United States
Tier 2 Sectoral / partial AmericasPrincipal framework: Sectoral federal laws + ~20 state privacy acts. Regulator: FTC + state regulators. No comprehensive federal law. Around 20 states have enacted comprehensive privacy acts led by California. EU transfers rely on the Data Privacy Framework — certified organisations only.
At a glance
- Principal law
- Sectoral federal laws + ~20 state privacy acts
- Regulator
- FTC + state regulators
- Breach notification
- No federal general rule — all 50 states have breach statutes (typically 30–60 days); sector rules such as HIPAA apply
- Maximum penalty
- FTC Act §5 enforcement; state laws e.g. California $2,500–$7,500 per violation
- DPO required
- No general requirement
- Digital consent age
- 13 under COPPA (parental consent)
- Extraterritorial reach
- State laws reach businesses targeting their residents
Structure
- Structural pattern
- Pattern 1 — patchwork, no floor
- Sub-jurisdictions
- 0 (fully-independent)
- ISO code
- US
Transfers and adequacy
- EU member
- No
- EEA member
- No
- Holds EU adequacy
- No
Partial or framework-based arrangement rather than a full adequacy decision.
Instruments
COPPA
15 U.S.C. 6501-6506; 16 CFR Part 312
CCPA/CPRA
Cal. Civ. Code sec. 1798.100 et seq.
FCRA
15 U.S.C. 1681 et seq.
HIPAA
Pub. L. 104-191, as amended by the HITECH Act 2009; 45 CFR Parts 160 and 164
GLBA
Pub. L. 106-102, Title V; Regulation P, 12 CFR Part 1016; FTC Safeguards Rule, 16 CFR Part 314
VCDPA
Va. Code sec. 59.1-575 et seq.
Sub-jurisdictions
Each is independently substantive — there is no national floor for them to derogate from.
California
California is the substantive centre of gravity of US state privacy law.
Virginia
Virginia was the second US state to enact a comprehensive privacy law and is the template for the "business-friendly" state model: AG-only enforcement, no private right of action, and a permanent cure period.
How the concepts differ here
The governance concepts are written from a GDPR-family default. These are the recorded departures for this jurisdiction, including those inherited from its legal family. An absent entry means nobody has checked, not that the position matches the default.
| Concept | How it differs | Position here | Scope |
|---|---|---|---|
| Choosing and documenting a lawful basis | Does not apply | There is no general "lawful basis" requirement. Processing is permitted by default and constrained by notice, purpose disclosure and opt-out rights instead. | US state privacy acts |
| The principles, end to end | Does not apply | No general principles article. Comparable duties exist but are scattered through specific obligations rather than stated as overarching principles. | US state privacy acts |
| The rights, and how they interact | Works differently | A different set: know, delete, correct, opt out of sale/sharing and targeted advertising, limit use of sensitive data, and non-discrimination for exercising them. | US state privacy acts |
| Automated decisions, profiling and AI | Works differently | Framed as opt-out rights over profiling in furtherance of significant decisions, rather than a prohibition on solely automated decisions with safeguards. | US state privacy acts |
| Appropriate technical and organisational measures | Works differently | A reasonableness standard rather than an explicit appropriateness assessment against state of the art, cost and risk. | US state privacy acts |
Sources
- Regulator FTC — privacy and security
- Primary California CCPA/CPRA — Attorney General
Never independently verified — seeded from the prototype.