Data Protection Atlas

United States

Tier 2 Sectoral / partial Americas

Principal framework: Sectoral federal laws + ~20 state privacy acts. Regulator: FTC + state regulators. No comprehensive federal law. Around 20 states have enacted comprehensive privacy acts led by California. EU transfers rely on the Data Privacy Framework — certified organisations only.

At a glance

Principal law
Sectoral federal laws + ~20 state privacy acts
Regulator
FTC + state regulators
Breach notification
No federal general rule — all 50 states have breach statutes (typically 30–60 days); sector rules such as HIPAA apply
Maximum penalty
FTC Act §5 enforcement; state laws e.g. California $2,500–$7,500 per violation
DPO required
No general requirement
Digital consent age
13 under COPPA (parental consent)
Extraterritorial reach
State laws reach businesses targeting their residents

Structure

Structural pattern
Pattern 1 — patchwork, no floor
Sub-jurisdictions
0 (fully-independent)
ISO code
US

Transfers and adequacy

EU member
No
EEA member
No
Holds EU adequacy
No

Partial or framework-based arrangement rather than a full adequacy decision.

Instruments

Sub-jurisdictions

Each is independently substantive — there is no national floor for them to derogate from.

How the concepts differ here

The governance concepts are written from a GDPR-family default. These are the recorded departures for this jurisdiction, including those inherited from its legal family. An absent entry means nobody has checked, not that the position matches the default.

Concept How it differs Position here Scope
Choosing and documenting a lawful basis Does not apply There is no general "lawful basis" requirement. Processing is permitted by default and constrained by notice, purpose disclosure and opt-out rights instead. US state privacy acts
The principles, end to end Does not apply No general principles article. Comparable duties exist but are scattered through specific obligations rather than stated as overarching principles. US state privacy acts
The rights, and how they interact Works differently A different set: know, delete, correct, opt out of sale/sharing and targeted advertising, limit use of sensitive data, and non-discrimination for exercising them. US state privacy acts
Automated decisions, profiling and AI Works differently Framed as opt-out rights over profiling in furtherance of significant decisions, rather than a prohibition on solely automated decisions with safeguards. US state privacy acts
Appropriate technical and organisational measures Works differently A reasonableness standard rather than an explicit appropriateness assessment against state of the art, cost and risk. US state privacy acts

Sources

Never independently verified — seeded from the prototype.