Rights
Sectoral federal rules plus comprehensive state statutes
There is no general federal privacy statute. Health data (HIPAA), financial data (GLBA) and children's data (COPPA) are regulated separately, while comprehensive obligations come from state law led by California.
Key rules
- The CCPA/CPRA gives California residents access, deletion, correction and opt-out-of-sale rights.
- The FTC polices unfair or deceptive privacy practices under Section 5 of the FTC Act.
- Breach notification is governed by all 50 states, with differing deadlines and thresholds.
Governing law
- California Consumer Privacy Act as amended by CPRA (Cal. Civ. Code § 1798.100)
- HIPAA Privacy Rule (45 C.F.R. Part 164)
Penalties and consequences
- Up to $7,500 per intentional CCPA violation
- FTC consent decrees with 20-year compliance monitoring
In practice
Compliance is usually built to the strictest applicable state standard and then applied nationally, because maintaining fifty separate data flows is more expensive than levelling up.