No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

Wave of State Data Protection Laws Is a Gathering Compliance Nightmare

Doing business in multiple states? You’d better have someone in charge of data privacy & security

by Scott Allendevaux
September 26, 2023
in Data Privacy, Opinion
wall of filing cabinets holding private information

In absence of a single national data privacy law, companies continue to face a multi-state balancing act. Data privacy practitioner Scott Allendevaux sets the scene.

A patchwork of advancing data privacy bills across the nation is creating a figurative field of landmines waiting to explode. Indeed, consumer data privacy bills are flying through legislatures in red and blue states alike. The bills are as diverse as the states passing them, leaving multistate companies to deal with a patchwork of rapidly changing rules. 

In the absence of a national standard for data protection, states are stepping up to assure consumers have protections in place. It’s becoming a logistical nightmare for companies, particularly cloud service providers and companies that reach out directly to consumers. 

Without a strong data-protection program, any piece of data carrying personal information could inadvertently cause a company to run afoul of a state law. Information has no boundaries. It zips across state lines, oblivious to the different laws and regulations that govern states. That’s where the challenge lies.

data privacy on bumper sticker
Data Privacy

A National Privacy Law Doesn’t Appear on the Near-Horizon in the US. Globally, It’s a Different Story.

by Kevin Coy and Erin Doyle
August 8, 2023

International law around data privacy continues to evolve as jurisdictions around the world seek to develop and refine their regulatory schemes governing collection and processing of consumer data by businesses.

Read moreDetails

It’s understandable that states want to protect consumers’ personal information. Most companies have experienced more than one data breach. That’s especially true for cloud-based companies. 

Early privacy laws focused on managing data breaches and user security issues such as password protection. For a long time, California was the only statewith a law protecting consumers’ rights to manage their own data. Things are changing fast. Several states have now passed comprehensive privacy laws.  More are coming. Upwards of 100 privacy-protection bills have been introduced in state legislatures. 

For companies, that means navigating an ever-changing regulatory landscape with different definitions and different levels of rigor.

In some states, residents can opt out of certain data-processing activities or correct their own data. Other states have different privacy laws for large companies than for smaller ones. Different states also require companies to disclose privacy information at different stages of data collection. 

There’s no shame in being confused. Consumer privacy bills vary so much from state to state that even the definition of a consumer isn’t consistent. That’s a difficult thing for a software engineer to address, and it’s changing rapidly as more states adopt new laws. 

Compliance is no longer about checking boxes. It’s about implementing a robust set of data-protection measures that respect people’s rights to their own data, and it’s about companies being transparent and accountable in the digital world. 

A company has to determine which data protection laws it has to comply with, and what those laws say. Multinational companies are already doing this with countries that have comprehensive data protection laws, such as the UK GDPR. Some 137 nations have privacy laws, and the laws are as diverse as the countries that enacted them. 

So how does a company keep up? 

Every multistate company needs a security officer and privacy officer — or someone else charged with keeping track of the laws and making sure they’re being followed. That means constantly updating the company’s privacy policy and keeping residents of individual states apprised of their rights under state law. There should also be a contact name, email and phone number on the website — and the contact should be checking for messages every day.

It’s a complex world for companies to navigate, and it underscores the need for a unified approach. But it’s not clear when that will happen. The U.S. badly needs a unified data-protection law like the EU’s. The EU, in 1995, had a similar set of challenges. Leaders recognized the importance of ensuring a consistent level of protection. They saw that making the transference of information less complicated would propel the economy. In the U.S, the complexities of different data-protection walls act as a hindrance to growth.

It’s not just about simplifying compliance for business; it’s about ensuring Americans’ fundamental right to have their data protected. It’s essential that state and federal legislators, as well as federal agencies like the Federal Trade Commission, work together to make sure that happens. In the meantime, it’s up to companies to stay on top of the changing landscape.

It takes nine to 12 months to build a data-protection program. But it’s essential for a company that reaches across state lines. That’s the first thing a federal regulator or attorney general will look at in the event of a data breach. If there’s no program in place, all bets are off. 

Tags: California Consumer Privacy Act (CCPA)California Privacy Rights Act (CPRA)Data GovernanceGDPR
Previous Post

California Poised to Enact Landmark Climate Reporting Rules

Next Post

Why Data Privacy and Cybersecurity Must Be at the Top of CEOs’ Communications Agendas

Scott Allendevaux

Scott Allendevaux

Scott Allendevaux, LP, CISSP, CIPP/US, HCISPP, CIPT, CIPM is senior practice lead at Allendevaux & Co., an Ohio-based cybersecurity agency.

Related Posts

news roundup_062124

Activist Investors Significantly Increase M&A Sale Pushes

by Staff and Wire Reports
July 30, 2026

Massive data security confidence comes with high data security concerns.

us flags on wall street

A Field Guide to Privacy Law for Companies Entering the US Market

by Kevin Coy and Erin Doyle
July 20, 2026

Businesses wanting to operate in the US have a variety of laws and regulations to consider

data privacy concept human figure padlock

Data Privacy Rules Built for Human Behavior Have an AI Agent Problem

by Srikanth Sallaka
June 8, 2026

Regulators are beginning to treat under-governed AI deployments as intentional conduct

algorithm diagram

Surveillance Pricing: You’re Watching Consumers — and Government Is Watching You

by Kwamina Williford, Christopher J. Armstrong, Ashley Joyner Chavous and Benjamin Genn
May 22, 2026

Practices that rely on consumer data or opaque pricing mechanics are increasingly evaluated through a consumer protection and data governance...

Next Post
ceo speaking concept

Why Data Privacy and Cybersecurity Must Be at the Top of CEOs’ Communications Agendas

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights