The Growth of State-Specific Data Protection Laws in the U.S.

Road map of the United States

Several years ago, the EU collectively introduced GDPR (General Data Privacy Requirements), which went into effect on May 25, 2018, and covers all 27 member countries of the EU. 

Although not perfect, it advanced individual rights regarding data privacy. In some cases, individual countries have added additional requirements above GDPR, but it remains the gold standard. GDPR is generally considered the most robust privacy protection law in the world.

California Consumer Privacy Act

There is no serious traction for a national data protection law in the United States, but some forward-leaning states have taken action and put state-specific laws into place. It’s essential to understand who those laws impact (and who they don’t). For example, the CCPA (California Consumer Privacy Act) applies to for-profit businesses that do business in California and meet any of the following requirements:

  • Have annual gross revenue over $25,000,000;

  • Buy, receive, or sell the PII of 50,000 or more California residents, households, or devices;

  • Get 50% or more of their annual revenue from selling California residents’ PII.

Much like GDPR is constantly evolving, so is the CCPA. Think of it this way: data privacy requirements are a journey, not a destination. There are currently bills in the California legislature that, if passed, will amend the CCPA/CPRA, potentially impacting how organizations approach the law.

Virginia Consumer Data Protection Act

Similarly, the Virginia Consumer Data Protection Act (VCDPA) went into effect on January 1, 2023. The bill is only eight pages long, concise, and a better model than the overly complex CCPA for other states in the future.  

However, the law needs more clarity. It starts with applicability that covers companies that do business in the Commonwealth but also includes companies whose products target residents of Virginia, only without a definition of “targeted.” 

It includes other similar aspects, such as the consumer’s right to request their data be deleted (note I did not say redacted). Unlike other laws, it protects data that can be linked to a person but not to a device (covered in CCPA). 

Data protection laws in the U.S. will only continue to spread across states. The map above from the International Association of Privacy Professionals (IAPP) gives a good overview of where each state is in the process of passing its data protection laws.

As this is a blog post and not a white paper, our objective is to get you to realize both the complexity and evolving nature of data protection laws on a global basis and to try to point you to the right resources to help get your arms around the issues and do your best to stay one step in front of the bad guys.

 

The ETHIX360 blog brings you weekly updates on all things human resources and compliance.


MEET THE AUTHOR

J Rollins is the co-founder and CEO of ETHIX360. J is a well known leader and innovator who has served on senior leadership teams ranging in responsibility from Chief Revenue Officer, Chief Marketing Officer, SVP of Product Strategy and Chief Operating Officer.


ABOUT ETHIX360

At ETHIX360, our goal is simple: to provide an affordable, flexible, and comprehensive answer to employee communication, policy management, corporate training and case management on issues related to corporate ethics, code of conduct, fraud, bribery, and workplace violence.

RELATED BLOGS

J Rollins

J Rollins is the CEO of ETHIX360. J is a well-known leader and innovator who has served on senior leadership teams ranging in responsibility from Chief Revenue Officer, Chief Marketing Officer, SVP of Product Strategy, and Chief Operating Officer. J has consistently delivered on strategy and tactics with a thorough understanding of market requirements and competitive positioning to define a leadership position in emerging markets and technologies.

https://www.linkedin.com/in/jrollins/
Previous
Previous

What Does Working From Home Mean for Workplace Romance?

Next
Next

Anti-bullying Programs for Schools: How to Protect Children as a Parent