Unlike the European Union, which operates under a single regulation, the General Data Protection Regulation (GDPR), US data privacy laws don’t sit under one single federal framework. Privacy laws in the US are split across sector-specific federal laws and a growing number of state privacy laws that apply to businesses handling data from residents of those states.
This makes privacy compliance harder to manage, especially for businesses operating across multiple states or collecting different types of personal data.
In this guide, we unpack the main US data privacy laws, what they protect, the rights they give consumers, and what businesses can do to build a privacy governance foundation that is easier to manage as requirements continue to change.
For a quick-reference overview of all active and upcoming state laws, see our US privacy law compliance guide and the US privacy legislation cheatsheet.
Main US data privacy laws
Most US privacy laws are based on the same core privacy principles: transparency, consumer control, data security, and accountability. How those principles apply depends on the law, the state, and the type of data involved.
Federal privacy laws
Federal privacy laws in the US are sector-specific rather than universal. Each targets a particular industry or data type:
| Law | What it covers |
|---|---|
| Privacy Act of 1974 | How federal government agencies collect and use personal information |
| HIPAA | Health information held by healthcare providers, insurers, and their partners |
| Gramm-Leach-Bliley Act (GLBA) | Financial data held by banks, credit unions, and investment firms |
| COPPA | Personal data collected from children under 13 |
| Video Privacy Protection Act (VPPA) | Viewing history shared by streaming services and apps |
| Fair Credit Reporting Act (FCRA) | Consumer credit information held by reporting agencies |
| Right to Financial Privacy Act (RFPA) | Federal agency access to bank records |
| PADFAA (2024) | Transfers of sensitive US data to foreign adversaries |
State comprehensive privacy laws
Since 2020, more than a dozen states have passed broad consumer privacy laws that apply across industries. Unlike the federal statutes above, these laws cover most businesses that collect and process personal data from state residents, subject to applicability thresholds.
| State | Law | Effective date |
|---|---|---|
| California | CCPA / CPRA | Jan 1, 2020 / Jan 1, 2023 |
| Virginia | VCDPA | Jan 1, 2023 |
| Colorado | CPA | Jul 1, 2023 |
| Connecticut | CTDPA | Jul 1, 2023 |
| Utah | UCPA | Dec 31, 2023 |
| Oregon | OCPA | Jul 1, 2024 |
| Texas | TDPSA | Jul 1, 2024 |
| Montana | MTCDPA | Oct 1, 2024 |
| Iowa, Delaware, New Hampshire, Nebraska | Various | Jan 1, 2025 |
| New Jersey | NJDPA | Jan 15, 2025 |
| Tennessee | TIPA | Jul 1, 2025 |
| Minnesota | MCDPA | Jul 31, 2025 |
| Indiana, Kentucky, Rhode Island | Various | Jan 1, 2026 |
What counts as personal information?
Definitions vary across US privacy laws, but these categories are important because they determine what businesses must disclose in their data privacy policies.
General personal information: Under most state laws, this means any information that identifies, relates to, or is reasonably linked to a specific individual, including names, email addresses, browsing history, location data, and behavioral inferences.
Sensitive personal information: A distinct category requiring stronger protection, typically including biometric data, health information, precise geolocation, genetic data, racial or ethnic origin, religious beliefs, sexual orientation, financial account details, and data relating to children. Most state laws require opt-in consent before processing sensitive data. See iubenda’s sensitive personal information comparison for a state-by-state breakdown.
Protected Health Information (PHI): Under HIPAA, this covers all individually identifiable health information held or transmitted by covered entities, including diagnoses, treatment records, payment data, and anything that could identify a patient in connection with their care.
Nonpublic Personal Information (NPI): The GLBA term for financial data: any personally identifiable financial information a consumer provides to, or that results from a transaction with, a financial institution.
Your data privacy rights as a US consumer
Most comprehensive state privacy laws share a common set of consumer rights, although each US data privacy law defines and applies those rights slightly differently.
- Right to know and access: Request what personal data a business holds about you, where it came from, and how it’s used
- Right to delete: Ask a business to delete your personal data, subject to certain legal exceptions
- Right to opt out: Stop the sale or sharing of your data for targeted advertising
- Right to correct: Request corrections to inaccurate personal data
- Right to portability: Receive your data in a transferable format
- Right to limit sensitive data use: Restrict processing of sensitive personal information to what’s necessary for the service (California and several other states)
- Right to non-discrimination: Businesses can’t penalize you for exercising your privacy rights
To exercise these rights: locate the business’s privacy policy or “Do Not Sell or Share My Personal Information” link, submit your request through their designated channel (web form, email, or toll-free number), and verify your identity as required. Businesses must respond within 45 days. If a request is denied or ignored, you can file a complaint with your state Attorney General, or in California, with the California Privacy Protection Agency (CPPA).
Key federal laws: what you need to know
Federal privacy laws in the US usually focus on specific sectors or data types, rather than applying to every business.
HIPAA
HIPAA applies to healthcare providers, health plans, and their business associates. It gives patients the right to access their medical records, request corrections, and restrict certain disclosures of their PHI. The law is divided into a Privacy Rule (how PHI can be used and disclosed) and a Security Rule (technical and administrative safeguards for electronic PHI). Civil penalties reach up to $1.5 million per violation category per year.
COPPA
COPPA protects children under 13 by requiring verifiable parental consent before websites, apps, or online services collect their personal data. It applies to services aimed at children, as well as general-audience platforms that know they are collecting children’s data. The FTC’s 2024 updates also added a separate opt-in requirement for the use of children’s data in targeted advertising. Penalties can reach $51,744 per violation.
GLBA
GLBA covers banks, credit unions, investment firms, insurance companies, and other financial services providers. It requires clear privacy notices to customers, the right to opt out of data sharing with non-affiliated third parties, and a formal information security program under the Safeguards Rule. Enforcement sits with the FTC and federal banking regulators.
Key state laws: deep dives
California (CCPA/CPRA)
California has the most comprehensive privacy framework in the US. The CCPA/CPRA applies to for-profit businesses that meet certain thresholds, including annual revenue of $25 million or more, processing data from 100,000+ consumers, or earning at least 50% of revenue from selling personal data.
The law gives consumers rights to access, delete, correct, and transfer their data, opt out of certain uses, and limit how sensitive data is used. Businesses must also recognize Global Privacy Control (GPC) signals. Penalties can reach $7,500 per intentional violation and are enforced by the CPPA. See iubenda’s CCPA/CPRA guide and CPRA overview.
Utah (UCPA)
The Utah privacy law, effective December 31, 2023, is one of the more business-friendly frameworks. It applies to businesses with $25 million+ in revenue that process data on 100,000+ Utah consumers, or 25,000+ consumers, where 50%+ of revenue comes from data sales. Consumers have rights to access, delete, opt out, and receive portable data, but no right to correct. Utah does not require opt-in consent for sensitive data, only a notice obligation. Enforcement is solely by the Attorney General, with no private right of action. See iubenda’s UCPA guide.
Delaware (DPDPA)
Delaware’s law, effective January 1, 2025, follows a more consumer-protective model. It applies to businesses processing data on 35,000+ Delaware consumers, or on 10,000+ consumers when 20%+ of revenue comes from data sales. Consumers have rights to access, delete, correct, portability, and opt out. Opt-in consent is required for sensitive data, and data protection assessments are mandatory for high-risk processing. See iubenda’s DPDPA guide.
CCPA vs. VCDPA at a glance
| CCPA/CPRA (California) | VCDPA (Virginia) | |
|---|---|---|
| Effective | Jan 2020 / Jan 2023 | Jan 2023 |
| Thresholds | $25M revenue OR 100K consumers OR 50% revenue from data sales | 100K consumers OR 25K consumers + 50% revenue from data sales |
| Consumer rights | Access, delete, portability, opt-out, correct, limit sensitive data | Access, delete, portability, opt-out, correct |
| Sensitive data | Opt-in consent required | Opt-in consent required |
| GPC recognition | Required | Not required |
| Private right of action | Limited (data breaches) | None |
| Enforcement | CPPA + Attorney General | Attorney General only |
| Max penalty | $7,500 per intentional violation | $7,500 per violation |
See iubenda’s VCDPA guide for a more detailed overview.
US privacy laws vs. GDPR
The biggest difference between US privacy laws and the GDPR is how privacy compliance is structured. The GDPR creates a single broad framework, while the US system is split between federal sector laws and state-level requirements.
| US privacy laws | GDPR | |
|---|---|---|
| Structure | Fragmented: state laws + sector-specific federal statutes | Single regulation across all EU/EEA member states |
| Coverage | Industry-specific federally; broader but threshold-based at state level | All sectors, all personal data, no thresholds |
| Consent model | Opt-out in most cases | Opt-in required as one of several legal bases |
| Legal basis for processing | No universal requirement | Required for all processing |
| Enforcement | FTC, state Attorneys General, sector regulators | National Data Protection Authorities |
| Max penalties | $2,500-$7,500 per violation (state); higher under HIPAA/COPPA | Up to €20M or 4% of global annual turnover |
| Private right of action | Limited | Individuals can complain to DPAs and courts |
| Breach notification | Varies by state | 72 hours to supervisory authority |
Privacy compliance checklist for US businesses
Not sure where to start? Use this privacy compliance checklist to build a stronger foundation for managing US data privacy laws.
- Check which laws apply. Review applicability thresholds for each state where your customers are based. See our US privacy legislation cheatsheet to compare them side by side
- Inventory your data. Map what personal data you collect, where it’s stored, and which third parties receive it. Flag any sensitive data categories
- Update your privacy policy. Disclose your data practices, list consumer rights, and provide clear contact details for requests
- Build a request handling process. Set up a submission channel, identity verification procedure, and 45-day response workflow
- Review vendor contracts. Confirm data processing agreements are in place and that service providers are contractually limited in how they can use your data
- Apply technical safeguards. Encryption, access controls, and an incident response plan are a baseline across most US privacy laws
- Keep your privacy governance current. Review your privacy policy annually, track new state legislation, and document your compliance efforts.
For a practical guide to implementing these steps, here’s how to comply with US state privacy laws using iubenda.
Build a privacy setup that keeps up with US data privacy laws
US data privacy laws are expanding state by state, which means your privacy setup can’t be a one-time task. If your business collects personal data from people in the US, you need to know which laws may apply, what rights users have, and what your Privacy Policy needs to explain.
The next practical step is to review your data privacy policies and make sure they reflect how your business collects, uses, shares, and protects personal data. iubenda can help you generate and maintain a Privacy and Cookie Policy tailored to your business, making it easier to keep your disclosures clear, accurate, and aligned with evolving requirements.