{"id":2660,"date":"2022-05-11T15:35:00","date_gmt":"2022-05-11T21:35:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=2660"},"modified":"2024-12-05T09:55:15","modified_gmt":"2024-12-05T15:55:15","slug":"simplifying-us-privacy-landscape","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/simplifying-us-privacy-landscape\/","title":{"rendered":"Simplifying the Complex US Privacy Landscape"},"content":{"rendered":"\t\t<section id=\"block_476e784bad613ec5cb7ca5b6df94c323\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">Articles<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>Simplifying the Complex US Privacy Landscape<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_4afde5c9a36b2d28ba28c6440eddfc36\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<h2>What\u2019s the current state of the US privacy landscape?<\/h2>\n<p>In the last 4 years, the US privacy landscape shifts every time a new state law regulating consumers\u2019 privacy gets enacted.<\/p>\n<p>During this period, the US went from the first privacy law focused on consumer rights, the\u00a0<i>California Consumer Privacy Act<\/i>\u00a0(CCPA), to 5 new consumer privacy state laws (<a href=\"https:\/\/info.trustarc.com\/Web-Resource-2020-01-13-Nymity-CCPAComplianceToolkit_LP.html\" target=\"_blank\" rel=\"noopener\">California<\/a>,\u00a0<a href=\"https:\/\/blog.trustarc.com\/2021\/03\/02\/virginia-consumer-data-protection-act\/\" target=\"_blank\" rel=\"noopener\">Virginia<\/a>,\u00a0<a href=\"https:\/\/info.trustarc.com\/Web-Resource-2021-07-09-ColoradoPrivacyActWP_LP.html\" target=\"_blank\" rel=\"noopener\">Colorado<\/a>,\u00a0<a href=\"https:\/\/trustarc.com\/resource-s\/the-ins-and-outs-of-the-utah-consumer-privacy-law\/\" target=\"_blank\" rel=\"noopener\">Utah<\/a>, and\u00a0<a href=\"https:\/\/blog.trustarc.com\/2022\/06\/30\/connecticut-personal-data-privacy-and-online-monitoring-act\/\" target=\"_blank\" rel=\"noopener\">Connecticut<\/a>).<\/p>\n<p>If consumer privacy laws follow the trend seen in the data breach notification or the insurance data security spaces, more states will jump on this bandwagon.<\/p>\n<p>Complying with these privacy laws \u2013 especially when needing to comply with several \u2013 takes incredible resources and effort.<\/p>\n<p><strong>But if you look at the big picture, there are common grounds and opportunities between these state laws.<\/strong><\/p>\n<p>Ideally, there would be a single federal law. Yet the lack of a federal privacy law results in some states with unique requirements.<\/p>\n<p>Despite their differences, the core principles are the same. That\u2019s where your focus needs to be to develop an efficient compliance strategy.<\/p>\n<p>Prioritize your efforts and address the most relevant nuances of the US privacy landscape in the following core areas.<\/p>\n<h2>Individual rights<\/h2>\n<p>Mostly all the current state privacy laws have regulated the right to access, deletion, correction, portability, and opt-out, minus Utah, which did not include the right of correction within their law.<\/p>\n<p>The CCPA modified by CPRA includes two additional rights, the right to know and the right to limit the use and disclosure of personal data.<\/p>\n<p>While the state laws have a general deadline of 45 days for responding to individual requests, opt-out requests, may need to be dealt with within 15 days in California and Connecticut.<\/p>\n<p>Opt-out requests may include from sales of data or targeted advertising, may need to be dealt with within 15 days in California\u00a0and Connecticut.<\/p>\n<h2>General obligations<\/h2>\n<p>Obligations such as information security, having agreements with processors, privacy notice requirements, purpose limitations, DPIA, and requirements around data minimization and processing sensitive data and\u00a0<a href=\"https:\/\/blog.trustarc.com\/2022\/06\/28\/california-childrens-privacy-protection-laws\/\" target=\"_blank\" rel=\"noopener\">data from children<\/a>, are present in most of the current state laws.<\/p>\n<p>Additionally, the CCPA has a record keeping obligation that is unique to this jurisdiction (at least 24 months) and shares the obligation to implement opt-out mechanisms (do-not-sell link or opt-out preference signal) with Colorado\u00a0and Connecticut.<\/p>\n<h2>State privacy law enforcement<\/h2>\n<p>The State Attorneys General are the government agencies in charge of enforcing the current consumer privacy laws, except for Colorado, where district attorneys have enforcement powers.<\/p>\n<p>There is no private right of action in most of the laws, besides\u00a0<a href=\"https:\/\/oag.ca.gov\/privacy\/ccpa\" target=\"_blank\" rel=\"noopener\">the CCPA, which includes a private right of action<\/a>\u00a0for matters related to security breaches.<\/p>\n<p>Additionally, all the current state laws have included a period to allow a business to cure any alleged violation before the AG initiates any enforcement actions.<\/p>\n<p>Colorado and Connecticut established a temporary\u00a0cure period of 60 days while Virginia and Utah established a permanent 30-day period.<\/p>\n<p>California is the only State that established a cure period exclusively for violations related to security breaches where individuals must provide businesses with 30 days to cure any violation before initiating actions to pursue statutory damages.<\/p>\n\t\t\t\t\t\t\t\t<div class=\"wide-img\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/US-Consumer-Privacy-Resource_infographic-1-scaled.jpg\" class=\"attachment-full size-full\" alt=\"\" srcset=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/US-Consumer-Privacy-Resource_infographic-1-scaled.jpg 2560w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/US-Consumer-Privacy-Resource_infographic-1-300x261.jpg 300w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/US-Consumer-Privacy-Resource_infographic-1-1024x892.jpg 1024w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/US-Consumer-Privacy-Resource_infographic-1-768x669.jpg 768w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/US-Consumer-Privacy-Resource_infographic-1-1536x1338.jpg 1536w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/US-Consumer-Privacy-Resource_infographic-1-2048x1784.jpg 2048w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/US-Consumer-Privacy-Resource_infographic-1-1440x1254.jpg 1440w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<p><i>This summary provides general information about applicable laws and does not constitute legal advice regarding specific facts or circumstances.<\/i><\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<ol>\n<li>CCPA Regs. \u00a7999.315(f)<\/li>\n<li>Public Act No. 22-15 \u2013 Connecticut Act Concerning Personal Data and Online Monitoring \u2013 S.6(a)(6)<\/li>\n<li>The California Attorney General must issue implementing regulations on risk assessments with respect to processing of personal information by July 1st, 2022 \u2013 see \u2013 S.21(15)(b).<\/li>\n<li>Cal. Code Regs. Tit. 11, \u00a7 999.317<\/li>\n<li>The Colorado Attorney General will adopt rules regarding a universal opt-out mechanism by July 1st, 2023.<\/li>\n<li>Colorado\u2019s cure period will be in force until January 1st, 2025 (See Colo. Rev. Stat. \u00a7 6-1-1311(d)) and Connecticut will be mandatory until December 31, 2024. From January 1st, 2025, the AG may provide business with a cure period taking into considerations established in the law (See Public Act No. 22-15\u00a711).<\/li>\n<\/ol>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/us-consumer-privacy-laws\/\" class=\"badge\">US Consumer Privacy Laws<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t","protected":false},"excerpt":{"rendered":"<p>What&#8217;s the Current State of the US Privacy Landscape? To develop an efficient compliance strategy, prioritize your efforts and address the most relevant nuances of the US privacy landscape in the following core areas.<\/p>\n","protected":false},"featured_media":1258,"template":"","topic-resource":[114],"type-resource":[6],"class_list":["post-2660","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-us-consumer-privacy-laws","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Simplifying the Complex US Privacy Landscape | TrustArc<\/title>\n<meta name=\"description\" content=\"What&#039;s the Current State of the US Privacy Landscape? To develop an efficient compliance strategy, prioritize your efforts and address the most relevant nuances of the US privacy landscape in the following core areas.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/simplifying-us-privacy-landscape\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/simplifying-us-privacy-landscape\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/simplifying-us-privacy-landscape\\\/\",\"name\":\"Simplifying the Complex US Privacy Landscape | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/simplifying-us-privacy-landscape\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/simplifying-us-privacy-landscape\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-rect-pink-test.png\",\"datePublished\":\"2022-05-11T21:35:00+00:00\",\"dateModified\":\"2024-12-05T15:55:15+00:00\",\"description\":\"What's the Current State of the US Privacy Landscape? To develop an efficient compliance strategy, prioritize your efforts and address the most relevant nuances of the US privacy landscape in the following core areas.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/simplifying-us-privacy-landscape\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/simplifying-us-privacy-landscape\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-rect-pink-test.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-rect-pink-test.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Simplifying the Complex US Privacy Landscape | TrustArc","description":"What's the Current State of the US Privacy Landscape? To develop an efficient compliance strategy, prioritize your efforts and address the most relevant nuances of the US privacy landscape in the following core areas.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/simplifying-us-privacy-landscape\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/simplifying-us-privacy-landscape\/","url":"https:\/\/trustarc.com\/resource\/simplifying-us-privacy-landscape\/","name":"Simplifying the Complex US Privacy Landscape | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/simplifying-us-privacy-landscape\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/simplifying-us-privacy-landscape\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-rect-pink-test.png","datePublished":"2022-05-11T21:35:00+00:00","dateModified":"2024-12-05T15:55:15+00:00","description":"What's the Current State of the US Privacy Landscape? To develop an efficient compliance strategy, prioritize your efforts and address the most relevant nuances of the US privacy landscape in the following core areas.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/simplifying-us-privacy-landscape\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/simplifying-us-privacy-landscape\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-rect-pink-test.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-rect-pink-test.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/2660","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1258"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=2660"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=2660"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=2660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}