X

CBA Blog

Privacy and Data Protection: A Broad Overview of EU and U.S. Privacy Laws in the Digital and AI Era

Every time you click "accept" or "reject" on a cookie banner, you exercise a legal right that barely existed two decades ago: the right to control your personal information. That right traces back to the General Data Protection Regulation (GDPR), which set the global benchmark for modern privacy laws. This blog provides a brief overview of the GDPR and U.S. privacy frameworks and explores how the rapid growth of Artificial Intelligence (AI) is reshaping the future of privacy and data protection.

 

The European Union: How GDPR Came to Be?

The GDPR story did not begin with a single event, but with a slow build-up of concern over digital privacy, corporate data practices, and government surveillance. The then-existing law was drafted before smartphones, social media, or cloud computing, which was outdated and unequipped for the modern digital economy. The European Commission began drafting GDPR as early as 2010, well before Edward Snowden made headlines, recognizing that the EU needed a stronger, unified framework across all member states.[i]

Then came June 2013, when Edward Snowden leaked classified documents revealing that the U.S. government had been conducting mass surveillance on a staggering scale, secretly collecting the phone records, emails, and internet communications of millions of people worldwide, including European citizens. The revelations sent shockwaves through Europe and ignited a fierce debate over digital privacy and the role American tech companies played in facilitating government surveillance, injecting new urgency into the GDPR negotiations. After the Commission's 2012 draft, GDPR went through four years of heavily lobbied negotiation before a final text was agreed in 2016, followed by a two-year transition period before it took full effect on May 25, 2018, now widely regarded as the gold standard of data privacy legislation worldwide.[ii]

What Does GDPR Do?

At its core, GDPR rests on a simple idea that people should control their own data. Organizations must collect data only for a specific, legitimate purpose, gather only the minimum necessary, and keep it accurate and secure, with clear, informed consent required before collection. In return, individuals get a robust set of rights to access the data a company holds on them, correct inaccuracies, and even have their data deleted entirely under the "right to be forgotten," along with rights to data portability, objection, and restriction of processing.[iii]

Companies face significant obligations to comply. They must report data breaches within 72 hours of discovery, appoint a Data Protection Officer if they're large or handle sensitive data, and conduct formal impact assessments before high-risk processing. National Data Protection Authorities enforce the law, and fines can reach 20 million or 4% of global annual revenue, whichever is higher. GDPR enforcement has resulted in significant penalties against major technology companies, including Meta (€1.2 billion for unlawful EU-U.S. data transfers), [iv] Amazon (€746 million for GDPR violations related to behavioral advertising),[v] and Google (€50 million for inadequate transparency and consent practices), [vi] demonstrating regulators' willingness to impose substantial fines for serious privacy violations.

The United States: Sectoral and State-by-State Legislations

The American Privacy Rights Act (APRA) is an effort to create a single national privacy law (similar to GDRP) in the United States. Despite bipartisan support, Congress has struggled to agree on whether a federal law should preempt stronger state laws, whether individuals should have a private right of action, how strong the enforcement should be, and constitutional and political sticking points that have produced a fragmented framework rather than a comprehensive national statute.[vii] Another major obstacle to APRA has been opposition from the technology and digital advertising industries and their influence on legislators - arguing that strict privacy requirements would increase compliance costs, limit data needed for personalized services, advertising, AI, and deter innovation. Privacy advocates, however, contend that industry lobbying has delayed or weakened the legislation by opposing stronger enforcement, limiting consumers' ability to sue, and protecting data-driven business models.[viii]

Therefore, U.S. lacks a national unified privacy act, and it takes a sectoral and state-by-state approach to data privacy. Where the EU treats data protection as a fundamental right and can adopt uniform rules across member states, the U.S. regulates privacy through sector-specific federal laws and state legislation.

Sector Specific Federal Laws:

  • Health Insurance Portability and Accountability Act (HIPAA): HIPAA protects health information held by healthcare providers, insurance companies, and their business partners. It limits how patient data can be used or disclosed and gives individuals rights to access and correct their medical records.[ix]
  • Children's Online Privacy Protection Act (COPPA): COPPA protects the personal information of children under 13 online. Websites and apps directed at children must notify parents, obtain parental consent before collecting personal data, and maintain reasonable security safeguards.[x]
  • Gramm-Leach-Bliley Act (GLBA): GLBA applies to financial institutions such as banks, lenders, and insurance companies. It requires them to disclose their data-sharing practices, protect customers' financial information, and provide certain opt-out rights.[xi]

 

  • Family Educational Rights and Privacy Act (FERPA): FERPA protects student education records maintained by schools receiving federal funding. It gives parents and eligible students rights to review records, request corrections, and control most disclosures of student information.[xii]
  • Fair Credit Reporting Act (FCRA): FCRA regulates credit bureaus and consumer reporting agencies. It gives consumers rights to access their credit reports, dispute inaccurate information, and be notified when a report is used to make decisions about credit, employment, or insurance.[xiii]
  • Electronic Communications Privacy Act (ECPA): The Electronic Communications Privacy Act (ECPA) protects electronic communications such as emails, phone calls, text messages, and certain stored electronic data. It sets rules for when communications can be intercepted or accessed by government agencies and others.[xiv]
  • Video Privacy Protection Act (VPPA): The Video Privacy Protection Act (VPPA) protects information about an individual's video-viewing history. It generally prohibits video service providers from disclosing viewing data without the consumer's consent.[xv]
  • Telephone Consumer Protection Act (TCPA): The Telephone Consumer Protection Act (TCPA) regulates telemarketing calls, robocalls, text messages, and fax advertisements. It generally requires consumer consent for certain automated marketing communications and supports the National Do Not Call Registry.[xvi]
  • CAN-SPAM Act (commercial email): The CAN-SPAM Act regulates commercial email marketing. It requires businesses to provide accurate sender information, avoid deceptive subject lines, include an opt-out mechanism, and honor unsubscribe requests.[xvii]

 

 

State Privacy Laws:

Twenty states have enacted comprehensive consumer privacy laws, most modeled after the GDPR by providing rights to access, correct, delete, and opt out of the processing of personal information. California's CCPA/CPRA remains the most comprehensive and GDPR-like law and is the only one with a limited private right of action. California has led state privacy initiatives, with many other states following its approach. The states that have enacted comprehensive privacy laws are listed below in the order they were adopted.

  • California - California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
  • Virginia - Virginia Consumer Data Protection Act (VCDPA)
  • Colorado - Colorado Privacy Act (CPA)
  • Connecticut - Connecticut Data Privacy Act (CTDPA)
  • Utah - Utah Consumer Privacy Act (UCPA)
  • Iowa - Iowa Consumer Data Protection Act (ICDPA)
  • Indiana - Indiana Consumer Data Protection Act (INCDPA)
  • Tennessee - Tennessee Information Protection Act (TIPA)
  • Montana - Montana Consumer Data Privacy Act (MCDPA)
  • Oregon - Oregon Consumer Privacy Act (OCPA)
  • Texas - Texas Data Privacy and Security Act (TDPSA)
  • Delaware - Delaware Personal Data Privacy Act (DPDPA)
  • New Hampshire - New Hampshire Privacy Act (SB 255)
  • New Jersey - New Jersey Data Privacy Act (NJDPA)
  • Nebraska - Nebraska Data Privacy Act (NDPA)
  • Minnesota - Minnesota Consumer Data Privacy Act (MCDPA)
  • Maryland - Maryland Online Data Privacy Act (MODPA)
  • Kentucky - Kentucky Consumer Data Protection Act (KCDPA)
  • Rhode Island - Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
  • Florida - Florida Digital Bill of Rights (FDBR)
  • Oklahoma - Oklahoma Computer Data Privacy Act (OKCDPA)- has been enacted and will become effective in 2027

How the AI is Reshaping the Privacy Landscape

AI is reshaping the privacy and data protection landscape by dramatically increasing the volume, variety, and sensitivity of data that organizations collect, analyze, and reuse. Modern AI systems, particularly generative AI models, often rely on massive datasets that may contain personal information, raising questions about lawful data collection, transparency, consent, purpose limitation, and data minimization. Regulators are responding by extending privacy law to cover algorithmic accountability, automated decision-making, biometric surveillance, cross-border data transfers, and the governance of AI training data itself. For example, the European Data Protection Board has stated that GDPR principles remain central to the development and deployment of AI models, including requirements around lawful processing, anonymity, and legitimate interest assessments.

The EU AI Act, which operates alongside the GDPR, introduces a risk-based framework for AI systems and imposes additional obligations on providers of high-risk AI applications. In the United States, there is still no comprehensive federal AI law; instead, AI is governed through a combination of existing federal laws, state privacy statutes, consumer protection requirements, and emerging state AI regulations. As a result, privacy professionals are playing an increasingly important role in AI governance, helping organizations manage the legal, ethical, secure, and accountable adoption of AI system and models.

What is Next?

GDPR and the U.S.’s sectoral or state laws represent two different bets about how to protect personal data; while one built on a single, uniform right; the other is shaped by decades of political compromise, and AI does not resolve that divide. While Europe is discovering that even a comprehensive framework needs time and flexibility to keep pace with the technology it was written to govern; the U.S. is discovering that a patchwork built for the data economy of the 2010 is tasked to do double duty as an AI governance regime it was never designed for. Whichever model proves more durable, one thing is already clear: privacy law and AI governance are no longer separate conversations, and any organization treating them that way is already behind.

 

 

[i] https://eur-lex.europa.eu/EN/legal-content/summary/general-data-protection-regulation-gdpr.html

[ii] https://www.britannica.com/biography/Edward-Snowden

[iii] https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679

[iv] https://iapp.org/news/a/meta-fined-gdpr-record-1-2-billion-euros-in-data-transfer-case

[v] https://cnpd.public.lu/en/actualites/national/2025/03/amazon-decision.html

[vi] https://www.congress.gov/crs_external_products/LSB/PDF/LSB10264/LSB10264.6.pdf

[vii] chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://www.congress.gov/crs_external_products/R/PDF/R48667/R48667.1.pdf

[ix] https://www.hhs.gov/hipaa/for-professionals/privacy/index.html

[x] https://www.ftc.gov/legal-library/browse/statutes/childrens-online-privacy-protection-act

[xi] https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act

[xii] http://studentprivacy.ed.gov/ferpa

[xiii] https://www.consumerfinance.gov/compliance/compliance-resources/other-applicable-requirements/fair-credit-reporting-act/

[xiv] https://bja.ojp.gov/program/it/privacy-civil-liberties/authorities/statutes/1285

[xv] https://www.law.cornell.edu/uscode/text/18/2710

[xvi] https://www.fcc.gov/document/telephone-consumer-protection-act-1991

[xvii] https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business

 

 

Related