The evolving landscape of data privacy laws in the United States is signaling companies to reassess their data handling frameworks, especially with the imminent introduction of laws in eight additional states set to apply in 2025. Regardless of a company’s physical location, if certain business thresholds are met, adherence to these new regulations will be compulsory.
In states like California, New Hampshire, Texas, and Virginia, the formation of specialized privacy units has intensified the enforcement of these laws. Noteworthy actions include California Attorney General Rob Bonta’s settlement of multiple California Consumer Privacy Act violation cases. Companies such as Sephora and DoorDash have faced scrutiny, highlighting the increased vigilance expected from businesses.
In Texas, aggressive enforcement led by Attorney General Ken Paxton has been marked by substantial actions, including a $1.4 billion settlement with Meta. These efforts, coupled with multistate collaborations, underscore the growing regulatory challenges companies face.
The Federal Trade Commission (FTC) has broadened its privacy enforcement remit, particularly concerning health and location data. Actions against companies such as BetterHelp and Celebral illustrate the Commission’s focus on unauthorized data sharing. Moreover, the FTC’s amendment of the Health Breach Notification Rule extending to health apps, and its actions against Mobilewalla and others, signify an emphasized stance on location data as sensitive information.
Artificial Intelligence (AI) further complicates these regulatory challenges. Recognizing AI’s potential impact on privacy, the FTC has introduced mechanisms like “algorithmic disgorgement” to enforce data privacy compliance, requiring companies to delete AI models derived from unlawfully obtained data. Some state laws now offer consumers the right to opt-out of automated decision-making, addressing AI-related privacy issues.
Come 2025, states such as New Hampshire, Delaware, Iowa, and others will enforce new data privacy statutes. Although these laws largely echo existing statutes in terms of consumer protections, nuances exist. For instance, the Delaware Personal Data Privacy Act differs by not exempting nonprofits. Meanwhile, the Minnesota Consumer Data Privacy Act stands out by demanding opt-in consent for the sale of sensitive personal data and instituting a data tracking best practice not commonly required.
For companies navigating this intricate web of regulations, strategic compliance is key. Businesses must decide between adopting a uniform nationwide approach or customizing compliance per state. Regardless of the approach, a comprehensive reassessment of data processing practices, inclusive of AI interactions and privacy impact assessments, is critical. Consumer-facing policies should be evaluated and internal guidelines established, particularly for employee interactions with AI systems.
Consulting with adept privacy attorneys and developing a robust compliance program emerge as sensible strategies for businesses aiming to bolster consumer trust and avoid regulatory pitfalls. The increasing complexity of privacy regulations underscores the value of expert guidance and proactive adaptability in today’s data-driven landscape.