Given the plethora of new legislation that has emerged globally in recent years, the directory has required some renovation. First launched in 2017, this resource is a one-stop-shop for information on data protection authorities for privacy professionals navigating international data protection and privacy laws. Contact a qualified attorney to make sure your rights and interests get protected. Visit our attorney directory to find a lawyer near you who can help. An attorney can offer tailored advice and help prevent common mistakes. A qualified attorney can assess whether you have viable legal options and explain the realistic outcomes you might expect.
There are exceptions, however, for the data of children under the age of 13 and for sensitive data. The law’s scope tracks closely with the Texas Data Privacy and Security Act (TDPSA), including its http://www.familiesforexcellentschools.org/privacy-policy applicability, sensitive data, and its requirement to honor universal opt-out mechanisms. It grants them certain rights, outlined below, and provides controllers, or the entity that determines the purpose and means of processing personal data, with specific requirements for how to handle data and consumer requests related to their data.
Children’s data is not defined as “sensitive,” but controllers must comply with COPPA Controller must provide consumer with notice and right to opt-out of data collection Consent required to process personal data for targeted advertising or sell personal data if Controller has actual knowledge, and willfully disregards, that the consumer https://genethics.ca/blog/ensuring-genethics-privacy-and-data-protection-safeguarding-the-genetic-information-of-individuals is years of age Personal information pertaining to children is not defined as “sensitive,” but parental consent is required for the “sale” of personal information pertaining to children under 13, and teens under 16 must opt-in to a “sale” of their personal information We previously provided a summary of the California, Virginia, and Colorado laws (available here), and Utah and Connecticut have since enacted new privacy laws. Twenty states have enacted comprehensive consumer privacy laws as of 2026, led by California’s CCPA/CPRA.
Let me outline the key differences between E.U.’s GDPR and U.S.’s CCPA:
- This act placed increased limits and requirements for data collection by financial institutions, as well as limited how that information could be collected and stored.
- It doesn’t apply to general audience websites unless they have specific services that attract children to their site.
- As such, this metric has surpassed Gartner’s prediction that 75% of the population would be covered by 2024.
- For organizations to meet their obligations under global data privacy legislations, they need an effective consent management process.
- The EU AI Act requires that personal data processed by AI systems comply with existing data protection laws like the GDPR.
- Consent required to process personal data for targeted advertising or sell personal data if Controller has actual knowledge, and willfully disregards, that the consumer is years of age
Most states require attorney general notification when breaches exceed a threshold, typically 250 to 1,000 affected residents. It passed a House subcommittee in May 2024 but was never brought to a full committee vote. While there is no comprehensive federal data privacy law, several sector-specific statutes provide strong protections within their domains. Several states that have not passed an omnibus statute have enacted narrower laws that protect specific categories of data, and in some cases these reach further than a comprehensive law would. As of 2026, twenty states have comprehensive privacy laws in effect, covering consumer rights like the ability to access, delete, and opt out of the sale of personal data.
Modern tort law
The law defines consumers as residents of the state acting only as an individual, not in commercial or employment contexts. A “controller” is an individual or legal entity that determines the purpose and means of processing personal data. The New Jersey Data Protection Act (NJDPA) is a data privacy law that gives New Jersey residents control over their personal data, providing certain rights and imposing obligations on those who control and process consumer data.
Sectoral State Privacy Laws
- The Gramm-Leach-Bliley Act (GLBA) applies to financial institutions, broadly defined.
- While many of these eight state privacy laws are similar to current privacy laws in effect, there are some noteworthy differences that you will need to be mindful of heading into the New Year.
- The rapidly changing landscape of consumer data privacy laws and regulations across the globe can make it difficult for organizations to stay up to date with the requirements that apply to them.
- A cross-border data transfer occurs anytime personal data is sent from a country covered by the UK or EU GDPR to a country outside of that legal territory.
The EU AI Act requires that personal data processed by AI systems comply with existing data protection laws like the GDPR. Such processing is permitted only when bias detection can’t be done effectively using other data types. This is allowed only under specific conditions with strict access limits, security measures, and data deletion rules. These classifications are based on factors like the system’s intended purpose, how independently it operates, and its potential impact on health, safety, and fundamental rights. It applies to all AI systems used within the EU, regardless of where the company, educational institution, or other organization using or developing AI is located. This regulation creates rules for AI technologies across the EU, focusing on safety, transparency, and the protection of basic rights.
Certain states have privacy laws that deal with genetic-specific information. Major federal laws that apply to biobanks are regulations by the Food and Drug Administration and Common Rule. Sign up to benefit from their deep understanding, tips and best practices regarding how your company can manage compliance risk while unlocking the business value of your communications data.
What are the core consumer rights and business obligations under US privacy laws?
Idaho does not currently have a comprehensive data privacy law in place, nor are there any related bills moving through the state government. Currently, Hawaii does not have an official comprehensive consumer data privacy law. Currently, Georgia does not have a comprehensive consumer data privacy law in place. The District of Columbia does not have a comprehensive consumer data privacy law in force, nor are any related bills in the works.
Because of COPPA’s limits on data collection for children, some companies—notably, social media sites like Facebook and Twitter—require their users to verify they are 13 years of age or older when signing up. Companies must also maintain the confidentiality of data collected from children and must only keep it as long as necessary to fulfill the purpose for which it was collected. Parents must have the opportunity to access their child’s data, review or delete it and prevent the company from collecting further data about their child. The law requires these institutions, including “companies that offer consumers financial products or services like loans, financial or investment advice, or insurance,” according to the Federal Trade Commission, to safeguard sensitive data and explain how it uses customer data. The GLBA, signed into law by Clinton in 1998, covers data privacy for financial institutions.
