USA Federal
Summary
Law: There is currently no general federal privacy regulation.
Regulator: The Federal Trade Commission (FTC) takes enforcement action against organizations for violations of Section 5 of the FTC Act, which prohibits unfair or deceptive acts in or affecting commerce.
Summary: There are several related federal laws, including the Health Insurance Portability and Accountability Act of 1996 (HIPAA) which regulates the privacy and security of health information, the Gramm-Leach-Bliley Act of 1999 (GLBA) which requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data, and the Children's Online Privacy Protection Act of 1998 (COPPA) which imposes requirements on operators of websites or online services directed at children under 13 years old.
Furthermore, on July 10, 2023, the European Commission voted to adopt its adequacy decision for the EU-US Data Privacy Framework (DPF), concluding that the US provides a level of protection essentially equivalent to that of the EU for personal data transferred under the EU-US DPF from a controller or a processor in the EU to certified organizations in the US. The adequacy decision has the effect that personal data transfers from controllers and processors in the EU to certified organizations in the US may take place without needing further authorization. On August 14, 2024, the Swiss Federal Council announced that certified US companies under the new Swiss-U.S. Data Privacy Framework (Swiss-US DPF) offer an adequate level of protection, allowing for the transfer of personal data between Switzerland and certified US companies without additional guarantees.
Multiple actions relating to artificial intelligence (AI) have also been fielded in the US, including the Executive Order on Safe, Secure, and Trustworthy Artificial Intelligence, directing the creation of guidelines and standards on AI, alongside other bills introduced at the federal level.
Other key laws and regulations include:
- Electronic Communications Privacy Act of 1986
- Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH)
- Telemarketing and Consumer Fraud and Abuse Prevention Act of 1994 (TCFAPA)
- Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003 (CAN-SPAM)
- Fair Credit Reporting Act of 1970 (FCRA)
- Telephone Consumer Protection Act of 1991 (TCPA)
- Privacy Act of 1974
- Fair and Accurate Credit Transactions Act of 2003 (FACTA)
- Video Privacy Protection Act of 1988 (VPPA)
You can follow legislative developments in the US through the US State Law Tracker.