Privacy laws in the United States

Data privacy laws in the US regulate the use, collection, and disclosure of data and individuals’ rights concerning the data once it is shared.

The United States doesn’t have one comprehensive law that covers the privacy of all types of data. Instead, there are laws covering only specific types of data in special circumstances or applicable to given states.

There are a few major data privacy acts in the US:

The law that revolutionized the approach to data privacy in the US was the California Consumer Privacy Act (CCPA), expanded with the California Privacy Rights Act (CPRA) and applicable to businesses in California. It gives consumers rights concerning their personal data and imposes certain obligations on businesses that collect or sell it.

Only a few other US states have their own data privacy laws, including:

US companies operating in the EU are also obliged to adhere to GDPR.

You may also like:

Data privacy laws in the United States and how they affect your business

11 new privacy laws around the world and how they’ll affect your analytics

Data privacy breach

EU-US data privacy framework


  • Anonymous website visitor tracking: How to do useful analytics without personal data [Updated]

    Regulations worldwide, like GDPR or the ePrivacy Regulation, set a high bar for collecting user data. For one, GDPR requires consent to process the data if it’s reasonably likely that such data could be used to identify an individual. The problem is that consent opt-in rates typically vary between 30% and 70-80%. The solution? Anonymizing…

  • What is PII, non-PII, and personal data? [UPDATED]

    Personally identifiable information (PII) and personal data are two classifications of data that often confuse organizations that collect, store and analyze such data. Both terms cover common ground, classifying information that could reveal an individual’s identity directly or indirectly. PII is used in the US, but no specific legal document defines it. The legal system…