Data Privacy Regulation — US Sectoral, State Comprehensive, GDPR, AI Layer
US data privacy law is a sector-by-sector patchwork — financial (GLBA), health (HIPAA), children (COPPA), education (FERPA), credit reporting (FCRA) — supplemented since 2018 by a wave of state comprehensive laws led by California’s CCPA/CPRA. The EU’s General Data Protection Regulation (GDPR, in force May 2018) operates as a parallel global standard with extraterritorial reach. The UK departed from EU jurisdiction in 2021 but maintains a near-mirror regime under the UK GDPR + DPA 2018. Layered on top: biometric-specific statutes (Illinois BIPA, Texas CUBI, Washington My Health My Data), automated decision-making rules (CCPA ADMT, Colorado AI Act, NYC AEDT), and the sectoral preemption questions that determine whether and how the regimes interlock. This note maps the architecture as of mid-2026: the US sectoral statutes; the 20-state comprehensive-law wave; EU GDPR mechanics; UK divergence; the AI-specific privacy layer; and the enforcement patterns that operate across them. By 2026, every multistate US business handling consumer personal information must comply with at least 6-12 distinct comprehensive privacy regimes plus all relevant sectoral statutes plus GDPR if any EU resident data is processed.
See also
- eu-competition-and-regulation
- constitutional-law
- employment-and-environmental-law
- contracts-and-ip
- administrative-law
- finance-regulation
- fintech-architecture-deep
- federal-statutes-and-court-system
- treaties-and-regulatory-agencies
1. The US Sectoral Foundation
1.1 HIPAA — Health
The Health Insurance Portability and Accountability Act of 1996 (Pub. L. 104-191) authorized HHS to issue regulations protecting health information. Implementing rules:
- Privacy Rule (45 CFR §§ 164.500-534, December 2000, effective April 2003) — governs use and disclosure of “protected health information” (PHI) by covered entities (health plans, health care clearinghouses, health care providers transmitting health information electronically) and their business associates. Restricts disclosure to that necessary for treatment, payment, or health care operations, with patient-authorization required for marketing and most other uses. Patient access rights, accounting of disclosures.
- Security Rule (45 CFR §§ 164.302-318) — administrative, physical, and technical safeguards for electronic PHI.
- Breach Notification Rule (45 CFR §§ 164.400-414) — notification to affected individuals, HHS, and (for breaches affecting 500+ residents of a state) prominent media within 60 days.
- HITECH Act 2009 — extended HIPAA to business associates as direct liability; tiered penalties up to $1.5M annual cap per violation type.
- 2024 Reproductive Health Privacy Rule (HHS final rule April 2024) — added “Privacy Rule with Respect to Reproductive Health Care” prohibiting disclosure of PHI for law enforcement investigation of reproductive health care that was lawful at the place provided. Litigated extensively; Fifth Circuit declined to stay; nationwide implementation December 2024.
HHS Office for Civil Rights (OCR) enforces HIPAA. Notable settlements: Anthem Inc 2018 (4.8M); Memorial Healthcare System 2017 (6.85M); CHSPSC 2020 ($2.3M). Substantial increase in settlement values 2018-2024.
1.2 GLBA — Financial
The Gramm-Leach-Bliley Act of 1999 (Pub. L. 106-102) Title V created the federal financial privacy regime:
- Privacy Rule — annual privacy notices to consumers; opt-out before sharing nonpublic personal information with nonaffiliated third parties (exceptions: service providers, joint marketing, law enforcement). 16 CFR Part 313 (FTC) + parallel bank-regulator rules at 12 CFR Parts 40 (OCC), 216 (FRS), 332 (FDIC), 573 (NCUA) + 17 CFR § 248 (SEC) for broker-dealers and investment advisers + CFTC Reg P at 17 CFR § 160 + CFPB at 12 CFR § 1016 (post-Dodd-Frank for nondepository).
- Safeguards Rule — FTC 2003, substantially updated December 2021 (87 FR 70272), effective June 2023. Required information security program, including: appointed qualified individual; risk assessment; specific safeguards (access controls, multi-factor auth, encryption); training; service provider oversight; incident response plan; written annual report to the board; nondisclosure agreements. The 2021 update was the most significant privacy-related rule the FTC issued in twenty years.
Federal banking agencies’ parallel “Standards for Safeguarding Customer Information” (12 CFR Part 30 Appendix B for OCC; etc.) reach FDIC-insured depositories.
The CFPB’s “open banking” Section 1033 final rule (October 2024, 89 FR 90838) implements Dodd-Frank’s data-portability provision — consumers can authorize sharing of financial account information with third parties. Effective for largest providers April 2026, scaled phase-in through 2030.
1.3 COPPA — Children Online
The Children’s Online Privacy Protection Act of 1998 (15 USC §§ 6501-6506). Operators of websites/online services directed to children under 13 (or with actual knowledge they’re collecting from under-13) must:
- Provide privacy notice.
- Obtain verifiable parental consent before collection.
- Permit parents to review/delete child’s information.
- Maintain confidentiality, security, and integrity.
- Retain only as long as reasonably necessary.
FTC enforces. The COPPA Rule (16 CFR Part 312) implements. Substantial enforcement: YouTube/Google 2019 (5.7M) and 2024 (DOJ filed action — multibillion-dollar penalty sought); Microsoft Xbox 2023 (275M COPPA penalty + $245M consumer redress).
FTC proposed substantial COPPA Rule amendments January 2024 (89 FR 2034) tightening definitions of “personal information” (added biometric identifiers), restricting third-party advertising, requiring separate consent for targeted advertising vs internal operations, data retention limits. Final rule pending in 2026.
1.4 FERPA — Education
Family Educational Rights and Privacy Act of 1974 (20 USC § 1232g) governs education records of schools receiving federal funding. Requires written parental consent (or consent of student over 18) to disclose education records.
Limited enforcement — withdrawal of federal funding is the only remedy; never invoked. No private right of action (Gonzaga University v Doe, 536 US 273 (2002)).
1.5 FCRA — Consumer Reports
The Fair Credit Reporting Act of 1970 (15 USC § 1681) regulates “consumer reporting agencies” — Equifax, Experian, TransUnion plus thousands of specialty CRAs (LexisNexis, ChoicePoint/LexisNexis, employment screeners, tenant screeners, medical-information CRAs).
Core obligations:
- Accuracy + maximum possible accuracy standard.
- Permissible purposes for furnishing reports (employment, credit, insurance, certain government purposes).
- Adverse action notice (when a consumer report is used to deny credit, employment, insurance).
- Consumer access + dispute rights.
- Identity theft red flags.
- Pre-employment use — written disclosure + consent.
FACT Act 2003 amendments (Pub. L. 108-159) added: identity-theft red flag rules; consumer credit freeze rights; truncation of payment card numbers; annual free credit reports; disposal rule (16 CFR Part 682).
CFPB rulemaking — March 2025 final rule expanding FCRA’s “automated valuation models” oversight (parallel to AVM rule for AVM-users). Pending broader rule on data brokers (proposed June 2024, 89 FR 51536) classifying data brokers selling certain types of consumer reports as CRAs.
1.6 TCPA — Telephone Consumer Protection
47 USC § 227. Restricts auto-dialed calls, prerecorded calls, and texts to mobile phones; restrictions on robocalls to landlines. The DNC (Do Not Call) registry administered by FTC. Statutory damages $500/violation (treble for willful) make TCPA a leading consumer-class-action vehicle.
FCC interpretation has cycled — ACA International v FCC, 885 F.3d 687 (DC Cir 2018), vacated the 2015 FCC declaratory ruling expanding “automatic telephone dialing system.” Facebook Inc v Duguid, 592 US 395 (2021) (Sotomayor) narrowed ATDS definition to systems with “random or sequential number generator.”
1.7 CAN-SPAM, VPPA, ECPA
- CAN-SPAM Act of 2003 (15 USC §§ 7701-7713) — commercial email regulation; opt-out, header accuracy.
- VPPA (Video Privacy Protection Act of 1988, 18 USC § 2710) — restricts disclosure of video-rental records. Reborn 2014-2024 as a major class-action vehicle for digital streaming consent issues (Vizio, Disney, Hulu, NFL, etc. — courts split on whether website visitors are “subscribers”).
- ECPA / Wiretap Act (18 USC §§ 2510-2523) — interception of electronic communications; Stored Communications Act (18 USC §§ 2701-2713); Pen Register/Trap and Trace Act (18 USC §§ 3121-3127). One-party consent under federal law; two-party consent under several state laws (California, Connecticut, Florida, Illinois, Massachusetts, Maryland, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, Washington). Underlies wiretap claims against website session-replay tools (FullStory, Hotjar, etc. — substantial class action wave 2022-2024).
- Privacy Act of 1974 (5 USC § 552a) — federal agency Privacy Act, requires notice (System of Records Notices, SORNs); restricts disclosure; provides access and correction rights. No application to private sector.
2. The State Comprehensive Privacy Law Wave (2018-2026)
Twenty US states had enacted comprehensive consumer privacy laws by mid-2026, on top of California’s pioneering CCPA (2018) and CPRA (2020 ballot initiative, effective 2023). The wave accelerated through 2024-2025 with most legislatures passing variants of a common template.
2.1 California — CCPA and CPRA
The California Consumer Privacy Act of 2018 (Cal. Civ. Code §§ 1798.100-1798.199.100; AB 375, signed June 2018, effective January 2020) was the first US comprehensive privacy law. Created consumer rights to:
- Know what personal information is collected.
- Delete personal information.
- Opt-out of sale.
- Non-discrimination for exercising rights.
The California Privacy Rights Act (Proposition 24, November 2020 ballot, effective January 2023) substantially expanded CCPA:
- Added “sensitive personal information” category with separate rights.
- Right to correct inaccurate personal information.
- Right to limit use and disclosure of sensitive personal information.
- Right to opt-out of sharing (parallel to opt-out of sale, capturing cross-context behavioral advertising).
- Right of access including 12-month look-back.
- Data minimization, purpose limitation, retention limits (statutory requirements, not just consumer requests).
- Service provider + contractor + third party distinctions with required contract terms.
- Created the California Privacy Protection Agency (CPPA) — first dedicated US state privacy regulator, five-member board.
CPPA rulemaking authority includes ADMT (automated decision-making technology), risk assessments, cybersecurity audits. CPPA’s “ADMT” final regulations adopted November 2024, effective 2025-2027 phased, require:
- Pre-use notice for significant ADMT decisions.
- Right to opt-out of ADMT for certain uses.
- Right to access information about ADMT logic.
- Risk assessments before deploying significant ADMT.
CPPA also enforced cybersecurity audit and risk assessment requirements through 2025-2026 rulemaking.
CPRA fines: up to 7,500 per intentional violation or involving minor’s data. Annual gross revenue threshold $25M, or processes 100,000+ consumer records, or 50%+ revenue from selling/sharing personal info.
CPPA enforcement actions: \1.55M DoorDash (February 2024); \$32.7M Healthline (July 2025).
2.2 The 19 Other States (as of mid-2026)
In rough order of effective date:
- Virginia VCDPA (effective January 2023). Governor Northam signed March 2021. Modeled loosely on Washington Privacy Act bill template. AG enforcement; no private right of action.
- Colorado Privacy Act (CPA) (effective July 2023). Governor Polis signed July 2021. Notable for “universal opt-out mechanism” (UOOM) recognition (Global Privacy Control, etc.) from July 2024.
- Connecticut CTDPA (effective July 2023). Notable for narrower threshold (100K consumers or 25K + 25% revenue from sale).
- Utah UCPA (effective December 2023). Most business-friendly variant — opt-out for sensitive data (not opt-in); narrow definitions; no data minimization principle.
- Iowa ICDPA (effective January 2025). Threshold 100K consumers / 25K + 50% revenue from sale.
- Indiana INCDPA (effective January 2026). Modeled on Virginia template.
- Tennessee TIPA (effective July 2025). Notable for the “voluntary safe harbor” for compliance with NIST Privacy Framework, ISO 27701, or other voluntary standards.
- Texas TDPSA (Texas Data Privacy and Security Act, effective July 2024). Lower threshold than most — applies to any entity conducting business in Texas, processing personal data, and not an SBA-classified small business. Broader than other state laws on threshold.
- Florida FDBR (Florida Digital Bill of Rights, effective July 2024). Targeted at large platforms — applies only to controllers with $1B+ revenue and engaging in specified targeted activities.
- Montana CDPA (effective October 2024). Similar to Connecticut template.
- Oregon Consumer Privacy Act (effective July 2024).
- Delaware DPDPA (effective January 2025).
- New Jersey NJDPA (effective January 2025).
- New Hampshire NHCDP (effective January 2025).
- Maine MCDPA (effective January 2026).
- Kentucky KCDPA (effective January 2026).
- Minnesota CDPA (Minnesota Consumer Data Privacy Act, effective July 2025).
- Maryland MODPA (Maryland Online Data Privacy Act, effective October 2025). Notable for adopting data minimization as substantive limit (not just consumer-request-driven) and prohibition on sale of sensitive data; restrictions on processing minors’ data.
- Rhode Island Data Transparency and Privacy Protection Act (effective January 2026).
- Nebraska Data Privacy Act (effective January 2025).
2.3 Common Template and Variations
The dominant template (Virginia / Colorado / Connecticut / Utah-style) has these features:
Scope thresholds — controllers processing 100,000+ consumer records, or 25,000+ with 25%-50% revenue from sale (varies). Texas drops the threshold to any controller doing business in the state. Florida applies only to large platforms.
Consumer rights — access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling for significant decisions.
Controller obligations — data minimization (in some states); purpose specification; security; data protection assessments for high-risk processing; sensitive data opt-in (in most states; Utah opt-out only).
Sensitive data — racial/ethnic origin, religious beliefs, mental/physical health, sexual orientation, citizenship/immigration status, biometric data, genetic data, precise geolocation, children’s data. Opt-in consent in most states.
Enforcement — state AG (with limited concurrent authority in some states). No private right of action except CCPA’s narrow security-breach private right (Cal. Civ. Code § 1798.150).
Right to cure — most states require AG to provide notice + opportunity to cure before enforcement (Virginia 30 days, Connecticut 60 days). California’s right-to-cure (under CCPA) was eliminated by CPRA for most violations. Some states’ cure rights sunset after a transition period (Connecticut’s expired December 2024).
Universal Opt-Out Mechanisms (UOOMs) — recognition of browser-level signals (Global Privacy Control / GPC) as legally binding opt-outs. California (since 2021), Colorado (since July 2024), Connecticut, Delaware, New Jersey, others.
2.4 State AG Enforcement Patterns
California AG / CPPA — Sephora (1.55M, 2024), Healthline ($32.7M, 2025), Sweepstakes companies (multiple 2024-2025). Tilting Point Media; Tovala; HotPay; OpenAI investigation initiated 2024 (preliminary inquiries).
Texas AG (under Paxton, 2025 transition to Brent Webster) — enforcement actions against Pieces Technologies (October 2024, AI healthcare claims), Meta (BIPA-equivalent settlement July 2024 — $1.4B), TikTok (ongoing investigation), Google (multiple matters).
Connecticut AG — Tory Burch (March 2024, CTDPA enforcement, $50K initial), Whoop (June 2024 cure period).
New York AG (not a comprehensive privacy law state, but uses GBL § 349 and Executive Law § 63(12)) - has been the most active state AG in cybersecurity (Equifax 2019 - \400K; multiple ongoing).
3. EU GDPR — The Global Standard
The General Data Protection Regulation (Regulation EU 2016/679, in force May 25, 2018) replaced the 1995 Data Protection Directive. Unlike a directive (requires Member State transposition), the GDPR is directly applicable across the EU.
3.1 Article 3 — Territorial Scope (Extraterritoriality)
GDPR applies to:
- Processing in the context of the activities of an establishment of a controller or processor in the EU (regardless of whether the processing takes place in the EU).
- Processing by a controller or processor outside the EU of personal data of data subjects who are in the EU, where the processing activities relate to: (i) offering goods or services to such data subjects in the EU; or (ii) monitoring of their behavior (e.g., online behavioral advertising tracking) so far as the behavior takes place within the EU.
The “monitoring behavior” prong is the key US-business hook — virtually any website using analytics for EU visitors falls within scope.
3.2 Article 5 — Principles
Six core principles plus accountability:
- Lawfulness, fairness, transparency — must have a lawful basis (Art 6) and be transparent to data subjects (Arts 12-14).
- Purpose limitation — collected for specified, explicit, legitimate purposes; not further processed in incompatible manner.
- Data minimization — adequate, relevant, limited to what is necessary.
- Accuracy — accurate and kept up to date; inaccurate data erased or rectified.
- Storage limitation — kept in identifiable form no longer than necessary.
- Integrity and confidentiality — appropriate security.
Plus the meta-principle of accountability (Art 5(2)) — controller must demonstrate compliance.
3.3 Article 6 — Lawful Bases
Six lawful bases for processing:
- Consent — must be freely given, specific, informed, unambiguous (Art 4(11)).
- Contract — necessary for performance of a contract with the data subject or pre-contractual steps.
- Legal obligation — required by EU/Member State law.
- Vital interests — protection of life of data subject or another natural person.
- Public task — performance of task in the public interest.
- Legitimate interests — pursued by controller or third party, except where overridden by interests/rights of data subject (the “balancing test”).
Meta’s reliance on legitimate interests for behavioral advertising was rejected by EDPB and CJEU (Meta Platforms Ireland v Bundeskartellamt, C-252/21, July 4, 2023) — leading to the November 2023 launch of paid ad-free subscription as a “consent or pay” alternative. The EDPB’s April 2024 opinion (Opinion 08/2024) further restricted “consent or pay” for large online platforms.
3.4 Article 9 — Special Categories
Special-category data: racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, genetic data, biometric data (where uniquely identifying), health data, data concerning sex life or sexual orientation.
Article 9(1) prohibits processing absent one of the Art 9(2) exceptions, including: explicit consent, employment law, vital interests, foundation/association activities, manifestly made public by data subject, legal claims, substantial public interest, preventive/occupational medicine, public health, archiving/scientific/historical/statistical purposes.
3.5 Data Subject Rights (Articles 12-22)
- Article 13/14 — information at collection.
- Article 15 — right of access.
- Article 16 — right to rectification.
- Article 17 — right to erasure (“right to be forgotten”).
- Article 18 — right to restriction of processing.
- Article 19 — notification obligations.
- Article 20 — right to data portability.
- Article 21 — right to object (with absolute right to object to direct marketing).
- Article 22 — automated decision-making — right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects, with exceptions.
The CJEU’s interpretation of Article 22 in SCHUFA Holding AG (C-634/21, December 2023) — automated credit scoring is “automated decision-making” within Article 22 even if the human-controlled creditor uses the score; the scoring entity must meet Article 22 conditions.
3.6 Controller and Processor Obligations
- DPO (Art 37) — Data Protection Officer required for public authorities, large-scale special category processing, or large-scale systematic monitoring.
- DPIA (Art 35) — Data Protection Impact Assessment for high-risk processing.
- Records of Processing (Art 30) — internal documentation.
- Data breach notification (Arts 33, 34) — to supervisory authority within 72 hours of becoming aware; to data subjects if high risk to rights and freedoms.
- Processor contracts (Art 28) — required terms.
- Privacy by design and default (Art 25).
3.7 International Transfers (Chapter V)
The GDPR restricts personal data transfers to “third countries” lacking “adequate” data protection (Art 45). Mechanisms:
- Adequacy decisions by European Commission (Art 45): UK, Switzerland, Canada (commercial only), Japan, South Korea, New Zealand, Argentina, Israel, Andorra, Faroe Islands, Guernsey, Isle of Man, Jersey, Uruguay. Plus the EU-US Data Privacy Framework (replacing Privacy Shield, adopted July 10, 2023, EU Commission Decision 2023/1795).
- Standard Contractual Clauses (Art 46, SCCs — new modular form adopted June 2021, mandatory from December 2022).
- Binding Corporate Rules (Art 47, BCRs) — for intra-group transfers.
- Derogations (Art 49) — explicit consent, contract performance, vital interests, etc.
The CJEU’s Schrems II decision (C-311/18, July 16, 2020) invalidated the EU-US Privacy Shield and imposed stringent supplementary measures for SCC use to the US, citing US surveillance laws (FISA § 702, Executive Order 12333). The Biden Administration’s Executive Order 14086 (October 2022) created the Data Protection Review Court within DOJ to address Schrems II concerns; the Privacy Framework adopted July 2023 on this foundation.
Schrems III — Max Schrems and others have already filed challenges to the 2023 Privacy Framework; litigation pending at the General Court (T-553/23 and others). Outcome unknown through 2026.
The UK and Switzerland have parallel UK-US and Swiss-US Data Privacy Framework arrangements (October 2023).
3.8 Enforcement and Fines
Article 83 — administrative fines:
- Lower tier — up to €10M or 2% of worldwide annual turnover (whichever higher): violations of Arts 8 (children’s consent), 11 (identification), 25-39 (controller/processor obligations), 42-43 (certification).
- Higher tier — up to €20M or 4%: violations of Arts 5-7, 9 (lawful basis, principles, consent, special categories), 12-22 (data subject rights), Chapter V (international transfers), Member State-specific provisions.
Top fines (cumulative through 2025):
- Meta Ireland — €1.2B (May 2023, Irish DPC, Facebook US transfers under SCCs).
- TikTok — €530M (May 2025, Irish DPC, children’s data + transfers to China).
- Meta — €405M (September 2022, Instagram children’s data).
- Amazon — €746M (July 2021, Luxembourg).
- Meta — €390M (January 2023, behavioral advertising lawful basis).
- Meta — €265M (November 2022, Facebook data scraping).
- WhatsApp — €225M (September 2021).
- Google LLC — €50M (January 2019, CNIL).
- Clearview AI — €20M each (Italy, France, Greece, UK 2021-2024).
The one-stop shop mechanism (Arts 56, 60) designates the lead supervisory authority based on main establishment — typically the Irish DPC for Meta, Google, X/Twitter, TikTok, Apple, Microsoft. Heavy criticism of Irish DPC enforcement pace; EDPB binding decisions under Art 65 forced higher fines in many cases.
The European Data Protection Board (EDPB) coordinates supervisory authorities (Arts 68-76) and issues guidelines, opinions, binding decisions on disputes between SAs.
3.9 GDPR-Adjacent Regulations
The EU’s broader digital regulatory wave intersects with GDPR:
- ePrivacy Directive 2002/58 + national implementations (cookies, electronic communications) — the EC’s long-promised ePrivacy Regulation remains unfinalized through 2026.
- NIS2 Directive (Regulation EU 2022/2555) — cybersecurity requirements for essential and important entities; transposition deadline October 2024.
- DORA (Digital Operational Resilience Act, Regulation EU 2022/2554) — ICT risk management for financial entities; effective January 2025.
- Data Act (Regulation EU 2023/2854) — connected-device data sharing, B2B and B2G; effective September 2025.
- Data Governance Act (Regulation EU 2022/868) — public sector data reuse, data intermediation services.
- AI Act (Regulation EU 2024/1689) — see Section 6 below.
4. UK GDPR — Post-Brexit Divergence
The UK left the EU on January 31, 2020. The Data Protection Act 2018 (UK) implemented the original GDPR; post-Brexit the UK GDPR is the retained EU regulation as modified by UK statutory instrument (Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019).
The EU Commission adopted an adequacy decision for the UK on June 28, 2021 (Decision 2021/1772), permitting transfers from EU to UK under standard rules. The adequacy decision was subject to a four-year sunset and was renewed on December 17, 2024 for another four years (subject to ongoing review of UK divergence).
UK regulatory landscape post-2024:
- Information Commissioner’s Office (ICO) — UK supervisory authority. Enforcement actions: Clearview AI £7.5M (May 2022, set aside by First-tier Tribunal October 2023 on jurisdictional grounds, ICO appeal pending); British Airways £20M (originally £183M proposed, 2020); Marriott £18.4M (originally £99M, 2020); TikTok £12.7M (April 2023); ICO/CMA joint guidance on AI 2024.
- Data Protection and Digital Information Bill — proposed by Conservative government 2022-2024, intended to streamline UK GDPR; failed at second-reading dissolution in May 2024 general election. The Labour government’s Data (Use and Access) Bill introduced October 2024 takes a narrower deregulatory approach focused on data sharing for research and public services; expected royal assent 2026.
UK key divergence points from EU GDPR (most still under consultation):
- Treatment of “scientific research” exception (broadened).
- Cookie/PEC requirements (potentially eased for low-risk cookies).
- AI processing under Article 22 (UK ICO guidance more permissive).
- DPO threshold modifications.
- Data subject access request limitations.
The UK ICO and CMA published a joint statement May 2023 on competition and consumer protection in foundation AI models.
5. Biometric and Health-Tech Laws
5.1 Illinois BIPA — the Largest US Biometric Statute
Illinois Biometric Information Privacy Act (740 ILCS 14, enacted October 2008). Requires:
- Written notice of collection, purpose, and length of retention.
- Written consent before collecting biometric identifiers (retina/iris scan, fingerprint, voiceprint, scan of hand or face geometry) or “biometric information” (information based on biometric identifiers used to identify).
- Written retention/destruction policy.
- Prohibition on sale, lease, or trade.
- Reasonable care in storage.
Private right of action — 5,000 per intentional or reckless violation. Plus attorneys’ fees.
BIPA litigation exploded post-Rosenbach v Six Flags Entertainment Corp, 129 N.E.3d 1197 (Ill 2019) — no actual harm required; bare statutory violation creates standing.
Notable settlements:
- Facebook / Meta — $650M (2021, photo tagging).
- TikTok — $92M (2021).
- Google — $100M (2022, Google Photos face grouping).
- White Castle — would have been $17B+ (per Cothron v White Castle, 216 N.E.3d 918 (Ill 2023) — held each scan is a separate violation; settled at undisclosed amount post-decision).
- Snapchat — $35M (2022).
- Clearview AI — settled federal MDL May 2022 — equitable relief plus class equity allocation.
Illinois amended BIPA in August 2024 (Public Act 103-769, effective August 2024) — overruled Cothron’s “per-scan” interpretation: a single accrual of liability per type of violation per individual, regardless of scan count. Substantially reduced exposure prospectively; preserved per-scan rules for pre-amendment conduct.
5.2 Texas CUBI and Other State Biometric Laws
- Texas CUBI (Capture or Use of Biometric Identifier, Tex. Bus. & Com. Code § 503.001) — similar to BIPA but no private right of action; AG enforcement only. Texas v Meta (July 2024 settlement) — $1.4B (BIPA-equivalent settlement for photo tagging).
- Washington Biometric Identifier Act 2017 — limited; preempted certain uses.
- Colorado, Connecticut, Virginia, etc. state comprehensive laws — treat biometric data as “sensitive personal information.”
5.3 Washington My Health My Data Act (MHMDA)
Washington Revised Code Chapter 19.373, enacted April 2023, effective March 31, 2024 (large entities) and June 30, 2024 (small). The most expansive state health-privacy law.
Scope: “consumer health data” broadly defined to cover any personal data identifying past, present, or future physical or mental health status, including any data that could reasonably be associated with such status (precise geolocation near a healthcare facility; biometric identifiers; gender-affirming care; reproductive/sexual health; processing of body measurements).
Requirements:
- Affirmative consent before collection (not opt-out).
- Separate consent for sharing.
- Confirmation of consent — must obtain again after specified period.
- Sale — separate authorization required.
- Right to withdraw consent; right to delete.
- Geofencing prohibition — cannot create geofences around healthcare facilities for tracking/advertising/notifications.
Enforcement: Washington AG + private right of action under Washington Consumer Protection Act.
Litigation: a wave of class actions filed Q1 2025 against websites using analytics/pixels in healthcare-adjacent contexts. Several large-pharmacy chains, hospital systems, and telehealth providers sued.
Similar laws: Connecticut MHMDA (effective July 2024), Nevada CCPA-style for health data (effective March 2024). Other states considering.
6. The AI Privacy Layer
6.1 EU AI Act
Regulation EU 2024/1689 (the “AI Act”), in force August 2024 with phased applicability:
- February 2025 — prohibited practices and AI literacy requirements.
- August 2025 — general-purpose AI model rules.
- August 2026 — high-risk AI system requirements (most provisions).
- August 2027 — high-risk AI systems already on market.
Risk-tiered framework:
- Prohibited practices (Art 5) — social scoring by public authorities; emotion recognition in workplace/education (with limited safety exceptions); biometric categorization based on sensitive attributes; untargeted scraping of facial images for facial recognition databases; real-time remote biometric identification in publicly accessible spaces (with narrow law enforcement exceptions).
- High-risk AI systems (Art 6, Annex III) — biometric identification; critical infrastructure; education; employment; access to essential public/private services; law enforcement; migration; administration of justice. Conformity assessment, risk management, data governance, transparency, human oversight, accuracy/robustness/cybersecurity requirements.
- Limited-risk AI — transparency requirements (e.g., chatbots must disclose AI nature; deepfakes labeled).
- Minimal-risk AI — no specific obligations.
General-purpose AI models (Art 51) — transparency obligations; technical documentation; copyright compliance; summary of training content. Models with “systemic risk” (>10^25 FLOPs training compute) — additional model evaluation, adversarial testing, incident reporting, cybersecurity.
Fines: up to €35M or 7% of worldwide annual turnover (prohibited practices); up to €15M or 3% (most other violations); €7.5M or 1% (incorrect information to authorities).
Implementation: AI Office within European Commission; national competent authorities in Member States; European Artificial Intelligence Board.
6.2 Colorado AI Act
Colorado Artificial Intelligence Act (SB 24-205, signed May 17, 2024, effective February 1, 2026). The first US comprehensive AI statute.
Scope: “high-risk artificial intelligence system” — system that, when deployed, makes or is a substantial factor in making a “consequential decision” (education, employment, financial/lending, government services, healthcare, housing, insurance, legal services).
Requirements:
- Developers — disclose to deployers; document harms; reasonable care to protect from algorithmic discrimination.
- Deployers — implement risk management policy; complete impact assessment; notify consumers; right to correct/appeal/opt-out; report to AG.
Enforcement: Colorado AG (exclusive). Discrimination claims rebuttable presumption framework.
Governor Polis raised concerns at signing and committed to revisit before February 2026 effective date. Multi-stakeholder review process underway 2024-2025.
6.3 NYC Local Law 144 (AEDT)
NYC Automated Employment Decision Tools law (Local Law 144 of 2021, effective July 5, 2023). First US AI-employment regulation.
Requires:
- Annual independent bias audit of AEDT used in employment decisions in NYC.
- Public posting of audit results summary.
- Notice to job candidates 10 days before use.
- Notice of alternative procedure or accommodation.
Enforcement: NYC Department of Consumer and Worker Protection. Civil penalties up to 1,500/day for subsequent.
Implementation has been measured; few public bias audits as of 2024-2025. Enforcement build-up underway.
6.4 Other State AI Initiatives
- California SB 1047 (Safe and Secure Innovation for Frontier AI Models) — vetoed by Governor Newsom September 2024. Would have required developers of frontier models (>10^26 FLOPs or >$100M training cost) to implement safety protocols, kill switches, and shut-down capabilities.
- California SB 942 (CAIPA — AI Provenance Act) — signed September 2024 — requires AI-generated content labeling.
- California AB 2013 (AI training data transparency) — signed September 2024.
- California SB 1120 (insurance AI) — signed September 2024 — restricts insurance AI from making sole adverse coverage decisions.
- Tennessee ELVIS Act (March 2024) — first state law protecting voice/likeness from AI mimicry.
- Utah AI Policy Act (March 2024).
- Multiple states’ AI election/deepfake laws — Texas, Michigan, Minnesota, Washington, others.
6.5 Federal AI Policy
- AI Bill of Rights (Biden OSTP, October 2022) — non-binding framework.
- Executive Order 14110 (Biden, October 30, 2023) — comprehensive AI executive order; safety testing for dual-use foundation models; NIST AI Risk Management Framework; OPM AI workforce.
- Executive Order 14110 rescinded by President Trump January 23, 2025.
- Executive Order 14179 (Trump, January 23, 2025) — “Removing Barriers to American Leadership in Artificial Intelligence” — directs review and rescission of Biden-era AI rules.
- NIST AI RMF (January 2023, voluntary).
- FTC Section 5 — used against AI products for deceptive claims (Rite Aid 2023 facial recognition; DoNotPay 2024 settled).
7. Federal Privacy Legislation Status
A comprehensive federal privacy law has been proposed and revised across multiple congressional sessions:
- American Privacy Rights Act (APRA) — bipartisan H.R. 8818, introduced April 2024 by Cantwell + McMorris Rodgers. Modified COPPA, established private right of action with specific damages, FTC enforcement. Stalled in House Energy & Commerce in July 2024 after Republican members withdrew support over scope of preemption + private right of action.
- ADPPA (American Data Privacy and Protection Act) — H.R. 8152, the 2022 predecessor. Reached House E&C markup but stalled at the floor.
- Several sector-specific bills through 2024-2025 — Kids Online Safety Act (KOSA, Senate passage July 2024, stalled in House through 2024); COPPA 2.0; The Privacy Act for Children.
No comprehensive federal law as of mid-2026; state law landscape continues to fragment.
8. Sectoral Preemption Analysis
When a comprehensive state privacy law (e.g., CCPA) applies to a financial institution also subject to GLBA, which controls?
State comprehensive laws typically include sectoral carve-outs:
- GLBA-covered data — exempted in Virginia, Colorado, Connecticut, Utah, etc. California originally exempted GLBA-regulated data; carved back somewhat in CCPA/CPRA — the GLBA exemption is for “personal information collected, processed, sold, or disclosed pursuant to the GLBA” only; non-GLBA personal information remains subject to CCPA even at GLBA-covered institutions.
- HIPAA-covered data — generally exempted at the entity-and-data level (e.g., a hospital’s HIPAA-covered PHI is exempt from CCPA, but the hospital’s marketing data is not).
- FCRA-regulated data — generally exempted.
- GLBA-FCRA-HIPAA “entity-level” exemptions in Virginia, Utah and others exempt the entire regulated entity (not just the regulated data); California is data-level.
The sectoral interplay produces compliance friction — a single national bank holding company must operate parallel CCPA-only programs for non-GLBA data, GLBA Safeguards Rule programs for GLBA-covered data, HIPAA programs for any group health plan PHI, FCRA programs for any consumer-reporting data, plus state-level overlays.
The CFPB’s 1033 rule (October 2024) imposes additional data-portability obligations on financial institutions that overlap with CCPA portability rights.
9. Federal Agency Privacy Statutes
- Privacy Act of 1974 (5 USC § 552a) — federal agency record systems. Notice (SORN — System of Records Notice), access and correction rights, accuracy requirements, restrictions on disclosure (12 statutory exceptions), accounting of disclosures. Computer Matching and Privacy Protection Act of 1988 amendments. Office of Management and Budget guidance (Circular A-130). Enforcement by injunctive relief and civil damages (actual damages or $1,000 statutory minimum).
- E-Government Act of 2002 — Privacy Impact Assessments (PIAs) for federal IT systems.
- Federal Information Security Modernization Act of 2014 (FISMA) — agency information security programs.
- FedRAMP — Federal Risk and Authorization Management Program — cloud security baseline for federal use; established 2011, expanded by FedRAMP Authorization Act 2022 (codifying program statutorily).
- StateRAMP — parallel state-level program established 2020 by consortium of state CIOs.
10. Where to Read More
- eu-competition-and-regulation — broader EU digital regulation context (DMA, DSA)
- constitutional-law — First and Fourth Amendment privacy doctrine
- employment-and-environmental-law — employer-employee privacy
- administrative-law — agency rulemaking and the FTC’s privacy authority
- securities-and-corporate-law — board oversight of cybersecurity/AI risk under Caremark
- finance-regulation — GLBA, CFPB authority
- sec-disclosure-regime — Item 1.05 cybersecurity disclosure
- fintech-architecture-deep — open banking, biometric authentication, AI in financial services
- treaties-and-regulatory-agencies — EU agency mapping