No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

The United States of Data Privacy: The Future of GDPR in the Land of the Free

Is a Federal Data Privacy Regulation on the Horizon?

by Alex Scheinman
September 23, 2019
in Data Privacy
wooden gavel on american flag

The GDPR united 28 disparate data privacy laws across EU member states. It’s only logical that the same will happen in the U.S. ACA Aponix’s Alex Scheinman discusses what American companies might expect going forward.

When it comes to data privacy, the fate of the United States is written in the star spangled banner. While a number of issues have served to divide the nation’s citizens over the past few years, concerns around data protection have created a rare consensus that more needs to be done.

Since the General Data Protection Regulation (GDPR) in Europe put data privacy firmly in the international consciousness, pressure has been swelling from the ground up for both firms and governments around the world to follow suit. On top of this, the spate of high breaches that saw the likes of Facebook and Google weighted with hefty fines has caused firms worldwide to finally sit up and take note.

In the U.S., there’s not a single state that isn’t facing pressure from both consumers and consumer advocacy groups to enshrine data protection into law. Both California and Vermont have already taken the plunge, and we could soon be seeing a number of different data privacy regulations springing up all over the U.S.

It’s a déjà vu moment for the global regulatory scene, with American firms now faced with the same challenge as European firms faced less than a decade ago: an increasingly fragmented regulatory environment. Yet while European firms were faced with the challenge of complying with 27 similar but different data protection laws, the lack of any sort of federal data privacy directive in the U.S. means that firms could be facing 50 vastly differing sets of rules.

The prospect already has businesses like technology giants Facebook and Amazon knocking at government doors, pushing for a single federal data privacy law. Such a bill, like GDPR, would reduce the compliance headache for firms by harmonizing data privacy requirements across the whole country, establishing a more business-friendly regulatory environment.

In response, U.S. senators last month held a hearing to get opinions from industry experts and lobbyists on the development of a similar federal data privacy law. The problem is, with so many voices and vested interests at play, it’s going to be incredibly difficult for congress members to arrive at a consensus.

The California Consumer Privacy Act (CCPA), currently America’s closest cousin to the GDPR, has been most widely accepted as a sensible basis on which to build. Passed in June 2018, it has taken preliminary steps to outline the basic rights of California residents to knowledge of and access to their personal data. Yet businesses are already pushing for this regulation to be watered down, which would of course be a hard sell for both consumers and regulators.

With calls for a single federal law now coming from all directions, the biggest loser in the U.S.’ own GDPR narrative will be the firms that fail to prepare. Those left twiddling their thumbs waiting for this to officially become federal law will find themselves faced with high premiums for vendor or consultancy services in the eleventh hour. With major fines coming down the pipeline, every firm across all 50 states needs to follow the global trend and shift their thinking when it comes to data privacy.

Tags: California Consumer Privacy Act (CCPA)GDPR
Previous Post

Data Breach Costs and Attacks Continue to Increase in 2019

Next Post

On ADA Website Compliance, the DOJ Has a Chance to End the Chaos in the Courts

Alex Scheinman

Alex Scheinman

Alex Scheinman is Director of Privacy at ACA Aponix, the cybersecurity, privacy and risk division of ACA Compliance Group.

Related Posts

us flags on wall street

A Field Guide to Privacy Law for Companies Entering the US Market

by Kevin Coy and Erin Doyle
July 20, 2026

Businesses wanting to operate in the US have a variety of laws and regulations to consider

data privacy concept human figure padlock

Data Privacy Rules Built for Human Behavior Have an AI Agent Problem

by Srikanth Sallaka
June 8, 2026

Regulators are beginning to treat under-governed AI deployments as intentional conduct

internet of things and cloud devices

EU Data Act: Time for a Reality Check

by Zach Judge-Raza and Jamie Elbert
March 17, 2026

New rules could spark compliance tension: share too much personal data run afoul of GDPR, share too little and face...

small child using smartphone

The US Is Not Alone in Regulating Children’s Data Privacy. Here’s a Primer on the Global State of Play.

by Ceren Canal Aruoba
February 2, 2026

Emerging policies extend beyond data privacy into product governance and algorithmic accountability

Next Post
blue keyboard button with handicap symbol

On ADA Website Compliance, the DOJ Has a Chance to End the Chaos in the Courts

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights