In the United States, there isn’t a singular, comprehensive legislation that regulates data privacy. Instead, there is a patchwork of ever-changing laws on both the state and federal levels that focus on data privacy.
If you’re looking to have a career in data privacy, understanding data privacy laws is critical to your career. When it comes to education in data privacy to prepare you for your career, Seattle University is the place to be. Our program and professors take into account the rapidly changing regulations and technology and prepare our students to become leaders in their fields.
Major Privacy Laws
While comprehensive legislation does not exist concerning data privacy in the U.S., there are a few key laws to know. These laws were enacted throughout the decades to protect specific consumer information, such as health and finances.
United States Privacy Act of 1974
The U.S. Privacy Act of 1974 is a piece of federal legislation. It was enacted to protect individual, personal information, and regulated government agencies. According to the United States Office of Special Counsel, “The Privacy Act provides protections to individuals in three primary ways. It provides individuals with:
- the right to request their records, subject to Privacy Act exemptions;
- the right to request a change to their records that are not accurate, relevant, timely, or complete; and
- the right to be protected against unwarranted invasion of their privacy resulting from the collection, maintenance, use, and disclosure of their personal information.”
As a result of this Act, federal agencies cannot disclose personal information without the consent of the individual unless it falls under twelve established exemptions.
Health Insurance Portability and Accountability Act of 1996
The Health Insurance Portability and Accountability Act, commonly known as HIPAA, is a federal law that protects sensitive medical and health information. It was created by the United States Department of Health and Human Services. It safeguards protected health information, also known as PHI, by covered entities. Covered entities are:
- Healthcare providers,
- Health insurers,
- Healthcare clearinghouses, and
- Business associates.
Any PHI cannot be disclosed without the individual’s consent.
Gramm-Leach-Bliley Act of 1999
The Gramm-Leach-Bliley Act, known as the GLBA, is an act that was passed by the federal government to protect financial information. According to the Federal Trade Commission (FTC), the GLBA, “requires financial institutions – companies that offer consumers financial products or services like loans, financial or investment advice, or insurance – to explain their information-sharing practices to their customers and to safeguard sensitive data.”
Children’s Online Privacy Protection Act of 1998
Congress enacted the final major piece of privacy legislation, which protects children. According to the FTC, the Children’s Online Privacy Protection Act (COPPA), “imposes certain requirements on operators of websites or online services directed to children under 13 years of age, and on operators of other websites or online services that have actual knowledge that they are collecting personal information online from a child under 13 years of age.”
State Laws
The above-mentioned acts are pieces of legislation enacted by the federal government. In addition to this, states have their own laws that govern privacy. The degree of protection varies. Some states, such as California with the California Privacy Rights Act (CPRA), have heavier protections for California residents, while others have no laws at all. States such as Virginia have the Consumer Data Protection Act, a new law that provides Virginia residents certain rights for personal data collected by businesses under conditions outlined in the law. Enforcement actions that protect consumers keep people safe and businesses from liability.
Keeping Track of the Patchwork at Seattle University
The world of privacy is ever-changing and complex, where personal data privacy and online monitoring are constantly at risk. If you choose to work in this industry, you must be aware of what laws govern your organization, both on the state and federal levels. Businesses face constant threats from malevolent forces trying to hack into systems and comprise data security.
Earning an MLS at Seattle University School of Law prepares you for this and more. In our online Master of Legal Studies in Compliance and Risk Management program, you’ll become immersed in this rapidly evolving regulatory space and learn to make vital decisions that protect your organization and its data. Learn more about its Cybersecurity Compliance concentration and how to apply today! Contact our admissions office today to get started.


