Today, data is one of the most valuable assets a company can possess.
Organizations collect data for many reasons, including:
But this value also attracts cybercriminals. Major breaches can result in:
As a result, businesses must treat data protection as a core element of corporate governance rather than a purely technical issue.
Although the terms are often used together, data privacy and data security are not one and the same.
Data security focuses on protecting information from unauthorized access, theft, or misuse. One common framework used in cybersecurity is the ‘CIA Triad,’ which emphasizes:
Data privacy, by contrast, focuses on how organizations use the information they collect.
A company can technically protect data from hackers, but still violate privacy rules if it uses the information in ways that consumers did not expect or authorize.
This distinction has become increasingly important as businesses rely more heavily on analytics, digital platforms, and artificial intelligence.
Bruce de’Medici of Grey Oar describes the modern risk landscape as a three-part framework including cyber hygiene, data hygiene, and AI hygiene.
Each of these areas presents different risks:
These issues are closely interconnected. AI systems rely heavily on large datasets, and those datasets must be protected and used responsibly. A weakness in one area can easily expose vulnerabilities in another.
Artificial intelligence has dramatically expanded the scope of privacy and cybersecurity issues.
AI systems often process massive volumes of data and may make automated decisions affecting individuals. These systems can introduce risks such as:
Effective governance here requires understanding not only the law but also how AI systems are constructed. AI ‘model cards’ and similar documentation help organizations evaluate potential risks associated with AI tools. However, many businesses adopt new technologies without conducting meaningful risk analysis. This can expose organizations to legal and operational problems later.
An emerging issue with AI is the use of unauthorized AI tools by employees.
This phenomenon, often called shadow AI, occurs when employees use public tools like generative AI chatbots without corporate oversight.
Potential risks include:
To address this issue, organizations should implement AI acceptable-use policies that clearly define:
Many privacy regulations also require companies to manage the risks posed by third-party service providers.
Organizations often share personal data with vendors for activities such as:
Modern privacy laws typically require contracts that include provisions covering:
Unlike the European Union’s GDPR, the United States does not have a single nationwide privacy law.
Instead, regulation comes from multiple sources, including:
This layered structure makes compliance significantly more complex.
“We’re dealing with a framework where laws are constantly evolving, and companies need to assess the risks those laws pose and find ways to manage that risk,” notes Kamran Salour of Lewis Brisbois
Businesses operating nationally may need to comply with dozens of different laws simultaneously.
Several federal statutes regulate specific categories of personal information.
Gramm-Leach-Bliley Act (GLBA)
The GLBA applies to financial institutions offering services such as loans, investment advice, or insurance.
The law requires companies to:
Organizations must also maintain privacy policies explaining how personal data is used and shared.
Health Insurance Portability and Accountability Act (HIPAA)
HIPAA governs medical information and applies to healthcare providers, insurers, and clearinghouses that handle protected health information (PHI).
HIPAA includes two major rules:
HIPAA violations can lead to substantial penalties and enforcement actions by the US Department of Health and Human Services.
Federal Trade Commission Enforcement
The Federal Trade Commission (FTC) plays a major role in privacy regulation.
Under Section 5 of the FTC Act, the agency can bring cases against companies that engage in “unfair or deceptive” practices, including:
FTC enforcement often results in settlements requiring companies to implement long-term security and compliance programs.
In recent years, state legislatures have taken the lead in expanding privacy protections.
California’s Consumer Privacy Act (CCPA) was one of the first comprehensive laws, granting consumers rights such as access to personal data, deletion of personal data, and the ability to opt out of data sales. Since then, many states have enacted similar legislation.
Although these laws share common themes, each contains unique definitions, exemptions, and enforcement provisions. This variation makes compliance challenging for organizations that operate in multiple states.
Privacy laws are closely linked with cybersecurity obligations.
For example, New York’s cybersecurity regulations require financial institutions operating in the state to implement minimum security standards. Similarly, the New York SHIELD Act expanded data breach notification requirements and requires businesses holding personal information of New York residents to implement reasonable security safeguards. Across the United States, all states maintain their own breach notification laws.
When a breach occurs, companies may need to notify:
The requirements differ by jurisdiction, making incident response planning essential.
Strong privacy and cybersecurity programs rely on clear governance structures.
As Jeffrey Zeskind of HIPAA Consultants emphasizes, “We need to understand the users, the employees. Why are they using it? How are they using it? What are the guardrails for that use?”
Organizations often rely on international frameworks such as:
These frameworks help companies identify gaps in their security and privacy practices. Even businesses that do not pursue formal certification can use these standards as guidance when designing compliance programs.
The legal environment surrounding privacy, cybersecurity, and artificial intelligence is evolving rapidly, making this one of the biggest challenges in modern compliance.
Jake Bernstein of K&LGates suggests that legal advice on these issues must be grounded in technical understanding. This reality has changed how legal professionals approach privacy and cybersecurity.
Instead of working in isolation, lawyers increasingly collaborate with:
The goal is to create governance structures that align legal requirements with real-world operational practices.
Organizations that invest in strong governance programs, combining legal expertise, technological understanding, and operational discipline, will be best positioned to manage the risks. For businesses operating in today’s digital economy, proactive privacy and cybersecurity compliance are fundamental components of responsible corporate management.
To learn more about this topic, view Introduction to US Privacy and Data Security: Regulations and Requirements. The quoted remarks referenced in this article were made either during this webinar or shortly thereafter during post-webinar interviews with the panelists. Readers may also be interested to read other articles about cybersecurity.
This article was originally published on March 18, 2026.
©2026. DailyDACTM, LLC d/b/a/ Financial PoiseTM. This article is subject to the disclaimers found here.
Financial Poise helps trusted advisors (accountants, attorneys, business brokers, consultants, financial advisors, investment bankers, etc.) by providing a meritocracy-based platform on which to demonstrate their thought leadership. The thought leadership of these advisors is expressed in the form of educational articles, so we can provide our readers high-quality, unbiased education about investing, owning a business…