The U.S. Has No Federal Comprehensive Privacy Law
Last reviewed:
The United States regulates privacy sectorally (HIPAA, GLBA, COPPA) and as of this writing has no federal comprehensive privacy law, unlike most countries that follow a GDPR-style comprehensive model.
Most countries follow a comprehensive approach to privacy (often called data protection), and many are modeled on the EU's GDPR. The United States instead uses a sectoral approach, regulating privacy through laws aimed at specific sectors such as HIPAA (health), the GLBA (finance), and COPPA (children).
Despite decades of advocacy, no federal comprehensive privacy law exists as of this writing. One novel proposal under consideration would impose a data fiduciary duty on companies handling data, requiring them to act in good faith on behalf of consumers.
Because Congress has not enacted a comprehensive law, states stepped in. This is why a patchwork of state comprehensive laws exists - it is a direct response to federal inaction.
Key terms - quick answers
What is “Comprehensive privacy law”?
What is “Sectoral approach”?
What is “GDPR”?
What is “Data fiduciary duty”?
Keep going - free
Every study note on this site is free. So are these: