A Field Guide to Privacy Law for Companies Entering the US Market

Many non‑US businesses assume that compliance with the European Union’s GDPR or a similar home‑country law will largely address US requirements, Kevin Coy and Erin Doyle of Arnall Golden Gregory write. But the US regulatory picture is fragmented, highly sector- and state-specific and generates distinct regulatory and litigation risks that often are not addressed by compliance with home-country laws.

Compliance professionals, in‑house counsel and business leaders should consider 12 areas of data privacy and security diligence, contract terms and governance when planning US operations. 

These areas are not mutually exclusive, and they often overlap. This list is also not exhaustive. Discrete federal and state privacy laws regulate a host of other areas not addressed here, ranging from motor vehicle records and educational records to video rental records, library records and loyalty program information, among others.

1. Sectoral federal privacy laws 

While the US does not have an omnibus privacy law, it does have a number of sectoral and issue-specific privacy laws. HIPAA regulations, covering certain health‑related entities, and the Gramm-Leach-Bliley Act, which regulates financial institutions, are prominent examples.

HIPAA governs protected health information held by “covered entities,” including many healthcare providers and health plans and their “business associates,” a broad array of companies providing services that involve processing protected health information on behalf of covered entities. Covered entities and their business associates must address HIPAA’s privacy, security and data breach notification regulations, including specific contracting and compliance requirements.

Some states, such as Washington and Nevada, have adopted robust health information privacy laws intended to fill gaps regarding the privacy of consumer health data where the HIPAA privacy rules do not apply, and the Washington law includes a private right of action.

The Gramm-Leach-Bliley Act applies to a wide array of financial institutions, not just banks, and requires specific privacy notices, regulates the sharing of “non‑public personal information” and imposes information security requirements.

Foreign businesses entering the health or financial services sectors should treat HIPAA and the Gramm-Leach-Bliley Act as primary regulatory regimes, not as mere supplements to home-country requirements.

2. State privacy laws

The US still lacks a single federal GDPR‑style law, but more than 20 states have now enacted comprehensive consumer privacy statutes, starting with the California Consumer Privacy Act and followed by states like Virginia, Colorado, Connecticut, Texas and others. California is one of the most operationally demanding states: It created a dedicated privacy regulator, the California Privacy Protection Agency and is comparatively aggressive with enforcement.

Each state’s law is distinct, but they all typically include privacy notice requirements, consumer rights obligations (for example, access, deletion, correction and opt‑out options), purpose limitation concepts, data minimization concepts and vendor contracting obligations. While these laws apply across sectors, they do not apply to all businesses due to a range of different applicability triggers and exceptions. As a result, the impact of this category of state laws depends on the size and scope of business operations and the states where business will be conducted. A threshold assessment of which state laws actually apply to an entity should therefore be considered a necessary first step in any US privacy strategy.

3. Marketing and communications privacy

In the marketing and communications space, the US federal CAN‑SPAM Act and similar state laws set rules for commercial email, including identification requirements, opt‑out mechanisms and header‑information accuracy. The Telephone Consumer Protection Act and parallel state mini‑TCPA statutes heavily regulate telemarketing, text messaging and certain automated calling. Do-not-call list rules also apply particularly but not exclusively to telemarketing communications. Some of these laws have driven substantial class action litigation.

4. Website tracking and video or call recording

Additional US laws regulate the recording of videos or calls and using website tracking technologies. Federal and state wiretapping and eavesdropping statutes, as well as call‑recording laws, require one‑party or all‑party consent to record depending on the jurisdiction. Additionally, plaintiffs are increasingly challenging “session replay” and other online tracking technologies like cookies and pixels under these legal frameworks.

For businesses considering US physical retail stores or other locations in the US, notices regarding video surveillance also may be required. Businesses entering the US market that are planning to engage in these types of activities should carefully review their practices in these areas to address compliance concerns and mitigate potential risk.

5. Children’s privacy

Businesses processing personal data about children must consider federal and state privacy laws. US federal law is anchored by the Children’s Online Privacy Protection Act, which applies to online services directed to children under 13 or that knowingly collect personal information from such children. COPPA requires clear notices, verifiable parental consent before collecting most data, limits on use and disclosure and reasonable security. COPPA is enforced primarily by the US Federal Trade Commission and state attorneys general.

In parallel, an expanding set of state child‑focused privacy and online safety laws (for example, age‑appropriate design‑style codes and teen‑specific protections) for people up to age 18 are imposing additional obligations around profiling, targeted advertising and default settings for minors, creating a multilayered regulatory framework.

6. AI and automated decision-making technology laws

New and proposed state laws governing AI and automated decision‑making technology are proliferating, focusing on AI transparency, data minimization, bias and discrimination risks and the need for impact assessments where models rely on sensitive personal information or materially affect individuals (for example, employment, housing, credit or access to essential services).

Non‑US businesses may need to adapt AI governance programs built around GDPR, the EU AI Act or other laws to address specific US disclosure, consent, notice and opt‑out expectations, as well as heightened scrutiny of training data, profiling and the reuse of consumer and employee data for AI purposes.

7. Employee and applicant privacy

Businesses entering the US market may be surprised by the patchwork of US employee‑focused rules. The federal Fair Credit Reporting Act and similar laws in many states regulate the use of third‑party background screening reports regarding applicants and employees, as well as use of such reports for other purposes. State and local “ban the box,” “fair chance” and antidiscrimination laws restrict when and how criminal history information can be requested and used during hiring, typically requiring delayed inquiries and individualized assessments. Other state laws restrict the use of credit reports and salary history information as part of the hiring process.

Employers also face state laws regarding lawful off‑duty conduct (for example, protecting certain lawful products or activities), drug‑testing constraints and restrictions on requesting social media credentials or disciplining employees for lawful online activity. These laws collectively require careful coordination of global human resources and compliance policies. Employee health plans also may be subject to HIPAA requirements for covered entities.

8. Biometrics privacy laws

Several states have enacted biometric privacy statutes, the Illinois Biometric Information Privacy Act being the most prominent example that is frequently cited in private class actions. These laws can apply to technologies like fingerprint time clocks, facial recognition for physical or logical access and voiceprints. These often require informed consent, data retention limits and secure disposal.

9. Cybersecurity laws

Data security obligations are increasingly being codified not just as general “reasonable security” requirements but as more detailed statutory standards and regulatory guidance. Many state privacy laws expressly require appropriate technical, administrative and physical safeguards connected to the sensitivity and volume of personal data, and some state laws prescribe specific controls, risk assessments, audits and governance structures particularly in financial services and critical infrastructure contexts. In addition, California will soon require certain businesses covered by COPPA to conduct cybersecurity audits and submit certifications. These state rules sit alongside — and sometimes go beyond — federal sectoral requirements, such as those under HIPAA or the Gramm-Leach-Bliley Act.

Businesses that have designed their security programs around GDPR or a single global standard should assess whether US state- or sector-specific mandates regarding encryption, access management, multifactor authentication, vendor oversight, incident response, board‑level reporting and regulatory reporting require tailored enhancements for US operations.

10. Data breach notification laws

All US states and territories have data breach notification statutes that impose obligations to notify individuals (and sometimes regulators or credit bureaus) when defined personal information is accessed or acquired without authorization, often subject to specific notification timelines and notice content requirements. These laws differ on the scope of covered entities and covered data, whether they carry risk‑of‑harm exceptions and whether delays are permitted for law enforcement needs, so multistate incidents require coordinated, state‑specific analysis.

In addition, some businesses are subject to federal breach notification rules under regimes, such as Securities and Exchange Commission requirements for reporting by publicly traded companies, HIPAA or the Gramm-Leach-Bliley Act. As such, businesses entering the US market should consider developing US-focused breach notification protocols to anticipate their response to a breach of US personal data.

11. Government and bulk US sensitive data transfer regulations

Unlike GDPR and many national data protection laws, the US has not traditionally regulated the export of personal data to other jurisdictions. In January 2025, however, the US Department of Justice finalized regulations that restrict or prohibit certain “covered data transactions” involving bulk US sensitive personal data or US government‑related data with specified “countries of concern” and “covered persons.” The rule defines “bulk US sensitive personal data” broadly to include categories like certain personal identifiers, precise geolocation, biometric identifiers, health and financial data and human genetic and molecular biological data when certain thresholds are met within a 12‑month period.

A separate law enacted in 2024 also restricts the sale or transfer of personal data by third-party data brokers to “adversary countries” or entities under their control, which could apply instead of or in addition to the DOJ regulations. Compliance with these requirements necessitates an understanding of data flows given that contractual safeguards differ depending on whether the parties involved are US, foreign or covered persons under these regulations. These measures would apply in addition to any data transfer requirements required by home-country data protection laws, such as GDPR.

12. Federal and state unfair or deceptive acts and practices laws

The FTC and state regulators have long used federal and state prohibitions on unfair or deceptive acts and practices (UDAP) to bring actions against businesses that have failed to keep their privacy and data security promises, as well as to act against businesses that engage in unfair privacy and data security practices. While businesses may overlook UDAP laws because they are broad prohibitions rather than detailed operational compliance regimes, federal and state regulators have brought hundreds of UDAP cases over the years. To avoid engaging in deceptive practices, it is important to ensure that a business’s public privacy and security promises are kept in practice. Additionally, unfairness claims do not require an unkept promise. For example, they can be brought if inadequate data security practices result in substantial injury to a consumer that the consumer could not have reasonably avoided. As a result, businesses considering US market entry should consider reviewing their privacy policies, notices and other promises and data security practices from this broader perspective in addition to more specific requirements applicable to their US operations.

Regulatory and litigation risks

Many of the privacy and security laws and regulations discussed above provide private rights of action that make the US litigation environment particularly attractive for class-action plaintiffs. Meanwhile, federal and state regulators — including the FTC, sectoral regulators, state attorneys general and specialized bodies like the California Privacy Protection Agency — actively bring regulatory enforcement actions for privacy and security violations.

Compliance with the GDPR or other non‑US data protection frameworks likely will support US compliance efforts, but it is not determinative. Even in instances where US federal and state laws share the same privacy protection goals as non-US privacy regulations, US laws can differ significantly regarding issues like scope, legal bases, consent standards, notice design and content, automated‑decision rules and, crucially, private litigation exposure. Non‑US businesses planning to enter or expand in the US market should therefore consider undertaking a targeted US privacy and data use assessment covering consumer, employee and business-to-business data flows to calibrate governance, contracting, technology and insurance strategies to this distinct regulatory and litigation landscape.

Similar Posts

Leave a Reply