• Skip to primary navigation
  • Skip to main content
  • Skip to footer
The Evolution of ESG RegulationThe Evolution of ESG RegulationThe Evolution of ESG Regulation

CUBE global

  • Products
        • RegPlatform product overviewOur enterprise product, providing regulatory intelligence for large, global financial institutions looking to tackle complex compliance.
        • RegAssure product overviewOur highly intuitive, seamless compliance product, that grows with your small or medium sized business.
        • CUBE's technology
  • Solutions
        • PrivacyGlobal governance for data privacy regulations, the world over
        • RecordsHolistic oversight of ever-growing regulations for records
        • CybersecurityAutomated workflows for up to date, relevant data on cyber
        • Technology riskEffective policies and controls to mitigate technology risk
        • Financial crime and AMLWatertight audit trails to show risk-based rationale
        • View all solutions
  • Resources
        • Resource hubLifting the lid on financial services, compliance, and regulation
        • Read

        • Case Studies
        • Blog posts
        • Reports
        • RegNews
        • Brochures
        • Find

        • Compliance Corner
        • Compliance confessions
        • ESG Conference
        • CUBE’s regulation game
        • Listen

        • Videos
        • Webinars
        • Podcasts
  • Partners
        • Advisory and consulting partnersEnhance your regulatory compliance offering with the entire suite of CUBE regulatory data.
        • Integration partnersCompliance is complex enough without over-complicated integration procedures.
        • Technology partnersAdd value to existing customer applications with a unified window into regulatory intelligence.
        • Partners overview
  • About us
        • About usThe story of who we are, how we got here and why we’re exceptionally proud of what we do
        • TeamThe visionaries and leaders powering CUBE’s success
        • NewsThe latest news from CUBE
        • CareersOur movement to transform regulatory data into regulatory intelligence
        • ContactWant to know more? Get in touch
  • Request a demo
Customer login
Home » Resources » 5 ways to stay compliant with US data privacy regulations

May 9, 2023 | Amanda Khatri

Estimated reading time: 7 minutes

5 ways to stay compliant with US data privacy regulations


As we embark on a digital future where apps, social media platforms, search engines and other websites can access and store our data, it is more important than ever to respect individual data rights. Since the General Data Protection Regulation (GDPR) came to fruition, approximately 120 countries have adopted regulations to ensure an adequate level of data protection.  

Following suit, at the start of 2023, two new privacy regulations came into effect in the United States (US). This includes:

  • The California Privacy Rights Act (CPRA) is an amendment to the California Privacy Act (CCPA).
  • The Virginia Consumer Data Protection Act (VCDPA).

Throughout this year, several new data obligations will come into force.

  • On 1 July 2023, the Colorado Privacy Act (CPA) and Connecticut Data Privacy Act (CTDPA) will be published.
  • On 31 December 2023, the Utah Consumer Privacy Act (UCPA) will be effective.
  • On 1 January 2025, the Iowa Consumer Data Protection Act (ICDPA) will be live.
  • Indiana has passed a data privacy law and is waiting for the Governor’s signature. Once signed, Indiana will be the seventh state to enact data privacy legislation.

Many more states are in the process of joining the bandwagon and will implement state-level, GDPR-inspired data privacy obligations. Currently, in addition to the seven states, there are 18 states actively working on comprehensive privacy regulations. This will affect how corporations collect, store and use personal data from individuals and aim to ensure increased transparency and control over personal data, which is essential as privacy concerns are on the rise.

How is the US data privacy landscape changing?

In the past, corporations have collected individual data without express permission, thus, the US took steps to regulate how this information is used to mitigate risk and harm. There are regulations on a federal level for different industries including the Graham-Leach-Bliley Act (GBLA) for financial services, the Health Insurance Portability and Accountability Act (HIPAA) for the medical sectors, Family Educational Rights and Privacy Act (FERPA) for education and Children’s Online Privacy Protection Act (COPPA) for children.

The European Union (EU) had a different stance on personal data. The GDPR established data privacy as a human right, where individuals can choose what happens with their information. Following the EU’s rights-based framework, the US’ new state laws in California, Colorado and so forth, also differ between the data controller and data processor. The processor is the company (e.g. usually third parties) that processes data on behalf of the controller, whereas the controller has the right to choose how and where their data is processed. For example, when a bank collects clients’ data when they open a bank account, the third party that stores, digitizes and catalogs the information on behalf of the bank, is the data processor.

The state-level data privacy laws in California, Colorado, Connecticut, Utah, and Virginia all comprise similarities to the GDPR and focus on individual rights to data. Each obligation is different and should be assessed carefully to ensure full compliance.

RegulationSummary
California Privacy Rights Act (CPRA)The CPRA established various individual rights inspired by the GDPR. It also created a state agency with obligations similar to the EU’s data protection agencies. If a firm is to be found to be non-compliant, it is liable for a penalty of $2,500 per violation or $7,500 for every intentional violation.
Virginia Consumer Data Privacy Act (VCDPA)Sharing similarities with California’s CPRA and additional obligations that reflect the GDPR, the VCDPA applies to those that do business in Virginia or cater products and services to those residing in Virginia. It provides customers with the right to access, correct, delete and opt out of personal data use.
Colorado Privacy Act (CPA)The CPA adapts terminology from the GDPR and shares similarities with the CPRA. Colorado was the following state after Virginia to introduce data privacy regulations. Comparable to Virginia’s law, the CPA applies to firms operating in Colorado or supplying products or services to those living in Colorado.  
Connecticut Data Privacy Act (CTDPA)Connecticut’s data privacy regulation is most similar to Colorado’s CPA, providing Connecticut residents with specific rights over their personal data and establishing certain obligations and privacy protection standards for data controllers processing data.
Utah Consumer Privacy Act (UCPA)Following in the footsteps of Colorado, Utah developed its data privacy law known as the UCPA on 24 March 2022. Compared to Virginia’s VCDPA and Colorado’s CPA, Utah’s UCPA provides fewer data privacy rights and contains provisions that are more beneficial to businesses.
Iowa Consumer Data Protection Act (ICDPA)As the sixth state to pass a comprehensive privacy law, it features similar elements from the Connecticut, Utah, Virginia, Colorado and California regulations. The main differences include Iowa’s definition of “personal data” and “sensitive data.”

A roadmap to data privacy compliance

Navigating and managing emerging data laws can be a daunting task, here are several steps firms can take to ensure compliance:

1. Understand the regulations

This is a no-brainer, corporations need to understand which regulations apply to them and which elements of the said obligation are relevant, in particular, which state-level regulations could be applicable to your business. Manually doing this can be tricky as it is easy to miss something. Using regulatory change management software is ideal for identifying relevant data privacy regulations and filtering out hundreds of pages to ensure quick, easy, and reliable compliance.

2. Ensure there is clarity around roles and responsibilities

Choose a nominated person responsible for looking after data privacy, this could be someone in IT such as the Chief Information Officer as well as compliance team member input. The UK is currently working on passing a GDPR bill that recommends a “senior responsible individual.” As part of this step, firms should consider an audit to identify gaps in privacy regulatory frameworks, think of clear steps on how to address these risks and who is in charge of each step. The audit should include a review of how data is currently collected, stored and used and whether these breach any data laws. Using regulatory intelligence can ensure that compliance gaps are identified in real time, providing compliance teams and nominated persons with ample time to address issues promptly.

3. Update existing privacy frameworks

Once the compliance team are aware of the gaps in data privacy regulations, they can move on to the next step of implementing these changes to current privacy policies. This ensures compliance and avoids hefty fines from regulators.

4. Implement continuous monitoring of emerging data privacy regulations

 As we enter further into the digital age, there will bound to be new or changing data privacy obligations at the state and federal levels. Therefore, compliance is not a one-time job or a box-ticking exercise. It is an ongoing process and requires constant monitoring to identify risks quickly. To manage data privacy laws effectively, regulatory change management software uses artificial intelligence, machine learning and horizon scanning abilities to anticipate emerging regulatory changes, ensuring your firm stays ahead of new state or federal-level privacy obligations.

5. Provide employee training and awareness

After the GDPR was implemented, firms provided data privacy training at work. This included logging off when one was not at their computer or not writing down any personal details of a customer as these could cause a GDPR breach. By providing training at US firms, employees will be more aware of their roles and responsibilities to adhere to privacy regulations and help the firm to also be compliant.

CUBE comment

The data landscape is constantly changing and evolving. With change comes more regulatory oversight and obligations. Continuous monitoring of data privacy developments is needed. It is great to see the US protecting consumer data, however, they do remain fragmented and at a state level. There have been various attempts at federal data privacy regulation, the American Data Privacy and Protection Act (ADPPA) has come the closest to being the most comprehensive. Currently, the ADPPA is still in the draft stage, but once approved it will impact all the state laws.

As more data privacy regulations develop, there will be greater oversight and scrutiny to ensure firms act correctly and abide by these laws. Compliance should not be an afterthought. It should be approached head on and with the help of CUBE’s regulatory change management solution, firms can be confident with their data privacy compliance frameworks.

Get in touch today to discover how CUBE can help your firm with data privacy regulation.


Speak to CUBE

Related resources
View all articles
Recent US and UK crypto regulation developments
Blogs

Taming the crypto wild west: the US and UK strengthen regulation

cryptocurrency and global financial inclusion
Blogs

How will embracing cryptocurrency bring global financial inclusion?

Cryptocurrency regulation
Blogs

Effective immediately: FINRA revises sanction guidelines and increases penalties for individuals

Bitcoin is a popular cryptocurrency
Blogs

Cryptocurrency and ESG: the contradictions and complexities


Want CUBE updates and latest industry news sent straight to your inbox?

Footer

Add CUBE logo here

  • Products
    • Partners
    • Solutions
  • Resource hub
    • Blogs
    • Reports
    • Brochures
    • Compliance Corner
    • Webinars
    • Podcasts
    • Videos
  • Behind CUBE
    • About us
    • Meet the team
    • Careers
    • News US
    • Contact us
  • The legal bits
    • Privacy policy
    • Cookie policy
    • Terms of use
    • Accessibility
Follow us:
  • LinkedIn
  • Twitter
  • YouTube

© 2023 CUBE Content Governance Global Limited

  • English
  • US