Privacy Law by Industry

Privacy Law by Industry

US privacy law is organized largely by sector. Health information is regulated by who holds it, financial information by whether the business is significantly engaged in financial activities, and student records by whether a school takes Department of Education funds. Each of the six guides below describes the federal and state rules that reach one sector, by the terms of the laws themselves, with a numbered list of the statutes, regulations and agency pages it relies on.

The Six Industry Guides

Coverage by Sector

Six sectors have a full guide. Three more have a news hub collecting the site’s reporting on enforcement, legislation and court decisions in that sector.

How Sector Rules Stack

Sector rules sit on top of the general privacy laws, not in place of them. HIPAA does not preempt more stringent state law, so a hospital can answer to HIPAA and to its state’s medical privacy statute at once. State comprehensive laws exempt GLBA in two incompatible ways: Virginia exempts the financial institution, while California exempts only the regulated data. A retailer’s loyalty program can fall under the CCPA, marketing consent rules and breach notification law at the same time.

Several federal laws cut across every sector, and each has its own guide:

  • CAN-SPAM: conduct rules for every commercial email message
  • TCPA: consent for marketing calls and texts
  • COPPA: online services directed to children under 13
  • FCRA: background checks and consumer reports
  • VPPA: disclosure of video viewing records
  • State breach notification laws: deadlines and regulator notice in 48 states

Rules for a particular state are on the state pages, and new enforcement actions, rules and court decisions are reported in the news section. The guides describe what the laws say; they do not assess how any law applies to a particular business. How we report.