technical, administrative and physical safeguards connected to the sensitivity and volume of personal data, and some state laws prescribe specific controls, risk assessments, audits and governance structures particularly in financial services and critical infrastructure contexts. In addition, California will soon require certain businesses covered by COPPA to conduct cybersecurity audits and submit certifications. These state rules sit alongside — and sometimes go beyond — federal sectoral requirements, such as those under HIPAA or the Gramm-Leach-Bliley Act.

Businesses that have designed their security programs around GDPR or a single global standard should assess whether US state- or sector-specific mandates regarding encryption, access management, multifactor authentication, vendor oversight, incident response, board‑level reporting and regulatory reporting require tailored enhancements for US operations.

10. Data breach notification laws

All US states and territories have data breach notification statutes that impose obligations to notify individuals (and sometimes regulators or credit bureaus) when defined personal information is accessed or acquired without authorization, often subject to specific notification timelines and notice content requirements. These laws differ on the scope of covered entities and covered data, whether they carry risk‑of‑harm exceptions and whether delays are permitted for law enforcement needs, so multistate incidents require coordinated, state‑specific analysis.

In addition, some businesses are subject to federal breach notification rules under regimes, such as Securities and Exchange Commission requirements for reporting by publicly traded companies, HIPAA or the Gramm-Leach-Bliley Act. As such, businesses entering the US market should consider developing US-focused breach notification protocols to anticipate their response to a breach of US personal data.

11. Government and bulk US sensitive data transfer regulations

Unlike GDPR and many national data protection laws, the US has not traditionally regulated the export of personal data to other jurisdictions. In January 2025, however, the US Department of Justice finalized regulations that restrict or prohibit certain “covered data transactions” involving bulk US sensitive personal data or US government‑related data with specified “countries of concern” and “covered persons.” The rule defines “bulk US sensitive personal data” broadly to include categories like certain personal identifiers, precise geolocation, biometric identifiers, health and financial data and human genetic and molecular biological data when certain thresholds are met within a 12‑month period.

A separate law enacted in 2024 also restricts the sale or transfer of personal data by third-party data brokers to “adversary countries” or entities under their control, which could apply instead of or in addition to the DOJ regulations. Compliance with these requirements necessitates an understanding of data flows given that contractual safeguards differ depending on whether the parties involved are US, foreign or covered persons under these regulations. These measures would apply in addition to any data transfer requirements required by home-country data protection laws, such as GDPR.

12. Federal and state unfair or deceptive acts and practices laws

The FTC and state regulators have long used federal and state prohibitions on unfair or deceptive acts and practices (UDAP) to bring actions against businesses that have failed to keep their privacy and data security promises, as well as to act against businesses that engage in unfair privacy and data security practices. While businesses may overlook UDAP laws because they are broad prohibitions rather than detailed operational compliance regimes, federal and state regulators have brought hundreds of UDAP cases over the years. To avoid engaging in deceptive practices, it is important to ensure that a business’s public privacy and security promises are kept in practice. Additionally, unfairness claims do not require an unkept promise. For example, they can be brought if inadequate data security practices result in substantial injury to a consumer that the consumer could not have reasonably avoided. As a result, businesses considering US market entry should consider reviewing their privacy policies, notices and other promises and data security practices from this broader perspective in addition to more specific requirements applicable to their US operations.

Regulatory and litigation risks

Many of the privacy and security laws and regulations discussed above provide private rights of action that make the US litigation environment particularly attractive for class-action plaintiffs. Meanwhile, federal and state regulators — including the FTC, sectoral regulators, state attorneys general and specialized bodies like the California Privacy Protection Agency — actively bring regulatory enforcement actions for privacy and security violations.

Compliance with the GDPR or other non‑US data protection frameworks likely will support US compliance efforts, but it is not determinative. Even in instances where US federal and state laws share the same privacy protection goals as non-US privacy regulations, US laws can differ significantly regarding issues like scope, legal bases, consent standards, notice design and content, automated‑decision rules and, crucially, private litigation exposure. Non‑US businesses planning to enter or expand in the US market should therefore consider undertaking a targeted US privacy and data use assessment covering consumer, employee and business-to-business data flows to calibrate governance, contracting, technology and insurance strategies to this distinct regulatory and litigation landscape.

Tags: Artificial Intelligence (AI)GDPRHIPAA
Previous Post

When Misconduct Reaches the C-Suite, Who Investigates?

Kevin Coy and Erin Doyle

Kevin Coy and Erin Doyle

Kevin Coy is a partner and co-chair of Arnall Golden Gregory’s data privacy practice. Kevin has an established reputation for advising organizations as they consider domestic and international privacy law and policy matters.
Erin Doyle is an associate in Arnall Golden Gregory’s data privacy practice. Erin focuses her practice on providing regulatory counseling, advising a wide range of companies on compliance with various state, federal and international privacy laws.

Related Posts

news roundup data grungy

43% of GRC Professionals Say AI Makes Their Jobs Harder

by Staff and Wire Reports
July 16, 2026

Plus: AI’s place in signing M&A deals; leaders use shadow AI more than employees

CCI Getting Governance Right 2026

Getting Governance Right 2026

by Corporate Compliance Insights
July 15, 2026

Boards today face a governance landscape that is broader, faster-moving and less forgiving than ever before. This collection of 14...

hand checking off checklist

10 Questions Every Organization Should Ask a Potential AI Vendor

by Angela Juneau
July 15, 2026

Adopting AI without understanding how it was built and how it handles data can expose an organization to risks that...

ai religious exemption collage pope leo

For Some Workers, AI Resistance Is a Matter of Faith

by Bernadette Sargeant and Luke VanFleteren
July 15, 2026

Employee resistance to AI in the workplace may be more than a PR problem. For some workers, especially after Pope...

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights