Privacy laws in the United States

Data privacy laws in the US regulate the use, collection, and disclosure of data and individuals’ rights concerning the data once it is shared.

The United States doesn’t have one comprehensive law that covers the privacy of all types of data. Instead, there are laws covering only specific types of data in special circumstances or applicable to given states.

There are a few major data privacy acts in the US:

The law that revolutionized the approach to data privacy in the US was the California Consumer Privacy Act (CCPA), expanded with the California Privacy Rights Act (CPRA) and applicable to businesses in California. It gives consumers rights concerning their personal data and imposes certain obligations on businesses that collect or sell it.

Only a few other US states have their own data privacy laws, including:

US companies operating in the EU are also obliged to adhere to GDPR.

You may also like:

Data privacy laws in the United States and how they affect your business

11 new privacy laws around the world and how they’ll affect your analytics

Data privacy breach

EU-US data privacy framework


  • PHI and PII

    HIPAA violations and fines: What healthcare organizations need to know

    Quick summary HIPAA violations happen when a covered entity or business associate fails to meet the HIPAA Privacy, Security or Breach Notification Rule. Civil penalties range from a few hundred dollars to more than $2 million per violation, set across four tiers based on how much the organization knew.  What this guide covers: HIPAA violation…

  • The EDPB’s new data anonymization guidelines: what they mean for your analytics data

    Removing names, cookies and IP addresses is no longer enough to anonymize data. Here’s what the 2026 EDPB framework actually requires for anonymous data collection, what’s still unresolved, and how to configure your analytics to stay compliant while keeping the full view of traffic marketers rely on.