Every time you click "accept" or "reject" on a cookie banner, you exercise a legal right that barely existed two decades ago: the right to control your personal information. That right traces back to the General Data Protection Regulation (GDPR), which set the global benchmark for modern privacy laws. This blog provides a brief overview of the GDPR and U.S. privacy frameworks and explores how the rapid growth of Artificial Intelligence (AI) is reshaping the future of privacy and data protection.
The European Union: How GDPR Came to Be?
The GDPR story did not begin with a single event, but with a slow build-up of concern over digital privacy, corporate data practices, and government surveillance. The then-existing law was drafted before smartphones, social media, or cloud computing, which was outdated and unequipped for the modern digital economy. The European Commission began drafting GDPR as early as 2010, well before Edward Snowden made headlines, recognizing that the EU needed a stronger, unified framework across all member states.[i]
Then came June 2013, when Edward Snowden leaked classified documents revealing that the U.S. government had been conducting mass surveillance on a staggering scale, secretly collecting the phone records, emails, and internet communications of millions of people worldwide, including European citizens. The revelations sent shockwaves through Europe and ignited a fierce debate over digital privacy and the role American tech companies played in facilitating government surveillance, injecting new urgency into the GDPR negotiations. After the Commission's 2012 draft, GDPR went through four years of heavily lobbied negotiation before a final text was agreed in 2016, followed by a two-year transition period before it took full effect on May 25, 2018, now widely regarded as the gold standard of data privacy legislation worldwide.[ii]
What Does GDPR Do?
At its core, GDPR rests on a simple idea that people should control their own data. Organizations must collect data only for a specific, legitimate purpose, gather only the minimum necessary, and keep it accurate and secure, with clear, informed consent required before collection. In return, individuals get a robust set of rights to access the data a company holds on them, correct inaccuracies, and even have their data deleted entirely under the "right to be forgotten," along with rights to data portability, objection, and restriction of processing.[iii]
Companies face significant obligations to comply. They must report data breaches within 72 hours of discovery, appoint a Data Protection Officer if they're large or handle sensitive data, and conduct formal impact assessments before high-risk processing. National Data Protection Authorities enforce the law, and fines can reach €20 million or 4% of global annual revenue, whichever is higher. GDPR enforcement has resulted in significant penalties against major technology companies, including Meta (€1.2 billion for unlawful EU-U.S. data transfers), [iv] Amazon (€746 million for GDPR violations related to behavioral advertising),[v] and Google (€50 million for inadequate transparency and consent practices), [vi] demonstrating regulators' willingness to impose substantial fines for serious privacy violations.
The United States: Sectoral and State-by-State Legislations
The American Privacy Rights Act (APRA) is an effort to create a single national privacy law (similar to GDRP) in the United States. Despite bipartisan support, Congress has struggled to agree on whether a federal law should preempt stronger state laws, whether individuals should have a private right of action, how strong the enforcement should be, and constitutional and political sticking points that have produced a fragmented framework rather than a comprehensive national statute.[vii] Another major obstacle to APRA has been opposition from the technology and digital advertising industries and their influence on legislators - arguing that strict privacy requirements would increase compliance costs, limit data needed for personalized services, advertising, AI, and deter innovation. Privacy advocates, however, contend that industry lobbying has delayed or weakened the legislation by opposing stronger enforcement, limiting consumers' ability to sue, and protecting data-driven business models.[viii]
Sector Specific Federal Laws:
State Privacy Laws:
Twenty states have enacted comprehensive consumer privacy laws, most modeled after the GDPR by providing rights to access, correct, delete, and opt out of the processing of personal information. California's CCPA/CPRA remains the most comprehensive and GDPR-like law and is the only one with a limited private right of action. California has led state privacy initiatives, with many other states following its approach. The states that have enacted comprehensive privacy laws are listed below in the order they were adopted.
[i] https://eur-lex.europa.eu/EN/legal-content/summary/general-data-protection-regulation-gdpr.html
[ii] https://www.britannica.com/biography/Edward-Snowden
[iii] https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679
[iv] https://iapp.org/news/a/meta-fined-gdpr-record-1-2-billion-euros-in-data-transfer-case
[v] https://cnpd.public.lu/en/actualites/national/2025/03/amazon-decision.html
[vi] https://www.congress.gov/crs_external_products/LSB/PDF/LSB10264/LSB10264.6.pdf
[vii] chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://www.congress.gov/crs_external_products/R/PDF/R48667/R48667.1.pdf
[viii] https://issueone.org/press/report-how-big-techs-lobbying-blitzes-captured-state-privacy-laws/
[ix] https://www.hhs.gov/hipaa/for-professionals/privacy/index.html
[x] https://www.ftc.gov/legal-library/browse/statutes/childrens-online-privacy-protection-act
[xi] https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act
[xii] http://studentprivacy.ed.gov/ferpa
[xiii] https://www.consumerfinance.gov/compliance/compliance-resources/other-applicable-requirements/fair-credit-reporting-act/
[xiv] https://bja.ojp.gov/program/it/privacy-civil-liberties/authorities/statutes/1285
[xv] https://www.law.cornell.edu/uscode/text/18/2710
[xvi] https://www.fcc.gov/document/telephone-consumer-protection-act-1991
[xvii] https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business