Financial Poise
US Data Privacy & Data Security

The US Data Privacy & Data Security Landscape

The Rise of Data as a Business Asset

Today, data is one of the most valuable assets a company can possess.

Organizations collect data for many reasons, including:

  • customer service improvements
  • marketing insights
  • product development
  • fraud prevention
  • regulatory compliance

But this value also attracts cybercriminals. Major breaches can result in:

  • direct financial losses
  • regulatory penalties
  • class action lawsuits
  • reputational damage

As a result, businesses must treat data protection as a core element of corporate governance rather than a purely technical issue.

Data Privacy vs. Data Security

Although the terms are often used together, data privacy and data security are not one and the same.

Data security focuses on protecting information from unauthorized access, theft, or misuse. One common framework used in cybersecurity is the ‘CIA Triad,’ which emphasizes:

  • Confidentiality: restricting access to authorized individuals
  • Integrity: ensuring information remains accurate and unaltered
  • Availability: making sure systems and data are accessible when needed

Data privacy, by contrast, focuses on how organizations use the information they collect.

A company can technically protect data from hackers, but still violate privacy rules if it uses the information in ways that consumers did not expect or authorize.

This distinction has become increasingly important as businesses rely more heavily on analytics, digital platforms, and artificial intelligence.

Understanding Modern Digital Risk

Bruce de’Medici of Grey Oar describes the modern risk landscape as a three-part framework including cyber hygiene, data hygiene, and AI hygiene.

Each of these areas presents different risks:

  • Cyber hygiene focuses on protecting systems from attacks and breaches.
  • Data hygiene addresses how organizations store, use, and share information.
  • AI hygiene concerns the governance and responsible deployment of artificial intelligence.

These issues are closely interconnected. AI systems rely heavily on large datasets, and those datasets must be protected and used responsibly. A weakness in one area can easily expose vulnerabilities in another.

Artificial Intelligence and the Next Wave of Compliance Challenges

Artificial intelligence has dramatically expanded the scope of privacy and cybersecurity issues.

AI systems often process massive volumes of data and may make automated decisions affecting individuals. These systems can introduce risks such as:

  • algorithmic bias
  • improper data use
  • intellectual property conflicts
  • regulatory violations

Effective governance here requires understanding not only the law but also how AI systems are constructed. AI ‘model cards’ and similar documentation help organizations evaluate potential risks associated with AI tools. However, many businesses adopt new technologies without conducting meaningful risk analysis. This can expose organizations to legal and operational problems later.

An emerging issue with AI is the use of unauthorized AI tools by employees.

This phenomenon, often called shadow AI, occurs when employees use public tools like generative AI chatbots without corporate oversight.

Potential risks include:

  • disclosure of confidential company information
  • exposure of trade secrets
  • sharing personal data with third-party systems
  • violations of privacy regulations

To address this issue, organizations should implement AI acceptable-use policies that clearly define:

  • which tools employees may use
  • what information may be shared
  • how AI-generated outputs must be reviewed

Vendor Risk and Third-Party Contracts

Many privacy regulations also require companies to manage the risks posed by third-party service providers.

Organizations often share personal data with vendors for activities such as:

  • cloud storage
  • payment processing
  • marketing analytics

Modern privacy laws typically require contracts that include provisions covering:

  • data processing instructions
  • confidentiality obligations
  • audit rights
  • deletion or return of data

Regulation in the United States

Unlike the European Union’s GDPR, the United States does not have a single nationwide privacy law.

Instead, regulation comes from multiple sources, including:

  • federal statutes
  • state consumer privacy laws
  • sector-specific regulations
  • enforcement actions by federal agencies

This layered structure makes compliance significantly more complex.

“We’re dealing with a framework where laws are constantly evolving, and companies need to assess the risks those laws pose and find ways to manage that risk,” notes Kamran Salour of Lewis Brisbois

Businesses operating nationally may need to comply with dozens of different laws simultaneously.

Key Federal Privacy Laws

Several federal statutes regulate specific categories of personal information.

Gramm-Leach-Bliley Act (GLBA)

The GLBA applies to financial institutions offering services such as loans, investment advice, or insurance.

The law requires companies to:

  • disclose their information-sharing practices
  • protect sensitive financial information
  • implement safeguards to secure customer data

Organizations must also maintain privacy policies explaining how personal data is used and shared.

Health Insurance Portability and Accountability Act (HIPAA)

HIPAA governs medical information and applies to healthcare providers, insurers, and clearinghouses that handle protected health information (PHI).

HIPAA includes two major rules:

  • the Privacy Rule, which regulates how health data may be used or disclosed
  • the Security Rule, which requires safeguards for electronic health information

HIPAA violations can lead to substantial penalties and enforcement actions by the US Department of Health and Human Services.

Federal Trade Commission Enforcement

The Federal Trade Commission (FTC) plays a major role in privacy regulation.

Under Section 5 of the FTC Act, the agency can bring cases against companies that engage in “unfair or deceptive” practices, including:

  • inadequate cybersecurity protections
  • misleading privacy policies
  • failure to honor data-use commitments

FTC enforcement often results in settlements requiring companies to implement long-term security and compliance programs.

State Privacy Laws

In recent years, state legislatures have taken the lead in expanding privacy protections.

California’s Consumer Privacy Act (CCPA) was one of the first comprehensive laws, granting consumers rights such as access to personal data, deletion of personal data, and the ability to opt out of data sales. Since then, many states have enacted similar legislation.

Although these laws share common themes, each contains unique definitions, exemptions, and enforcement provisions. This variation makes compliance challenging for organizations that operate in multiple states.

Cybersecurity Regulations and Breach Notification

Privacy laws are closely linked with cybersecurity obligations.

For example, New York’s cybersecurity regulations require financial institutions operating in the state to implement minimum security standards. Similarly, the New York SHIELD Act expanded data breach notification requirements and requires businesses holding personal information of New York residents to implement reasonable security safeguards. Across the United States, all states maintain their own breach notification laws.

When a breach occurs, companies may need to notify:

  • affected individuals
  • state regulators
  • federal authorities

The requirements differ by jurisdiction, making incident response planning essential.

Governance and Compliance Frameworks

Strong privacy and cybersecurity programs rely on clear governance structures.

As Jeffrey Zeskind of HIPAA Consultants emphasizes, “We need to understand the users, the employees. Why are they using it? How are they using it? What are the guardrails for that use?”

Organizations often rely on international frameworks such as:

These frameworks help companies identify gaps in their security and privacy practices. Even businesses that do not pursue formal certification can use these standards as guidance when designing compliance programs.

Looking Ahead

The legal environment surrounding privacy, cybersecurity, and artificial intelligence is evolving rapidly, making this one of the biggest challenges in modern compliance.

Jake Bernstein of K&LGates suggests that legal advice on these issues must be grounded in technical understanding. This reality has changed how legal professionals approach privacy and cybersecurity.

Instead of working in isolation, lawyers increasingly collaborate with:

  • information security teams
  • data scientists
  • engineers
  • risk managers

The goal is to create governance structures that align legal requirements with real-world operational practices.

Organizations that invest in strong governance programs, combining legal expertise, technological understanding, and operational discipline, will be best positioned to manage the risks. For businesses operating in today’s digital economy, proactive privacy and cybersecurity compliance are fundamental components of responsible corporate management.


To learn more about this topic, view Introduction to US Privacy and Data Security: Regulations and Requirements. The quoted remarks referenced in this article were made either during this webinar or shortly thereafter during post-webinar interviews with the panelists. Readers may also be interested to read other articles about cybersecurity.

This article was originally published on March 18, 2026.

©2026. DailyDACTM, LLC d/b/a/ Financial PoiseTM. This article is subject to the disclaimers found here.

 

 

Share this page:

About The Financial Poise Editors

Financial Poise helps trusted advisors (accountants, attorneys, business brokers, consultants, financial advisors, investment bankers, etc.) by providing a meritocracy-based platform on which to demonstrate their thought leadership. The thought leadership of these advisors is expressed in the form of educational articles, so we can provide our readers high-quality, unbiased education about investing, owning a business…

Read Full Bio »

Follow The Financial Poise Editors on: