We use cookies on this website. By using this site, you agree that we may store and access cookies on your device Read More Got it!
logo
  • Home
  • Products
    • Secure Drive Wiping SoftwareSecurely Erase Data From HDDs & SSDs in PC, Mac & Server
    • Bulk Drive Erasure Over Network Erase Loose Drives, PC, Laptop & Servers Over A Network
    • Mobile Wiping & Diagnostics Software Erase & Diagnose iOS® & Android® Simultaneously
    • File Eraser SoftwarePermanently wipe files and folders, and erase traces of apps & Internet activity.
  • Solutions
    • Enterprise & SMBWipe hard drives, laptops, desktops, Mac® devices, mobile phones & rackmount storage.
    • Managed Service Provider & SIGlobally trusted data wiping & diagnostic solutions to augment your managed services competences
    • Government Attain Compliance by Securely Erasing Data on HDDs & SSDs in PC, Mac, Laptops, Servers & Mobile Devices.
    • ITAD & Refurbisher Bulk erase loose drives, laptops, desktops, Mac devices, rackmount storage & mobile devices with centralized control.
    • Individual & Home User Safeguard invasion of privacy at the time of disposing old PC, laptop & mobile phone
  • Resources
    • CertificationsBitRaser - Tested & certified by multiple International Bodies
    • Reports & Certficates Tamper proof erasure reports & certificates to help meet audit trails
    • Data Erasure StandardsGlobal erasure standards that help you comply to international laws & regulations
    • Technical Articles Series of articles to help understand data erasure & diagnostics
    • Product FactsheetExplore in-depth details of the features, benefits..
    • Deployment Get instructions on using BitRaser for wiping PC..
    • Case Studies Read Our Customer Case Studies Illustrating The Real-World Usage In Diverse Business Scenarios.
    • Frequently Asked Questions (FAQs) Our Top FAQs That Will Help You Get Answers To Your Questions.
    • Blog Gain Latest Insights Into Data Erasure, Data Protection, Privacy And Regulations.
  • Partners
  • Products

    CASE STUDIES

    The best way to know about our solution is to read our customer case studies illustrating the real-world usage in diverse business scenarios.

    Read All Case Studies

    • Secure Drive Wiping Software
      Securely Erase Data From HDDs & SSDs in PC, Mac & Server
    • Bulk Drive Erasure Over Network
      Erase Loose Drives, PC, Laptop & Servers Over A Network
    • Mobile Wiping & Diagnostics Software
      Erase & Diagnose iOS® & Android® Simultaneously
    • File Erasure Software
      Permanently Wipe Files & Folders, Erase Traces Of Apps & Internet Activity
  • Solutions

    BITRASER® DATA ERASURE SOFTWARE

    Efficient, Easy & Permanent Wiping Of Sensitive Data Across Storage Devices. Guaranteed Data Privacy.

    Learn More

    • Enterprise & SMB
      Wipe Hard Drives, Laptops, Desktops, Mac® Devices, Mobile Phones & Rackmount Storage.
    • Managed Service Provider & SI
      Globally Trusted Data Wiping & Diagnostic Solutions To Augment Your Managed Service Competences.
    • Government

      Attain Compliance by Securely Erasing Data on HDDs & SSDs in PC, Mac, Laptops, Servers & Mobile Devices.

    • ITAD & Refurbisher
      Bulk Erase Loose Drives, Laptops, Desktops, Mac Devices, Rackmount Storage & Mobile Devices.
    • Individual & Home User
      Safeguard Invasion Of Privacy At The Time Of Disposing Old PC, Laptop & Mobile Phone.
  • Resources
    • Product Certifications
      BitRaser - Tested & certified by multiple International Bodies
    • Sample Reports & Certificates
      Tamper proof erasure reports & certificates to help meet audit trails
    • Data Erasure Standards
      Global erasure standards that help you comply to international laws & regulations
    • Technical Articles
      Series of articles to help understand data erasure & diagnostics
    • Product Factsheets
      Explore in-depth details of the features, benefits and specifications of our variants.
    • Deployment
      Get Instructions On using BitRaser for wiping PC, Mac, hard drives, mobile devices & files.
    • Case Studies
      Read our customer case studies illustrating the real-world usage in diverse business scenarios.
    • Frequently Asked Questions (FAQs)
      Our Top FAQs That Will Help You Get Answers To Your Questions.
    • Blog
      Gain latest insights into data erasure, data protection, privacy and regulations.
  • Partners
  • +1-844-775-0101
  • Submit Enquiry

US Data Privacy Laws: Navigating The Maze

  • author image

    Written By Pravin Mehta linkdin

  • calender

    Updated on May 21, 2021

  • clock

    Min Reading 3 Min

The shaping of modern data privacy laws like GDPR and CCPA is attributed to the need for more robust governance of digital data across varied channels and scenarios. In the United States, there are hundreds of federal and state laws, including several proposed and enacted privacy bills, to protect individuals’ data privacy. The US data protection laws, spanning the nation’s 50 states and territories, govern the collection, storage, processing, and disposal of personally identifiable information (PII). They obligate organizations to comply with prevalent data privacy standards concerning the handling of personal information.

This article surveys the US data privacy legislative landscape, overviewing the major laws and regulations in different states to help businesses navigate the maze.

US Data Privacy Laws: An Overview

Notably, there is no single, predominant US federal privacy law to protect data privacy, but there are nearly 20 sector-specific laws that are focused on industries like finance, healthcare, telecom, etc. These sectoral laws, such as the US Privacy Act of 1974, HIPAA, COPPA (The Children's Online Privacy Protection Act ), GLBA, and SOX, etc., have specific provisions for handling different types of personal data. This data could include personal health information, credit report, children’s information, etc. In addition, the country has over 100 “State-Level” data privacy laws, including 25 privacy-focused laws in California alone. Some of these prominent US data protection laws include California Consumer Privacy Act (CCPA), New York SHIELD Act, New York Privacy Act, Nevada Privacy Law, Maine Privacy Law, etc.

At the federal level, the US Federal Trade Commission (FTC) oversees the enforcement of these data protection laws, but there is no overarching federal law to ensure compliance with privacy regulations in US. Therefore, a majority of data privacy regulation in the US is based on state-level laws. Due to conflicting or incompatible provisions in these laws, businesses might find it challenging to understand their obligations clearly. For instance, data breach notification is a standard provision in the US data privacy laws, but the definition of personal data and data breach varies. Also, data destruction or deletion standards may vary, a majority of data privacy laws compel organizations to destroy personal data on request.

Data Privacy Regulations in the US: 

The following are some of the prominent data privacy laws in the United States:

1. California Consumer Privacy Act (CCPA)

CCPA, enacted in 2020, regulates the collection of California residents’ personal data by companies. The California state privacy law, officially called Assembly Bill No. 375, empowers consumers in the state to exercise more control over their data.

Key provisions

  • Right to know: CCPA allows consumers to request companies for disclosure of their personal information collected, used, shared, or sold.
  • Right to delete: The law allows consumers to seek deletion of their personal information with a maximum notification time of 45 days.
  • Right to opt-out: The consumers can request companies to stop selling their personal information, i.e., opt-out of sales and marketing campaigns.
  • Right to non-discrimination: No company can discriminate against a consumer because they exercised their rights as per CCPA.

CCPA Applicability

CCPA applies to all for-profit companies that conduct business in California and meet any of the following conditions:

  • Gross annual revenue > $25 million.
  • Generate 50% or more of their annual revenue by selling consumer’s data.
  • Purchase, collect or sell the data of more than 50,000 households, devices, or consumers.

Penalty Imposed By CCPA

CCPA imposes a penalty of $7,500 per episode of intentional violation and $2,500 per inadvertent violation. So if 1000 Californians, complain of violation, then the organization might be looking at a total penalty of USD $7.5 million.

You may like to read our article on Deciphered - The Basics of CCPA.

2. New York Privacy Act (NYPA)

The New York Privacy Act is among the latest data privacy laws in the US, which will guarantee every New York resident the right to access, control, and erase their personal data collected from them. The NY State Senate Bill S5642 obligates companies that collect information of New York residents to disclose their methods of de-identifying personal data.

Key Provisions

  • Section 1102 of the New York Privacy Act mandates companies to acquire consumers’ expressed and documented consent before sharing or selling their personal data.
  • Section 1103 obligates companies to notify the consumers of their rights as per the law. It also obligates them to allow customers the right to opt-in or opt-out.
  • Section 1106 mandates that companies must maintain the required oversight to ensure compliance concerning de-identified data.
  • Right to Deletion: NYPA empowers New York residents to request deletion of their personal data, and the company must delete it without undue delay.

Applicability

The New York Privacy Act applies to legal entities, i.e., individuals or companies that conduct business in New York State or intentionally target products or services to New York state residents.

Penalty Implication

The law has provisions to impose civil penalties and damages based on the number of affected individuals, the extent of the violation, and the company's size and revenue. The act allows civil penalties of up to $5000 per violation. Therefore, for a data breach involving 1000 users, a penalty of USD $5 Million will be imposed.

3. Nevada Privacy Law

The Nevada privacy law, officially known as Nevada Revised Statutes Chapter 603A, governs the collection of personally Identifiable Information (PII) by websites. The law obligates businesses with websites that collect PII to have a privacy policy with explicit disclosures. The privacy law in Nevada defines the following information as PII in combination with a natural person’s first name or initial and last name:

  • Social security number
  • Driver’s license number
  • Account number
  • Health insurance identification number
  • Email address or other unique identifiers with password
  • Credit card or debit card number in combination with a password or access code

Key Provisions

  • NRS 603A.200 Destruction of certain records: The law mandates companies that maintain records with personal data or PII to take reasonable measures to ensure the destruction of records when they are no longer maintained.
  • NRS 603A.210 Security measure: The data collector, including government agency, higher education institution, corporation, financial institution, retail operator, or any other business entity, shall maintain reasonable measures to protect the customers’ personal data and PII.
  • NRS 603A.220 Disclosure of breach: The data collector shall disclose any security breach and notify Nevada residents whose unencrypted personal data is believed to have been compromised.

Applicability

The Nevada privacy law applies to all individuals and organizations that own and operate a website for business purpose or collect and maintain the personal data of consumers residing in Nevada.

Penalty

The Nevada privacy law has provisions to impose civil action, reparation, injunction, and a civil penalty of up to $5000 for each violation.

4. Maine Privacy Law

The Maine privacy law 2020, formally known as An Act to Protect the Privacy of Online Customer Information, focuses on protecting the personal information of customers in Maine who use or have used broadband Internet access service. It defines the following as customer personal information:

  • PII such as name, billing information, social security number, etc.
  • Web browsing and application usage history
  • Geolocation data
  • Financial and health information
  • Information on customer’s children
  • Device details
  • IP address

Key Provisions

  • Customer consent: The law prohibits broadband Internet access service providers from using, divulging, selling, or allowing access to personal data without the customer’s express consent.
  • Security of personal information: Maine privacy law obligates providers to take reasonable measures to safeguard customer personal data from unauthorized access.
  • Notification: The provider is responsible for notifying the customers of the provider’s obligations and customers’ rights through the point of sale medium and publicly accessible website.

Applicability

The Maine privacy law applies to all broadband Internet access service providers who serve customers physically located and billed in the state.

Penalty Implication

Maine Privacy Law does not explicitly mention the quantum of penalty for non-compliance. Presently, any non-compliance or enforcement of private rights of action will be adjudicated in courts of law.

5. Washington Biometric Privacy Law

The Washington Biometric Privacy Law, officially known as House Bill 1493 (“H.B.1493”), was enacted in 2017 to govern how individuals and non-government organizations collect, use, and store “biometric identifiers” of Washington citizens. The law defines biometric identifiers as the data generated by automatic measurements of a person’s biological traits like fingerprints, eye retinas, voiceprints, etc., which can identify that individual.

Key Provisions

  • Citizen’s consent: The law mandates businesses to obtain individuals’ explicit consent before collecting their biometric data. It obligates businesses to disclose how they use the biometric data and notify individuals of any changes in the use of their data.
  • Non-disclosure of biometric identifiers: Individuals’ biometric data cannot be sold, leased, or otherwise disclosed for a commercial purpose without express consent.

Applicability

The Washington Biometric Privacy Law applies to all individuals and non-government entities who collect biometric data for commercial purposes.

Penalty

Washington Biometric Privacy Law also is silent on penalties for non-compliance and does not include a private right of action. Although, the law allows for enforcement of private rights of action by the state's attorney general.

Read Complete Timeline
Close Timeline

Consumers’ “Right to Delete”: What US Data Privacy Laws Entail?

A majority of data privacy laws in the United States, including CCPA and Virginia Consumer Data Protection Act (VCDPA), have provisions that allow individuals to request deletion of their data. This “right to deletion” obligates businesses to delete the consumers’ personal information, with a few exceptions where companies can retain the information when they need to comply with federal regulations, cooperate with law enforcement agencies, defend legal claims, etc. Specific clauses and proposals, such as CCPA 999.313 (d) (2), in US privacy laws also mandate businesses to permanently erase the personal data on their system.

Briefly, this would mean businesses with a well-defined data erasure strategy would have a firm grip on their “data deletion” obligations. Nonetheless, navigating the maze of US data privacy laws is imperative for businesses to understand the “legislative patchwork” and play by the rules.

BitRaser is NIST Certified

See All Certifications

Related Articles

NIST 800-88 Clear Standard For Media Sanitization

Aug 02, 2021

How Permanent Media Sanitization Helps in CMMC Compliance?

July 18, 2022

What Is Degaussing: Pros, Cons and Alternative?

Dec 23, 2021


REACH US

Stellar Data Recovery Inc.

48 Bridge Street Metuchen, New Jersey 08840, United States

Call Us

+1-844-775-0101

Email Us

sales@bitraser.com

Follow Us

linkedin youtube

Useful Links

  • About Us
  • Legal Policy
  • Privacy Policy
  • Cookies Policy
  • Sitemap

NEWS AND EVENTS

  • News & Press Release
  • Events

PARTNERS

  • Our Partnership Models
  • Reseller
  • Distributor
  • OEM
  • ITAD

RESOURCES

  • Knowledge Series
  • Technical Articles
  • Knowledge Base
  • Blogs
  • Reports & Certificates
  • Download Brochure
  • Deployment
  • Product FactSheets
  • Case Studies
  • Our Clients
  • Residual Data Study

BitRaser® & Stellar Data Recovery are Registered Trademarks of Stellar Information Technology Pvt. Ltd. © Copyright 2023 Stellar Information Technology Pvt. Ltd. All Trademarks Acknowledged.

ISO Certified
NAID VENDOR
ERN VENDOR

Submit Enquiry

Submit Enquiry

Usage*:     Business   Personal
hbK1D

I understand that the above information is protected by Stellar's Privacy Policy.

ayTBM

I understand that the above information is protected by Stellar's Privacy Policy.

Modal body..
24 Internationally Recognized Erasure Standards
NIST Clear
NIST-ATA Purge
US Department of Defense, DoD 5220.22-M (3 passes)
US Department of Defense, DoD 5200.22-M (ECE) (7 passes)
US Department of Defense, DoD 5200.28-STD (7 passes)
Russian Standard – GOST-R-50739-95 (2 passes)
B.Schneier’s algorithm (7 passes)
German Standard VSITR (7 passes)
Peter Gutmann (35 passes)
US Army AR 380-19 (3 passes)
North Atlantic Treaty Organization-NATO Standard (7 passes)
US Air Force AFSSI 5020 (3 passes)
Pfitzner algorithm (33 passes)
Canadian RCMP TSSIT OPS-II (4 passes)
British HMG IS5 (3 passes)
Zeroes
Pseudo-random
Pseudo-random & Zeroes (2 passes)
Random Random Zero (6 passes)
British HMG IS5 Baseline standard 
NAVSO P-5239-26 (3 passes) 
NCSG-TG-025 (3 passes)  
5 Customized Algorithms & more

Listening...