US data privacy laws: complete guide for businesses and consumers

Unlike the European Union, which operates under a single regulation, the General Data Protection Regulation (GDPR), US data privacy laws don’t sit under one single federal framework. Privacy laws in the US are split across sector-specific federal laws and a growing number of state privacy laws that apply to businesses handling data from residents of those states.

This makes privacy compliance harder to manage, especially for businesses operating across multiple states or collecting different types of personal data.

In this guide, we unpack the main US data privacy laws, what they protect, the rights they give consumers, and what businesses can do to build a privacy governance foundation that is easier to manage as requirements continue to change.

For a quick-reference overview of all active and upcoming state laws, see our US privacy law compliance guide and the US privacy legislation cheatsheet.

Main US data privacy laws

Most US privacy laws are based on the same core privacy principles: transparency, consumer control, data security, and accountability. How those principles apply depends on the law, the state, and the type of data involved.

Federal privacy laws

Federal privacy laws in the US are sector-specific rather than universal. Each targets a particular industry or data type:

LawWhat it covers
Privacy Act of 1974How federal government agencies collect and use personal information
HIPAAHealth information held by healthcare providers, insurers, and their partners
Gramm-Leach-Bliley Act (GLBA)Financial data held by banks, credit unions, and investment firms
COPPAPersonal data collected from children under 13
Video Privacy Protection Act (VPPA)Viewing history shared by streaming services and apps
Fair Credit Reporting Act (FCRA)Consumer credit information held by reporting agencies
Right to Financial Privacy Act (RFPA)Federal agency access to bank records
PADFAA (2024)Transfers of sensitive US data to foreign adversaries

State comprehensive privacy laws

Since 2020, more than a dozen states have passed broad consumer privacy laws that apply across industries. Unlike the federal statutes above, these laws cover most businesses that collect and process personal data from state residents, subject to applicability thresholds.

StateLawEffective date
CaliforniaCCPA / CPRAJan 1, 2020 / Jan 1, 2023
VirginiaVCDPAJan 1, 2023
ColoradoCPAJul 1, 2023
ConnecticutCTDPAJul 1, 2023
UtahUCPADec 31, 2023
OregonOCPAJul 1, 2024
TexasTDPSAJul 1, 2024
MontanaMTCDPAOct 1, 2024
Iowa, Delaware, New Hampshire, NebraskaVariousJan 1, 2025
New JerseyNJDPAJan 15, 2025
TennesseeTIPAJul 1, 2025
MinnesotaMCDPAJul 31, 2025
Indiana, Kentucky, Rhode IslandVariousJan 1, 2026

What counts as personal information?

Definitions vary across US privacy laws, but these categories are important because they determine what businesses must disclose in their data privacy policies.

General personal information: Under most state laws, this means any information that identifies, relates to, or is reasonably linked to a specific individual, including names, email addresses, browsing history, location data, and behavioral inferences.

Sensitive personal information: A distinct category requiring stronger protection, typically including biometric data, health information, precise geolocation, genetic data, racial or ethnic origin, religious beliefs, sexual orientation, financial account details, and data relating to children. Most state laws require opt-in consent before processing sensitive data. See iubenda’s sensitive personal information comparison for a state-by-state breakdown.

Protected Health Information (PHI): Under HIPAA, this covers all individually identifiable health information held or transmitted by covered entities, including diagnoses, treatment records, payment data, and anything that could identify a patient in connection with their care.

Nonpublic Personal Information (NPI): The GLBA term for financial data: any personally identifiable financial information a consumer provides to, or that results from a transaction with, a financial institution.

Your data privacy rights as a US consumer

Most comprehensive state privacy laws share a common set of consumer rights, although each US data privacy law defines and applies those rights slightly differently.

  • Right to know and access: Request what personal data a business holds about you, where it came from, and how it’s used
  • Right to delete: Ask a business to delete your personal data, subject to certain legal exceptions
  • Right to opt out: Stop the sale or sharing of your data for targeted advertising
  • Right to correct: Request corrections to inaccurate personal data
  • Right to portability: Receive your data in a transferable format
  • Right to limit sensitive data use: Restrict processing of sensitive personal information to what’s necessary for the service (California and several other states)
  • Right to non-discrimination: Businesses can’t penalize you for exercising your privacy rights

To exercise these rights: locate the business’s privacy policy or “Do Not Sell or Share My Personal Information” link, submit your request through their designated channel (web form, email, or toll-free number), and verify your identity as required. Businesses must respond within 45 days. If a request is denied or ignored, you can file a complaint with your state Attorney General, or in California, with the California Privacy Protection Agency (CPPA).

Key federal laws: what you need to know

Federal privacy laws in the US usually focus on specific sectors or data types, rather than applying to every business.

HIPAA
HIPAA applies to healthcare providers, health plans, and their business associates. It gives patients the right to access their medical records, request corrections, and restrict certain disclosures of their PHI. The law is divided into a Privacy Rule (how PHI can be used and disclosed) and a Security Rule (technical and administrative safeguards for electronic PHI). Civil penalties reach up to $1.5 million per violation category per year.

COPPA
COPPA protects children under 13 by requiring verifiable parental consent before websites, apps, or online services collect their personal data. It applies to services aimed at children, as well as general-audience platforms that know they are collecting children’s data. The FTC’s 2024 updates also added a separate opt-in requirement for the use of children’s data in targeted advertising. Penalties can reach $51,744 per violation.

GLBA
GLBA covers banks, credit unions, investment firms, insurance companies, and other financial services providers. It requires clear privacy notices to customers, the right to opt out of data sharing with non-affiliated third parties, and a formal information security program under the Safeguards Rule. Enforcement sits with the FTC and federal banking regulators.

Key state laws: deep dives

California (CCPA/CPRA)
California has the most comprehensive privacy framework in the US. The CCPA/CPRA applies to for-profit businesses that meet certain thresholds, including annual revenue of $25 million or more, processing data from 100,000+ consumers, or earning at least 50% of revenue from selling personal data.

The law gives consumers rights to access, delete, correct, and transfer their data, opt out of certain uses, and limit how sensitive data is used. Businesses must also recognize Global Privacy Control (GPC) signals. Penalties can reach $7,500 per intentional violation and are enforced by the CPPA. See iubenda’s CCPA/CPRA guide and CPRA overview.

Utah (UCPA)
The Utah privacy law, effective December 31, 2023, is one of the more business-friendly frameworks. It applies to businesses with $25 million+ in revenue that process data on 100,000+ Utah consumers, or 25,000+ consumers, where 50%+ of revenue comes from data sales. Consumers have rights to access, delete, opt out, and receive portable data, but no right to correct. Utah does not require opt-in consent for sensitive data, only a notice obligation. Enforcement is solely by the Attorney General, with no private right of action. See iubenda’s UCPA guide.

Delaware (DPDPA)
Delaware’s law, effective January 1, 2025, follows a more consumer-protective model. It applies to businesses processing data on 35,000+ Delaware consumers, or on 10,000+ consumers when 20%+ of revenue comes from data sales. Consumers have rights to access, delete, correct, portability, and opt out. Opt-in consent is required for sensitive data, and data protection assessments are mandatory for high-risk processing. See iubenda’s DPDPA guide.

CCPA vs. VCDPA at a glance

CCPA/CPRA (California)VCDPA (Virginia)
EffectiveJan 2020 / Jan 2023Jan 2023
Thresholds$25M revenue OR 100K consumers OR 50% revenue from data sales100K consumers OR 25K consumers + 50% revenue from data sales
Consumer rightsAccess, delete, portability, opt-out, correct, limit sensitive dataAccess, delete, portability, opt-out, correct
Sensitive dataOpt-in consent requiredOpt-in consent required
GPC recognitionRequiredNot required
Private right of actionLimited (data breaches)None
EnforcementCPPA + Attorney GeneralAttorney General only
Max penalty$7,500 per intentional violation$7,500 per violation

See iubenda’s VCDPA guide for a more detailed overview.

US privacy laws vs. GDPR

The biggest difference between US privacy laws and the GDPR is how privacy compliance is structured. The GDPR creates a single broad framework, while the US system is split between federal sector laws and state-level requirements.

US privacy lawsGDPR
StructureFragmented: state laws + sector-specific federal statutesSingle regulation across all EU/EEA member states
CoverageIndustry-specific federally; broader but threshold-based at state levelAll sectors, all personal data, no thresholds
Consent modelOpt-out in most casesOpt-in required as one of several legal bases
Legal basis for processingNo universal requirementRequired for all processing
EnforcementFTC, state Attorneys General, sector regulatorsNational Data Protection Authorities
Max penalties$2,500-$7,500 per violation (state); higher under HIPAA/COPPAUp to €20M or 4% of global annual turnover
Private right of actionLimitedIndividuals can complain to DPAs and courts
Breach notificationVaries by state72 hours to supervisory authority

Privacy compliance checklist for US businesses

Not sure where to start? Use this privacy compliance checklist to build a stronger foundation for managing US data privacy laws.

  1. Check which laws apply. Review applicability thresholds for each state where your customers are based. See our US privacy legislation cheatsheet to compare them side by side
  2. Inventory your data. Map what personal data you collect, where it’s stored, and which third parties receive it. Flag any sensitive data categories
  3. Update your privacy policy. Disclose your data practices, list consumer rights, and provide clear contact details for requests
  4. Build a request handling process. Set up a submission channel, identity verification procedure, and 45-day response workflow
  5. Review vendor contracts. Confirm data processing agreements are in place and that service providers are contractually limited in how they can use your data
  6. Apply technical safeguards. Encryption, access controls, and an incident response plan are a baseline across most US privacy laws
  7. Keep your privacy governance current. Review your privacy policy annually, track new state legislation, and document your compliance efforts.

For a practical guide to implementing these steps, here’s how to comply with US state privacy laws using iubenda.

Build a privacy setup that keeps up with US data privacy laws

US data privacy laws are expanding state by state, which means your privacy setup can’t be a one-time task. If your business collects personal data from people in the US, you need to know which laws may apply, what rights users have, and what your Privacy Policy needs to explain.

The next practical step is to review your data privacy policies and make sure they reflect how your business collects, uses, shares, and protects personal data. iubenda can help you generate and maintain a Privacy and Cookie Policy tailored to your business, making it easier to keep your disclosures clear, accurate, and aligned with evolving requirements.

Follow us on: