A Field Guide to Privacy Law for Companies Entering the U.S. Market
AGG Privacy & Cybersecurity partners Kevin Coy and Erin Doyle co-authored an article for Corporate Compliance Insights providing guidance for non-U.S. businesses navigating U.S. data privacy and security requirements as they enter or expand in the US market.
Many non‑U.S. businesses assume that compliance with the EU’s GDPR or a similar home‑country law will largely address U.S. requirements. However, “the U.S. regulatory picture is fragmented, highly sector- and state-specific and generates distinct regulatory and litigation risks that often are not addressed by compliance with home-country laws,” Kevin and Erin advised.
Kevin and Erin identified 12 key areas of data privacy and security diligence, contract terms and governance that compliance professionals, in-house counsel and business leaders should consider when planning U.S. operations, including:
- Sectoral federal privacy laws
- State privacy laws
- Marketing and communications privacy
- Website tracking and video or call recording
- Children’s privacy
- AI and automated decision-making technology laws
- Employee and applicant privacy
- Biometrics privacy laws
- Cybersecurity laws
- Data breach notification laws
- Government and bulk U.S. sensitive data transfer regulations
- Federal and state unfair or deceptive acts and practices law
They note that many of these laws carry private rights of action that fuel an active U.S. class-action litigation environment.
“Compliance with the GDPR or other non-U.S. data protection frameworks likely will support U.S. compliance efforts, but it is not determinative,” Kevin and Erin emphasized. “Even in instances where U.S. federal and state laws share the same privacy protection goals as non-U.S. privacy regulations, U.S. laws can differ significantly regarding issues like scope, legal bases, consent standards, notice design and content, automated‑decision rules and, crucially, private litigation exposure.”
They recommend that non-U.S. businesses entering or expanding in the U.S. market undertake a targeted privacy and data use assessment covering consumer, employee and business-to-business data flows, calibrating governance, contracting, technology, and insurance strategies to this distinct regulatory and litigation landscape.
To view the full article, please click here.
Related Services
Related Industries
- Kevin L. Coy
Partner
- Erin E. Doyle
Partner
