
Key Takeaways
Data Privacy Law
Data privacy laws are regulations that govern how organizations collect, store, use, and share personal information about individuals. They establish rights for data subjects — such as the right to access or delete their information — and corresponding obligations for businesses that handle that data. Non-compliance can result in significant financial penalties and reputational harm.
Most modern data privacy frameworks follow a principles-based approach, requiring businesses to demonstrate lawful basis for processing, data minimization, and accountability through documented policies and procedures.
Why Data Privacy Law Now Affects Nearly Every Business
The era when data privacy was primarily a concern for large technology companies has passed. Today, a small e-commerce retailer, a regional staffing firm, or a local healthcare practice may all be subject to binding legal obligations simply by collecting customer email addresses, processing employee records, or tracking website visitors.
Privacy legislation has expanded dramatically over the past decade. The European Union's General Data Protection Regulation (GDPR), which took effect in 2018, set a global standard for data protection. In the United States, California led with the California Consumer Privacy Act (CCPA), amended and strengthened by the California Privacy Rights Act (CPRA). As of 2024, more than a dozen US states — including Virginia, Colorado, Connecticut, Texas, and Florida — have enacted their own comprehensive privacy statutes, with more states actively considering legislation.
For business operators, the practical implication is clear: if your organization collects any form of personal information, you almost certainly have compliance obligations. Understanding the landscape is the essential first step. See our guide to regulatory compliance for new businesses for a broader map of the obligations businesses face from the start.
Core Frameworks: GDPR and US State Laws
While dozens of laws are now in play, two frameworks provide the most useful anchors for understanding the field.
GDPR (European Union)
GDPR applies to any organization — worldwide — that processes personal data of individuals in the EU or EEA. It requires businesses to have a documented lawful basis for each category of data they process, to honor individual rights (access, correction, deletion, portability), to report data breaches within 72 hours, and to maintain records of processing activities. Fines for serious violations can reach €20 million or 4% of global annual turnover.
CCPA / CPRA (California)
California's framework applies to for-profit businesses meeting defined thresholds. It grants California residents the right to know what data is collected, the right to delete it, and the right to opt out of the sale or sharing of their information. The CPRA, which took effect in 2023, introduced a dedicated enforcement agency — the California Privacy Protection Agency — and added new obligations around sensitive personal information.
US State Law Patchwork
Virginia's Consumer Data Protection Act, Colorado's Privacy Act, and similar statutes follow broadly comparable structures but differ in thresholds, exemptions, and consumer rights. Businesses operating nationally should conduct a state-by-state analysis rather than assuming a single policy covers all jurisdictions.
€20M
Maximum GDPR fine per violation
GDPR enforcement allows fines of up to €20 million or 4% of global annual turnover, whichever is greater, for the most serious violations.
$7,500
Maximum CCPA fine per intentional violation
California's privacy law authorizes the California Privacy Protection Agency to impose civil penalties of up to $7,500 per intentional violation.
13+
US states with comprehensive privacy laws
As of 2024, more than thirteen US states have enacted comprehensive consumer data privacy statutes, with additional states advancing legislation.
72 hours
GDPR breach notification window
Under GDPR, businesses must notify the relevant supervisory authority of a qualifying personal data breach within 72 hours of becoming aware of it.
What Businesses Are Actually Required to Do
Across major privacy frameworks, several obligations recur consistently.
- Privacy notice: Businesses must inform individuals — clearly and at the time of collection — about what data is gathered, why, and how it is used.
- Consent or lawful basis: Under GDPR, processing requires a documented legal basis. Under US state laws, certain uses (particularly the sale of data) require an opt-out mechanism, and some sensitive data categories require opt-in consent.
- Data subject rights: Businesses must have processes to receive and respond to requests from individuals seeking access to, correction of, or deletion of their data — typically within 30 to 45 days.
- Data security: Reasonable technical and organizational measures must be in place to protect personal data from unauthorized access or breach.
- Vendor management: When sharing personal data with third-party processors or service providers, businesses must have appropriate contractual protections in place.
These requirements intersect with other compliance areas. Employee data, for example, is personal data — meaning HR recordkeeping practices carry privacy implications. See our HR compliance reference guide for context on where employment and data obligations overlap.
Start With a Data Inventory Before Drafting Policies
Many businesses make the mistake of writing a privacy policy before fully understanding their own data practices. A data inventory — documenting what you collect, why, and where it goes — should come first. Policies built on an accurate inventory are both more compliant and easier to maintain as your business evolves.
Building a Practical Privacy Compliance Program
Compliance does not require a dedicated legal department, but it does require deliberate action. A workable foundation typically involves three phases.
- Data inventory: Map what personal data your business collects, where it originates, how it flows internally, who has access, and whether it is shared externally. This inventory is both a compliance tool and a governance asset.
- Policy and process development: Draft or update a privacy notice that accurately reflects your data practices. Establish internal procedures for handling data subject requests, managing third-party vendors, and responding to breaches.
- Ongoing review: Privacy obligations evolve as laws change and as your business grows. Build periodic reviews into your compliance calendar. Our annual compliance calendar reference outlines how businesses can structure recurring legal and regulatory reviews.
Privacy compliance intersects with technology procurement as well. Software tools that process customer or employee data impose their own considerations — a topic explored further in our overview of software licensing complexity for businesses.
This article provides general informational and educational content about data privacy law. It is not legal advice and should not be relied upon as a substitute for consultation with a qualified attorney familiar with your specific circumstances and jurisdiction.
