US privacy law is organized largely by sector. Health information is regulated by who holds it, financial information by whether the business is significantly engaged in financial activities, and student records by whether a school takes Department of Education funds. Each of the six guides below describes the federal and state rules that reach one sector, by the terms of the laws themselves, with a numbered list of the statutes, regulations and agency pages it relies on.
HIPAA binds covered entities and their business associates, not health information as such. The guide works through 45 CFR Parts 160 and 164 and the state laws layered on top.
A software business can fall under several regimes at once, depending on whose data it handles and in what role. Section 5 of the FTC Act applies to any company making privacy or security representations.
GLBA’s definition of financial institution reaches well past banks, to mortgage brokers, auto dealers that arrange credit, tax preparers and debt collectors.
The CCPA reaches a business meeting any one of three alternative thresholds, so a retailer with heavy advertising integration can be covered well below the revenue figure.
FERPA (20 U.S.C. 1232g and 34 CFR Part 99) attaches to schools that receive Department of Education funds, which leaves many private K-12 schools outside it.
There is no single US employment privacy statute. Employers operate under a patchwork of federal statutes, state personnel records and social media laws, and state biometric and comprehensive privacy laws.
Six sectors have a full guide. Three more have a news hub collecting the site’s reporting on enforcement, legislation and court decisions in that sector.
Sector rules sit on top of the general privacy laws, not in place of them. HIPAA does not preempt more stringent state law, so a hospital can answer to HIPAA and to its state’s medical privacy statute at once. State comprehensive laws exempt GLBA in two incompatible ways: Virginia exempts the financial institution, while California exempts only the regulated data. A retailer’s loyalty program can fall under the CCPA, marketing consent rules and breach notification law at the same time.
Several federal laws cut across every sector, and each has its own guide:
Rules for a particular state are on the state pages, and new enforcement actions, rules and court decisions are reported in the news section. The guides describe what the laws say; they do not assess how any law applies to a particular business. How we report.