The U.S. Has No Federal Comprehensive Privacy Law
The United States regulates privacy sectorally (HIPAA, GLBA, COPPA) and as of this writing has no federal comprehensive privacy law, unlike most countries that follow a GDPR-style comprehensive model.
How this supports CIPP/US study
Use this lesson to compare state-law scope, rights, exceptions and enforcement before choosing an answer. Continue with the CIPP/US exam questions.
Most countries follow a comprehensive approach to privacy (often called data protection), and many are modeled on the EU's GDPR. The United States instead uses a sectoral approach, regulating privacy through laws aimed at specific sectors such as HIPAA (health), the GLBA (finance), and COPPA (children).
Despite decades of advocacy, no federal comprehensive privacy law exists as of this writing. One novel proposal under consideration would impose a data fiduciary duty on companies handling data, requiring them to act in good faith on behalf of consumers.
Because Congress has not enacted a comprehensive law, states stepped in. This is why a patchwork of state comprehensive laws exists - it is a direct response to federal inaction.
Key terms - quick answers
What is “Comprehensive privacy law”?
What is “Sectoral approach”?
What is “GDPR”?
What is “Data fiduciary duty”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.